Class GemmaLegacyAwarePasswordEncoderTest

java.lang.Object
ubic.gemma.core.security.authentication.GemmaLegacyAwarePasswordEncoderTest

public class GemmaLegacyAwarePasswordEncoderTest extends Object
Verifies GemmaLegacyAwarePasswordEncoder against fixtures lifted from gemma-core/src/main/resources/sql/init-data.sql — these are the actual hashes shipped with Gemma so any production user row with the legacy SHA-1 format must still be recognized as legacy (and trigger upgradeEncoding). Legacy verification itself is the responsibility of LegacyAwareDaoAuthenticationProvider, which can see the username from UserDetails — see LegacyAwareDaoAuthenticationProviderTest.
  • Constructor Details

    • GemmaLegacyAwarePasswordEncoderTest

      public GemmaLegacyAwarePasswordEncoderTest()
  • Method Details

    • legacyHash_isRecognizedAsLegacyFormat

      @Test public void legacyHash_isRecognizedAsLegacyFormat()
    • legacyHash_isFlaggedForUpgrade

      @Test public void legacyHash_isFlaggedForUpgrade()
    • legacyHash_matchesIsFailClosed

      @Test public void legacyHash_matchesIsFailClosed()
    • encode_producesBcryptPrefixed_andMatchesBack

      @Test public void encode_producesBcryptPrefixed_andMatchesBack()
    • bcryptHash_isNotFlaggedForUpgrade

      @Test public void bcryptHash_isNotFlaggedForUpgrade()
    • encode_isNotDeterministic

      @Test public void encode_isNotDeterministic()
    • unknownFormat_failsClosed

      @Test public void unknownFormat_failsClosed()
    • bareBcrypt_matchesWithoutPrefix

      @Test public void bareBcrypt_matchesWithoutPrefix()
    • isBareBcrypt_acceptsKnownVariants

      @Test public void isBareBcrypt_acceptsKnownVariants()
    • isLegacySha1Hex_rejectsBcryptAndOther

      @Test public void isLegacySha1Hex_rejectsBcryptAndOther()
    • sha1HexUsernameSalt_helperMatchesFixtures

      @Test public void sha1HexUsernameSalt_helperMatchesFixtures()
    • constantTimeHexEquals_caseInsensitive

      @Test public void constantTimeHexEquals_caseInsensitive()