|
19 | 19 | from cryptography.hazmat.primitives import serialization |
20 | 20 | from cryptography.hazmat.primitives.asymmetric import ec, rsa |
21 | 21 |
|
| 22 | +from tesla_fleet_api.exceptions import PrivateKeyError |
22 | 23 | from tesla_fleet_api.tesla.tesla import Tesla |
23 | 24 |
|
24 | 25 |
|
@@ -715,3 +716,121 @@ async def test_defaults_unchanged_for_existing_rsa_key_read(self) -> None: |
715 | 716 | read_back = await Tesla().get_rsa_private_key(path, key_size=1024) |
716 | 717 |
|
717 | 718 | self.assertEqual(_rsa_pem(read_back), _rsa_pem(created)) |
| 719 | + |
| 720 | + |
| 721 | +class PrivateKeyErrorTests(IsolatedAsyncioTestCase): |
| 722 | + """An existing-but-unusable key file must raise ``PrivateKeyError`` with the right reason.""" |
| 723 | + |
| 724 | + async def test_ec_loader_unreadable(self) -> None: |
| 725 | + with tempfile.TemporaryDirectory() as tmp_dir: |
| 726 | + path = str(Path(tmp_dir) / "private_key.pem") |
| 727 | + os.mkdir(path) |
| 728 | + |
| 729 | + with self.assertRaises(PrivateKeyError) as ctx: |
| 730 | + await Tesla().get_private_key(path) |
| 731 | + |
| 732 | + self.assertEqual(ctx.exception.reason, "unreadable") |
| 733 | + self.assertIsInstance(ctx.exception.__cause__, OSError) |
| 734 | + self.assertIn(path, ctx.exception.message) |
| 735 | + |
| 736 | + async def test_ec_loader_malformed(self) -> None: |
| 737 | + with tempfile.TemporaryDirectory() as tmp_dir: |
| 738 | + path = str(Path(tmp_dir) / "private_key.pem") |
| 739 | + Path(path).write_bytes(b"not a pem file") |
| 740 | + |
| 741 | + with self.assertRaises(PrivateKeyError) as ctx: |
| 742 | + await Tesla().get_private_key(path) |
| 743 | + |
| 744 | + self.assertEqual(ctx.exception.reason, "malformed") |
| 745 | + self.assertIsInstance(ctx.exception.__cause__, ValueError) |
| 746 | + self.assertIn(path, ctx.exception.message) |
| 747 | + |
| 748 | + async def test_ec_loader_encrypted(self) -> None: |
| 749 | + with tempfile.TemporaryDirectory() as tmp_dir: |
| 750 | + path = str(Path(tmp_dir) / "private_key.pem") |
| 751 | + key = ec.generate_private_key(ec.SECP256R1()) |
| 752 | + pem = key.private_bytes( |
| 753 | + encoding=serialization.Encoding.PEM, |
| 754 | + format=serialization.PrivateFormat.TraditionalOpenSSL, |
| 755 | + encryption_algorithm=serialization.BestAvailableEncryption( |
| 756 | + b"correct horse battery staple" |
| 757 | + ), |
| 758 | + ) |
| 759 | + Path(path).write_bytes(pem) |
| 760 | + |
| 761 | + with self.assertRaises(PrivateKeyError) as ctx: |
| 762 | + await Tesla().get_private_key(path) |
| 763 | + |
| 764 | + self.assertEqual(ctx.exception.reason, "encrypted") |
| 765 | + self.assertIsInstance(ctx.exception.__cause__, TypeError) |
| 766 | + self.assertIn(path, ctx.exception.message) |
| 767 | + |
| 768 | + async def test_ec_loader_wrong_type(self) -> None: |
| 769 | + with tempfile.TemporaryDirectory() as tmp_dir: |
| 770 | + path = str(Path(tmp_dir) / "private_key.pem") |
| 771 | + key = rsa.generate_private_key(public_exponent=65537, key_size=1024) |
| 772 | + Path(path).write_bytes(_rsa_pem(key)) |
