|
|
|
@ -3,8 +3,6 @@
|
|
|
|
|
|
|
|
|
|
from __future__ import annotations
|
|
|
|
|
|
|
|
|
|
import sys
|
|
|
|
|
|
|
|
|
|
import pytest
|
|
|
|
|
|
|
|
|
|
from ansible.errors import AnsibleError, AnsibleFilterError
|
|
|
|
@ -12,18 +10,6 @@ from ansible.plugins.filter.core import get_encrypted_password
|
|
|
|
|
from ansible.utils import encrypt
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
class passlib_off(object):
|
|
|
|
|
def __init__(self):
|
|
|
|
|
self.orig = encrypt.PASSLIB_AVAILABLE
|
|
|
|
|
|
|
|
|
|
def __enter__(self):
|
|
|
|
|
encrypt.PASSLIB_AVAILABLE = False
|
|
|
|
|
return self
|
|
|
|
|
|
|
|
|
|
def __exit__(self, exception_type, exception_value, traceback):
|
|
|
|
|
encrypt.PASSLIB_AVAILABLE = self.orig
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def assert_hash(expected, secret, algorithm, **settings):
|
|
|
|
|
|
|
|
|
|
assert encrypt.do_encrypt(secret, algorithm, **settings) == expected
|
|
|
|
@ -35,31 +21,12 @@ def assert_hash(expected, secret, algorithm, **settings):
|
|
|
|
|
assert excinfo.value.args[0] == "passlib must be installed and usable to hash with '%s'" % algorithm
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
@pytest.mark.skipif(sys.platform.startswith('darwin'), reason='macOS requires passlib')
|
|
|
|
|
@pytest.mark.skipif(sys.version_info >= (3, 13), reason='Python <= 3.12 required')
|
|
|
|
|
def test_passlib_or_crypt_no_passlib():
|
|
|
|
|
with passlib_off():
|
|
|
|
|
expected = "$5$rounds=5000$12345678$uAZsE3BenI2G.nA8DpTl.9Dc8JiqacI53pEqRr5ppT7"
|
|
|
|
|
assert encrypt.passlib_or_crypt("123", "sha256_crypt", salt="12345678", rounds=5000) == expected
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_passlib_or_crypt():
|
|
|
|
|
@pytest.mark.skipif(not encrypt.PASSLIB_AVAILABLE, reason='passlib must be installed to run this test')
|
|
|
|
|
def test_passlib():
|
|
|
|
|
expected = "$5$12345678$uAZsE3BenI2G.nA8DpTl.9Dc8JiqacI53pEqRr5ppT7"
|
|
|
|
|
assert encrypt.passlib_or_crypt("123", "sha256_crypt", salt="12345678", rounds=5000) == expected
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
@pytest.mark.skipif(sys.platform.startswith('darwin'), reason='macOS requires passlib')
|
|
|
|
|
@pytest.mark.skipif(sys.version_info >= (3, 13), reason='Python <= 3.12 required')
|
|
|
|
|
def test_encrypt_with_rounds_no_passlib():
|
|
|
|
|
with passlib_off():
|
|
|
|
|
assert_hash("$5$rounds=5000$12345678$uAZsE3BenI2G.nA8DpTl.9Dc8JiqacI53pEqRr5ppT7",
|
|
|
|
|
secret="123", algorithm="sha256_crypt", salt="12345678", rounds=5000)
|
|
|
|
|
assert_hash("$5$rounds=10000$12345678$JBinliYMFEcBeAXKZnLjenhgEhTmJBvZn3aR8l70Oy/",
|
|
|
|
|
secret="123", algorithm="sha256_crypt", salt="12345678", rounds=10000)
|
|
|
|
|
assert_hash("$6$rounds=5000$12345678$LcV9LQiaPekQxZ.OfkMADjFdSO2k9zfbDQrHPVcYjSLqSdjLYpsgqviYvTEP/R41yPmhH3CCeEDqVhW1VHr3L.",
|
|
|
|
|
secret="123", algorithm="sha512_crypt", salt="12345678", rounds=5000)
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
@pytest.mark.skipif(not encrypt.PASSLIB_AVAILABLE, reason='passlib must be installed to run this test')
|
|
|
|
|
def test_encrypt_with_ident():
|
|
|
|
|
assert_hash("$2$12$123456789012345678901ufd3hZRrev.WXCbemqGIV/gmWaTGLImm",
|
|
|
|
@ -88,20 +55,6 @@ def test_encrypt_with_rounds():
|
|
|
|
|
secret="123", algorithm="sha512_crypt", salt="12345678", rounds=5000)
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
@pytest.mark.skipif(sys.platform.startswith('darwin'), reason='macOS requires passlib')
|
|
|
|
|
@pytest.mark.skipif(sys.version_info >= (3, 13), reason='Python <= 3.12 required')
|
|
|
|
|
def test_encrypt_default_rounds_no_passlib():
|
|
|
|
|
with passlib_off():
|
|
|
|
|
assert_hash("$1$12345678$tRy4cXc3kmcfRZVj4iFXr/",
|
|
|
|
|
secret="123", algorithm="md5_crypt", salt="12345678")
