client_server_test.go 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520
  1. // Copyright 2013 The Gorilla WebSocket Authors. All rights reserved.
  2. // Use of this source code is governed by a BSD-style
  3. // license that can be found in the LICENSE file.
  4. package websocket
  5. import (
  6. "crypto/tls"
  7. "crypto/x509"
  8. "encoding/base64"
  9. "io"
  10. "io/ioutil"
  11. "net/http"
  12. "net/http/cookiejar"
  13. "net/http/httptest"
  14. "net/url"
  15. "reflect"
  16. "strings"
  17. "testing"
  18. "time"
  19. )
  20. var cstUpgrader = Upgrader{
  21. Subprotocols: []string{"p0", "p1"},
  22. ReadBufferSize: 1024,
  23. WriteBufferSize: 1024,
  24. EnableCompression: true,
  25. Error: func(w http.ResponseWriter, r *http.Request, status int, reason error) {
  26. http.Error(w, reason.Error(), status)
  27. },
  28. }
  29. var cstDialer = Dialer{
  30. Subprotocols: []string{"p1", "p2"},
  31. ReadBufferSize: 1024,
  32. WriteBufferSize: 1024,
  33. }
  34. type cstHandler struct{ *testing.T }
  35. type cstServer struct {
  36. *httptest.Server
  37. URL string
  38. }
  39. const (
  40. cstPath = "/a/b"
  41. cstRawQuery = "x=y"
  42. cstRequestURI = cstPath + "?" + cstRawQuery
  43. )
  44. func newServer(t *testing.T) *cstServer {
  45. var s cstServer
  46. s.Server = httptest.NewServer(cstHandler{t})
  47. s.Server.URL += cstRequestURI
  48. s.URL = makeWsProto(s.Server.URL)
  49. return &s
  50. }
  51. func newTLSServer(t *testing.T) *cstServer {
  52. var s cstServer
  53. s.Server = httptest.NewTLSServer(cstHandler{t})
  54. s.Server.URL += cstRequestURI
  55. s.URL = makeWsProto(s.Server.URL)
  56. return &s
  57. }
  58. func (t cstHandler) ServeHTTP(w http.ResponseWriter, r *http.Request) {
  59. if r.URL.Path != cstPath {
  60. t.Logf("path=%v, want %v", r.URL.Path, cstPath)
  61. http.Error(w, "bad path", 400)
  62. return
  63. }
  64. if r.URL.RawQuery != cstRawQuery {
  65. t.Logf("query=%v, want %v", r.URL.RawQuery, cstRawQuery)
  66. http.Error(w, "bad path", 400)
  67. return
  68. }
  69. subprotos := Subprotocols(r)
  70. if !reflect.DeepEqual(subprotos, cstDialer.Subprotocols) {
  71. t.Logf("subprotols=%v, want %v", subprotos, cstDialer.Subprotocols)
  72. http.Error(w, "bad protocol", 400)
  73. return
  74. }
  75. ws, err := cstUpgrader.Upgrade(w, r, http.Header{"Set-Cookie": {"sessionID=1234"}})
  76. if err != nil {
  77. t.Logf("Upgrade: %v", err)
  78. return
  79. }
  80. defer ws.Close()
  81. if ws.Subprotocol() != "p1" {
  82. t.Logf("Subprotocol() = %s, want p1", ws.Subprotocol())
  83. ws.Close()
  84. return
  85. }
  86. op, rd, err := ws.NextReader()
  87. if err != nil {
  88. t.Logf("NextReader: %v", err)
  89. return
  90. }
  91. wr, err := ws.NextWriter(op)
  92. if err != nil {
  93. t.Logf("NextWriter: %v", err)
  94. return
  95. }
  96. if _, err = io.Copy(wr, rd); err != nil {
  97. t.Logf("NextWriter: %v", err)
  98. return
  99. }
  100. if err := wr.Close(); err != nil {
  101. t.Logf("Close: %v", err)
  102. return
  103. }
  104. }
  105. func makeWsProto(s string) string {
  106. return "ws" + strings.TrimPrefix(s, "http")
  107. }
  108. func sendRecv(t *testing.T, ws *Conn) {
  109. const message = "Hello World!"
