diff --git a/.serena/.gitignore b/.serena/.gitignore
new file mode 100644
index 0000000..14d86ad
--- /dev/null
+++ b/.serena/.gitignore
@@ -0,0 +1 @@
+/cache
diff --git a/.serena/project.yml b/.serena/project.yml
new file mode 100644
index 0000000..f96e3cb
--- /dev/null
+++ b/.serena/project.yml
@@ -0,0 +1,71 @@
+# language of the project (csharp, python, rust, java, typescript, go, cpp, or ruby)
+# * For C, use cpp
+# * For JavaScript, use typescript
+# Special requirements:
+# * csharp: Requires the presence of a .sln file in the project folder.
+language: rust
+
+# the encoding used by text files in the project
+# For a list of possible encodings, see https://docs.python.org/3.11/library/codecs.html#standard-encodings
+encoding: "utf-8"
+
+# whether to use the project's gitignore file to ignore files
+# Added on 2025-04-07
+ignore_all_files_in_gitignore: true
+# list of additional paths to ignore
+# same syntax as gitignore, so you can use * and **
+# Was previously called `ignored_dirs`, please update your config if you are using that.
+# Added (renamed) on 2025-04-07
+ignored_paths: []
+
+# whether the project is in read-only mode
+# If set to true, all editing tools will be disabled and attempts to use them will result in an error
+# Added on 2025-04-18
+read_only: false
+
+# list of tool names to exclude. We recommend not excluding any tools, see the readme for more details.
+# Below is the complete list of tools for convenience.
+# To make sure you have the latest list of tools, and to view their descriptions,
+# execute `uv run scripts/print_tool_overview.py`.
+#
+# * `activate_project`: Activates a project by name.
+# * `check_onboarding_performed`: Checks whether project onboarding was already performed.
+# * `create_text_file`: Creates/overwrites a file in the project directory.
+# * `delete_lines`: Deletes a range of lines within a file.
+# * `delete_memory`: Deletes a memory from Serena's project-specific memory store.
+# * `execute_shell_command`: Executes a shell command.
+# * `find_referencing_code_snippets`: Finds code snippets in which the symbol at the given location is referenced.
+# * `find_referencing_symbols`: Finds symbols that reference the symbol at the given location (optionally filtered by type).
+# * `find_symbol`: Performs a global (or local) search for symbols with/containing a given name/substring (optionally filtered by type).
+# * `get_current_config`: Prints the current configuration of the agent, including the active and available projects, tools, contexts, and modes.
+# * `get_symbols_overview`: Gets an overview of the top-level symbols defined in a given file.
+# * `initial_instructions`: Gets the initial instructions for the current project.
+# Should only be used in settings where the system prompt cannot be set,
+# e.g. in clients you have no control over, like Claude Desktop.
+# * `insert_after_symbol`: Inserts content after the end of the definition of a given symbol.
+# * `insert_at_line`: Inserts content at a given line in a file.
+# * `insert_before_symbol`: Inserts content before the beginning of the definition of a given symbol.
+# * `list_dir`: Lists files and directories in the given directory (optionally with recursion).
+# * `list_memories`: Lists memories in Serena's project-specific memory store.
+# * `onboarding`: Performs onboarding (identifying the project structure and essential tasks, e.g. for testing or building).
+# * `prepare_for_new_conversation`: Provides instructions for preparing for a new conversation (in order to continue with the necessary context).
+# * `read_file`: Reads a file within the project directory.
+# * `read_memory`: Reads the memory with the given name from Serena's project-specific memory store.
+# * `remove_project`: Removes a project from the Serena configuration.
+# * `replace_lines`: Replaces a range of lines within a file with new content.
+# * `replace_symbol_body`: Replaces the full definition of a symbol.
+# * `restart_language_server`: Restarts the language server, may be necessary when edits not through Serena happen.
+# * `search_for_pattern`: Performs a search for a pattern in the project.
+# * `summarize_changes`: Provides instructions for summarizing the changes made to the codebase.
+# * `switch_modes`: Activates modes by providing a list of their names
+# * `think_about_collected_information`: Thinking tool for pondering the completeness of collected information.
+# * `think_about_task_adherence`: Thinking tool for determining whether the agent is still on track with the current task.
+# * `think_about_whether_you_are_done`: Thinking tool for determining whether the task is truly completed.
+# * `write_memory`: Writes a named memory (for future reference) to Serena's project-specific memory store.
+excluded_tools: []
+
+# initial prompt for the project. It will always be given to the LLM upon activating the project
+# (contrary to the memories, which are loaded on demand).
+initial_prompt: ""
+
+project_name: "imphnen-backend-service"
diff --git a/run-all-tests.sh b/run-all-tests.sh
deleted file mode 100644
index c948638..0000000
--- a/run-all-tests.sh
+++ /dev/null
@@ -1,130 +0,0 @@
-#!/bin/bash
-
-# ==============================================================================
-# IMPHNEN API - Master Test Runner
-# Menjalankan semua test suite untuk coverage lengkap
-# ==============================================================================
-
-# Colors
-CYAN='\033[0;36m'
-GREEN='\033[0;32m'
-RED='\033[0;31m'
-YELLOW='\033[0;33m'
-NC='\033[0m'
-
-echo -e "${CYAN}================================================================${NC}"
-echo -e "${CYAN} IMPHNEN Backend - Complete API Test Suite${NC}"
-echo -e "${CYAN}================================================================${NC}"
-echo ""
-
-# Check if server is running
-BASE_URL="http://127.0.0.1:4099"
-if curl -s --head "$BASE_URL/v1/cms/landing/events" > /dev/null 2>&1; then
- echo -e "${GREEN}✓ Server is running at $BASE_URL${NC}"
-else
- echo -e "${RED}✗ Server is not running!${NC}"
- echo -e "${YELLOW}Please start the server first with: cargo run --bin api --release${NC}"
- exit 1
-fi
-
-echo ""
-
-# Counters
-TOTAL_SUITES=0
-PASSED_SUITES=0
-FAILED_SUITES=0
-
-run_test_suite() {
- local suite_name=$1
- local suite_command=$2
- local suite_description=$3
-
- ((TOTAL_SUITES++))
-
- echo -e "${CYAN}━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━${NC}"
- echo -e "${CYAN}Test Suite #${TOTAL_SUITES}: ${suite_name}${NC}"
- echo -e "${CYAN}Description: ${suite_description}${NC}"
- echo -e "${CYAN}━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━${NC}"
- echo ""
-
- # Run the test suite
- if eval "$suite_command"; then
- echo ""
- echo -e "${GREEN}✓ Suite Passed: ${suite_name}${NC}"
- ((PASSED_SUITES++))
- else
- echo ""
- echo -e "${RED}✗ Suite Failed: ${suite_name}${NC}"
- ((FAILED_SUITES++))
- fi
-
- echo ""
-}
-
-# ==============================================================================
-# RUN ALL TEST SUITES
-# ==============================================================================
-
-echo -e "${YELLOW}Starting comprehensive API testing...${NC}"
-echo ""
-sleep 1
-
-# Suite 1: Main Test Suite (dari test.sh)
-run_test_suite \
- "Main API Test Suite" \
- "bash test.sh -dk" \
- "Comprehensive tests covering all major endpoints with multiple user roles"
-
-# Suite 2: Comprehensive API Coverage
-run_test_suite \
- "Extended API Coverage" \
- "bash test-comprehensive-api.sh" \
- "Detailed tests for all CRUD operations on every endpoint"
-
-# Suite 3: Cargo Unit Tests
-run_test_suite \
- "Rust Unit Tests" \
- "cargo test --lib 2>&1 | grep -E '(test result|running)'" \
- "Unit tests for Rust codebase"
-
-# Suite 4: Cargo Integration Tests
-run_test_suite \
- "Rust Integration Tests" \
- "cargo test --test '*' 2>&1 | grep -E '(test result|running)'" \
- "Integration tests for full system behavior"
-
-# ==============================================================================
-# FINAL SUMMARY
-# ==============================================================================
-
-echo ""
-echo -e "${CYAN}================================================================${NC}"
-echo -e "${CYAN} FINAL TEST SUMMARY${NC}"
-echo -e "${CYAN}================================================================${NC}"
-echo ""
-echo -e "Total Test Suites Run: ${TOTAL_SUITES}"
-echo -e "${GREEN}Passed Suites: ${PASSED_SUITES}${NC}"
-echo -e "${RED}Failed Suites: ${FAILED_SUITES}${NC}"
-echo ""
-
-SUCCESS_RATE=0
-if [ "$TOTAL_SUITES" -gt 0 ]; then
- SUCCESS_RATE=$(( (PASSED_SUITES * 100) / TOTAL_SUITES ))
-fi
-
-echo -e "Overall Success Rate: ${SUCCESS_RATE}%"
-echo ""
-
-if [ "$FAILED_SUITES" -eq 0 ]; then
- echo -e "${GREEN}========================================${NC}"
- echo -e "${GREEN} ✓ ALL TEST SUITES PASSED!${NC}"
- echo -e "${GREEN}========================================${NC}"
- exit 0
-else
- echo -e "${RED}========================================${NC}"
- echo -e "${RED} ✗ SOME TEST SUITES FAILED${NC}"
- echo -e "${RED}========================================${NC}"
- echo ""
- echo -e "${YELLOW}Please review the output above to identify failed tests.${NC}"
- exit 1
-fi
diff --git a/run-tests.sh b/run-tests.sh
index bd2205a..1f93202 100644
--- a/run-tests.sh
+++ b/run-tests.sh
@@ -28,7 +28,7 @@ while getopts "s:" opt; do
\?)
