fix: exclude signature from signing string in BoxIMClient
Prevents stale signature values from leaking into the MD5 signing calculation, matching the news_service.py pattern. Adds a test that passes a stale signature in extra params and verifies the returned signature is freshly computed.
This commit is contained in:
@@ -32,6 +32,8 @@ class BoxIMClient:
|
||||
keys = sorted(params.keys())
|
||||
sign_parts = []
|
||||
for k in keys:
|
||||
if k in ("signature", "accessSecret"):
|
||||
continue
|
||||
v = params.get(k)
|
||||
if v and v != "" and v != []:
|
||||
sign_parts.append(f"{k}={v}")
|
||||
|
||||
@@ -98,6 +98,28 @@ def test_build_sign_params_contains_required_fields(mock_config):
|
||||
assert len(params["nonce"]) == 12
|
||||
|
||||
|
||||
def test_build_sign_params_excludes_signature_and_accessSecret_from_signing_string(mock_config):
|
||||
"""signature and accessSecret must be excluded from the signing string to match news_service.py."""
|
||||
from services.boxim_client import BoxIMClient
|
||||
|
||||
client = BoxIMClient(mock_config)
|
||||
|
||||
# Pass params that already contain a stale "signature" value
|
||||
params_with_stale_sig = client._build_sign_params({
|
||||
"userId": "u1",
|
||||
"signature": "OLD_STALE_SIG",
|
||||
})
|
||||
|
||||
# The returned signature must be freshly computed (32-char MD5 uppercase),
|
||||
# NOT the stale value we passed in.
|
||||
assert params_with_stale_sig["signature"] != "OLD_STALE_SIG"
|
||||
assert len(params_with_stale_sig["signature"]) == 32
|
||||
|
||||
# Calling with the same extra params but no stale signature should also work.
|
||||
params_clean = client._build_sign_params({"userId": "u1"})
|
||||
assert len(params_clean["signature"]) == 32
|
||||
|
||||
|
||||
def test_build_sign_params_signature_is_deterministic(mock_config):
|
||||
"""Same inputs should produce valid MD5 signatures."""
|
||||
from services.boxim_client import BoxIMClient
|
||||
|
||||
Reference in New Issue
Block a user