  110. if err := ws.SetWriteDeadline(time.Now().Add(time.Second)); err != nil {
  111. t.Fatalf("SetWriteDeadline: %v", err)
  112. }
  113. if err := ws.WriteMessage(TextMessage, []byte(message)); err != nil {
  114. t.Fatalf("WriteMessage: %v", err)
  115. }
  116. if err := ws.SetReadDeadline(time.Now().Add(time.Second)); err != nil {
  117. t.Fatalf("SetReadDeadline: %v", err)
  118. }
  119. _, p, err := ws.ReadMessage()
  120. if err != nil {
  121. t.Fatalf("ReadMessage: %v", err)
  122. }
  123. if string(p) != message {
  124. t.Fatalf("message=%s, want %s", p, message)
  125. }
  126. }
  127. func TestProxyDial(t *testing.T) {
  128. s := newServer(t)
  129. defer s.Close()
  130. surl, _ := url.Parse(s.URL)
  131. cstDialer.Proxy = http.ProxyURL(surl)
  132. connect := false
  133. origHandler := s.Server.Config.Handler
  134. // Capture the request Host header.
  135. s.Server.Config.Handler = http.HandlerFunc(
  136. func(w http.ResponseWriter, r *http.Request) {
  137. if r.Method == "CONNECT" {
  138. connect = true
  139. w.WriteHeader(200)
  140. return
  141. }
  142. if !connect {
  143. t.Log("connect not received")
  144. http.Error(w, "connect not received", 405)
  145. return
  146. }
  147. origHandler.ServeHTTP(w, r)
  148. })
  149. ws, _, err := cstDialer.Dial(s.URL, nil)
  150. if err != nil {
  151. t.Fatalf("Dial: %v", err)
  152. }
  153. defer ws.Close()
  154. sendRecv(t, ws)
  155. cstDialer.Proxy = http.ProxyFromEnvironment
  156. }
  157. func TestProxyAuthorizationDial(t *testing.T) {
  158. s := newServer(t)
  159. defer s.Close()
  160. surl, _ := url.Parse(s.URL)
  161. surl.User = url.UserPassword("username", "password")
  162. cstDialer.Proxy = http.ProxyURL(surl)
  163. connect := false
  164. origHandler := s.Server.Config.Handler
  165. // Capture the request Host header.
  166. s.Server.Config.Handler = http.HandlerFunc(
  167. func(w http.ResponseWriter, r *http.Request) {
  168. proxyAuth := r.Header.Get("Proxy-Authorization")
  169. expectedProxyAuth := "Basic " + base64.StdEncoding.EncodeToString([]byte("username:password"))
  170. if r.Method == "CONNECT" && proxyAuth == expectedProxyAuth {
  171. connect = true
  172. w.WriteHeader(200)
  173. return
  174. }
  175. if !connect {
  176. t.Log("connect with proxy authorization not received")
  177. http.Error(w, "connect with proxy authorization not received", 405)
  178. return
  179. }
  180. origHandler.ServeHTTP(w, r)
  181. })
  182. ws, _, err := cstDialer.Dial(s.URL, nil)
  183. if err != nil {
  184. t.Fatalf("Dial: %v", err)
  185. }
  186. defer ws.Close()
  187. sendRecv(t, ws)
  188. cstDialer.Proxy = http.ProxyFromEnvironment
  189. }
  190. func TestDial(t *testing.T) {
  191. s := newServer(t)
  192. defer s.Close()
  193. ws, _, err := cstDialer.Dial(s.URL, nil)
  194. if err != nil {
  195. t.Fatalf("Dial: %v", err)
  196. }
  197. defer ws.Close()
  198. sendRecv(t, ws)
  199. }
  200. func TestDialCookieJar(t *testing.T) {
  201. s := newServer(t)
  202. defer s.Close()
  203. jar, _ := cookiejar.New(nil)
  204. d := cstDialer
  205. d.Jar = jar
  206. u, _ := url.Parse(s.URL)
  207. switch u.Scheme {
  208. case "ws":
  209. u.Scheme = "http"
  210. case "wss":
  211. u.Scheme = "https"
  212. }
  213. cookies := []*http.Cookie{{Name: "gorilla", Value: "ws", Path: "/"}}
  214. d.Jar.SetCookies(u, cookies)
  215. ws, _, err := d.Dial(s.URL, nil)
  216. if err != nil {
  217. t.Fatalf("Dial: %v", err)
  218. }
  219. defer ws.Close()
  220. var gorilla string
  221. var sessionID string
  222. for _, c := range d.Jar.Cookies(u) {
  223. if c.Name == "gorilla" {
  224. gorilla = c.Value
  225. }
  226. if c.Name == "sessionID" {
  227. sessionID = c.Value
  228. }
  229. }
  230. if gorilla != "ws" {
  231. t.Error("Cookie not present in jar.")