echo "Usage: $0 [-s suite_name]"
echo " -s suite_name: Run only a specific test suite"
- echo " Available suites: auth, users, roles, teams, mentors, cms, gacha, hackathon"
+ echo " Available suites: auth, users, roles, teams, security, mentors, cms, gacha, hackathon"
exit 1
;;
esac
@@ -231,6 +231,9 @@ if [ -n "$SPECIFIC_SUITE" ]; then
teams)
run_test_suite "IAM - Teams" "$SCRIPT_DIR/tests/iam/test-teams.sh"
;;
+ security)
+ run_test_suite "IAM - Security & Authorization" "$SCRIPT_DIR/tests/iam/test-security.sh"
+ ;;
mentors)
run_test_suite "Dimentorin - Mentors" "$SCRIPT_DIR/tests/dimentorin/test-mentors.sh"
;;
@@ -245,7 +248,7 @@ if [ -n "$SPECIFIC_SUITE" ]; then
;;
*)
echo -e "${RED}Unknown suite: $SPECIFIC_SUITE${NC}"
- echo -e "${YELLOW}Available suites: auth, users, roles, teams, mentors, cms, gacha, hackathon${NC}"
+ echo -e "${YELLOW}Available suites: auth, users, roles, teams, security, mentors, cms, gacha, hackathon${NC}"
cleanup
exit 1
;;
@@ -256,6 +259,7 @@ else
run_test_suite "IAM - Users" "$SCRIPT_DIR/tests/iam/test-users.sh"
run_test_suite "IAM - Roles & Permissions" "$SCRIPT_DIR/tests/iam/test-roles-permissions.sh"
run_test_suite "IAM - Teams" "$SCRIPT_DIR/tests/iam/test-teams.sh"
+ run_test_suite "IAM - Security & Authorization" "$SCRIPT_DIR/tests/iam/test-security.sh"
run_test_suite "Dimentorin - Mentors" "$SCRIPT_DIR/tests/dimentorin/test-mentors.sh"
run_test_suite "CMS - Events & Testimonials" "$SCRIPT_DIR/tests/cms/test-cms.sh"
run_test_suite "Gacha - Items & Rolls" "$SCRIPT_DIR/tests/gacha/test-gacha.sh"
diff --git a/test-comprehensive-api.sh b/test-comprehensive-api.sh
deleted file mode 100644
index 679ebd9..0000000
--- a/test-comprehensive-api.sh
+++ /dev/null
@@ -1,717 +0,0 @@
-#!/bin/bash
-
-# ==============================================================================
-# IMPHNEN API Comprehensive Test Suite - Extended Coverage
-# Tests untuk semua endpoint yang belum tercakup di test.sh
-# ==============================================================================
-
-# Source the main test.sh for shared variables and functions
-# Assuming test.sh exports needed variables
-
-BASE_URL="${BASE_URL:-http://127.0.0.1:4099}"
-AUTH_TOKEN=""
-
-# Colors
-CYAN='\033[0;36m'
-YELLOW='\033[0;33m'
-GREEN='\033[0;32m'
-RED='\033[0;31m'
-BLUE='\033[0;34m'
-NC='\033[0m'
-
-PASS_COUNT=0
-FAIL_COUNT=0
-TEST_RESULTS=()
-FAILED_TESTS_SUMMARY=()
-
-write_test_log() {
- local level=$1
- local message=$2
- local color=$NC
-
- case $level in
- "SUCCESS") color=$GREEN ;;
- "ERROR") color=$RED ;;
- "WARN") color=$YELLOW ;;
- "INFO") color=$CYAN ;;
- esac
-
- printf "[$(date +'%H:%M:%S')] [${color}%-7s${NC}] %s\n" "$level" "$message" >&2
-}
-
-test_api_endpoint() {
- local test_name=$1
- local method=$2
- local endpoint=$3
- local expected_status=$4
- local body=$5
- local require_auth=$6
-
- local headers=(-H "Content-Type: application/json")
- if [[ "$require_auth" = true && -n "$AUTH_TOKEN" ]]; then
- headers+=(-H "Authorization: Bearer $AUTH_TOKEN")
- elif [[ "$require_auth" = true && -z "$AUTH_TOKEN" ]]; then
- write_test_log "WARN" "✗ $test_name - Dilewati: token autentikasi tidak tersedia"
- return
- fi
-
- local start_req_time=$(date +%s%3N)
-
- local temp_file=$(mktemp)
- local status_file=$(mktemp)
-
- curl -s -X "$method" "${headers[@]}" -d "$body" "$BASE_URL$endpoint" \
- -D "$status_file" -o "$temp_file"
-
- response_body=$(cat "$temp_file")
- http_status=$(head -n 1 "$status_file" | cut -d' ' -f2)
-
- rm -f "$temp_file" "$status_file"
-
- local end_req_time=$(date +%s%3N)
- local duration=$((end_req_time - start_req_time))
-
- local status="FAIL"
- local error_msg=""
-
- if [[ "$http_status" =~ ^[0-9]+$ ]] && [ "$http_status" -eq "$expected_status" ]; then
- status="PASS"
- ((PASS_COUNT++))
- write_test_log "SUCCESS" "✓ $test_name - Sukses (Status: $http_status, Waktu: ${duration}ms)"
- else
- status="FAIL"
- ((FAIL_COUNT++))
- write_test_log "ERROR" " Response Body: $response_body"
- if [[ ! "$http_status" =~ ^[0-9]+$ ]]; then
- error_msg="Failed to get valid HTTP status code (got: $http_status)"
- else
- error_msg="Status yang diharapkan $expected_status, tetapi mendapat $http_status."
- fi
- write_test_log "ERROR" "✗ $test_name - Gagal: $error_msg"
- FAILED_TESTS_SUMMARY+=("✗ $test_name - $error_msg")
- fi
-
- result_json=$(jq -n --arg name "$test_name" --arg ep "$endpoint" --arg meth "$method" \
- --arg stat "$status" --arg code "$http_status" --arg dur "$duration" \
- --arg err "$error_msg" \
- '{TestName: $name, Endpoint: $ep, Method: $meth, Status: $stat, StatusCode: $code, ResponseTimeMs: $dur, Error: $err}')
- TEST_RESULTS+=("$result_json")
- printf "%s" "$response_body"
-}
-
-get_auth_token() {
- write_test_log "INFO" "Mengautentikasi test user..."
- local login_data
- login_data=$(jq -n '{email: "admin@example.com", password: "password"}')
-
- local temp_file=$(mktemp)
- local status_file=$(mktemp)
-
- curl -s -X "POST" -H "Content-Type: application/json" -d "$login_data" "$BASE_URL/v1/auth/login" \
- -D "$status_file" -o "$temp_file"
-
- local response_body=$(cat "$temp_file")
- local http_status=$(head -n 1 "$status_file" | cut -d' ' -f2)
-
- rm -f "$temp_file" "$status_file"
-
- if [[ "$http_status" =~ ^[0-9]+$ ]] && [ "$http_status" -eq 200 ]; then
- AUTH_TOKEN=$(echo "$response_body" | jq -r '.data.token.access_token // empty')
- if [[ -n "$AUTH_TOKEN" ]]; then
- write_test_log "SUCCESS" "Autentikasi berhasil"
- ((PASS_COUNT++))
- else
- write_test_log "ERROR" "Token tidak ditemukan"
- ((FAIL_COUNT++))
- fi
- else
- write_test_log "ERROR" "Login gagal dengan status: $http_status"
- ((FAIL_COUNT++))
- fi
-}
-
-# ==============================================================================
-# IAM ENDPOINTS - AUTH
-# ==============================================================================
-test_auth_comprehensive() {
- printf "\n${CYAN}=== Testing Auth Endpoints (Comprehensive) ===${NC}\n"
-
- # Login
- local login_data=$(jq -n '{email: "admin@example.com", password: "password"}')
- test_api_endpoint "POST /v1/auth/login" "POST" "/v1/auth/login" 200 "$login_data" false
-
- # Login Mentor
- local mentor_login=$(jq -n '{email: "mentor@example.com", password: "password"}')
- test_api_endpoint "POST /v1/auth/login-mentor" "POST" "/v1/auth/login-mentor" 200 "$mentor_login" false
-
- # Register (will fail without valid data, but tests endpoint)
- local register_data=$(jq -n '{
- email: "newuser'$(date +%s)'@test.com",
- password: "Password123!",
- fullname: "Test User",
- phone_number: "081234567890"
- }')
- test_api_endpoint "POST /v1/auth/register" "POST" "/v1/auth/register" 200 "$register_data" false
-
- # Verify Email (expect failure with fake OTP)
- local verify_data=$(jq -n '{email: "test@test.com", otp: 123456}')
- test_api_endpoint "POST /v1/auth/verify-email" "POST" "/v1/auth/verify-email" 401 "$verify_data" false
-
- # Resend OTP
- local resend_data=$(jq -n '{email: "admin@example.com"}')
- test_api_endpoint "POST /v1/auth/send-otp" "POST" "/v1/auth/send-otp" 200 "$resend_data" false
-
- # Forgot Password
- test_api_endpoint "POST /v1/auth/forgot" "POST" "/v1/auth/forgot" 200 "$resend_data" false
-
- # New Password (expect failure with invalid token)
- local new_pass_data=$(jq -n '{token: "invalid", password: "NewPass123!"}')
- test_api_endpoint "POST /v1/auth/new-password" "POST" "/v1/auth/new-password" 400 "$new_pass_data" false
-
- # Refresh Token (get token first)
- local refresh_token=$(curl -s -X POST -H "Content-Type: application/json" \
- -d "$login_data" "$BASE_URL/v1/auth/login" | jq -r '.data.token.refresh_token // empty')
-
- if [ -n "$refresh_token" ]; then
- local refresh_data=$(jq -n --arg token "$refresh_token" '{refresh_token: $token}')
- test_api_endpoint "POST /v1/auth/refresh" "POST" "/v1/auth/refresh" 200 "$refresh_data" false
- fi
-
- # Logout
- test_api_endpoint "POST /v1/auth/logout" "POST" "/v1/auth/logout" 200 "" true
-}
-
-# ==============================================================================
-# IAM ENDPOINTS - USERS
-# ==============================================================================
-test_users_comprehensive() {
- printf "\n${CYAN}=== Testing Users Endpoints (Comprehensive) ===${NC}\n"
-
- # Get Users List
- test_api_endpoint "GET /v1/users" "GET" "/v1/users" 200 "" true
- test_api_endpoint "GET /v1/users?page=1&limit=10" "GET" "/v1/users?page=1&limit=10" 200 "" true
- test_api_endpoint "GET /v1/users?search=admin" "GET" "/v1/users?search=admin" 200 "" true
- test_api_endpoint "GET /v1/users?sort_by=created_at&order=DESC" "GET" "/v1/users?sort_by=created_at&order=DESC" 200 "" true
-
- # Get User Me
- test_api_endpoint "GET /v1/users/me" "GET" "/v1/users/me" 200 "" true
-
- # Update User Me
- local update_me_data=$(jq -n '{
- fullname: "Updated Admin",
- phone_number: "081234567890",
- gender: "Male",
- birthdate: "1990-01-01"
- }')
- test_api_endpoint "PUT /v1/users/me" "PUT" "/v1/users/me" 200 "$update_me_data" true
-
- # Get User By ID (use a known ID from seed data)
- local test_user_id="c3b1d6a8-8d4f-4b36-b789-2e532ec7a7b2"
- test_api_endpoint "GET /v1/users/detail/:id" "GET" "/v1/users/detail/$test_user_id" 200 "" true
-
- # Create User
- local create_user_data=$(jq -n '{
- email: "testuser'$(date +%s)'@test.com",
- password: "Password123!",
- fullname: "Test User Created",
- phone_number: "081234567891",
- is_active: true,
- role_id: "5713cb37-dc02-4e87-8048-d7a41d352059"
- }')
- local create_response=$(test_api_endpoint "POST /v1/users/create" "POST" "/v1/users/create" 201 "$create_user_data" true)
- local created_user_id=$(echo "$create_response" | jq -r '.data.id // empty')
-
- if [ -n "$created_user_id" ]; then
