exchange

Base system with REST service to issue digital coins, run by the payment service provider
Log | Files | Refs | Submodules | README | LICENSE

test_kyc_api.c (25683B)


      1 /*
      2   This file is part of TALER
      3   Copyright (C) 2014-2024 Taler Systems SA
      4 
      5   TALER is free software; you can redistribute it and/or modify
      6   it under the terms of the GNU General Public License as
      7   published by the Free Software Foundation; either version 3, or
      8   (at your option) any later version.
      9 
     10   TALER is distributed in the hope that it will be useful, but
     11   WITHOUT ANY WARRANTY; without even the implied warranty of
     12   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
     13   GNU General Public License for more details.
     14 
     15   You should have received a copy of the GNU General Public
     16   License along with TALER; see the file COPYING.  If not, see
     17   <http://www.gnu.org/licenses/>
     18 */
     19 /**
     20  * @file testing/test_kyc_api.c
     21  * @brief testcase to test the KYC processes
     22  * @author Christian Grothoff
     23  */
     24 #include "taler/taler_util.h"
     25 #include "taler/taler_attributes.h"
     26 #include "taler/taler_json_lib.h"
     27 #include <gnunet/gnunet_util_lib.h>
     28 #include <microhttpd.h>
     29 #include "taler/taler_bank_service.h"
     30 #include "taler/taler_testing_lib.h"
     31 
     32 
     33 /**
     34  * Configuration file we use.  One (big) configuration is used
     35  * for the various components for this test.
     36  */
     37 #define CONFIG_FILE "test_kyc_api.conf"
     38 
     39 /**
     40  * Our credentials.
     41  */
     42 struct TALER_TESTING_Credentials cred;
     43 
     44 
     45 /**
     46  * Execute the taler-exchange-wirewatch command with
     47  * our configuration file.
     48  *
     49  * @param label label to use for the command.
     50  */
     51 #define CMD_EXEC_WIREWATCH(label)           \
     52         TALER_TESTING_cmd_exec_wirewatch2 ( \
     53           label,                            \
     54           CONFIG_FILE,                      \
     55           "exchange-account-2")
     56 
     57 /**
     58  * Execute the taler-exchange-aggregator, closer and transfer commands with
     59  * our configuration file.
     60  *
     61  * @param label label to use for the command.
     62  */
     63 #define CMD_EXEC_AGGREGATOR(label)                   \
     64         TALER_TESTING_cmd_sleep (                    \
     65           label "-sleep", 1),                        \
     66         TALER_TESTING_cmd_exec_aggregator_with_kyc ( \
     67           label, CONFIG_FILE),                       \
     68         TALER_TESTING_cmd_exec_transfer (            \
     69           label, CONFIG_FILE)
     70 
     71 /**
     72  * Run wire transfer of funds from some user's account to the
     73  * exchange.
     74  *
     75  * @param label label to use for the command.
     76  * @param amount amount to transfer, i.e. "EUR:1"
     77  */
     78 #define CMD_TRANSFER_TO_EXCHANGE(label,amount) \
     79         TALER_TESTING_cmd_admin_add_incoming ( \
     80           label,                               \
     81           amount,                              \
     82           &cred.ba,                            \
     83           cred.user42_payto)
     84 
     85 /**
     86  * Main function that will tell the interpreter what commands to
     87  * run.
     88  *
     89  * @param cls closure
     90  */
     91 static void
     92 run (void *cls,
     93      struct TALER_TESTING_Interpreter *is)
     94 {
     95   struct TALER_TESTING_Command withdraw[] = {
     96     CMD_TRANSFER_TO_EXCHANGE (
     97       "create-reserve-1",
     98       "EUR:15.02"),
     99     TALER_TESTING_cmd_check_bank_admin_transfer (
    100       "check-create-reserve-1",
    101       "EUR:15.02",
    102       cred.user42_payto,
    103       cred.exchange_payto,
    104       "create-reserve-1"),
    105     CMD_EXEC_WIREWATCH ("wirewatch-1"),
    106     TALER_TESTING_cmd_withdraw_amount (
    107       "withdraw-coin-1-no-kyc",
    108       "create-reserve-1",
    109       "EUR:10",
    110       0,    /* age restriction off */
    111       MHD_HTTP_UNAVAILABLE_FOR_LEGAL_REASONS),
    112     TALER_TESTING_cmd_withdraw_amount (
    113       "withdraw-coin-1",
    114       "create-reserve-1",
    115       "EUR:5",
    116       0,    /* age restriction off */
    117       MHD_HTTP_OK),
    118     TALER_TESTING_cmd_end ()
    119   };
    120 
    121   /**
    122    * Test withdraw with KYC.
