|
| 1 | +import * as assert from 'assert'; |
| 2 | +import { createHmac } from 'crypto'; |
| 3 | +import { deriveEnterpriseSalt } from '../../src'; |
| 4 | + |
| 5 | +describe('deriveEnterpriseSalt', function () { |
| 6 | + // base64url-encoded salt as the server would provide |
| 7 | + const BASE_SALT = Buffer.from('server-provided-base-salt').toString('base64url'); |
| 8 | + const ENTERPRISE_ID = 'ent-abc123'; |
| 9 | + |
| 10 | + it('returns a base64 string', function () { |
| 11 | + const result = deriveEnterpriseSalt(BASE_SALT, ENTERPRISE_ID); |
| 12 | + assert.match(result, /^[A-Za-z0-9+/]+=*$/); |
| 13 | + }); |
| 14 | + |
| 15 | + it('matches a known HMAC-SHA256 test vector', function () { |
| 16 | + const key = Buffer.from(BASE_SALT, 'base64url'); |
| 17 | + const expected = createHmac('sha256', key).update(ENTERPRISE_ID, 'utf8').digest('base64'); |
| 18 | + assert.strictEqual(deriveEnterpriseSalt(BASE_SALT, ENTERPRISE_ID), expected); |
| 19 | + }); |
| 20 | + |
| 21 | + it('is deterministic — same inputs produce same output', function () { |
| 22 | + assert.strictEqual( |
| 23 | + deriveEnterpriseSalt(BASE_SALT, ENTERPRISE_ID), |
| 24 | + deriveEnterpriseSalt(BASE_SALT, ENTERPRISE_ID) |
| 25 | + ); |
| 26 | + }); |
| 27 | + |
| 28 | + it('produces different output for different enterprise IDs', function () { |
| 29 | + const a = deriveEnterpriseSalt(BASE_SALT, 'ent-aaa'); |
| 30 | + const b = deriveEnterpriseSalt(BASE_SALT, 'ent-bbb'); |
| 31 | + assert.notStrictEqual(a, b); |
| 32 | + }); |
| 33 | + |
| 34 | + it('produces different output for different base salts', function () { |
| 35 | + const saltA = Buffer.from('salt-one').toString('base64url'); |
| 36 | + const saltB = Buffer.from('salt-two').toString('base64url'); |
| 37 | + assert.notStrictEqual(deriveEnterpriseSalt(saltA, ENTERPRISE_ID), deriveEnterpriseSalt(saltB, ENTERPRISE_ID)); |
| 38 | + }); |
| 39 | + |
| 40 | + it('throws if baseSalt is undefined', function () { |
| 41 | + assert.throws(() => deriveEnterpriseSalt(undefined, ENTERPRISE_ID), /Failed to derive enterprise salt/); |
| 42 | + }); |
| 43 | + |
| 44 | + it('throws if baseSalt is an empty string', function () { |
| 45 | + assert.throws(() => deriveEnterpriseSalt('', ENTERPRISE_ID), /Failed to derive enterprise salt/); |
| 46 | + }); |
| 47 | +}); |
0 commit comments