- # Update User
- local update_user_data=$(jq -n '{
- email: "updated'$(date +%s)'@test.com",
- fullname: "Updated Test User",
- phone_number: "081234567892",
- is_active: true,
- role_id: "5713cb37-dc02-4e87-8048-d7a41d352059"
- }')
- test_api_endpoint "PUT /v1/users/update/:id" "PUT" "/v1/users/update/$created_user_id" 200 "$update_user_data" true
-
- # Activate/Deactivate User
- local activate_data=$(jq -n '{is_active: false}')
- test_api_endpoint "PATCH /v1/users/activate/:id" "PATCH" "/v1/users/activate/$created_user_id" 200 "$activate_data" true
-
- local reactivate_data=$(jq -n '{is_active: true}')
- test_api_endpoint "PATCH /v1/users/activate/:id (reactivate)" "PATCH" "/v1/users/activate/$created_user_id" 200 "$reactivate_data" true
-
- # Delete User
- test_api_endpoint "DELETE /v1/users/delete/:id" "DELETE" "/v1/users/delete/$created_user_id" 200 "" true
- fi
-
- # Upload File (requires multipart, skip for now)
- # test_api_endpoint "POST /v1/users/upload" "POST" "/v1/users/upload" 200 "" true
-}
-
-# ==============================================================================
-# IAM ENDPOINTS - ROLES
-# ==============================================================================
-test_roles_comprehensive() {
- printf "\n${CYAN}=== Testing Roles Endpoints (Comprehensive) ===${NC}\n"
-
- # Get Roles List
- test_api_endpoint "GET /v1/roles" "GET" "/v1/roles" 200 "" true
- test_api_endpoint "GET /v1/roles?page=1&limit=10" "GET" "/v1/roles?page=1&limit=10" 200 "" true
-
- # Get Role By ID
- local test_role_id="5713cb37-dc02-4e87-8048-d7a41d352059"
- test_api_endpoint "GET /v1/roles/:id" "GET" "/v1/roles/$test_role_id" 200 "" true
-
- # Create Role
- local create_role_data=$(jq -n '{
- name: "Test Role '$(date +%s)'",
- description: "Test role description",
- permissions: []
- }')
- local create_role_response=$(test_api_endpoint "POST /v1/roles" "POST" "/v1/roles" 201 "$create_role_data" true)
- local created_role_id=$(echo "$create_role_response" | jq -r '.data.id // empty')
-
- if [ -n "$created_role_id" ]; then
- # Update Role
- local update_role_data=$(jq -n '{
- name: "Updated Test Role",
- description: "Updated description",
- permissions: []
- }')
- test_api_endpoint "PUT /v1/roles/:id" "PUT" "/v1/roles/$created_role_id" 200 "$update_role_data" true
-
- # Delete Role
- test_api_endpoint "DELETE /v1/roles/:id" "DELETE" "/v1/roles/$created_role_id" 200 "" true
- fi
-}
-
-# ==============================================================================
-# IAM ENDPOINTS - PERMISSIONS
-# ==============================================================================
-test_permissions_comprehensive() {
- printf "\n${CYAN}=== Testing Permissions Endpoints (Comprehensive) ===${NC}\n"
-
- # Get Permissions List
- test_api_endpoint "GET /v1/permissions" "GET" "/v1/permissions" 200 "" true
- test_api_endpoint "GET /v1/permissions?page=1&limit=10" "GET" "/v1/permissions?page=1&limit=10" 200 "" true
-
- # Get Permission By ID (use known ID)
- local test_perm_id="00000000-0000-0000-0000-000000000001"
- test_api_endpoint "GET /v1/permissions/:id" "GET" "/v1/permissions/$test_perm_id" 200 "" true
-
- # Create Permission
- local create_perm_data=$(jq -n '{
- name: "Test Permission '$(date +%s)'",
- description: "Test permission description"
- }')
- local create_perm_response=$(test_api_endpoint "POST /v1/permissions" "POST" "/v1/permissions" 201 "$create_perm_data" true)
- local created_perm_id=$(echo "$create_perm_response" | jq -r '.data.id // empty')
-
- if [ -n "$created_perm_id" ]; then
- # Update Permission
- local update_perm_data=$(jq -n '{
- name: "Updated Test Permission",
- description: "Updated description"
- }')
- test_api_endpoint "PUT /v1/permissions/:id" "PUT" "/v1/permissions/$created_perm_id" 200 "$update_perm_data" true
-
- # Delete Permission
- test_api_endpoint "DELETE /v1/permissions/:id" "DELETE" "/v1/permissions/$created_perm_id" 200 "" true
- fi
-}
-
-# ==============================================================================
-# IAM ENDPOINTS - TEAMS
-# ==============================================================================
-test_teams_comprehensive() {
- printf "\n${CYAN}=== Testing Teams Endpoints (Comprehensive) ===${NC}\n"
-
- # Admin Endpoints
- test_api_endpoint "GET /v1/teams/admin" "GET" "/v1/teams/admin" 200 "" true
- test_api_endpoint "GET /v1/teams/admin?page=1&limit=10" "GET" "/v1/teams/admin?page=1&limit=10" 200 "" true
-
- # Public Endpoints
- test_api_endpoint "GET /v1/teams" "GET" "/v1/teams" 200 "" false
- test_api_endpoint "GET /v1/teams?search=test" "GET" "/v1/teams?search=test" 200 "" false
- test_api_endpoint "GET /v1/teams/search?query=dev" "GET" "/v1/teams/search?query=dev" 200 "" false
-
- # Get Team By ID
- local test_team_id="team-001"
- test_api_endpoint "GET /v1/teams/admin/:id" "GET" "/v1/teams/admin/$test_team_id" 200 "" true
- test_api_endpoint "GET /v1/teams/admin/:id/members" "GET" "/v1/teams/admin/$test_team_id/members" 200 "" true
-
- # Create Team
- local create_team_data=$(jq -n '{
- name: "Test Team '$(date +%s)'",
- description: "Test team description",
- is_open: true,
- max_members: 5
- }')
- local create_team_response=$(test_api_endpoint "POST /v1/teams/admin" "POST" "/v1/teams/admin" 201 "$create_team_data" true)
- local created_team_id=$(echo "$create_team_response" | jq -r '.data.id // empty')
-
- if [ -n "$created_team_id" ]; then
- # Update Team
- local update_team_data=$(jq -n '{
- name: "Updated Test Team",
- description: "Updated description",
- is_open: false,
- max_members: 10
- }')
- test_api_endpoint "PUT /v1/teams/admin/:id" "PUT" "/v1/teams/admin/$created_team_id" 200 "$update_team_data" true
-
- # Invite Members
- local invite_data=$(jq -n '{
- user_ids: ["c3b1d6a8-8d4f-4b36-b789-2e532ec7a7b2"]
- }')
- test_api_endpoint "POST /v1/teams/admin/:id/invite" "POST" "/v1/teams/admin/$created_team_id/invite" 200 "$invite_data" true
-
- # Delete Team
- test_api_endpoint "DELETE /v1/teams/admin/:id" "DELETE" "/v1/teams/admin/$created_team_id" 200 "" true
- fi
-}
-
-# ==============================================================================
-# DIMENTORIN ENDPOINTS - MENTORS
-# ==============================================================================
-test_mentors_comprehensive() {
- printf "\n${CYAN}=== Testing Mentors Endpoints (Comprehensive) ===${NC}\n"
-
- # Get Mentors List
- test_api_endpoint "GET /v1/mentors" "GET" "/v1/mentors" 200 "" true
- test_api_endpoint "GET /v1/mentors?page=1&limit=10" "GET" "/v1/mentors?page=1&limit=10" 200 "" true
- test_api_endpoint "GET /v1/mentors?search=mentor" "GET" "/v1/mentors?search=mentor" 200 "" true
-
- # Get Mentor By ID
- local test_mentor_id="mentor-001"
- test_api_endpoint "GET /v1/mentors/:id" "GET" "/v1/mentors/$test_mentor_id" 200 "" true
-
- # Get Mentor Me (requires mentor token)
- # test_api_endpoint "GET /v1/mentors/me" "GET" "/v1/mentors/me" 200 "" true
-
- # Get Mentor Status
- # test_api_endpoint "GET /v1/mentors/status" "GET" "/v1/mentors/status" 200 "" true
-
- # Register Mentor
- local register_mentor_data=$(jq -n '{
- expertise: ["Rust", "Backend"],
- bio: "Test mentor bio",
- linkedin_url: "https://linkedin.com/in/test",
- github_url: "https://github.com/test",
- portfolio_url: "https://test.com"
- }')
- # test_api_endpoint "POST /v1/mentors/register" "POST" "/v1/mentors/register" 201 "$register_mentor_data" true
-
- # Update Mentor (admin)
- # local update_mentor_data=$(jq -n '{...}')
- # test_api_endpoint "PUT /v1/mentors/:id" "PUT" "/v1/mentors/$test_mentor_id" 200 "$update_mentor_data" true
-
- # Verify Mentor (admin)
- local verify_data=$(jq -n '{is_verified: true}')
- test_api_endpoint "PUT /v1/mentors/:id/verify" "PUT" "/v1/mentors/$test_mentor_id/verify" 200 "$verify_data" true
-
- # Delete Mentor (admin)
- # test_api_endpoint "DELETE /v1/mentors/:id" "DELETE" "/v1/mentors/$test_mentor_id" 200 "" true
-}
-
-# ==============================================================================
-# CMS ENDPOINTS - EVENTS
-# ==============================================================================
-test_events_comprehensive() {
- printf "\n${CYAN}=== Testing Events Endpoints (Comprehensive) ===${NC}\n"
-
- # Public Endpoints
- test_api_endpoint "GET /v1/cms/landing/events" "GET" "/v1/cms/landing/events" 200 "" false
- test_api_endpoint "GET /v1/cms/landing/events?page=1&limit=10" "GET" "/v1/cms/landing/events?page=1&limit=10" 200 "" false
- test_api_endpoint "GET /v1/cms/landing/events?search=test" "GET" "/v1/cms/landing/events?search=test" 200 "" false
-
- # Get Event By ID
- # Need to get an event ID first
- local events_response=$(curl -s "$BASE_URL/v1/cms/landing/events")
- local test_event_id=$(echo "$events_response" | jq -r '.data[0].id // empty')
-
- if [ -n "$test_event_id" ]; then
- test_api_endpoint "GET /v1/cms/landing/events/:id" "GET" "/v1/cms/landing/events/$test_event_id" 200 "" false
- fi
-
- # Create Event (protected)
- local create_event_data=$(jq -n '{
- title: "Test Event '$(date +%s)'",
- description: "Test event description",
- event_date: "'$(date -u +%Y-%m-%dT%H:%M:%SZ)'",
- location: "Online",
- image_url: "https://example.com/image.jpg",
- is_online: true
- }')
- local create_event_response=$(test_api_endpoint "POST /v1/cms/landing/events/create" "POST" "/v1/cms/landing/events/create" 201 "$create_event_data" true)
- local created_event_id=$(echo "$create_event_response" | jq -r '.data.id // empty')
-
- if [ -n "$created_event_id" ]; then
- # Update Event
- local update_event_data=$(jq -n '{
- title: "Updated Test Event",
- description: "Updated description",
- event_date: "'$(date -u +%Y-%m-%dT%H:%M:%SZ)'",