    123    */
    124   struct TALER_TESTING_Command withdraw_kyc[] = {
    125     CMD_TRANSFER_TO_EXCHANGE (
    126       "create-reserve-kyc",
    127       "EUR:15.02"),
    128     TALER_TESTING_cmd_check_bank_admin_transfer (
    129       "check-create-reserve-kyc",
    130       "EUR:15.02",
    131       cred.user42_payto,
    132       cred.exchange_payto,
    133       "create-reserve-kyc"),
    134     CMD_EXEC_WIREWATCH ("wirewatch-kyc"),
    135     TALER_TESTING_cmd_withdraw_amount (
    136       "withdraw-coin-1-lacking-kyc",
    137       "create-reserve-kyc",
    138       "EUR:10",
    139       0,     /* age restriction off */
    140       MHD_HTTP_UNAVAILABLE_FOR_LEGAL_REASONS),
    141     TALER_TESTING_cmd_admin_add_kycauth (
    142       "setup-account-key-withdraw",
    143       "EUR:0.01",
    144       &cred.ba,
    145       cred.user42_payto,
    146       NULL /* create new key */),
    147     CMD_EXEC_WIREWATCH (
    148       "import-kyc-account-withdraw"),
    149     TALER_TESTING_cmd_check_kyc_get (
    150       "check-kyc-withdraw",
    151       "withdraw-coin-1-lacking-kyc",
    152       "setup-account-key-withdraw",
    153       TALER_EXCHANGE_KLPT_KYC_AUTH_TRANSFER,
    154       MHD_HTTP_ACCEPTED),
    155     TALER_TESTING_cmd_get_kyc_info (
    156       "get-kyc-info-withdraw",
    157       "check-kyc-withdraw",
    158       MHD_HTTP_OK),
    159     TALER_TESTING_cmd_post_kyc_start (
    160       "start-kyc-process-withdraw",
    161       "get-kyc-info-withdraw",
    162       0,
    163       MHD_HTTP_OK),
    164     /* A code sent along with just the account instead of the state
    165        the exchange issued must not complete the process. */
    166     TALER_TESTING_cmd_proof_kyc_oauth2 (
    167       "proof-kyc-withdraw-oauth2-forged",
    168       "withdraw-coin-1-lacking-kyc",
    169       "test-oauth2",
    170       "pass",
    171       MHD_HTTP_FORBIDDEN),
    172     TALER_TESTING_cmd_proof_kyc_oauth2 (
    173       "proof-kyc-withdraw-oauth2",
    174       "start-kyc-process-withdraw",
    175       "test-oauth2",
    176       "pass",
    177       MHD_HTTP_SEE_OTHER),
    178     TALER_TESTING_cmd_withdraw_with_age_proof (
    179       "age-withdraw-coin-1-with-kyc",
    180       "create-reserve-kyc",
    181       1,
    182       MHD_HTTP_CREATED,
    183       "EUR:5",
    184       NULL),
    185     TALER_TESTING_cmd_withdraw_reveal_age_proof (
    186       "reveal-age-withdraw-coin-1-with-kyc",
    187       "age-withdraw-coin-1-with-kyc",
    188       MHD_HTTP_OK),
    189     /* Attestations above are bound to the originating *bank* account,
    190        not to the reserve (!). Hence, they are NOT found here! */
    191     TALER_TESTING_cmd_reserve_get_attestable (
    192       "reserve-get-attestable",
    193       "create-reserve-kyc",
    194       MHD_HTTP_NOT_FOUND,
    195       NULL),
    196     TALER_TESTING_cmd_end ()
    197   };
    198   struct TALER_TESTING_Command spend[] = {
    199     TALER_TESTING_cmd_set_var (
    200       "account-priv",
    201       TALER_TESTING_cmd_deposit (
    202         "deposit-simple-fail-kyc",
    203         "withdraw-coin-1",
    204         0,
    205         cred.user43_payto,
    206         "{\"items\":[{\"name\":\"ice cream\",\"value\":1}]}",
    207         GNUNET_TIME_UNIT_ZERO,
    208         "EUR:5",
    209         MHD_HTTP_UNAVAILABLE_FOR_LEGAL_REASONS)),
    210     TALER_TESTING_cmd_admin_add_kycauth (
    211       "kyc-auth-transfer",
    212       "EUR:0.01",
    213       &cred.ba,
    214       cred.user42_payto,
    215       "deposit-simple-fail-kyc"),
    216     TALER_TESTING_cmd_admin_add_kycauth (