|
|
|
|
|
assert_hash("$5$12345678$uAZsE3BenI2G.nA8DpTl.9Dc8JiqacI53pEqRr5ppT7",
|
|
|
|
|
secret="123", algorithm="sha256_crypt", salt="12345678")
|
|
|
|
|
assert_hash("$6$12345678$LcV9LQiaPekQxZ.OfkMADjFdSO2k9zfbDQrHPVcYjSLqSdjLYpsgqviYvTEP/R41yPmhH3CCeEDqVhW1VHr3L.",
|
|
|
|
|
secret="123", algorithm="sha512_crypt", salt="12345678")
|
|
|
|
|
|
|
|
|
|
assert encrypt.CryptHash("md5_crypt").hash("123")
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
# If passlib is not installed. this is identical to the test_encrypt_default_rounds_no_passlib() test
|
|
|
|
|
@pytest.mark.skipif(not encrypt.PASSLIB_AVAILABLE, reason='passlib must be installed to run this test')
|
|
|
|
|
def test_encrypt_default_rounds():
|
|
|
|
@ -115,17 +68,6 @@ def test_encrypt_default_rounds():
|
|
|
|
|
assert encrypt.PasslibHash("md5_crypt").hash("123")
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
@pytest.mark.skipif(sys.platform.startswith('darwin'), reason='macOS requires passlib')
|
|
|
|
|
@pytest.mark.skipif(sys.version_info >= (3, 13), reason='Python <= 3.12 required')
|
|
|
|
|
def test_password_hash_filter_no_passlib():
|
|
|
|
|
with passlib_off():
|
|
|
|
|
assert not encrypt.PASSLIB_AVAILABLE
|
|
|
|
|
assert get_encrypted_password("123", "md5", salt="12345678") == "$1$12345678$tRy4cXc3kmcfRZVj4iFXr/"
|
|
|
|
|
|
|
|
|
|
with pytest.raises(AnsibleFilterError):
|
|
|
|
|
get_encrypted_password("123", "crypt16", salt="12")
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
@pytest.mark.skipif(not encrypt.PASSLIB_AVAILABLE, reason='passlib must be installed to run this test')
|
|
|
|
|
def test_password_hash_filter_passlib():
|
|
|
|
|
|
|
|
|
@ -153,17 +95,6 @@ def test_password_hash_filter_passlib():
|
|
|
|
|
assert get_encrypted_password("123", "pbkdf2_sha256", ident='invalid_ident')
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
@pytest.mark.skipif(sys.platform.startswith('darwin'), reason='macOS requires passlib')
|
|
|
|
|
@pytest.mark.skipif(sys.version_info >= (3, 13), reason='Python <= 3.12 required')
|
|
|
|
|
def test_do_encrypt_no_passlib():
|
|
|
|
|
with passlib_off():
|
|
|
|
|
assert not encrypt.PASSLIB_AVAILABLE
|
|
|
|
|
assert encrypt.do_encrypt("123", "md5_crypt", salt="12345678") == "$1$12345678$tRy4cXc3kmcfRZVj4iFXr/"
|
|
|
|
|
|
|
|
|
|
with pytest.raises(AnsibleError):
|
|
|
|
|
encrypt.do_encrypt("123", "crypt16", salt="12")
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
@pytest.mark.skipif(not encrypt.PASSLIB_AVAILABLE, reason='passlib must be installed to run this test')
|
|
|
|
|
def test_do_encrypt_passlib():
|
|
|
|
|
with pytest.raises(AnsibleError):
|
|
|
|
@ -189,31 +120,6 @@ def test_random_salt():
|
|
|
|
|
assert res_char in expected_salt_candidate_chars
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
@pytest.mark.skipif(sys.platform.startswith('darwin'), reason='macOS requires passlib')
|
|
|
|
|
@pytest.mark.skipif(sys.version_info >= (3, 13), reason='Python <= 3.12 required')
|
|
|
|
|
def test_invalid_crypt_salt():
|
|
|
|
|
pytest.raises(
|
|
|
|
|
AnsibleError,
|
|
|
|
|
encrypt.CryptHash('bcrypt')._salt,
|
|
|
|
|
'_',
|
|
|
|
|
None
|
|
|
|
|
)
|
|
|
|
|
encrypt.CryptHash('bcrypt')._salt('1234567890123456789012', None)
|
|
|
|
|
pytest.raises(
|
|
|
|
|
AnsibleError,
|
|
|
|
|
encrypt.CryptHash('bcrypt')._salt,
|
|
|
|
|
'kljsdf',
|
|
|
|
|
None
|
|
|
|
|
)
|
|
|
|
|
encrypt.CryptHash('sha256_crypt')._salt('123456', None)
|
|
|
|
|
pytest.raises(
|
|
|
|
|
AnsibleError,
|
|
|
|
|
encrypt.CryptHash('sha256_crypt')._salt,
|
|
|
|
|
'1234567890123456789012',
|
|
|
|
|
None
|
|
|
|
|
)
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_passlib_bcrypt_salt(recwarn):
|
|
|
|
|
passlib_exc = pytest.importorskip("passlib.exc")
|
|
|
|
|
|
|
|
|
|