-
Notifications
You must be signed in to change notification settings - Fork 86
/
Copy pathtest_crypto_data_keys.py
69 lines (59 loc) · 2.47 KB
/
test_crypto_data_keys.py
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
# Copyright 2017 Amazon.com, Inc. or its affiliates. All Rights Reserved.
#
# Licensed under the Apache License, Version 2.0 (the "License"). You
# may not use this file except in compliance with the License. A copy of
# the License is located at
#
# http://aws.amazon.com/apache2.0/
#
# or in the "license" file accompanying this file. This file is
# distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF
# ANY KIND, either express or implied. See the License for the specific
# language governing permissions and limitations under the License.
"""Unit test suite for ``aws_encryption_sdk.internal.crypto.data_keys``."""
from mock import MagicMock, sentinel
import pytest
from pytest_mock import mocker # noqa pylint: disable=unused-import
import aws_encryption_sdk.internal.crypto.data_keys
from aws_encryption_sdk.internal.crypto.data_keys import derive_data_encryption_key
pytestmark = [pytest.mark.unit, pytest.mark.local]
@pytest.yield_fixture
def patch_default_backend(mocker):
mocker.patch.object(aws_encryption_sdk.internal.crypto.data_keys, 'default_backend')
yield aws_encryption_sdk.internal.crypto.data_keys.default_backend
@pytest.yield_fixture
def patch_struct(mocker):
mocker.patch.object(aws_encryption_sdk.internal.crypto.data_keys, 'struct')
yield aws_encryption_sdk.internal.crypto.data_keys.struct
def test_derive_data_encryption_key_with_hkdf(patch_default_backend, patch_struct):
algorithm = MagicMock()
algorithm.kdf_hash_type.return_value = sentinel.kdf_hash_type
test = derive_data_encryption_key(
source_key=sentinel.source_key,
algorithm=algorithm,
message_id=sentinel.message_id
)
patch_struct.pack.assert_called_with(
'>H16s',
algorithm.algorithm_id,
sentinel.message_id
)
algorithm.kdf_type.assert_called_with(
algorithm=sentinel.kdf_hash_type,
length=algorithm.data_key_len,
salt=None,
info=patch_struct.pack.return_value,
backend=patch_default_backend.return_value
)
algorithm.kdf_type.return_value.derive.assert_called_with(
sentinel.source_key
)
assert test == algorithm.kdf_type.return_value.derive.return_value
def test_derive_data_encryption_key_no_hkdf(patch_default_backend):
algorithm = MagicMock(kdf_type=None)
test = derive_data_encryption_key(
source_key=sentinel.source_key,
algorithm=algorithm,
message_id=sentinel.message_id
)
assert test == sentinel.source_key