    217       "kyc-auth-transfer",
    218       "EUR:0.01",
    219       &cred.ba,
    220       cred.user43_payto,
    221       "deposit-simple-fail-kyc"),
    222     CMD_EXEC_WIREWATCH (
    223       "import-kyc-account"),
    224     TALER_TESTING_cmd_deposit (
    225       "deposit-simple",
    226       "withdraw-coin-1",
    227       0,
    228       cred.user43_payto,
    229       "{\"items\":[{\"name\":\"ice cream\",\"value\":1}]}",
    230       GNUNET_TIME_UNIT_ZERO,
    231       "EUR:5",
    232       MHD_HTTP_OK),
    233     TALER_TESTING_cmd_deposits_get (
    234       "track-deposit",
    235       "deposit-simple",
    236       0,
    237       MHD_HTTP_ACCEPTED,
    238       NULL),
    239     TALER_TESTING_cmd_end ()
    240   };
    241 
    242 
    243   struct TALER_TESTING_Command track[] = {
    244     CMD_EXEC_AGGREGATOR ("run-aggregator-before-kyc"),
    245     TALER_TESTING_cmd_check_bank_empty (
    246       "check_bank_empty-no-kyc"),
    247     TALER_TESTING_cmd_deposits_get (
    248       "track-deposit-kyc-ready",
    249       "deposit-simple",
    250       0,
    251       MHD_HTTP_ACCEPTED,
    252       NULL),
    253     TALER_TESTING_cmd_admin_add_kycauth (
    254       "setup-account-key-deposit",
    255       "EUR:0.01",
    256       &cred.ba,
    257       cred.user43_payto,
    258       NULL /* create new key */),
    259     CMD_EXEC_WIREWATCH (
    260       "import-kyc-account-deposit"),
    261     TALER_TESTING_cmd_check_kyc_get (
    262       "check-kyc-deposit",
    263       "track-deposit-kyc-ready",
    264       "setup-account-key-deposit",
    265       TALER_EXCHANGE_KLPT_KYC_AUTH_TRANSFER,
    266       MHD_HTTP_ACCEPTED),
    267     TALER_TESTING_cmd_get_kyc_info (
    268       "get-kyc-info-deposit",
    269       "check-kyc-deposit",
    270       MHD_HTTP_OK),
    271     TALER_TESTING_cmd_post_kyc_start (
    272       "start-kyc-process-deposit",
    273       "get-kyc-info-deposit",
    274       0,
    275       MHD_HTTP_OK),
    276     TALER_TESTING_cmd_proof_kyc_oauth2 (
    277       "proof-kyc-no-service",
    278       "start-kyc-process-deposit",
    279       "test-oauth2",
    280       "bad",
    281       MHD_HTTP_BAD_GATEWAY),
    282     TALER_TESTING_cmd_oauth_with_birthdate (
    283       "start-oauth-service",
    284       "2005-00-00",
    285       6666),
    286     TALER_TESTING_cmd_proof_kyc_oauth2 (
    287       "proof-kyc-fail",
    288       "start-kyc-process-deposit",
    289       "test-oauth2",
    290       "bad",
    291       MHD_HTTP_FORBIDDEN),
    292     TALER_TESTING_cmd_check_kyc_get (
    293       "check-kyc-deposit-again",
    294       "track-deposit-kyc-ready",
    295       "setup-account-key-deposit",
    296       TALER_EXCHANGE_KLPT_KYC_AUTH_TRANSFER,
    297       MHD_HTTP_ACCEPTED),
    298     TALER_TESTING_cmd_get_kyc_info (
    299       "get-kyc-info-deposit-again",
    300       "check-kyc-deposit-again",
    301       MHD_HTTP_OK),
    302     TALER_TESTING_cmd_post_kyc_start (
    303       "start-kyc-process-deposit-again",
    304       "get-kyc-info-deposit-again",
    305       0,
    306       MHD_HTTP_OK),
    307     TALER_TESTING_cmd_proof_kyc_oauth2 (
    308       "proof-kyc-pass",
    309       "start-kyc-process-deposit-again",
    310       "test-oauth2",
    311       "pass",
    312       MHD_HTTP_SEE_OTHER),
    313     CMD_EXEC_AGGREGATOR (
    314       "run-aggregator-after-kyc"),
    315     TALER_TESTING_cmd_check_bank_transfer (
    316       "check_bank_transfer-499c",
    317       cred.exchange_url,
    318       "EUR:4.98",
    319       cred.exchange_payto,
    320       cred.user43_payto),