- location: "Jakarta",
- is_online: false
- }')
- test_api_endpoint "PATCH /v1/cms/landing/events/:id" "PATCH" "/v1/cms/landing/events/$created_event_id" 200 "$update_event_data" true
-
- # Delete Event
- test_api_endpoint "DELETE /v1/cms/landing/events/:id" "DELETE" "/v1/cms/landing/events/$created_event_id" 200 "" true
- fi
-}
-
-# ==============================================================================
-# CMS ENDPOINTS - TESTIMONIALS
-# ==============================================================================
-test_testimonials_comprehensive() {
- printf "\n${CYAN}=== Testing Testimonials Endpoints (Comprehensive) ===${NC}\n"
-
- # Public Endpoints
- test_api_endpoint "GET /v1/cms/landing/testimonials" "GET" "/v1/cms/landing/testimonials" 200 "" false
- test_api_endpoint "GET /v1/cms/landing/testimonials?page=1&limit=10" "GET" "/v1/cms/landing/testimonials?page=1&limit=10" 200 "" false
-
- # Get Testimonial By ID
- local testimonials_response=$(curl -s "$BASE_URL/v1/cms/landing/testimonials")
- local test_testimonial_id=$(echo "$testimonials_response" | jq -r '.data[0].id // empty')
-
- if [ -n "$test_testimonial_id" ]; then
- test_api_endpoint "GET /v1/cms/landing/testimonials/:id" "GET" "/v1/cms/landing/testimonials/$test_testimonial_id" 200 "" false
- fi
-
- # Create Testimonial (protected)
- local create_testimonial_data=$(jq -n '{
- role: "Student",
- content: "Test testimonial content '$(date +%s)'"
- }')
- local create_testimonial_response=$(test_api_endpoint "POST /v1/cms/landing/testimonials/create" "POST" "/v1/cms/landing/testimonials/create" 201 "$create_testimonial_data" true)
- local created_testimonial_id=$(echo "$create_testimonial_response" | jq -r '.data.id // empty')
-
- if [ -n "$created_testimonial_id" ]; then
- # Update Testimonial
- local update_testimonial_data=$(jq -n '{
- role: "Alumni",
- content: "Updated testimonial content"
- }')
- test_api_endpoint "PATCH /v1/cms/landing/testimonials/:id" "PATCH" "/v1/cms/landing/testimonials/$created_testimonial_id" 200 "$update_testimonial_data" true
-
- # Delete Testimonial
- test_api_endpoint "DELETE /v1/cms/landing/testimonials/:id" "DELETE" "/v1/cms/landing/testimonials/$created_testimonial_id" 200 "" true
- fi
-}
-
-# ==============================================================================
-# GACHA ENDPOINTS
-# ==============================================================================
-test_gacha_comprehensive() {
- printf "\n${CYAN}=== Testing Gacha Endpoints (Comprehensive) ===${NC}\n"
-
- # Gacha Items
- test_api_endpoint "GET /v1/gacha/items" "GET" "/v1/gacha/items" 200 "" true
- test_api_endpoint "GET /v1/gacha/items?page=1&limit=10" "GET" "/v1/gacha/items?page=1&limit=10" 200 "" true
-
- # Get Gacha Item By ID
- local items_response=$(curl -s -H "Authorization: Bearer $AUTH_TOKEN" "$BASE_URL/v1/gacha/items")
- local test_item_id=$(echo "$items_response" | jq -r '.data[0].id // empty')
-
- if [ -n "$test_item_id" ]; then
- test_api_endpoint "GET /v1/gacha/items/:id" "GET" "/v1/gacha/items/$test_item_id" 200 "" true
- fi
-
- # Create Gacha Item
- local create_item_data=$(jq -n '{
- name: "Test Item '$(date +%s)'",
- description: "Test item description",
- rarity: "COMMON",
- image_url: "https://example.com/item.jpg",
- weight: 100
- }')
- local create_item_response=$(test_api_endpoint "POST /v1/gacha/items" "POST" "/v1/gacha/items" 201 "$create_item_data" true)
- local created_item_id=$(echo "$create_item_response" | jq -r '.data.id // empty')
-
- if [ -n "$created_item_id" ]; then
- # Update Gacha Item
- local update_item_data=$(jq -n '{
- name: "Updated Test Item",
- description: "Updated description",
- rarity: "RARE",
- weight: 50
- }')
- test_api_endpoint "PUT /v1/gacha/items/:id" "PUT" "/v1/gacha/items/$created_item_id" 200 "$update_item_data" true
-
- # Delete Gacha Item
- test_api_endpoint "DELETE /v1/gacha/items/:id" "DELETE" "/v1/gacha/items/$created_item_id" 200 "" true
- fi
-
- # Gacha Rolls
- test_api_endpoint "POST /v1/gacha/rolls" "POST" "/v1/gacha/rolls" 201 "{}" true
- test_api_endpoint "POST /v1/gacha/rolls/execute" "POST" "/v1/gacha/rolls/execute" 200 "{}" true
-
- # Gacha Credits (internal endpoints, may require special auth)
- # test_api_endpoint "GET /v1/gacha/credits" "GET" "/v1/gacha/credits" 200 "" true
- # test_api_endpoint "POST /v1/gacha/credits/add" "POST" "/v1/gacha/credits/add" 200 '{"amount": 10}' true
- # test_api_endpoint "POST /v1/gacha/credits/consume" "POST" "/v1/gacha/credits/consume" 200 '{"amount": 1}' true
-
- # Gacha Claims
- # test_api_endpoint "POST /v1/gacha/claims" "POST" "/v1/gacha/claims" 201 "{}" true
-}
-
-# ==============================================================================
-# HACKATHON ENDPOINTS
-# ==============================================================================
-test_hackathon_comprehensive() {
- printf "\n${CYAN}=== Testing Hackathon Endpoints (Comprehensive) ===${NC}\n"
-
- # Get Hackathons
- test_api_endpoint "GET /v1/hackathons" "GET" "/v1/hackathons" 200 "" false
- test_api_endpoint "GET /v1/hackathons?page=1&limit=10" "GET" "/v1/hackathons?page=1&limit=10" 200 "" false
-
- # Create Hackathon
- local create_hackathon_data=$(jq -n '{
- title: "Test Hackathon '$(date +%s)'",
- description: "Test hackathon description",
- start_date: "'$(date -u +%Y-%m-%dT%H:%M:%SZ)'",
- end_date: "'$(date -u -d '+7 days' +%Y-%m-%dT%H:%M:%SZ)'",
- registration_deadline: "'$(date -u -d '+1 day' +%Y-%m-%dT%H:%M:%SZ)'",
- max_teams: 100,
- max_team_size: 5
- }')
- local create_hackathon_response=$(test_api_endpoint "POST /v1/hackathons" "POST" "/v1/hackathons" 201 "$create_hackathon_data" true)
- local created_hackathon_id=$(echo "$create_hackathon_response" | jq -r '.data.id // empty')
-
- if [ -n "$created_hackathon_id" ]; then
- # Get Hackathon By ID
- test_api_endpoint "GET /v1/hackathons/:id" "GET" "/v1/hackathons/$created_hackathon_id" 200 "" false
-
- # Update Hackathon
- local update_hackathon_data=$(jq -n '{
- title: "Updated Test Hackathon",
- description: "Updated description",
- max_teams: 150
- }')
- test_api_endpoint "PUT /v1/hackathons/:id" "PUT" "/v1/hackathons/$created_hackathon_id" 200 "$update_hackathon_data" true
-
- # Hackathon Events
- local create_event_data=$(jq -n --arg hackathon_id "$created_hackathon_id" '{
- hackathon_id: $hackathon_id,
- title: "Test Event",
- description: "Test event description",
- event_date: "'$(date -u +%Y-%m-%dT%H:%M:%SZ)'",
- location: "Online",
- is_mandatory: false
- }')
- local create_event_response=$(test_api_endpoint "POST /v1/hackathons/:id/events" "POST" "/v1/hackathons/$created_hackathon_id/events" 201 "$create_event_data" true)
- local created_event_id=$(echo "$create_event_response" | jq -r '.data.id // empty')
-
- if [ -n "$created_event_id" ]; then
- # Update Event
- local update_event_data=$(jq -n '{
- title: "Updated Test Event",
- is_mandatory: true
- }')
- test_api_endpoint "PUT /v1/hackathons/events/:id" "PUT" "/v1/hackathons/events/$created_event_id" 200 "$update_event_data" true
-
- # Delete Event
- test_api_endpoint "DELETE /v1/hackathons/events/:id" "DELETE" "/v1/hackathons/events/$created_event_id" 200 "" true
- fi
-
- # Hackathon Timeline
- local create_timeline_data=$(jq -n --arg hackathon_id "$created_hackathon_id" '{
- hackathon_id: $hackathon_id,
- phase_name: "Registration",
- description: "Registration phase",
- start_date: "'$(date -u +%Y-%m-%dT%H:%M:%SZ)'",
- end_date: "'$(date -u -d '+1 day' +%Y-%m-%dT%H:%M:%SZ)'",
- allowed_operations: ["REGISTER"]
- }')
- local create_timeline_response=$(test_api_endpoint "POST /v1/hackathons/:id/timeline" "POST" "/v1/hackathons/$created_hackathon_id/timeline" 201 "$create_timeline_data" true)
- local created_timeline_id=$(echo "$create_timeline_response" | jq -r '.data.id // empty')
-
- if [ -n "$created_timeline_id" ]; then
- # Update Timeline
- local update_timeline_data=$(jq -n '{
- phase_name: "Updated Registration",
- description: "Updated description"
- }')
- test_api_endpoint "PUT /v1/hackathons/timeline/:id" "PUT" "/v1/hackathons/timeline/$created_timeline_id" 200 "$update_timeline_data" true
-
- # Delete Timeline
- test_api_endpoint "DELETE /v1/hackathons/timeline/:id" "DELETE" "/v1/hackathons/timeline/$created_timeline_id" 200 "" true
- fi
-
- # Hackathon Submissions
- # test_api_endpoint "GET /v1/hackathons/:id/submissions" "GET" "/v1/hackathons/$created_hackathon_id/submissions" 200 "" true
- # test_api_endpoint "GET /v1/hackathons/submissions/me" "GET" "/v1/hackathons/submissions/me" 200 "" true
-
- # Admin Results
- # test_api_endpoint "GET /v1/hackathons/:id/results" "GET" "/v1/hackathons/$created_hackathon_id/results" 200 "" true
-
- # Public Results
- # test_api_endpoint "GET /v1/hackathons/:id/results/public" "GET" "/v1/hackathons/$created_hackathon_id/results/public" 200 "" false
-
- # Delete Hackathon
- test_api_endpoint "DELETE /v1/hackathons/:id" "DELETE" "/v1/hackathons/$created_hackathon_id" 200 "" true
- fi
-}
-
-# ==============================================================================
-# MAIN EXECUTION
-# ==============================================================================
-main() {
- printf "\n${CYAN}========================================${NC}\n"
- printf "${CYAN} IMPHNEN Comprehensive API Test Suite${NC}\n"
- printf "${CYAN}========================================${NC}\n\n"
-
- write_test_log "INFO" "Starting comprehensive API tests..."
- write_test_log "INFO" "Base URL: $BASE_URL"
-
- # Get authentication token first
- get_auth_token
-
- if [ -z "$AUTH_TOKEN" ]; then
- write_test_log "ERROR" "Failed to get auth token. Cannot proceed with protected endpoint tests."
