|
5 | 5 | using SecureFolderFS.Core.VaultAccess; |
6 | 6 | using SecureFolderFS.Sdk.Enums; |
7 | 7 | using SecureFolderFS.Sdk.Services; |
| 8 | +using SecureFolderFS.Sdk.ViewModels.Controls; |
8 | 9 | using SecureFolderFS.Sdk.ViewModels.Controls.Authentication; |
| 10 | +using SecureFolderFS.Sdk.ViewModels.Views.Credentials; |
9 | 11 | using SecureFolderFS.Sdk.ViewModels.Views.Overlays; |
10 | 12 | using SecureFolderFS.Shared; |
11 | 13 | using SecureFolderFS.Shared.ComponentModel; |
@@ -171,6 +173,91 @@ public async Task ModifyAuthentication_RemoveKeyFile_RequiresPasswordOnly() |
171 | 173 | configuredOptions.UnlockProcedure.Should().BeEquivalentTo(passwordOnlyProcedure); |
172 | 174 | } |
173 | 175 |
|
| 176 | + [Test] |
| 177 | + public async Task CredentialsConfirmation_ChangeChainedPassword_PreservesKeyFile() |
| 178 | + { |
| 179 | + // Arrange |
| 180 | + var vaultFolder = CreateVaultFolder(); |
| 181 | + var manager = DI.Service<IVaultManagerService>(); |
| 182 | + var vaultService = DI.Service<IVaultService>(); |
| 183 | + var vaultId = Guid.NewGuid().ToString("N"); |
| 184 | + |
| 185 | + var compositeProcedure = new AuthenticationMethod([AUTH_PASSWORD, AUTH_KEYFILE], null); |
| 186 | + using var initialCompositePasskey = await GetCreationCompositeCredentialAsync(vaultFolder, "Password#1", vaultId); |
| 187 | + using var _ = await manager.CreateAsync(vaultFolder, initialCompositePasskey, CreateOptions(compositeProcedure, vaultId)); |
| 188 | + |
| 189 | + using var unlockPasskey = await GetLoginCompositeCredentialAsync(vaultFolder, "Password#1", vaultId); |
| 190 | + using var unlockContract = await manager.UnlockAsync(vaultFolder, unlockPasskey); |
| 191 | + using var registerViewModel = new RegisterViewModel(AuthenticationStage.FirstStageOnly); |
| 192 | + using var confirmationViewModel = new CredentialsConfirmationViewModel(vaultFolder, registerViewModel, AuthenticationStage.FirstStageOnly) |
| 193 | + { |
| 194 | + UnlockContract = unlockContract, |
| 195 | + OldPasskey = unlockPasskey, |
| 196 | + OldAuthenticationMethodIds = [AUTH_PASSWORD, AUTH_KEYFILE] |
| 197 | + }; |
| 198 | + |
| 199 | + registerViewModel.CurrentViewModel = CreatePasswordCreationViewModel("Password#2"); |
| 200 | + |
| 201 | + // Act |
| 202 | + await confirmationViewModel.ConfirmAsync(CancellationToken.None); |
| 203 | + |
| 204 | + // Assert |
| 205 | + using var oldCompositePasskey = await GetLoginCompositeCredentialAsync(vaultFolder, "Password#1", vaultId); |
| 206 | + using var updatedCompositePasskey = await GetLoginCompositeCredentialAsync(vaultFolder, "Password#2", vaultId); |
| 207 | + using var updatedPasswordOnlyPasskey = await GetPasswordLoginCredentialAsync("Password#2"); |
| 208 | + |
| 209 | + (await CanUnlockAsync(manager, vaultFolder, oldCompositePasskey)).Should().BeFalse(); |
| 210 | + (await CanUnlockAsync(manager, vaultFolder, updatedCompositePasskey)).Should().BeTrue(); |
| 211 | + (await CanUnlockAsync(manager, vaultFolder, updatedPasswordOnlyPasskey)).Should().BeFalse(); |