    321     TALER_TESTING_cmd_check_bank_empty (
    322       "check_bank_empty"),
    323     TALER_TESTING_cmd_end ()
    324   };
    325 
    326   struct TALER_TESTING_Command wallet_kyc[] = {
    327     TALER_TESTING_cmd_wallet_kyc_get (
    328       "wallet-kyc-fail",
    329       NULL,
    330       "EUR:1000000",
    331       MHD_HTTP_UNAVAILABLE_FOR_LEGAL_REASONS),
    332     TALER_TESTING_cmd_check_kyc_get (
    333       "check-kyc-wallet",
    334       "wallet-kyc-fail",
    335       "wallet-kyc-fail",
    336       TALER_EXCHANGE_KLPT_KYC_AUTH_TRANSFER,
    337       MHD_HTTP_ACCEPTED),
    338     TALER_TESTING_cmd_get_kyc_info (
    339       "get-kyc-info-kyc-wallet",
    340       "check-kyc-wallet",
    341       MHD_HTTP_OK),
    342     TALER_TESTING_cmd_post_kyc_start (
    343       "start-kyc-wallet",
    344       "get-kyc-info-kyc-wallet",
    345       0,
    346       MHD_HTTP_OK),
    347     TALER_TESTING_cmd_proof_kyc_oauth2 (
    348       "proof-wallet-kyc",
    349       "start-kyc-wallet",
    350       "test-oauth2",
    351       "pass",
    352       MHD_HTTP_SEE_OTHER),
    353     TALER_TESTING_cmd_check_kyc_get (
    354       "wallet-kyc-check",
    355       "wallet-kyc-fail",
    356       "wallet-kyc-fail",
    357       TALER_EXCHANGE_KLPT_KYC_AUTH_TRANSFER,
    358       MHD_HTTP_OK),
    359     TALER_TESTING_cmd_reserve_get_attestable (
    360       "wallet-get-attestable",
    361       "wallet-kyc-fail",
    362       MHD_HTTP_OK,
    363       TALER_ATTRIBUTE_FULL_NAME,
    364       NULL),
    365     TALER_TESTING_cmd_reserve_attest (
    366       "wallet-get-attest",
    367       "wallet-kyc-fail",
    368       MHD_HTTP_OK,
    369       TALER_ATTRIBUTE_FULL_NAME,
    370       NULL),
    371     TALER_TESTING_cmd_end ()
    372   };
    373 
    374   /**
    375    * Test withdrawal for P2P
    376    */
    377   struct TALER_TESTING_Command p2p_withdraw[] = {
    378     /**
    379      * Move money to the exchange's bank account.
    380      */
    381     CMD_TRANSFER_TO_EXCHANGE (
    382       "p2p_create-reserve-1",
    383       "EUR:5.04"),
    384     CMD_TRANSFER_TO_EXCHANGE (
    385       "p2p_create-reserve-2",
    386       "EUR:5.01"),
    387     CMD_TRANSFER_TO_EXCHANGE (
    388       "p2p_create-reserve-3",
    389       "EUR:0.03"),
    390     TALER_TESTING_cmd_reserve_poll (
    391       "p2p_poll-reserve-1",
    392       "p2p_create-reserve-1",
    393       "EUR:5.04",
    394       GNUNET_TIME_UNIT_MINUTES,
    395       MHD_HTTP_OK),
    396     TALER_TESTING_cmd_check_bank_admin_transfer (
    397       "p2p_check-create-reserve-1",
    398       "EUR:5.04",
    399       cred.user42_payto,
    400       cred.exchange_payto,
    401       "p2p_create-reserve-1"),
    402     TALER_TESTING_cmd_check_bank_admin_transfer (
    403       "p2p_check-create-reserve-2",
    404       "EUR:5.01",
    405       cred.user42_payto,
    406       cred.exchange_payto,
    407       "p2p_create-reserve-2"),
    408     /**
    409      * Make a reserve exist, according to the previous
    410      * transfer.
    411      */
    412     CMD_EXEC_WIREWATCH ("p2p_wirewatch-1"),
    413     TALER_TESTING_cmd_reserve_poll_finish (
    414       "p2p_finish-poll-reserve-1",
    415       GNUNET_TIME_UNIT_SECONDS,
    416       "p2p_poll-reserve-1"),
    417     /**
    418      * Withdraw EUR:5.
    419      */
    420     TALER_TESTING_cmd_withdraw_amount (
    421       "p2p_withdraw-coin-1",
    422       "p2p_create-reserve-1",
    423       "EUR:5",
    424       0,      /* age restriction off */
    425       MHD_HTTP_OK),
    426     /**
    427      * Check the reserve is depleted.