- exit 1
- fi
-
- # Run all comprehensive tests
- test_auth_comprehensive
- test_users_comprehensive
- test_roles_comprehensive
- test_permissions_comprehensive
- test_teams_comprehensive
- test_mentors_comprehensive
- test_events_comprehensive
- test_testimonials_comprehensive
- test_gacha_comprehensive
- test_hackathon_comprehensive
-
- # Print summary
- local total_tests=$((PASS_COUNT + FAIL_COUNT))
- local success_rate=0
- if [ "$total_tests" -gt 0 ]; then
- success_rate=$(( (PASS_COUNT * 100) / total_tests ))
- fi
-
- printf "\n${CYAN}========================================${NC}\n"
- printf "${CYAN} Test Summary${NC}\n"
- printf "${CYAN}========================================${NC}\n"
- printf "Total Tests: %d\n" "$total_tests"
- printf "${GREEN}Passed: %d${NC}\n" "$PASS_COUNT"
- printf "${RED}Failed: %d${NC}\n" "$FAIL_COUNT"
- printf "Success Rate: %d%%\n\n" "$success_rate"
-
- if [ "$FAIL_COUNT" -gt 0 ]; then
- printf "${RED}Failed Tests:${NC}\n"
- for summary in "${FAILED_TESTS_SUMMARY[@]}"; do
- printf " %s\n" "$summary"
- done
- printf "\n"
- exit 1
- else
- printf "${GREEN}All tests passed!${NC}\n\n"
- exit 0
- fi
-}
-
-# Run main function
-main "$@"
diff --git a/tests/cms/test-cms.sh b/tests/cms/test-cms.sh
index 6ab7fb6..a8b6ae8 100644
--- a/tests/cms/test-cms.sh
+++ b/tests/cms/test-cms.sh
@@ -15,6 +15,9 @@ test_events_endpoints() {
test_api_endpoint "GET Events (Search)" "GET" "/v1/cms/landing/events?search=test" 200 "" false
test_api_endpoint "GET Events (Filter Online)" "GET" "/v1/cms/landing/events?filter=online" 200 "" false
+ # Security: Test SQL injection in search
+ test_api_endpoint "GET Events with SQL Injection (Should Be Safe)" "GET" "/v1/cms/landing/events?search=' OR '1'='1" 200 "" false
+
# Get event by ID - use correct endpoint /detail/{id}
local events_response=$(curl -s "$BASE_URL/v1/cms/landing/events")
local test_event_id=$(echo "$events_response" | jq -r '.data[0].id // empty')
@@ -23,8 +26,20 @@ test_events_endpoints() {
test_api_endpoint "GET Event By ID" "GET" "/v1/cms/landing/events/detail/$test_event_id" 200 "" false
fi
- # Create event (protected) - use correct field name
+ # Security: Test that create endpoint requires authentication
local create_event_data=$(jq -n '{
+ name: "Unauthorized Event '$(date +%s)'",
+ description: "Should not be created",
+ start_date: "'$(date -u +%Y-%m-%dT%H:%M:%SZ)'",
+ end_date: "'$(date -u -d '+2 hours' +%Y-%m-%dT%H:%M:%SZ)'",
+ detail_link: "https://example.com/event",
+ price: 0,
+ is_online: true
+ }')
+ test_api_endpoint "POST Create Event without Auth (Should Fail)" "POST" "/v1/cms/landing/events/create" 401 "$create_event_data" false
+
+ # Create event (protected) - use correct field name
+ create_event_data=$(jq -n '{
name: "Test Event '$(date +%s)'",
description: "Auto-generated test event",
start_date: "'$(date -u +%Y-%m-%dT%H:%M:%SZ)'",
@@ -37,6 +52,14 @@ test_events_endpoints() {
local created_event_id=$(echo "$create_event_response" | jq -r '.data.id // empty')
if [ -n "$created_event_id" ]; then
+ # Security: Test XSS in event name
+ local xss_event_data=$(jq -n --arg id "$created_event_id" '{
+ name: "",
+ description: "XSS test",
+ is_online: false
+ }')
+ test_api_endpoint "PATCH Update Event with XSS (Should Be Sanitized)" "PATCH" "/v1/cms/landing/events/update/$created_event_id" 200 "$xss_event_data" true
+
# Update event - use correct endpoint /update/{id} with PATCH
local update_event_data=$(jq -n '{
name: "Updated Test Event",
@@ -45,8 +68,19 @@ test_events_endpoints() {
}')
test_api_endpoint "PATCH Update Event" "PATCH" "/v1/cms/landing/events/update/$created_event_id" 200 "$update_event_data" true
+ # Security: Test unauthorized update
+ local saved_token="$AUTH_TOKEN"
+ AUTH_TOKEN=""
+ test_api_endpoint "PATCH Update Event without Auth (Should Fail)" "PATCH" "/v1/cms/landing/events/update/$created_event_id" 401 "$update_event_data" false
+ AUTH_TOKEN="$saved_token"
+
# Delete event - use correct endpoint /delete/{id}
test_api_endpoint "DELETE Event" "DELETE" "/v1/cms/landing/events/delete/$created_event_id" 200 "" true
+
+ # Security: Test unauthorized delete
+ AUTH_TOKEN=""
+ test_api_endpoint "DELETE Event without Auth (Should Fail)" "DELETE" "/v1/cms/landing/events/delete/$created_event_id" 401 "" false
+ AUTH_TOKEN="$saved_token"
fi
}
@@ -58,6 +92,9 @@ test_testimonials_endpoints() {
test_api_endpoint "GET Testimonials (Paginated)" "GET" "/v1/cms/landing/testimonials?page=1&limit=10" 200 "" false
test_api_endpoint "GET Testimonials (Search)" "GET" "/v1/cms/landing/testimonials?search=test" 200 "" false
+ # Security: Test SQL injection in search
+ test_api_endpoint "GET Testimonials with SQL Injection (Should Be Safe)" "GET" "/v1/cms/landing/testimonials?search=' OR '1'='1" 200 "" false
+
# Get testimonial by ID - use correct endpoint /detail/{id}
local testimonials_response=$(curl -s "$BASE_URL/v1/cms/landing/testimonials")
local test_testimonial_id=$(echo "$testimonials_response" | jq -r '.data[0].id // empty')
@@ -66,6 +103,13 @@ test_testimonials_endpoints() {
test_api_endpoint "GET Testimonial By ID" "GET" "/v1/cms/landing/testimonials/detail/$test_testimonial_id" 200 "" false
fi
+ # Security: Test that create endpoint requires authentication
+ local unauth_testimonial_data=$(jq -n '{
+ role: "Hacker",
+ content: "Unauthorized testimonial"
+ }')
+ test_api_endpoint "POST Create Testimonial without Auth (Should Fail)" "POST" "/v1/cms/landing/testimonials/create" 401 "$unauth_testimonial_data" false
+
# Create testimonial (protected)
local create_testimonial_data=$(jq -n '{
role: "Student",
@@ -75,6 +119,13 @@ test_testimonials_endpoints() {
local created_testimonial_id=$(echo "$create_testimonial_response" | jq -r '.data.id // empty')
if [ -n "$created_testimonial_id" ]; then
+ # Security: Test XSS in testimonial content
+ local xss_testimonial_data=$(jq -n '{
+ role: "Student",
+ content: ""
+ }')
+ test_api_endpoint "PATCH Update Testimonial with XSS (Should Be Sanitized)" "PATCH" "/v1/cms/landing/testimonials/update/$created_testimonial_id" 200 "$xss_testimonial_data" true
+
# Update testimonial - use correct endpoint /update/{id} with PATCH
local update_testimonial_data=$(jq -n '{
role: "Alumni",
@@ -82,8 +133,17 @@ test_testimonials_endpoints() {
}')
test_api_endpoint "PATCH Update Testimonial" "PATCH" "/v1/cms/landing/testimonials/update/$created_testimonial_id" 200 "$update_testimonial_data" true
+ # Security: Test unauthorized update
+ local saved_token="$AUTH_TOKEN"
+ AUTH_TOKEN=""
+ test_api_endpoint "PATCH Update Testimonial without Auth (Should Fail)" "PATCH" "/v1/cms/landing/testimonials/update/$created_testimonial_id" 401 "$update_testimonial_data" false
+ AUTH_TOKEN="$saved_token"
+
# Delete testimonial - use correct endpoint /delete/{id}
test_api_endpoint "DELETE Testimonial" "DELETE" "/v1/cms/landing/testimonials/delete/$created_testimonial_id" 200 "" true
+
+ # Security: Test that non-existent resource returns proper error
+ test_api_endpoint "DELETE Non-existent Testimonial (Should Fail)" "DELETE" "/v1/cms/landing/testimonials/delete/00000000-0000-0000-0000-000000000000" 404 "" true
fi
}
diff --git a/tests/iam/test-auth.sh b/tests/iam/test-auth.sh
index 0cf5de6..3e45df8 100644
--- a/tests/iam/test-auth.sh
+++ b/tests/iam/test-auth.sh
@@ -17,20 +17,55 @@ test_authentication_endpoints() {
invalid_login=$(jq -n '{email: "invalid@example.com", password: "wrongpassword"}')
test_api_endpoint "Invalid Login Test" "POST" "/v1/auth/login" 401 "$invalid_login"
+ # Security: Test SQL injection in login
+ local sql_injection_login=$(jq -n '{email: "admin@example.com\" OR \"1\"=\"1", password: "password"}')
+ test_api_endpoint "SQL Injection in Login Email (Should Fail)" "POST" "/v1/auth/login" 401 "$sql_injection_login"
+
+ local sql_injection_pass=$(jq -n '{email: "admin@example.com", password: "password\" OR \"1\"=\"1"}')
+ test_api_endpoint "SQL Injection in Login Password (Should Fail)" "POST" "/v1/auth/login" 401 "$sql_injection_pass"
+
+ # Security: Test XSS in login
+ local xss_login=$(jq -n '{email: "", password: "password"}')
+ test_api_endpoint "XSS in Login Email (Should Fail)" "POST" "/v1/auth/login" 401 "$xss_login"
+
+ # Security: Test empty credentials
+ local empty_login=$(jq -n '{email: "", password: ""}')
+ test_api_endpoint "Empty Credentials (Should Fail)" "POST" "/v1/auth/login" 400 "$empty_login"
+
+ # Security: Test missing fields
+ local missing_password=$(jq -n '{email: "admin@example.com"}')
+ test_api_endpoint "Missing Password (Should Fail)" "POST" "/v1/auth/login" 400 "$missing_password"
+
# Mentor login
local mentor_login=$(jq -n '{email: "mentor@example.com", password: "password"}')
test_api_endpoint "Mentor Login" "POST" "/v1/auth/login-mentor" 200 "$mentor_login" false
+ # Security: Test invalid mentor login
+ local invalid_mentor=$(jq -n '{email: "nonexistent@example.com", password: "wrongpass"}')
+ test_api_endpoint "Invalid Mentor Login (Should Fail)" "POST" "/v1/auth/login-mentor" 401 "$invalid_mentor"
+
# Forgot password
local forgot_password_data
forgot_password_data=$(jq -n --arg email "admin@example.com" '{email: $email}')
test_api_endpoint "Forgot Password Test" "POST" "/v1/auth/forgot" 200 "$forgot_password_data"
+ # Security: Test forgot password with invalid email
+ local invalid_forgot=$(jq -n '{email: "not_an_email"}')
+ test_api_endpoint "Forgot Password with Invalid Email (Should Fail)" "POST" "/v1/auth/forgot" 400 "$invalid_forgot"
+
+ # Security: Test forgot password with non-existent email (should not reveal if user exists)
+ local nonexistent_forgot=$(jq -n '{email: "nonexistent@example.com"}')
+ test_api_endpoint "Forgot Password with Non-existent Email" "POST" "/v1/auth/forgot" 200 "$nonexistent_forgot"
+
# Invalid new password (invalid token)
local new_password_data
new_password_data=$(jq -n --arg token "some_reset_token" --arg pass "newpassword123!A" '{token: $token, password: $pass}')
