From 737d852e477c049194ecad28ecbc73dc5fc58518 Mon Sep 17 00:00:00 2001
From: Daniel Gustafsson <dgustafsson@postgresql.org>
Date: Fri, 31 Mar 2023 14:52:41 +0200
Subject: [PATCH v6 2/2] Test SCRAM iteration changes with psql \password

A version of this test was included in the original patch for altering
SCRAM iteration count, but was omitted due to how interactive psql TAP
sessions worked before being refactored.

Discussion: https://postgr.es/m/20230130194350.zj5v467x4jgqt3d6@awork3.anarazel.de
Discussion: https://postgr.es/m/F72E7BC7-189F-4B17-BF47-9735EB72C364@yesql.se
---
 src/test/authentication/t/001_password.pl | 26 +++++++++++++++++++++++
 1 file changed, 26 insertions(+)

diff --git a/src/test/authentication/t/001_password.pl b/src/test/authentication/t/001_password.pl
index 00857fdae5..f414a8ba90 100644
--- a/src/test/authentication/t/001_password.pl
+++ b/src/test/authentication/t/001_password.pl
@@ -101,6 +101,32 @@ my $res = $node->safe_psql('postgres',
 	 WHERE rolname = 'scram_role_iter'");
 is($res, 'SCRAM-SHA-256$1024:', 'scram_iterations in server side ROLE');
 
+# If we don't have IO::Pty, forget it, because IPC::Run depends on that
+# to support pty connections
+SKIP:
+{
+	skip "IO::Pty required", 1 unless eval { require IO::Pty; };
+
+	# Alter the password on the created role using \password in psql to ensure
+	# that clientside password changes use the scram_iterations value when
+	# calculating SCRAM secrets.
+	my $session = $node->interactive_psql('postgres');
+
+	$session->set_query_timer_restart();
+	$session->query("SET password_encryption='scram-sha-256';");
+	$session->query("SET scram_iterations=42;");
+	$session->query_until(qr/Enter new password/, "\\password scram_role_iter\n");
+	$session->query_until(qr/Enter it again/, "pass\n");
+	$session->query_until(qr/postgres=# /, "pass\n");
+	$session->quit;
+
+	$res = $node->safe_psql('postgres',
+		"SELECT substr(rolpassword,1,17)
+		 FROM pg_authid
+		 WHERE rolname = 'scram_role_iter'");
+	is($res, 'SCRAM-SHA-256$42:', 'scram_iterations in psql \password command');
+}
+
 # Create a database to test regular expression.
 $node->safe_psql('postgres', "CREATE database regex_testdb;");
 
-- 
2.32.1 (Apple Git-133)

