From 6cf08622ed4a1aa2c471b410582344972f6f33cb Mon Sep 17 00:00:00 2001 From: Fang-Pen Lin Date: Thu, 30 Oct 2025 21:10:46 -0700 Subject: [PATCH] Add challenge --- .../bdd/features/pki/acme/challenge.feature | 20 ++++++++++++++++++ backend/bdd/features/steps/pki_acme.py | 21 +++++++++++++++++++ 2 files changed, 41 insertions(+) create mode 100644 backend/bdd/features/pki/acme/challenge.feature diff --git a/backend/bdd/features/pki/acme/challenge.feature b/backend/bdd/features/pki/acme/challenge.feature new file mode 100644 index 000000000..72573150c --- /dev/null +++ b/backend/bdd/features/pki/acme/challenge.feature @@ -0,0 +1,20 @@ +Feature: Challenge + + Scenario: Validate challenge + Given I have an ACME cert profile as "acme_profile" + When I have an ACME client connecting to {BASE_URL}/api/v1/pki/acme/profiles/{acme_profile.id}/directory +# # TODO: make it I have an account already instead? + Then I register a new ACME account with email fangpen@infisical.com and EAB key id {acme_profile.eab_kid} with secret {acme_profile.eab_secret} as acme_account + When I create certificate signing request as csr + Then I add names to certificate signing request csr + """ + { + "ORGANIZATION_NAME": "Infisical Inc", + "COMMON_NAME": "localhost" + } + """ + Then I create a RSA private key pair as cert_key + Then I sign the certificate signing request csr with private key cert_key and output it as csr_pem in PEM format + Then I submit the certificate signing request PEM csr_pem certificate order to the ACME server as order + Then I select challenge with type http-01 from order as challenge + diff --git a/backend/bdd/features/steps/pki_acme.py b/backend/bdd/features/steps/pki_acme.py index db9e8a28a..294b8cd1f 100644 --- a/backend/bdd/features/steps/pki_acme.py +++ b/backend/bdd/features/steps/pki_acme.py @@ -301,3 +301,24 @@ def step_impl(context: Context, var_path: str, expected: str): def step_impl(context: Context, var_path: str): value = eval_var(context, var_path) print(json.dumps(value.json(), indent=2)) + + +@then( + "I select challenge with type {challenge_type} from {var_path} as {challenge_var}" +) +def step_impl(context: Context, challenge_type: str, var_path: str, challenge_var: str): + order = eval_var(context, var_path) + if not isinstance(order, messages.OrderResource): + raise ValueError( + f"Expected OrderResource but got {(type(order),)!r} at {var_path!r}" + ) + auths = list(filter(lambda a: a.type == challenge_type, order.authorizations)) + if not auths: + raise ValueError( + f"Authorization type {challenge_type!r} not found in {var_path!r}" + ) + if len(auths) > 1: + raise ValueError( + f"More than one authorization for type {challenge_type!r} found in {var_path!r}" + ) + context.vars[challenge_var] = auths[0]