test_api_endpoint "New Password Test (Invalid Token)" "POST" "/v1/auth/new-password" 400 "$new_password_data"
+ # Security: Test weak password in reset
+ local weak_reset=$(jq -n --arg token "some_reset_token" '{token: $token, password: "123456"}')
+ test_api_endpoint "New Password with Weak Password (Should Fail)" "POST" "/v1/auth/new-password" 400 "$weak_reset"
+
# Refresh token
local refresh_token=$(curl -s -X POST -H "Content-Type: application/json" \
-d "$(jq -n '{email: "admin@example.com", password: "password"}')" \
@@ -40,6 +75,14 @@ test_authentication_endpoints() {
local refresh_data
refresh_data=$(jq -n --arg token "$refresh_token" '{refresh_token: $token}')
test_api_endpoint "Refresh Token Test" "POST" "/v1/auth/refresh" 200 "$refresh_data"
+
+ # Security: Test invalid refresh token
+ local invalid_refresh=$(jq -n '{refresh_token: "invalid_token_12345"}')
+ test_api_endpoint "Invalid Refresh Token (Should Fail)" "POST" "/v1/auth/refresh" 401 "$invalid_refresh"
+
+ # Security: Test expired/malformed refresh token
+ local malformed_refresh=$(jq -n '{refresh_token: "Bearer.malformed.token"}')
+ test_api_endpoint "Malformed Refresh Token (Should Fail)" "POST" "/v1/auth/refresh" 401 "$malformed_refresh"
else
write_test_log "WARN" "✗ Refresh Token Test - Dilewati: Refresh token tidak tersedia dari login"
fi
@@ -48,6 +91,10 @@ test_authentication_endpoints() {
local resend_data=$(jq -n '{email: "admin@example.com"}')
test_api_endpoint "Resend OTP" "POST" "/v1/auth/send-otp" 200 "$resend_data" false
+ # Security: Test resend OTP with invalid email
+ local invalid_otp=$(jq -n '{email: "not_an_email"}')
+ test_api_endpoint "Resend OTP with Invalid Email (Should Fail)" "POST" "/v1/auth/send-otp" 400 "$invalid_otp"
+
# Logout (skip - endpoint may not exist)
# test_api_endpoint "Logout" "POST" "/v1/auth/logout" 200 "" true
}
diff --git a/tests/iam/test-roles-permissions.sh b/tests/iam/test-roles-permissions.sh
index 3637ff2..30efc81 100644
--- a/tests/iam/test-roles-permissions.sh
+++ b/tests/iam/test-roles-permissions.sh
@@ -13,10 +13,20 @@ test_roles_and_permissions() {
test_api_endpoint "GET Roles List" "GET" "/v1/roles" 200 "" true
test_api_endpoint "GET Roles (Paginated)" "GET" "/v1/roles?page=1&limit=10" 200 "" true
+ # Security: Test unauthorized access to roles
+ local saved_token="$AUTH_TOKEN"
+ AUTH_TOKEN=""
+ test_api_endpoint "GET Roles without Auth (Should Fail)" "GET" "/v1/roles" 401 "" false
+ AUTH_TOKEN="$saved_token"
+
# Get role by ID - use correct endpoint /detail/{id}
local test_role_id="5713cb37-dc02-4e87-8048-d7a41d352059"
test_api_endpoint "GET Role By ID" "GET" "/v1/roles/detail/$test_role_id" 200 "" true
+ # Security: Test access to non-existent role
+ local fake_role_id="00000000-0000-0000-0000-000000000000"
+ test_api_endpoint "GET Non-existent Role (Should Fail)" "GET" "/v1/roles/detail/$fake_role_id" 404 "" true
+
# Create role - use correct endpoint /create
local create_role_data=$(jq -n '{
name: "Test Role '$(date +%s)'",
@@ -27,6 +37,9 @@ test_roles_and_permissions() {
local created_role_id=$(echo "$create_role_response" | jq -r '.data.id // empty')
if [ -n "$created_role_id" ]; then
+ # Security: Test duplicate role creation
+ test_api_endpoint "POST Create Duplicate Role (Should Fail)" "POST" "/v1/roles/create" 400 "$create_role_data" true
+
# Update role - use correct endpoint /update/{id}
local update_role_data=$(jq -n --arg ts "$EPOCHSECONDS" '{
name: ("Updated Test Role " + $ts),
@@ -35,14 +48,27 @@ test_roles_and_permissions() {
}')
test_api_endpoint "PUT Update Role" "PUT" "/v1/roles/update/$created_role_id" 200 "$update_role_data" true
+ # Security: Test unauthorized update
+ AUTH_TOKEN=""
+ test_api_endpoint "PUT Update Role without Auth (Should Fail)" "PUT" "/v1/roles/update/$created_role_id" 401 "$update_role_data" false
+ AUTH_TOKEN="$saved_token"
+
# Delete role - use correct endpoint /delete/{id}
test_api_endpoint "DELETE Role" "DELETE" "/v1/roles/delete/$created_role_id" 200 "" true
+
+ # Security: Test double delete
+ test_api_endpoint "DELETE Already Deleted Role (Should Fail)" "DELETE" "/v1/roles/delete/$created_role_id" 404 "" true
fi
# Permissions
test_api_endpoint "GET Permissions List" "GET" "/v1/permissions" 200 "" true
test_api_endpoint "GET Permissions (Paginated)" "GET" "/v1/permissions?page=1&limit=10" 200 "" true
+ # Security: Test unauthorized access to permissions
+ AUTH_TOKEN=""
+ test_api_endpoint "GET Permissions without Auth (Should Fail)" "GET" "/v1/permissions" 401 "" false
+ AUTH_TOKEN="$saved_token"
+
# Get permission by ID - use correct endpoint /detail/{id}
local test_perm_id="023e2dfe-93c3-4008-94a8-b5dff403f73b"
test_api_endpoint "GET Permission By ID" "GET" "/v1/permissions/detail/$test_perm_id" 200 "" true
diff --git a/tests/iam/test-security.sh b/tests/iam/test-security.sh
new file mode 100644
index 0000000..ead9e81
--- /dev/null
+++ b/tests/iam/test-security.sh
@@ -0,0 +1,590 @@
+#!/bin/bash
+
+# ==============================================================================
+# IAM Tests - Security & Authorization Tests
+# ==============================================================================
+
+source "$(dirname "$0")/../common/test-common.sh"
+
+test_unauthorized_access() {
+ printf "\n${CYAN}=== Testing Unauthorized Access ===${NC}\n"
+
+ # Test protected endpoints without authentication token
+ test_api_endpoint "GET Users without Auth" "GET" "/v1/users" 401 "" false
+ test_api_endpoint "GET User Me without Auth" "GET" "/v1/users/me" 401 "" false
+ test_api_endpoint "GET Roles without Auth" "GET" "/v1/roles" 401 "" false
+ test_api_endpoint "GET Permissions without Auth" "GET" "/v1/permissions" 401 "" false
+ test_api_endpoint "GET Teams Admin without Auth" "GET" "/v1/teams/admin" 401 "" false
+ test_api_endpoint "GET Mentors without Auth" "GET" "/v1/mentors" 401 "" false
+
+ # Test CMS endpoints - some may return 404 if not implemented
+ local cms_response=$(curl -s -w "\n%{http_code}" "$BASE_URL/v1/cms/events")
+ local cms_code=$(echo "$cms_response" | tail -1)
+ if [ "$cms_code" = "401" ] || [ "$cms_code" = "404" ]; then
+ write_test_log "SUCCESS" "✓ CMS Events endpoint properly protected or not implemented (code: $cms_code)"
+ else
+ write_test_log "WARN" "✗ CMS Events endpoint returned unexpected code: $cms_code"
+ fi
+
+ test_api_endpoint "GET Gacha Items without Auth" "GET" "/v1/gacha/items" 401 "" false
+
+ # Hackathon admin endpoint may return 404 if not implemented
+ local hackathon_response=$(curl -s -w "\n%{http_code}" "$BASE_URL/v1/hackathon")
+ local hackathon_code=$(echo "$hackathon_response" | tail -1)
+ if [ "$hackathon_code" = "401" ] || [ "$hackathon_code" = "404" ]; then
+ write_test_log "SUCCESS" "✓ Hackathon endpoint properly protected or not implemented (code: $hackathon_code)"
+ else
+ write_test_log "WARN" "✗ Hackathon endpoint returned unexpected code: $hackathon_code"
+ fi
+}
+
+test_invalid_token_access() {
+ printf "\n${CYAN}=== Testing Invalid/Expired Token Access ===${NC}\n"
+
+ # Save the original token
+ local original_token="$AUTH_TOKEN"
+
+ # Test with invalid token
+ AUTH_TOKEN="invalid_token_12345"
+ test_api_endpoint "GET Users with Invalid Token" "GET" "/v1/users" 401 "" true
+ test_api_endpoint "GET User Me with Invalid Token" "GET" "/v1/users/me" 401 "" true
+
+ # Test with malformed token
+ AUTH_TOKEN="Bearer.malformed.token"
+ test_api_endpoint "GET Users with Malformed Token" "GET" "/v1/users" 401 "" true
+
+ # Test with empty token
+ AUTH_TOKEN=""
+ test_api_endpoint "GET Users with Empty Token" "GET" "/v1/users" 401 "" true
+
+ # Restore original token
+ AUTH_TOKEN="$original_token"
+}
+
+test_role_based_access_control() {
+ printf "\n${CYAN}=== Testing Role-Based Access Control ===${NC}\n"
+
+ # Create a regular user (non-admin) and try to access admin endpoints
+ local regular_user_email="regular_user_$(date +%s)@example.com"
+ local create_user_data=$(jq -n \
+ --arg email "$regular_user_email" \
+ --arg pass "RegularUser123!" \
+ --arg fullname "Regular User Test" \
+ '{
+ email: $email,
+ password: $pass,
+ fullname: $fullname,
+ phone_number: "081234567890",
+ is_active: true,
+ role_id: "5713cb37-dc02-4e87-8048-d7a41d352059"
+ }')
+
+ local create_response=$(curl -s -X POST \
+ -H "Content-Type: application/json" \
+ -H "Authorization: Bearer $AUTH_TOKEN" \
+ -d "$create_user_data" \
+ "$BASE_URL/v1/users/create")
+
+ local created_user_id=$(echo "$create_response" | jq -r '.data.id // empty')
+
+ if [ -n "$created_user_id" ]; then
+ # Login as regular user
+ local user_login=$(jq -n --arg email "$regular_user_email" --arg pass "RegularUser123!" '{email: $email, password: $pass}')
+ local login_response=$(curl -s -X POST \
+ -H "Content-Type: application/json" \
+ -d "$user_login" \
+ "$BASE_URL/v1/auth/login")
+
+ local user_token=$(echo "$login_response" | jq -r '.data.token.access_token // empty')
+
+ if [ -n "$user_token" ]; then
+ # Save admin token
+ local admin_token="$AUTH_TOKEN"
+ AUTH_TOKEN="$user_token"
+
+ # Try to access admin endpoints with regular user token
+ test_api_endpoint "Regular User Access Admin Teams" "GET" "/v1/teams/admin" 403 "" true
+
+ # Try to create role - endpoint might be POST /v1/roles/create with 403 or POST /v1/roles with 405
+ local create_role_response=$(curl -s -w "\n%{http_code}" -X POST \
+ -H "Content-Type: application/json" \
+ -H "Authorization: Bearer $user_token" \
+ -d '{"name":"test_role","description":"test","permissions":[]}' \
+ "$BASE_URL/v1/roles/create")
+ local role_code=$(echo "$create_role_response" | tail -1)
+ if [ "$role_code" = "403" ] || [ "$role_code" = "405" ]; then
+ write_test_log "SUCCESS" "✓ Regular User Create Role properly denied (code: $role_code)"
+ else
+ write_test_log "ERROR" "✗ Regular User Create Role not properly denied (code: $role_code)"
+ fi
+
+ test_api_endpoint "Regular User Delete User" "DELETE" "/v1/users/delete/$created_user_id" 403 "" true
+
+ # Regular user should be able to access their own profile