    428      */
    429     TALER_TESTING_cmd_status (
    430       "p2p_status-1",
    431       "p2p_create-reserve-1",
    432       "EUR:0.03",
    433       MHD_HTTP_OK),
    434     TALER_TESTING_cmd_end ()
    435   };
    436   struct TALER_TESTING_Command push[] = {
    437     TALER_TESTING_cmd_purse_create_with_deposit (
    438       "purse-with-deposit",
    439       MHD_HTTP_OK,
    440       "{\"amount\":\"EUR:1\",\"summary\":\"ice cream\"}",
    441       true, /* upload contract */
    442       GNUNET_TIME_UNIT_MINUTES, /* expiration */
    443       "p2p_withdraw-coin-1",
    444       "EUR:1.01",
    445       NULL),
    446     TALER_TESTING_cmd_coin_history (
    447       "coin-history-purse-with-deposit",
    448       "p2p_withdraw-coin-1#0",
    449       "EUR:3.99",
    450       MHD_HTTP_OK),
    451     TALER_TESTING_cmd_purse_poll (
    452       "push-poll-purse-before-merge",
    453       MHD_HTTP_OK,
    454       "purse-with-deposit",
    455       "EUR:1",
    456       true,
    457       GNUNET_TIME_UNIT_MINUTES),
    458     TALER_TESTING_cmd_contract_get (
    459       "push-get-contract",
    460       MHD_HTTP_OK,
    461       true, /* for merge */
    462       "purse-with-deposit"),
    463     TALER_TESTING_cmd_purse_merge (
    464       "purse-merge-into-reserve",
    465       MHD_HTTP_UNAVAILABLE_FOR_LEGAL_REASONS,
    466       "push-get-contract",
    467       "p2p_create-reserve-1"),
    468     TALER_TESTING_cmd_check_kyc_get (
    469       "check-kyc-purse-merge",
    470       "purse-merge-into-reserve",
    471       "p2p_create-reserve-1",
    472       TALER_EXCHANGE_KLPT_KYC_AUTH_TRANSFER,
    473       MHD_HTTP_ACCEPTED),
    474     TALER_TESTING_cmd_get_kyc_info (
    475       "get-kyc-info-purse-merge-into-reserve",
    476       "check-kyc-purse-merge",
    477       MHD_HTTP_OK),
    478     TALER_TESTING_cmd_post_kyc_start (
    479       "start-kyc-process-purse-merge-into-reserve",
    480       "get-kyc-info-purse-merge-into-reserve",
    481       0,
    482       MHD_HTTP_OK),
    483     TALER_TESTING_cmd_proof_kyc_oauth2 (
    484       "p2p_proof-kyc",
    485       "start-kyc-process-purse-merge-into-reserve",
    486       "test-oauth2",
    487       "pass",
    488       MHD_HTTP_SEE_OTHER),
    489     TALER_TESTING_cmd_purse_merge (
    490       "purse-merge-into-reserve",
    491       MHD_HTTP_OK,
    492       "push-get-contract",
    493       "p2p_create-reserve-1"),
    494     TALER_TESTING_cmd_purse_poll_finish (
    495       "push-merge-purse-poll-finish",
    496       GNUNET_TIME_relative_multiply (
    497         GNUNET_TIME_UNIT_SECONDS,
    498         5),
    499       "push-poll-purse-before-merge"),
    500     TALER_TESTING_cmd_status (
    501       "push-check-post-merge-reserve-balance-get",
    502       "p2p_create-reserve-1",
    503       "EUR:1.03",
    504       MHD_HTTP_OK),
    505     TALER_TESTING_cmd_reserve_history (
    506       "push-check-post-merge-reserve-balance-post",
    507       "p2p_create-reserve-1",
    508       "EUR:1.03",
    509       MHD_HTTP_OK),
    510 
    511     TALER_TESTING_cmd_end ()
    512   };
    513   struct TALER_TESTING_Command pull[] = {
    514     TALER_TESTING_cmd_purse_create_with_reserve (
    515       "purse-create-with-reserve",
    516       MHD_HTTP_UNAVAILABLE_FOR_LEGAL_REASONS,
    517       "{\"amount\":\"EUR:1\",\"summary\":\"ice cream\"}",
    518       true /* upload contract */,
    519       true /* pay purse fee */,
    520       GNUNET_TIME_UNIT_MINUTES, /* expiration */
    521       "p2p_create-reserve-3"),
    522     TALER_TESTING_cmd_check_kyc_get (
    523       "check-kyc-purse-create",
    524       "purse-create-with-reserve",
    525       "purse-create-with-reserve",
    526       TALER_EXCHANGE_KLPT_KYC_AUTH_TRANSFER,
    527       MHD_HTTP_ACCEPTED),
    528     TALER_TESTING_cmd_get_kyc_info (
    529       "get-kyc-info-purse-create",
    530       "check-kyc-purse-create",
    531       MHD_HTTP_OK),
    532     TALER_TESTING_cmd_post_kyc_start (
    533       "start-kyc-process-purse-create",
    534       "get-kyc-info-purse-create",
    535       0,
    536       MHD_HTTP_OK),
