From e370d16db27657c782486a8b94e7655339a88129 Mon Sep 17 00:00:00 2001 From: Fang-Pen Lin Date: Thu, 6 Nov 2025 20:39:56 -0800 Subject: [PATCH] Uncomment --- .../features/pki/acme/access-control.feature | 90 +++++++++---------- 1 file changed, 45 insertions(+), 45 deletions(-) diff --git a/backend/bdd/features/pki/acme/access-control.feature b/backend/bdd/features/pki/acme/access-control.feature index 2fd346b5b..ed3f85ccf 100644 --- a/backend/bdd/features/pki/acme/access-control.feature +++ b/backend/bdd/features/pki/acme/access-control.feature @@ -1,49 +1,49 @@ Feature: Access Control -# -# Scenario Outline: Access across resources for a different account -# Given I have an ACME cert profile as "acme_profile" -# When I have an ACME client connecting to {BASE_URL}/api/v1/pki/acme/profiles/{acme_profile.id}/directory -# Then I register a new ACME account with email fangpen@infisical.com and EAB key id "{acme_profile.eab_kid}" with secret "{acme_profile.eab_secret}" as acme_account0 -# Then I memorize acme_account0.uri with jq "capture("/(?[^/]+)$") | .id" as account0_id -# When I create certificate signing request as csr -# Then I add names to certificate signing request csr -# """ -# { -# "COMMON_NAME": "localhost" -# } -# """ -# Then I create a RSA private key pair as cert_key -# Then I sign the certificate signing request csr with private key cert_key and output it as csr_pem in PEM format -# Then I submit the certificate signing request PEM csr_pem certificate order to the ACME server as order -# And I put away current ACME client as client0 -# -# When I have an ACME client connecting to {BASE_URL}/api/v1/pki/acme/profiles/{acme_profile.id}/directory -# Then I register a new ACME account with email maidu@infisical.com and EAB key id "{acme_profile.eab_kid}" with secret "{acme_profile.eab_secret}" as acme_account1 -# Then I peak and memorize the next nonce as nonce -# Then I memorize with jq "" as -# When I send a raw ACME request to "" -# """ -# { -# "protected": { -# "alg": "RS256", -# "nonce": "{nonce}", -# "url": "", -# "kid": "{acme_account1.uri}" -# }, -# "payload": {} -# } -# """ -# Then the value response.status_code should be equal to 404 -# -# Examples: Endpoints -# | src_var | jq | dest_var | url -# | order | . | not_used | {BASE_URL}/api/v1/pki/acme/profiles/{acme_profile.id}/accounts/{account0_id}/orders | -# | order | . | not_used | {order.uri} | -# | order | . | not_used | {order.uri}/finalize | -# | order | . | not_used | {order.uri}/certificate | -# | order | .authorizations[0].uri | auth_uri | {auth_uri} | -# | order | .authorizations[0].body.challenges[0].url | challenge_uri | {challenge_uri} | -# + + Scenario Outline: Access across resources for a different account + Given I have an ACME cert profile as "acme_profile" + When I have an ACME client connecting to {BASE_URL}/api/v1/pki/acme/profiles/{acme_profile.id}/directory + Then I register a new ACME account with email fangpen@infisical.com and EAB key id "{acme_profile.eab_kid}" with secret "{acme_profile.eab_secret}" as acme_account0 + Then I memorize acme_account0.uri with jq "capture("/(?[^/]+)$") | .id" as account0_id + When I create certificate signing request as csr + Then I add names to certificate signing request csr + """ + { + "COMMON_NAME": "localhost" + } + """ + Then I create a RSA private key pair as cert_key + Then I sign the certificate signing request csr with private key cert_key and output it as csr_pem in PEM format + Then I submit the certificate signing request PEM csr_pem certificate order to the ACME server as order + And I put away current ACME client as client0 + + When I have an ACME client connecting to {BASE_URL}/api/v1/pki/acme/profiles/{acme_profile.id}/directory + Then I register a new ACME account with email maidu@infisical.com and EAB key id "{acme_profile.eab_kid}" with secret "{acme_profile.eab_secret}" as acme_account1 + Then I peak and memorize the next nonce as nonce + Then I memorize with jq "" as + When I send a raw ACME request to "" + """ + { + "protected": { + "alg": "RS256", + "nonce": "{nonce}", + "url": "", + "kid": "{acme_account1.uri}" + }, + "payload": {} + } + """ + Then the value response.status_code should be equal to 404 + + Examples: Endpoints + | src_var | jq | dest_var | url + | order | . | not_used | {BASE_URL}/api/v1/pki/acme/profiles/{acme_profile.id}/accounts/{account0_id}/orders | + | order | . | not_used | {order.uri} | + | order | . | not_used | {order.uri}/finalize | + | order | . | not_used | {order.uri}/certificate | + | order | .authorizations[0].uri | auth_uri | {auth_uri} | + | order | .authorizations[0].body.challenges[0].url | challenge_uri | {challenge_uri} | + Scenario Outline: URL mismatch Given I have an ACME cert profile as "acme_profile" When I have an ACME client connecting to {BASE_URL}/api/v1/pki/acme/profiles/{acme_profile.id}/directory