When someone sends a message to your PNI, your responses (from your ACI) must include a PNI signature, and the sealed sender certificate you use during this period should include your phone number. This confirms to the other user that your ACI is associated with your PNI. This commit adds the state tracking that and ensures that both TSOutgoingMessage and OWSUDManager check that state when building 1:1 messages and choosing certificates, respectively. Later commits will set and clear this flag as needed.
132 lines
7.1 KiB
Swift
132 lines
7.1 KiB
Swift
//
|
|
// Copyright (c) 2022 Open Whisper Systems. All rights reserved.
|
|
//
|
|
|
|
@testable import SignalServiceKit
|
|
import XCTest
|
|
|
|
class OWSIdentityManagerTests: SSKBaseTestSwift {
|
|
override func setUp() {
|
|
super.setUp()
|
|
tsAccountManager.registerForTests(withLocalNumber: "+13235551234", uuid: UUID())
|
|
}
|
|
|
|
func testNewEmptyKey() {
|
|
let newKey = Randomness.generateRandomBytes(32)
|
|
let address = SignalServiceAddress(phoneNumber: "+12223334444")
|
|
write { transaction in
|
|
_ = OWSAccountIdFinder.ensureAccountId(forAddress: address, transaction: transaction)
|
|
XCTAssert(identityManager.isTrustedIdentityKey(newKey,
|
|
address: address,
|
|
direction: .outgoing,
|
|
transaction: transaction))
|
|
XCTAssert(identityManager.isTrustedIdentityKey(newKey,
|
|
address: address,
|
|
direction: .incoming,
|
|
transaction: transaction))
|
|
}
|
|
}
|
|
|
|
func testAlreadyRegisteredKey() {
|
|
let newKey = Randomness.generateRandomBytes(32)
|
|
let address = SignalServiceAddress(phoneNumber: "+12223334444")
|
|
write { transaction in
|
|
identityManager.saveRemoteIdentity(newKey, address: address, transaction: transaction)
|
|
XCTAssert(identityManager.isTrustedIdentityKey(newKey,
|
|
address: address,
|
|
direction: .outgoing,
|
|
transaction: transaction))
|
|
XCTAssert(identityManager.isTrustedIdentityKey(newKey,
|
|
address: address,
|
|
direction: .incoming,
|
|
transaction: transaction))
|
|
}
|
|
}
|
|
|
|
func testChangedKey() {
|
|
let originalKey = Randomness.generateRandomBytes(32)
|
|
let address = SignalServiceAddress(phoneNumber: "+12223334444")
|
|
write { transaction in
|
|
identityManager.saveRemoteIdentity(originalKey, address: address, transaction: transaction)
|
|
|
|
XCTAssert(identityManager.isTrustedIdentityKey(originalKey,
|
|
address: address,
|
|
direction: .outgoing,
|
|
transaction: transaction))
|
|
XCTAssert(identityManager.isTrustedIdentityKey(originalKey,
|
|
address: address,
|
|
direction: .incoming,
|
|
transaction: transaction))
|
|
|
|
let otherKey = Randomness.generateRandomBytes(32)
|
|
|
|
XCTAssertFalse(identityManager.isTrustedIdentityKey(otherKey,
|
|
address: address,
|
|
direction: .outgoing,
|
|
transaction: transaction))
|
|
XCTAssert(identityManager.isTrustedIdentityKey(otherKey,
|
|
address: address,
|
|
direction: .incoming,
|
|
transaction: transaction))
|
|
}
|
|
}
|
|
|
|
func testIdentityKey() {
|
|
let newKey = identityManager.generateNewIdentityKey(for: .aci)
|
|
XCTAssertEqual(newKey.publicKey.count, 32)
|
|
|
|
let pniKey = identityManager.generateNewIdentityKey(for: .pni)
|
|
XCTAssertEqual(pniKey.publicKey.count, 32)
|
|
XCTAssertNotEqual(pniKey.privateKey, newKey.privateKey)
|
|
|
|
let fetchedKey = identityManager.identityKeyPair(for: .aci)!
|
|
XCTAssertEqual(newKey.privateKey, fetchedKey.privateKey)
|
|
|
|
let fetchedPniKey = identityManager.identityKeyPair(for: .pni)!
|
|
XCTAssertEqual(pniKey.privateKey, fetchedPniKey.privateKey)
|
|
}
|
|
|
|
func testShouldSharePhoneNumber() {
|
|
let aliceAddress = SignalServiceAddress(uuid: UUID(), phoneNumber: "+12223334444")
|
|
let bobAddress = SignalServiceAddress(uuid: UUID(), phoneNumber: "+17775556666")
|
|
|
|
write { transaction in
|
|
// {}
|
|
XCTAssertFalse(identityManager.shouldSharePhoneNumber(with: aliceAddress, transaction: transaction))
|
|
XCTAssertFalse(identityManager.shouldSharePhoneNumber(with: bobAddress, transaction: transaction))
|
|
|
|
// {Alice}
|
|
identityManager.setShouldSharePhoneNumber(with: aliceAddress, transaction: transaction)
|
|
XCTAssertTrue(identityManager.shouldSharePhoneNumber(with: aliceAddress, transaction: transaction))
|
|
XCTAssertFalse(identityManager.shouldSharePhoneNumber(with: bobAddress, transaction: transaction))
|
|
|
|
// {Alice}; redundant set shouldn't change anything.
|
|
identityManager.setShouldSharePhoneNumber(with: aliceAddress, transaction: transaction)
|
|
XCTAssertTrue(identityManager.shouldSharePhoneNumber(with: aliceAddress, transaction: transaction))
|
|
XCTAssertFalse(identityManager.shouldSharePhoneNumber(with: bobAddress, transaction: transaction))
|
|
|
|
// {Alice, Bob}
|
|
identityManager.setShouldSharePhoneNumber(with: bobAddress, transaction: transaction)
|
|
XCTAssertTrue(identityManager.shouldSharePhoneNumber(with: aliceAddress, transaction: transaction))
|
|
XCTAssertTrue(identityManager.shouldSharePhoneNumber(with: bobAddress, transaction: transaction))
|
|
|
|
// {Bob}
|
|
identityManager.clearShouldSharePhoneNumber(with: aliceAddress, transaction: transaction)
|
|
XCTAssertFalse(identityManager.shouldSharePhoneNumber(with: aliceAddress, transaction: transaction))
|
|
XCTAssertTrue(identityManager.shouldSharePhoneNumber(with: bobAddress, transaction: transaction))
|
|
|
|
// {Bob}; redundant clear shouldn't change anything.
|
|
identityManager.clearShouldSharePhoneNumber(with: aliceAddress, transaction: transaction)
|
|
XCTAssertFalse(identityManager.shouldSharePhoneNumber(with: aliceAddress, transaction: transaction))
|
|
XCTAssertTrue(identityManager.shouldSharePhoneNumber(with: bobAddress, transaction: transaction))
|
|
|
|
// {Alice, Bob}
|
|
identityManager.setShouldSharePhoneNumber(with: aliceAddress, transaction: transaction)
|
|
// {}
|
|
identityManager.clearShouldSharePhoneNumberForEveryone(transaction: transaction)
|
|
XCTAssertFalse(identityManager.shouldSharePhoneNumber(with: aliceAddress, transaction: transaction))
|
|
XCTAssertFalse(identityManager.shouldSharePhoneNumber(with: bobAddress, transaction: transaction))
|
|
}
|
|
}
|
|
}
|