  232. }
  233. if sessionID != "1234" {
  234. t.Error("Set-Cookie not received from the server.")
  235. }
  236. sendRecv(t, ws)
  237. }
  238. func TestDialTLS(t *testing.T) {
  239. s := newTLSServer(t)
  240. defer s.Close()
  241. certs := x509.NewCertPool()
  242. for _, c := range s.TLS.Certificates {
  243. roots, err := x509.ParseCertificates(c.Certificate[len(c.Certificate)-1])
  244. if err != nil {
  245. t.Fatalf("error parsing server's root cert: %v", err)
  246. }
  247. for _, root := range roots {
  248. certs.AddCert(root)
  249. }
  250. }
  251. d := cstDialer
  252. d.TLSClientConfig = &tls.Config{RootCAs: certs}
  253. ws, _, err := d.Dial(s.URL, nil)
  254. if err != nil {
  255. t.Fatalf("Dial: %v", err)
  256. }
  257. defer ws.Close()
  258. sendRecv(t, ws)
  259. }
  260. func xTestDialTLSBadCert(t *testing.T) {
  261. // This test is deactivated because of noisy logging from the net/http package.
  262. s := newTLSServer(t)
  263. defer s.Close()
  264. ws, _, err := cstDialer.Dial(s.URL, nil)
  265. if err == nil {
  266. ws.Close()
  267. t.Fatalf("Dial: nil")
  268. }
  269. }
  270. func TestDialTLSNoVerify(t *testing.T) {
  271. s := newTLSServer(t)
  272. defer s.Close()
  273. d := cstDialer
  274. d.TLSClientConfig = &tls.Config{InsecureSkipVerify: true}
  275. ws, _, err := d.Dial(s.URL, nil)
  276. if err != nil {
  277. t.Fatalf("Dial: %v", err)
  278. }
  279. defer ws.Close()
  280. sendRecv(t, ws)
  281. }
  282. func TestDialTimeout(t *testing.T) {
  283. s := newServer(t)
  284. defer s.Close()
  285. d := cstDialer
  286. d.HandshakeTimeout = -1
  287. ws, _, err := d.Dial(s.URL, nil)
  288. if err == nil {
  289. ws.Close()
  290. t.Fatalf("Dial: nil")
  291. }
  292. }
  293. func TestDialBadScheme(t *testing.T) {
  294. s := newServer(t)
  295. defer s.Close()
  296. ws, _, err := cstDialer.Dial(s.Server.URL, nil)
  297. if err == nil {
  298. ws.Close()
  299. t.Fatalf("Dial: nil")
  300. }
  301. }
  302. func TestDialBadOrigin(t *testing.T) {
  303. s := newServer(t)
  304. defer s.Close()
  305. ws, resp, err := cstDialer.Dial(s.URL, http.Header{"Origin": {"bad"}})
  306. if err == nil {
  307. ws.Close()
  308. t.Fatalf("Dial: nil")
  309. }
  310. if resp == nil {
  311. t.Fatalf("resp=nil, err=%v", err)
  312. }
  313. if resp.StatusCode != http.StatusForbidden {
  314. t.Fatalf("status=%d, want %d", resp.StatusCode, http.StatusForbidden)
  315. }
  316. }
  317. func TestDialBadHeader(t *testing.T) {
  318. s := newServer(t)
  319. defer s.Close()
  320. for _, k := range []string{"Upgrade",
  321. "Connection",
  322. "Sec-Websocket-Key",
  323. "Sec-Websocket-Version",
  324. "Sec-Websocket-Protocol"} {
  325. h := http.Header{}
  326. h.Set(k, "bad")
  327. ws, _, err := cstDialer.Dial(s.URL, http.Header{"Origin": {"bad"}})
  328. if err == nil {
  329. ws.Close()
  330. t.Errorf("Dial with header %s returned nil", k)
  331. }
  332. }
  333. }
  334. func TestBadMethod(t *testing.T) {
  335. s := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
  336. ws, err := cstUpgrader.Upgrade(w, r, nil)
  337. if err == nil {
  338. t.Errorf("handshake succeeded, expect fail")
  339. ws.Close()
  340. }
  341. }))
  342. defer s.Close()
  343. req, err := http.NewRequest("POST", s.URL, strings.NewReader(""))