+ test_api_endpoint "Regular User Access Own Profile" "GET" "/v1/users/me" 200 "" true
+
+ # Restore admin token
+ AUTH_TOKEN="$admin_token"
+ else
+ write_test_log "WARN" "Failed to login as regular user for RBAC tests"
+ fi
+
+ # Cleanup: Delete the created user
+ curl -s -X DELETE \
+ -H "Authorization: Bearer $AUTH_TOKEN" \
+ "$BASE_URL/v1/users/delete/$created_user_id" > /dev/null
+ else
+ write_test_log "WARN" "Failed to create regular user for RBAC tests"
+ fi
+}
+
+test_csrf_and_headers() {
+ printf "\n${CYAN}=== Testing CSRF and Security Headers ===${NC}\n"
+
+ # Test that server returns appropriate security headers
+ local response_headers=$(curl -s -I "$BASE_URL/v1/auth/login")
+
+ # Check for security headers (these may vary based on your implementation)
+ if echo "$response_headers" | grep -iq "X-Content-Type-Options"; then
+ write_test_log "SUCCESS" "✓ X-Content-Type-Options header present"
+ else
+ write_test_log "WARN" "✗ X-Content-Type-Options header missing"
+ fi
+
+ if echo "$response_headers" | grep -iq "X-Frame-Options"; then
+ write_test_log "SUCCESS" "✓ X-Frame-Options header present"
+ else
+ write_test_log "WARN" "✗ X-Frame-Options header missing"
+ fi
+
+ # Test CORS headers
+ local cors_response=$(curl -s -I -H "Origin: https://malicious-site.com" "$BASE_URL/v1/auth/login")
+ if echo "$cors_response" | grep -iq "Access-Control-Allow-Origin"; then
+ write_test_log "INFO" "CORS headers present - verify configuration"
+ fi
+}
+
+test_sql_injection_attempts() {
+ printf "\n${CYAN}=== Testing SQL Injection Protection ===${NC}\n"
+
+ # Test SQL injection in login - should fail validation (400) or auth (401)
+ local sql_injection_login=$(jq -n '{email: "admin@example.com\" OR \"1\"=\"1", password: "password"}')
+ local response=$(curl -s -w "\n%{http_code}" -X POST \
+ -H "Content-Type: application/json" \
+ -d "$sql_injection_login" \
+ "$BASE_URL/v1/auth/login")
+ local http_code=$(echo "$response" | tail -1)
+ if [ "$http_code" = "400" ] || [ "$http_code" = "401" ]; then
+ write_test_log "SUCCESS" "✓ SQL Injection in Login Email properly rejected (code: $http_code)"
+ else
+ write_test_log "ERROR" "✗ SQL Injection in Login Email not properly handled (code: $http_code)"
+ fi
+
+ local sql_injection_pass=$(jq -n '{email: "admin@example.com", password: "password\" OR \"1\"=\"1"}')
+ test_api_endpoint "SQL Injection in Login Password" "POST" "/v1/auth/login" 401 "$sql_injection_pass" false
+
+ # Test SQL injection in search parameters - properly URL encode
+ local search_injection=$(printf "%s" "admin' OR '1'='1" | jq -sRr @uri)
+ local response=$(curl -s -w "\n%{http_code}" \
+ -H "Authorization: Bearer $AUTH_TOKEN" \
+ "$BASE_URL/v1/users?search=$search_injection")
+ local http_code=$(echo "$response" | tail -1)
+ if [ "$http_code" = "200" ]; then
+ local body=$(echo "$response" | sed '$d')
+ # Check if it returned all users or properly filtered
+ local count=$(echo "$body" | jq '.data | length' 2>/dev/null || echo "0")
+ write_test_log "SUCCESS" "✓ SQL Injection in User Search handled safely (returned $count users)"
+ else
+ write_test_log "WARN" "✗ SQL Injection in User Search failed (code: $http_code)"
+ fi
+
+ # Test UNION injection
+ local union_injection=$(printf "%s" "' UNION SELECT * FROM users--" | jq -sRr @uri)
+ local response=$(curl -s -w "\n%{http_code}" \
+ -H "Authorization: Bearer $AUTH_TOKEN" \
+ "$BASE_URL/v1/users?search=$union_injection")
+ local http_code=$(echo "$response" | tail -1)
+ if [ "$http_code" = "200" ]; then
+ write_test_log "SUCCESS" "✓ SQL Injection UNION attack handled safely"
+ else
+ write_test_log "WARN" "✗ SQL Injection UNION test failed (code: $http_code)"
+ fi
+
+ # Test sort injection
+ local sort_injection=$(printf "%s" "email; DROP TABLE users--" | jq -sRr @uri)
+ local response=$(curl -s -w "\n%{http_code}" \
+ -H "Authorization: Bearer $AUTH_TOKEN" \
+ "$BASE_URL/v1/users?sort_by=$sort_injection")
+ local http_code=$(echo "$response" | tail -1)
+ if [ "$http_code" = "200" ] || [ "$http_code" = "400" ]; then
+ write_test_log "SUCCESS" "✓ SQL Injection in Sort Parameter handled safely (code: $http_code)"
+ else
+ write_test_log "WARN" "✗ SQL Injection in Sort test failed (code: $http_code)"
+ fi
+}
+
+test_xss_attempts() {
+ printf "\n${CYAN}=== Testing XSS Protection ===${NC}\n"
+
+ # Create user with XSS payloads
+ local xss_email="xss_test_$(date +%s)@example.com"
+ local xss_user_data=$(jq -n \
+ --arg email "$xss_email" \
+ --arg fullname "" \
+ --arg phone "
" \
+ '{
+ email: $email,
+ password: "Test123!SecurePass",
+ fullname: $fullname,
+ phone_number: $phone,
+ is_active: true,
+ role_id: "5713cb37-dc02-4e87-8048-d7a41d352059"
+ }')
+
+ local xss_response=$(curl -s -X POST \
+ -H "Content-Type: application/json" \
+ -H "Authorization: Bearer $AUTH_TOKEN" \
+ -d "$xss_user_data" \
+ "$BASE_URL/v1/users/create")
+
+ local xss_user_id=$(echo "$xss_response" | jq -r '.data.id // empty')
+
+ if [ -n "$xss_user_id" ]; then
+ # Retrieve the user and check if XSS payload is escaped/sanitized
+ local get_user_response=$(curl -s \
+ -H "Authorization: Bearer $AUTH_TOKEN" \
+ "$BASE_URL/v1/users/detail/$xss_user_id")
+
+ local fullname=$(echo "$get_user_response" | jq -r '.data.fullname // empty')
+
+ # Check if dangerous characters are escaped or removed
+ if [[ "$fullname" == *""* ]]; then
+ write_test_log "ERROR" "✗ XSS payload not sanitized in fullname - SECURITY RISK!"
+ elif [[ "$fullname" == *"<script>"* ]] || [[ "$fullname" != *"<"* ]]; then
+ write_test_log "SUCCESS" "✓ XSS payload properly handled in fullname (escaped or stripped)"
+ else
+ write_test_log "SUCCESS" "✓ XSS payload handled in fullname (modified: $fullname)"
+ fi
+
+ # Cleanup
+ curl -s -X DELETE \
+ -H "Authorization: Bearer $AUTH_TOKEN" \
+ "$BASE_URL/v1/users/delete/$xss_user_id" > /dev/null
+ else
+ write_test_log "WARN" "Could not create user with XSS payload to test sanitization"
+ fi
+}
+
+test_rate_limiting() {
+ printf "\n${CYAN}=== Testing Rate Limiting ===${NC}\n"
+
+ # Test rapid login attempts
+ write_test_log "INFO" "Testing rapid login attempts (rate limiting)..."
+
+ local rate_limit_triggered=false
+ for i in {1..20}; do
+ local response=$(curl -s -w "\n%{http_code}" -X POST \
+ -H "Content-Type: application/json" \
+ -d '{"email":"admin@example.com","password":"wrongpassword"}' \
+ "$BASE_URL/v1/auth/login")
+
+ local http_code=$(echo "$response" | tail -1)
+
+ if [ "$http_code" = "429" ]; then
+ rate_limit_triggered=true
+ write_test_log "SUCCESS" "✓ Rate limiting triggered after $i attempts"
+ break
+ fi
+
+ sleep 0.1
+ done
+
+ if [ "$rate_limit_triggered" = false ]; then
+ write_test_log "WARN" "✗ Rate limiting not detected (or threshold > 20 attempts)"
+ fi
+}
+
+test_password_security() {
+ printf "\n${CYAN}=== Testing Password Security ===${NC}\n"
+
+ # Test weak passwords - they should be rejected (400 or 422)
+ local weak_passwords=("123456" "admin" "test" "abc123" "password123")
+
+ for weak_pass in "${weak_passwords[@]}"; do
+ local weak_user_data=$(jq -n \
+ --arg email "weak_$(date +%s)_${RANDOM}@example.com" \
+ --arg pass "$weak_pass" \
+ '{
+ email: $email,
+ password: $pass,
+ fullname: "Weak Password Test",
+ phone_number: "081234567890",
+ is_active: true,
+ role_id: "5713cb37-dc02-4e87-8048-d7a41d352059"
+ }')
+
+ local response=$(curl -s -w "\n%{http_code}" -X POST \
+ -H "Content-Type: application/json" \
+ -H "Authorization: Bearer $AUTH_TOKEN" \
+ -d "$weak_user_data" \
+ "$BASE_URL/v1/users/create")
+
+ local http_code=$(echo "$response" | tail -1)
+
+ if [ "$http_code" = "400" ] || [ "$http_code" = "422" ]; then
+ write_test_log "SUCCESS" "✓ Weak password '$weak_pass' rejected"
+ else
+ write_test_log "WARN" "✗ Weak password '$weak_pass' accepted (code: $http_code)"
+ # Cleanup if created
+ if [ "$http_code" = "201" ]; then
+ local user_id=$(echo "$response" | sed '$d' | jq -r '.data.id // empty')
+ if [ -n "$user_id" ]; then
+ curl -s -X DELETE -H "Authorization: Bearer $AUTH_TOKEN" "$BASE_URL/v1/users/delete/$user_id" > /dev/null
+ fi
+ fi
+ fi
+
+ sleep 0.1
+ done
+}
+
+test_data_exposure() {
+ printf "\n${CYAN}=== Testing Data Exposure Prevention ===${NC}\n"
+
+ # Ensure passwords are not returned in responses
+ local user_response=$(curl -s \
+ -H "Authorization: Bearer $AUTH_TOKEN" \
+ "$BASE_URL/v1/users/me")
+
+ if echo "$user_response" | jq -e '.data.password' > /dev/null 2>&1; then
+ write_test_log "ERROR" "✗ Password field exposed in user response"
+ else
+ write_test_log "SUCCESS" "✓ Password field not exposed in user response"
+ fi
+
+ # Test that error messages don't expose sensitive information
+ local error_response=$(curl -s -X POST \
+ -H "Content-Type: application/json" \
+ -d '{"email":"nonexistent@example.com","password":"password"}' \
+ "$BASE_URL/v1/auth/login")
+
+ local error_msg=$(echo "$error_response" | jq -r '.message // empty' | tr '[:upper:]' '[:lower:]')
+
+ # Check that error doesn't reveal if user exists
+ if [[ "$error_msg" == *"user not found"* ]] || [[ "$error_msg" == *"user does not exist"* ]]; then
+ write_test_log "WARN" "✗ Error message reveals user existence"
+ else
+ write_test_log "SUCCESS" "✓ Generic error message for invalid login"
+ fi
+}
+
+test_authorization_bypass() {
+ printf "\n${CYAN}=== Testing Authorization Bypass Attempts ===${NC}\n"
+
+ # Test accessing other users' data
+ local all_users=$(curl -s \
+ -H "Authorization: Bearer $AUTH_TOKEN" \
+ "$BASE_URL/v1/users")
+
+ local other_user_id=$(echo "$all_users" | jq -r '.data[1].id // empty')
+
+ if [ -n "$other_user_id" ]; then
+ # Create a new user
+ local test_user_email="bypass_test_$(date +%s)@example.com"
+ local create_user_data=$(jq -n \
+ --arg email "$test_user_email" \
+ '{
+ email: $email,
+ password: "Test123!",
+ fullname: "Bypass Test User",
+ phone_number: "081234567890",
+ is_active: true,
+ role_id: "5713cb37-dc02-4e87-8048-d7a41d352059"
+ }')
+
+ local create_response=$(curl -s -X POST \
+ -H "Content-Type: application/json" \