    537     TALER_TESTING_cmd_proof_kyc_oauth2 (
    538       "p2p_proof-kyc-pull",
    539       "start-kyc-process-purse-create",
    540       "test-oauth2",
    541       "pass",
    542       MHD_HTTP_SEE_OTHER),
    543     TALER_TESTING_cmd_purse_create_with_reserve (
    544       "purse-create-with-reserve",
    545       MHD_HTTP_OK,
    546       "{\"amount\":\"EUR:1\",\"summary\":\"ice cream\"}",
    547       true /* upload contract */,
    548       true /* pay purse fee */,
    549       GNUNET_TIME_UNIT_MINUTES, /* expiration */
    550       "p2p_create-reserve-3"),
    551     TALER_TESTING_cmd_contract_get (
    552       "pull-get-contract",
    553       MHD_HTTP_OK,
    554       false, /* for deposit */
    555       "purse-create-with-reserve"),
    556     TALER_TESTING_cmd_purse_poll (
    557       "pull-poll-purse-before-deposit",
    558       MHD_HTTP_OK,
    559       "purse-create-with-reserve",
    560       "EUR:1",
    561       false,
    562       GNUNET_TIME_UNIT_MINUTES),
    563     TALER_TESTING_cmd_purse_deposit_coins (
    564       "purse-deposit-coins",
    565       MHD_HTTP_OK,
    566       0 /* min age */,
    567       "purse-create-with-reserve",
    568       "p2p_withdraw-coin-1",
    569       "EUR:1.01",
    570       NULL),
    571     TALER_TESTING_cmd_coin_history (
    572       "coin-history-purse-pull-deposit",
    573       "p2p_withdraw-coin-1#0",
    574       "EUR:2.98",
    575       MHD_HTTP_OK),
    576     TALER_TESTING_cmd_purse_poll_finish (
    577       "pull-deposit-purse-poll-finish",
    578       GNUNET_TIME_relative_multiply (
    579         GNUNET_TIME_UNIT_SECONDS,
    580         5),
    581       "pull-poll-purse-before-deposit"),
    582     TALER_TESTING_cmd_status (
    583       "pull-check-post-merge-reserve-balance-get-2",
    584       "p2p_create-reserve-3",
    585       "EUR:1.03",
    586       MHD_HTTP_OK),
    587     TALER_TESTING_cmd_reserve_history (
    588       "push-check-post-merge-reserve-balance-post-2",
    589       "p2p_create-reserve-3",
    590       "EUR:1.03",
    591       MHD_HTTP_OK),
    592     TALER_TESTING_cmd_end ()
    593   };
    594   struct TALER_TESTING_Command aml[] = {
    595     TALER_TESTING_cmd_set_officer (
    596       "create-aml-officer-1",
    597       NULL,
    598       "Peter Falk",
    599       true,
    600       true),
    601     TALER_TESTING_cmd_get_aml_officer (
    602       "get-read-only-aml-officer",
    603       "create-aml-officer-1",
    604       MHD_HTTP_OK,
    605       "Peter Falk",
    606       true),
    607     TALER_TESTING_cmd_check_aml_decisions (
    608       "check-decisions-none-normal",
    609       "create-aml-officer-1",
    610       NULL,
    611       MHD_HTTP_OK),
    612     /* Trigger something upon which an AML officer could act */
    613     TALER_TESTING_cmd_wallet_kyc_get (
    614       "wallet-trigger-kyc-for-aml",
    615       NULL,
    616       "EUR:1000",
    617       MHD_HTTP_UNAVAILABLE_FOR_LEGAL_REASONS),
    618     TALER_TESTING_cmd_get_active_legitimization_measures (
    619       "check-decisions-wallet-pending",
    620       "create-aml-officer-1",
    621       "wallet-trigger-kyc-for-aml",
    622       MHD_HTTP_OK,
    623       "{\"measures\": [{\"check_name\": \"oauth-test-id\", \"prog_name\": \"oauth-output-check\", \"context\": {}}], \"is_and_combinator\": true, \"verboten\": false}"),
    624     /* Test that we are not allowed to take AML decisions as our
    625        AML staff account is on read-only */
    626     TALER_TESTING_cmd_take_aml_decision (
    627       "aml-decide-while-disabled",
    628       "create-aml-officer-1",
    629       "wallet-trigger-kyc-for-aml",
    630       true /* keep investigating */,
    631       GNUNET_TIME_UNIT_HOURS /* expiration */,
    632       NULL /* successor measure: default */,
    633       "{\"rules\":["
    634       "{\"timeframe\":{\"d_us\":3600000000},"
    635       " \"threshold\":\"EUR:10000\","
    636       " \"operation_type\":\"BALANCE\","
    637       " \"verboten\":true"
    638       "}"
    639       "]}" /* new rules */,
    640       "{}" /* properties */,