  344. if err != nil {
  345. t.Fatalf("NewRequest returned error %v", err)
  346. }
  347. req.Header.Set("Connection", "upgrade")
  348. req.Header.Set("Upgrade", "websocket")
  349. req.Header.Set("Sec-Websocket-Version", "13")
  350. resp, err := http.DefaultClient.Do(req)
  351. if err != nil {
  352. t.Fatalf("Do returned error %v", err)
  353. }
  354. resp.Body.Close()
  355. if resp.StatusCode != http.StatusMethodNotAllowed {
  356. t.Errorf("Status = %d, want %d", resp.StatusCode, http.StatusMethodNotAllowed)
  357. }
  358. }
  359. func TestHandshake(t *testing.T) {
  360. s := newServer(t)
  361. defer s.Close()
  362. ws, resp, err := cstDialer.Dial(s.URL, http.Header{"Origin": {s.URL}})
  363. if err != nil {
  364. t.Fatalf("Dial: %v", err)
  365. }
  366. defer ws.Close()
  367. var sessionID string
  368. for _, c := range resp.Cookies() {
  369. if c.Name == "sessionID" {
  370. sessionID = c.Value
  371. }
  372. }
  373. if sessionID != "1234" {
  374. t.Error("Set-Cookie not received from the server.")
  375. }
  376. if ws.Subprotocol() != "p1" {
  377. t.Errorf("ws.Subprotocol() = %s, want p1", ws.Subprotocol())
  378. }
  379. sendRecv(t, ws)
  380. }
  381. func TestRespOnBadHandshake(t *testing.T) {
  382. const expectedStatus = http.StatusGone
  383. const expectedBody = "This is the response body."
  384. s := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
  385. w.WriteHeader(expectedStatus)
  386. io.WriteString(w, expectedBody)
  387. }))
  388. defer s.Close()
  389. ws, resp, err := cstDialer.Dial(makeWsProto(s.URL), nil)
  390. if err == nil {
  391. ws.Close()
  392. t.Fatalf("Dial: nil")
  393. }
  394. if resp == nil {
  395. t.Fatalf("resp=nil, err=%v", err)
  396. }
  397. if resp.StatusCode != expectedStatus {
  398. t.Errorf("resp.StatusCode=%d, want %d", resp.StatusCode, expectedStatus)
  399. }
  400. p, err := ioutil.ReadAll(resp.Body)
  401. if err != nil {
  402. t.Fatalf("ReadFull(resp.Body) returned error %v", err)
  403. }
  404. if string(p) != expectedBody {
  405. t.Errorf("resp.Body=%s, want %s", p, expectedBody)
  406. }
  407. }
  408. // TestHostHeader confirms that the host header provided in the call to Dial is
  409. // sent to the server.
  410. func TestHostHeader(t *testing.T) {
  411. s := newServer(t)
  412. defer s.Close()
  413. specifiedHost := make(chan string, 1)
  414. origHandler := s.Server.Config.Handler
  415. // Capture the request Host header.
  416. s.Server.Config.Handler = http.HandlerFunc(
  417. func(w http.ResponseWriter, r *http.Request) {
  418. specifiedHost <- r.Host
  419. origHandler.ServeHTTP(w, r)
  420. })
  421. ws, _, err := cstDialer.Dial(s.URL, http.Header{"Host": {"testhost"}})
  422. if err != nil {
  423. t.Fatalf("Dial: %v", err)
  424. }
  425. defer ws.Close()
  426. if gotHost := <-specifiedHost; gotHost != "testhost" {
  427. t.Fatalf("gotHost = %q, want \"testhost\"", gotHost)
  428. }
  429. sendRecv(t, ws)
  430. }
  431. func TestDialCompression(t *testing.T) {
  432. s := newServer(t)
  433. defer s.Close()
  434. dialer := cstDialer
  435. dialer.EnableCompression = true
  436. ws, _, err := dialer.Dial(s.URL, nil)
  437. if err != nil {
  438. t.Fatalf("Dial: %v", err)
  439. }
  440. defer ws.Close()
  441. sendRecv(t, ws)
  442. }