+ -H "Authorization: Bearer $AUTH_TOKEN" \
+ -d "$create_user_data" \
+ "$BASE_URL/v1/users/create")
+
+ local new_user_id=$(echo "$create_response" | jq -r '.data.id // empty')
+
+ if [ -n "$new_user_id" ]; then
+ # Login as new user
+ local user_login=$(jq -n --arg email "$test_user_email" '{email: $email, password: "Test123!"}')
+ local login_response=$(curl -s -X POST \
+ -H "Content-Type: application/json" \
+ -d "$user_login" \
+ "$BASE_URL/v1/auth/login")
+
+ local new_user_token=$(echo "$login_response" | jq -r '.data.token.access_token // empty')
+
+ if [ -n "$new_user_token" ]; then
+ # Try to update another user's data
+ local admin_token="$AUTH_TOKEN"
+ AUTH_TOKEN="$new_user_token"
+
+ local update_data=$(jq -n '{fullname: "Hacked User"}')
+ test_api_endpoint "User Update Other User" "PUT" "/v1/users/update/$other_user_id" 403 "$update_data" true
+
+ # Try to delete another user
+ test_api_endpoint "User Delete Other User" "DELETE" "/v1/users/delete/$other_user_id" 403 "" true
+
+ # Restore admin token
+ AUTH_TOKEN="$admin_token"
+ fi
+
+ # Cleanup
+ curl -s -X DELETE \
+ -H "Authorization: Bearer $AUTH_TOKEN" \
+ "$BASE_URL/v1/users/delete/$new_user_id" > /dev/null
+ fi
+ fi
+}
+
+test_input_validation() {
+ printf "\n${CYAN}=== Testing Input Validation ===${NC}\n"
+
+ # Test invalid email formats
+ local invalid_emails=("notanemail" "test@" "@example.com")
+
+ for invalid_email in "${invalid_emails[@]}"; do
+ local invalid_data=$(jq -n \
+ --arg email "$invalid_email" \
+ '{
+ email: $email,
+ password: "Test123!SecurePass",
+ fullname: "Invalid Email Test",
+ phone_number: "081234567890",
+ is_active: true,
+ role_id: "5713cb37-dc02-4e87-8048-d7a41d352059"
+ }')
+
+ local response=$(curl -s -w "\n%{http_code}" -X POST \
+ -H "Content-Type: application/json" \
+ -H "Authorization: Bearer $AUTH_TOKEN" \
+ -d "$invalid_data" \
+ "$BASE_URL/v1/users/create")
+
+ local http_code=$(echo "$response" | tail -1)
+
+ if [ "$http_code" = "400" ] || [ "$http_code" = "422" ]; then
+ write_test_log "SUCCESS" "✓ Invalid email '$invalid_email' rejected"
+ else
+ write_test_log "WARN" "✗ Invalid email '$invalid_email' accepted (code: $http_code)"
+ # Cleanup if created
+ if [ "$http_code" = "201" ]; then
+ local user_id=$(echo "$response" | sed '$d' | jq -r '.data.id // empty')
+ if [ -n "$user_id" ]; then
+ curl -s -X DELETE -H "Authorization: Bearer $AUTH_TOKEN" "$BASE_URL/v1/users/delete/$user_id" > /dev/null
+ fi
+ fi
+ fi
+ done
+
+ # Test excessively long inputs (reduced to 500 chars to be more reasonable)
+ local long_string=$(printf 'A%.0s' {1..500})
+ local long_input_data=$(jq -n \
+ --arg email "long_$(date +%s)@example.com" \
+ --arg fullname "$long_string" \
+ '{
+ email: $email,
+ password: "Test123!SecurePass",
+ fullname: $fullname,
+ phone_number: "081234567890",
+ is_active: true,
+ role_id: "5713cb37-dc02-4e87-8048-d7a41d352059"
+ }')
+
+ local response=$(curl -s -w "\n%{http_code}" -X POST \
+ -H "Content-Type: application/json" \
+ -H "Authorization: Bearer $AUTH_TOKEN" \
+ -d "$long_input_data" \
+ "$BASE_URL/v1/users/create")
+
+ local http_code=$(echo "$response" | tail -1)
+
+ if [ "$http_code" = "400" ] || [ "$http_code" = "422" ]; then
+ write_test_log "SUCCESS" "✓ Excessively long input rejected"
+ else
+ write_test_log "WARN" "✗ Excessively long input (500 chars) accepted (code: $http_code)"
+ # Cleanup if created
+ if [ "$http_code" = "201" ]; then
+ local user_id=$(echo "$response" | sed '$d' | jq -r '.data.id // empty')
+ if [ -n "$user_id" ]; then
+ curl -s -X DELETE -H "Authorization: Bearer $AUTH_TOKEN" "$BASE_URL/v1/users/delete/$user_id" > /dev/null
+ fi
+ fi
+ fi
+}
+
+test_session_management() {
+ printf "\n${CYAN}=== Testing Session Management ===${NC}\n"
+
+ # Test token expiration (if applicable)
+ write_test_log "INFO" "Testing session management..."
+
+ # Test logout functionality - try common logout endpoints
+ local logout_endpoints=("/v1/auth/logout" "/v1/auth/signout" "/v2/auth/logout")
+ local logout_exists=false
+
+ for endpoint in "${logout_endpoints[@]}"; do
+ local logout_response=$(curl -s -w "\n%{http_code}" -X POST \
+ -H "Authorization: Bearer $AUTH_TOKEN" \
+ "$BASE_URL$endpoint")
+
+ local logout_code=$(echo "$logout_response" | tail -1)
+
+ if [ "$logout_code" = "200" ] || [ "$logout_code" = "204" ]; then
+ write_test_log "SUCCESS" "✓ Logout endpoint exists at $endpoint (code: $logout_code)"
+ logout_exists=true
+
+ # Try to use token after logout
+ local saved_token="$AUTH_TOKEN"
+ local after_logout_response=$(curl -s -w "\n%{http_code}" \
+ -H "Authorization: Bearer $saved_token" \
+ "$BASE_URL/v1/users/me")
+
+ local after_logout_code=$(echo "$after_logout_response" | tail -1)
+
+ if [ "$after_logout_code" = "401" ]; then
+ write_test_log "SUCCESS" "✓ Token invalidated after logout"
+ else
+ write_test_log "WARN" "✗ Token still valid after logout (code: $after_logout_code)"
+ fi
+
+ # Re-authenticate for remaining tests
+ get_auth_token
+ break
+ fi
+ done
+
+ if [ "$logout_exists" = false ]; then
+ write_test_log "WARN" "⚠ Logout endpoint not found (tested: ${logout_endpoints[*]})"
+ fi
+}
+
+# Run all security tests
+run_security_tests() {
+ test_unauthorized_access
+ test_invalid_token_access
+ test_role_based_access_control
+ test_csrf_and_headers
+ test_sql_injection_attempts
+ test_xss_attempts
+ test_rate_limiting
+ test_password_security
+ test_data_exposure
+ test_authorization_bypass
+ test_input_validation
+ test_session_management
+}
+
+# Run if executed directly
+if [[ "${BASH_SOURCE[0]}" == "${0}" ]]; then
+ get_auth_token
+ run_security_tests
+ print_test_summary
+ [ "$FAIL_COUNT" -eq 0 ] && exit 0 || exit 1
+fi
diff --git a/tests/iam/test-users.sh b/tests/iam/test-users.sh
index f424c0c..e40e95c 100644
--- a/tests/iam/test-users.sh
+++ b/tests/iam/test-users.sh
@@ -9,15 +9,29 @@ source "$(dirname "$0")/../common/test-common.sh"
test_user_management_endpoints() {
printf "\n${CYAN}=== Testing User Management Endpoints ===${NC}\n"
+ # Security: Test that endpoints require authentication
+ local saved_token="$AUTH_TOKEN"
+ AUTH_TOKEN=""
+ test_api_endpoint "GET Users without Auth (Should Fail)" "GET" "/v1/users" 401 "" false
+ AUTH_TOKEN="$saved_token"
+
# Get users list
test_api_endpoint "GET Users List" "GET" "/v1/users" 200 "" true
test_api_endpoint "GET Users (Paginated)" "GET" "/v1/users?page=1&limit=10" 200 "" true
test_api_endpoint "GET Users (Search)" "GET" "/v1/users?search=admin" 200 "" true
test_api_endpoint "GET Users (Sorted)" "GET" "/v1/users?sort_by=created_at&order=DESC" 200 "" true
+ # Security: Test SQL injection in search
+ test_api_endpoint "GET Users with SQL Injection (Should Be Safe)" "GET" "/v1/users?search=' OR '1'='1" 200 "" true
+
# Get user me
test_api_endpoint "GET User Me" "GET" "/v1/users/me" 200 "" true
+ # Security: Test access without token
+ AUTH_TOKEN=""
+ test_api_endpoint "GET User Me without Auth (Should Fail)" "GET" "/v1/users/me" 401 "" false
+ AUTH_TOKEN="$saved_token"
+
# Update user me - use correct endpoint /update/me
local update_me_data=$(jq -n '{
fullname: "Updated Admin User",
@@ -27,10 +41,20 @@ test_user_management_endpoints() {
}')
test_api_endpoint "PUT User Me" "PUT" "/v1/users/update/me" 200 "$update_me_data" true
+ # Security: Test XSS in user update
+ local xss_update_data=$(jq -n '{
+ fullname: "",
+ phone_number: "081234567890"
+ }')
+ test_api_endpoint "PUT User Me with XSS (Should Be Sanitized)" "PUT" "/v1/users/update/me" 200 "$xss_update_data" true
+
# Get user by ID
local test_user_id="c3b1d6a8-8d4f-4b36-b789-2e532ec7a7b2"
test_api_endpoint "GET User By ID" "GET" "/v1/users/detail/$test_user_id" 200 "" true
+ # Security: Test access to non-existent user
+ test_api_endpoint "GET Non-existent User (Should Fail)" "GET" "/v1/users/detail/00000000-0000-0000-0000-000000000000" 404 "" true
+
# Create new user
local new_user_email="test_user_$(date +%s)@example.com"
local create_user_data=$(jq -n \
@@ -51,6 +75,20 @@ test_user_management_endpoints() {
local created_user_id=$(echo "$create_response" | jq -r '.data.id // empty')
if [ -n "$created_user_id" ]; then
+ # Security: Test duplicate email
+ test_api_endpoint "POST Create Duplicate User (Should Fail)" "POST" "/v1/users/create" 400 "$create_user_data" true
+
+ # Security: Test invalid email format
+ local invalid_email_data=$(jq -n '{
+ email: "not_an_email",
+ password: "TestPassword123!",
+ fullname: "Invalid Email User",
+ phone_number: "089876543211",
+ is_active: true,
+ role_id: "5713cb37-dc02-4e87-8048-d7a41d352059"
+ }')
+ test_api_endpoint "POST Create User with Invalid Email (Should Fail)" "POST" "/v1/users/create" 400 "$invalid_email_data" true
+
# Update user
local update_user_data=$(jq -n \
--arg email "updated_$new_user_email" \
@@ -66,6 +104,11 @@ test_user_management_endpoints() {
}')
test_api_endpoint "PUT Update User" "PUT" "/v1/users/update/$created_user_id" 200 "$update_user_data" true
+ # Security: Test unauthorized update
+ AUTH_TOKEN=""
+ test_api_endpoint "PUT Update User without Auth (Should Fail)" "PUT" "/v1/users/update/$created_user_id" 401 "$update_user_data" false
+ AUTH_TOKEN="$saved_token"
+
# Deactivate user - endpoint uses PUT, not PATCH
local deactivate_data=$(jq -n '{is_active: false}')
test_api_endpoint "PUT Deactivate User" "PUT" "/v1/users/activate/$created_user_id" 200 "$deactivate_data" true
@@ -76,6 +119,14 @@ test_user_management_endpoints() {
# Delete user
test_api_endpoint "DELETE User" "DELETE" "/v1/users/delete/$created_user_id" 200 "" true
+
+ # Security: Test double delete
+ test_api_endpoint "DELETE Already Deleted User (Should Fail)" "DELETE" "/v1/users/delete/$created_user_id" 404 "" true
+
+ # Security: Test unauthorized delete
+ AUTH_TOKEN=""
+ test_api_endpoint "DELETE User without Auth (Should Fail)" "DELETE" "/v1/users/delete/$created_user_id" 401 "" false
+ AUTH_TOKEN="$saved_token"
else
write_test_log "WARN" "Skipping user update/delete tests - failed to create user"
fi