    641       "party time",
    642       MHD_HTTP_CONFLICT),
    643     /* Check that no decision was taken, but that we are allowed
    644        to read this information */
    645     TALER_TESTING_cmd_check_aml_decisions (
    646       "check-aml-decision-empty",
    647       "create-aml-officer-1",
    648       "aml-decide-while-disabled",
    649       MHD_HTTP_NO_CONTENT),
    650     TALER_TESTING_cmd_sleep (
    651       "sleep-1b",
    652       1),
    653     TALER_TESTING_cmd_set_officer (
    654       "create-aml-officer-1-enable",
    655       "create-aml-officer-1",
    656       "Peter Falk",
    657       true,
    658       false),
    659     TALER_TESTING_cmd_get_aml_officer (
    660       "get-read-write-aml-officer",
    661       "create-aml-officer-1",
    662       MHD_HTTP_OK,
    663       "Peter Falk",
    664       false),
    665     TALER_TESTING_cmd_take_aml_decision (
    666       "aml-decide",
    667       "create-aml-officer-1",
    668       "wallet-trigger-kyc-for-aml",
    669       true /* keep investigating */,
    670       GNUNET_TIME_UNIT_HOURS /* expiration */,
    671       NULL /* successor measure: default */,
    672       "{\"rules\":["
    673       "{\"timeframe\":{\"d_us\":3600000000},"
    674       " \"threshold\":\"EUR:10000\","
    675       " \"operation_type\":\"BALANCE\","
    676       " \"verboten\":true"
    677       "}"
    678       "]}" /* new rules */,
    679       "{}" /* properties */,
    680       "party time",
    681       MHD_HTTP_NO_CONTENT),
    682     TALER_TESTING_cmd_check_aml_decisions (
    683       "check-decisions-one-normal",
    684       "create-aml-officer-1",
    685       "aml-decide",
    686       MHD_HTTP_OK),
    687     TALER_TESTING_cmd_wallet_kyc_get (
    688       "wallet-trigger-kyc-for-aml-allowed",
    689       "wallet-trigger-kyc-for-aml",
    690       "EUR:1000",
    691       MHD_HTTP_OK),
    692     TALER_TESTING_cmd_wallet_kyc_get (
    693       "wallet-trigger-kyc-for-aml-denied-high",
    694       "wallet-trigger-kyc-for-aml",
    695       "EUR:20000",
    696       MHD_HTTP_UNAVAILABLE_FOR_LEGAL_REASONS),
    697     TALER_TESTING_cmd_sleep (
    698       "sleep-1d",
    699       1),
    700     TALER_TESTING_cmd_set_officer (
    701       "create-aml-officer-1-disable",
    702       "create-aml-officer-1",
    703       "Peter Falk",
    704       false,
    705       true),
    706     TALER_TESTING_cmd_get_aml_officer (
    707       "get-disabled-aml-officer",
    708       "create-aml-officer-1",
    709       MHD_HTTP_FORBIDDEN,
    710       NULL,
    711       true),
    712     /* Test that we are NOT allowed to read AML decisions now that
    713        our AML staff account is disabled */
    714     TALER_TESTING_cmd_check_aml_decisions (
    715       "check-aml-decision-disabled",
    716       "create-aml-officer-1",
    717       "aml-decide",
    718       MHD_HTTP_FORBIDDEN),
    719     TALER_TESTING_cmd_end ()
    720   };
    721 
    722   struct TALER_TESTING_Command aml_form[] = {
    723     TALER_TESTING_cmd_set_officer (
    724       "create-aml-form-officer-1",
    725       NULL,
    726       "Peter Falk",
    727       true,
    728       false),
    729     /* Trigger something upon which an AML officer could act */
    730     TALER_TESTING_cmd_wallet_kyc_get (
    731       "wallet-trigger-kyc-for-form-aml",
    732       NULL,
    733       "EUR:1000",
    734       MHD_HTTP_UNAVAILABLE_FOR_LEGAL_REASONS),
    735     TALER_TESTING_cmd_wallet_kyc_get (
    736       "wallet-trigger-kyc-for-form-aml-disallowed",
    737       "wallet-trigger-kyc-for-form-aml",
    738       "EUR:500",
    739       MHD_HTTP_UNAVAILABLE_FOR_LEGAL_REASONS),
    740     /* AML officer switches from Oauth2 to form */
    741     TALER_TESTING_cmd_take_aml_decision (
    742       "aml-decide-form",
    743       "create-aml-form-officer-1",
    744       "wallet-trigger-kyc-for-form-aml",
    745       false /* just awaiting KYC, no investigation */,
    746       GNUNET_TIME_UNIT_HOURS /* expiration */,
    747       NULL /* successor measure: default */,
    748       "{\"rules\":"
    749       " ["
    750       "   {"