| 773 | + |
| 774 | + with self.assertRaises(PrivateKeyError) as ctx: |
| 775 | + await Tesla().get_private_key(path) |
| 776 | + |
| 777 | + self.assertEqual(ctx.exception.reason, "wrong_type") |
| 778 | + self.assertIsNone(ctx.exception.__cause__) |
| 779 | + self.assertIn(path, ctx.exception.message) |
| 780 | + |
| 781 | + async def test_rsa_loader_unreadable(self) -> None: |
| 782 | + with tempfile.TemporaryDirectory() as tmp_dir: |
| 783 | + path = str(Path(tmp_dir) / "tedapi_rsa_private.pem") |
| 784 | + os.mkdir(path) |
| 785 | + |
| 786 | + with self.assertRaises(PrivateKeyError) as ctx: |
| 787 | + await Tesla().get_rsa_private_key(path, key_size=1024) |
| 788 | + |
| 789 | + self.assertEqual(ctx.exception.reason, "unreadable") |
| 790 | + self.assertIsInstance(ctx.exception.__cause__, OSError) |
| 791 | + self.assertIn(path, ctx.exception.message) |
| 792 | + |
| 793 | + async def test_rsa_loader_malformed(self) -> None: |
| 794 | + with tempfile.TemporaryDirectory() as tmp_dir: |
| 795 | + path = str(Path(tmp_dir) / "tedapi_rsa_private.pem") |
| 796 | + Path(path).write_bytes(b"not a pem file") |
| 797 | + |
| 798 | + with self.assertRaises(PrivateKeyError) as ctx: |
| 799 | + await Tesla().get_rsa_private_key(path, key_size=1024) |
| 800 | + |
| 801 | + self.assertEqual(ctx.exception.reason, "malformed") |
| 802 | + self.assertIsInstance(ctx.exception.__cause__, ValueError) |
| 803 | + self.assertIn(path, ctx.exception.message) |
| 804 | + |
| 805 | + async def test_rsa_loader_encrypted(self) -> None: |
| 806 | + with tempfile.TemporaryDirectory() as tmp_dir: |
| 807 | + path = str(Path(tmp_dir) / "tedapi_rsa_private.pem") |
| 808 | + key = rsa.generate_private_key(public_exponent=65537, key_size=1024) |
| 809 | + pem = key.private_bytes( |
| 810 | + encoding=serialization.Encoding.PEM, |
| 811 | + format=serialization.PrivateFormat.TraditionalOpenSSL, |
| 812 | + encryption_algorithm=serialization.BestAvailableEncryption( |
| 813 | + b"correct horse battery staple" |
| 814 | + ), |
| 815 | + ) |
| 816 | + Path(path).write_bytes(pem) |
| 817 | + |
| 818 | + with self.assertRaises(PrivateKeyError) as ctx: |
| 819 | + await Tesla().get_rsa_private_key(path, key_size=1024) |
| 820 | + |
| 821 | + self.assertEqual(ctx.exception.reason, "encrypted") |
| 822 | + self.assertIsInstance(ctx.exception.__cause__, TypeError) |
| 823 | + self.assertIn(path, ctx.exception.message) |
| 824 | + |
| 825 | + async def test_rsa_loader_wrong_type(self) -> None: |
| 826 | + with tempfile.TemporaryDirectory() as tmp_dir: |
| 827 | + path = str(Path(tmp_dir) / "tedapi_rsa_private.pem") |
| 828 | + key = ec.generate_private_key(ec.SECP256R1()) |
| 829 | + Path(path).write_bytes(_ec_pem(key)) |
| 830 | + |
| 831 | + with self.assertRaises(PrivateKeyError) as ctx: |
| 832 | + await Tesla().get_rsa_private_key(path, key_size=1024) |
| 833 | + |
| 834 | + self.assertEqual(ctx.exception.reason, "wrong_type") |
| 835 | + self.assertIsNone(ctx.exception.__cause__) |
| 836 | + self.assertIn(path, ctx.exception.message) |
0 commit comments