| 212 | + |
| 213 | + var configuredOptions = await vaultService.GetVaultOptionsAsync(vaultFolder); |
| 214 | + configuredOptions.UnlockProcedure.Should().BeEquivalentTo(compositeProcedure); |
| 215 | + } |
| 216 | + |
| 217 | + [Test] |
| 218 | + public async Task CredentialsConfirmation_ChangeChainedKeyFile_PreservesPassword() |
| 219 | + { |
| 220 | + // Arrange |
| 221 | + var vaultFolder = CreateVaultFolder(); |
| 222 | + var manager = DI.Service<IVaultManagerService>(); |
| 223 | + var vaultService = DI.Service<IVaultService>(); |
| 224 | + var vaultId = Guid.NewGuid().ToString("N"); |
| 225 | + |
| 226 | + var compositeProcedure = new AuthenticationMethod([AUTH_PASSWORD, AUTH_KEYFILE], null); |
| 227 | + using var initialCompositePasskey = await GetCreationCompositeCredentialAsync(vaultFolder, "Password#1", vaultId); |
| 228 | + using var _ = await manager.CreateAsync(vaultFolder, initialCompositePasskey, CreateOptions(compositeProcedure, vaultId)); |
| 229 | + |
| 230 | + using var unlockPasskey = await GetLoginCompositeCredentialAsync(vaultFolder, "Password#1", vaultId); |
| 231 | + using var oldKeyFile = unlockPasskey.Keys.ElementAt(1).CreateCopy(); |
| 232 | + using var unlockContract = await manager.UnlockAsync(vaultFolder, unlockPasskey); |
| 233 | + using var registerViewModel = new RegisterViewModel(AuthenticationStage.ProceedingStageOnly); |
| 234 | + using var confirmationViewModel = new CredentialsConfirmationViewModel(vaultFolder, registerViewModel, AuthenticationStage.ProceedingStageOnly) |
| 235 | + { |
| 236 | + UnlockContract = unlockContract, |
| 237 | + OldPasskey = unlockPasskey, |
| 238 | + OldAuthenticationMethodIds = [AUTH_PASSWORD, AUTH_KEYFILE] |
| 239 | + }; |
| 240 | + |
| 241 | + var newKeyFile = await GetKeyFileCreationCredentialAsync(vaultId); |
| 242 | + registerViewModel.Credentials.Add(newKeyFile); |
| 243 | + registerViewModel.CurrentViewModel = new KeyFileCreationViewModel(vaultId); |
| 244 | + |
| 245 | + // Act |
| 246 | + await confirmationViewModel.ConfirmAsync(CancellationToken.None); |
| 247 | + |
| 248 | + // Assert |
| 249 | + using var updatedCompositePasskey = await GetLoginCompositeCredentialAsync(vaultFolder, "Password#1", vaultId); |
| 250 | + using var oldCompositePasskey = new KeySequence(); |
| 251 | + oldCompositePasskey.Add(await GetPasswordLoginCredentialAsync("Password#1")); |
| 252 | + oldCompositePasskey.Add(oldKeyFile.CreateCopy()); |
| 253 | + |
| 254 | + (await CanUnlockAsync(manager, vaultFolder, updatedCompositePasskey)).Should().BeTrue(); |
| 255 | + (await CanUnlockAsync(manager, vaultFolder, oldCompositePasskey)).Should().BeFalse(); |
| 256 | + |
| 257 | + var configuredOptions = await vaultService.GetVaultOptionsAsync(vaultFolder); |
| 258 | + configuredOptions.UnlockProcedure.Should().BeEquivalentTo(compositeProcedure); |
| 259 | + } |
| 260 | + |
174 | 261 | [Test] |
175 | 262 | public async Task ModifyAuthentication_InvalidUnlockContract_ThrowsArgumentException() |
176 | 263 | { |
|
0 commit comments