    751       "     \"timeframe\":{\"d_us\":3600000000}"
    752       "     ,\"threshold\":\"EUR:0\""
    753       "     ,\"operation_type\":\"BALANCE\""
    754       "     ,\"display_priority\":65536"
    755       "     ,\"measures\":[\"form-measure\"]"
    756       "     ,\"verboten\":false"
    757       "   }"
    758       " ]" /* end new rules */
    759       ",\"new_measures\":\"form-measure\""
    760       ",\"custom_measures\":"
    761       "  {"
    762       "    \"form-measure\":"
    763       "    {"
    764       "       \"check_name\":\"test-form\""
    765       "      ,\"prog_name\":\"test-form-check\""
    766       "    }"
    767       "  }" /* end custom measures */
    768       "}",
    769       "{}" /* properties */,
    770       "form time",
    771       MHD_HTTP_NO_CONTENT),
    772     /* Wallet learns about form submission */
    773     TALER_TESTING_cmd_check_kyc_get (
    774       "check-kyc-form",
    775       "wallet-trigger-kyc-for-form-aml",
    776       "wallet-trigger-kyc-for-form-aml",
    777       TALER_EXCHANGE_KLPT_KYC_AUTH_TRANSFER,
    778       MHD_HTTP_ACCEPTED),
    779     TALER_TESTING_cmd_get_kyc_info (
    780       "get-kyc-info-form",
    781       "check-kyc-form",
    782       MHD_HTTP_OK),
    783     TALER_TESTING_cmd_post_kyc_form (
    784       "wallet-post-kyc-wrong-form",
    785       "get-kyc-info-form",
    786       0,  /* requirement index */
    787       "application/json",
    788       "{\"FORM_ID\":\"wrong\",\"FULL_NAME\":\"Bob\",\"DATE_OF_BIRTH\":\"1990-00-00\"}",
    789       MHD_HTTP_CONFLICT),
    790     TALER_TESTING_cmd_post_kyc_form (
    791       "wallet-post-kyc-form",
    792       "get-kyc-info-form",
    793       0,  /* requirement index */
    794       "application/json",
    795       "{\"FORM_ID\":\"full_name_and_birthdate\",\"FULL_NAME\":\"Bob\",\"DATE_OF_BIRTH\":\"1990-00-00\"}",
    796       MHD_HTTP_NO_CONTENT),
    797     /* now this should be allowed */
    798     TALER_TESTING_cmd_wallet_kyc_get (
    799       "wallet-trigger-kyc-for-form-aml-allowed",
    800       "wallet-trigger-kyc-for-form-aml",
    801       "EUR:500",
    802       MHD_HTTP_OK),
    803     TALER_TESTING_cmd_end ()
    804   };
    805 
    806 
    807   struct TALER_TESTING_Command commands[] = {
    808     TALER_TESTING_cmd_run_fakebank (
    809       "run-fakebank",
    810       cred.cfg,
    811       "exchange-account-2"),
    812     TALER_TESTING_cmd_system_start (
    813       "start-taler",
    814       CONFIG_FILE,
    815       "-e",
    816       NULL),
    817     TALER_TESTING_cmd_get_exchange (
    818       "get-exchange",
    819       cred.cfg,
    820       NULL,
    821       true,
    822       true),
    823     TALER_TESTING_cmd_batch (
    824       "withdraw",
    825       withdraw),
    826     TALER_TESTING_cmd_batch (
    827       "spend",
    828       spend),
    829     TALER_TESTING_cmd_batch (
    830       "track",
    831       track),
    832     TALER_TESTING_cmd_batch (
    833       "withdraw-kyc",
    834       withdraw_kyc),
    835     TALER_TESTING_cmd_batch (
    836       "wallet-kyc",
    837       wallet_kyc),
    838     TALER_TESTING_cmd_batch (
    839       "p2p_withdraw",
    840       p2p_withdraw),
    841     TALER_TESTING_cmd_batch (
    842       "push",
    843       push),
    844     TALER_TESTING_cmd_batch (
    845       "pull",
    846       pull),
    847     TALER_TESTING_cmd_batch ("aml",
    848                              aml),
    849     TALER_TESTING_cmd_batch ("aml-form",
    850                              aml_form),
    851     TALER_TESTING_cmd_end ()
    852   };
    853 
    854   (void) cls;
    855   TALER_TESTING_run (is,
    856                      commands);
    857 }
    858 
    859 
    860 int
    861 main (int argc,
    862       char *const *argv)
    863 {
    864   (void) argc;
    865   return TALER_TESTING_main (
    866     argv,
    867     "INFO",
    868     CONFIG_FILE,
    869     "exchange-account-2",
    870     TALER_TESTING_BS_FAKEBANK,
    871     &cred,
    872     &run,
    873     NULL);
    874 }
    875 
    876 
    877 /* end of test_kyc_api.c */