mirror of
https://github.com/featurebasedb/featurebase.git
synced 2026-10-08 20:07:51 +00:00
authz changes
This commit is contained in:
parent
10a7aa55ea
commit
1c907281bf
3 changed files with 22 additions and 25 deletions
|
|
@ -20,6 +20,7 @@ import (
|
|||
"strings"
|
||||
"testing"
|
||||
|
||||
"github.com/molecula/featurebase/v2/authn"
|
||||
"github.com/molecula/featurebase/v2/authz"
|
||||
)
|
||||
|
||||
|
|
@ -107,17 +108,17 @@ admin: "ac97c9e2-346b-42a2-b6da-18bcb61a32fe"`
|
|||
// initializes groups that are returned from identity provider
|
||||
groupName := "name"
|
||||
userId := "user-id"
|
||||
groupsList1 := []authz.Group{}
|
||||
groupsList2 := []authz.Group{{userId, "fake-group", groupName}}
|
||||
groupsList3 := []authz.Group{
|
||||
groupsList1 := []authn.Group{}
|
||||
groupsList2 := []authn.Group{{userId, "fake-group", groupName}}
|
||||
groupsList3 := []authn.Group{
|
||||
{userId, "dca35310-ecda-4f23-86cd-876aee55906b", groupName},
|
||||
{userId, "dca35310-ecda-4f23-86cd-876aee559900", groupName},
|
||||
}
|
||||
groupsList4 := []authz.Group{{userId, "ac97c9e2-346b-42a2-b6da-18bcb61a32fe", groupName}}
|
||||
groupsList4 := []authn.Group{{userId, "ac97c9e2-346b-42a2-b6da-18bcb61a32fe", groupName}}
|
||||
|
||||
tests := []struct {
|
||||
yamlData string
|
||||
groups []authz.Group
|
||||
groups []authn.Group
|
||||
index string
|
||||
userAccess string
|
||||
err string
|
||||
|
|
@ -201,11 +202,11 @@ admin: "ac97c9e2-346b-42a2-b6da-18bcb61a32fe"`
|
|||
|
||||
func TestAuth_IsAdmin(t *testing.T) {
|
||||
|
||||
group1 := []authz.Group{
|
||||
group1 := []authn.Group{
|
||||
{"admin-user-id", "ac97c9e2-346b-42a2-b6da-18bcb61a32fe", "admin-group"},
|
||||
}
|
||||
|
||||
group2 := []authz.Group{
|
||||
group2 := []authn.Group{
|
||||
{"user-id", "dca35310-ecda-4f23-86cd-876aee55906b", "group-name"},
|
||||
}
|
||||
|
||||
|
|
@ -217,7 +218,7 @@ func TestAuth_IsAdmin(t *testing.T) {
|
|||
}
|
||||
|
||||
tests := []struct {
|
||||
groups []authz.Group
|
||||
groups []authn.Group
|
||||
groupPermissions authz.GroupPermissions
|
||||
output bool
|
||||
}{
|
||||
|
|
@ -242,15 +243,15 @@ func TestAuth_IsAdmin(t *testing.T) {
|
|||
|
||||
func TestAuth_GetAuthorizedIndexList(t *testing.T) {
|
||||
|
||||
group1 := []authz.Group{
|
||||
group1 := []authn.Group{
|
||||
{"user-id", "dca35310-ecda-4f23-86cd-876aee55906b", "group-name"},
|
||||
}
|
||||
|
||||
group2 := []authz.Group{
|
||||
group2 := []authn.Group{
|
||||
{"admin-user-id", "ac97c9e2-346b-42a2-b6da-18bcb61a32fe", "admin-group"},
|
||||
}
|
||||
|
||||
group3 := []authz.Group{
|
||||
group3 := []authn.Group{
|
||||
{"user-id", "dca35310-ecda-4f23-86cd-876aee559900", "group-name"},
|
||||
}
|
||||
|
||||
|
|
@ -268,7 +269,7 @@ func TestAuth_GetAuthorizedIndexList(t *testing.T) {
|
|||
}
|
||||
|
||||
tests := []struct {
|
||||
groups []authz.Group
|
||||
groups []authn.Group
|
||||
permission string
|
||||
output []string
|
||||
}{
|
||||
|
|
|
|||
|
|
@ -15,7 +15,6 @@ import (
|
|||
"strings"
|
||||
"time"
|
||||
|
||||
|
||||
"github.com/molecula/featurebase/v2/authz"
|
||||
petcd "github.com/molecula/featurebase/v2/etcd"
|
||||
rbfcfg "github.com/molecula/featurebase/v2/rbf/cfg"
|
||||
|
|
@ -234,15 +233,14 @@ type Config struct {
|
|||
// Toggles /schema/details endpoint. If off, it returns empty.
|
||||
SchemaDetailsOn bool `toml:"schema-details-on"`
|
||||
|
||||
|
||||
Auth Auth
|
||||
}
|
||||
|
||||
type Auth struct {
|
||||
// Enable AuthZ/AuthN for featurebase server
|
||||
Enable bool `toml:"enable"`
|
||||
|
||||
ClientId string `toml:"client-id"`
|
||||
|
||||
ClientId string `toml:"client-id"`
|
||||
ClientSecret string `toml:"client-secret"`
|
||||
AuthorizeURL string `toml:"authorize-url"`
|
||||
TokenURL string `toml:"token-url"`
|
||||
|
|
@ -251,8 +249,7 @@ type Auth struct {
|
|||
Scopes []string `toml:"scopes"`
|
||||
HashKey string `toml:"hash-key"`
|
||||
BlockKey string `toml:"block-key"`
|
||||
PermissionsFile string `toml:"permissions"`
|
||||
Auth authz.Auth `toml:"auth"`
|
||||
PermissionsFile string `toml:"permissions"`
|
||||
}
|
||||
|
||||
// Namespace returns the namespace to use based on the Future flag.
|
||||
|
|
|
|||
|
|
@ -8,7 +8,6 @@ import (
|
|||
"os"
|
||||
"strings"
|
||||
"testing"
|
||||
"github.com/molecula/featurebase/v2/authz"
|
||||
)
|
||||
|
||||
type addrs struct{ bind, advertise string }
|
||||
|
|
@ -281,7 +280,7 @@ func TestConfig_validateAuth(t *testing.T) {
|
|||
errorMesgEmpty := "empty string"
|
||||
errorMesgURL := "invalid URL"
|
||||
errorMesgScope := "must provide scope"
|
||||
errorMesgKey := "invalid key length"
|
||||
errorMesgKey := "invalid key length"
|
||||
validTestURL := "https://url.com/"
|
||||
validClientID := "clientid"
|
||||
validClientSecret := "clientSecret"
|
||||
|
|
@ -366,8 +365,8 @@ func TestConfig_validateAuth(t *testing.T) {
|
|||
{
|
||||
// Auth enabled, all configs are set properly except scope
|
||||
[]string{
|
||||
errorMesgScope,
|
||||
},
|
||||
errorMesgScope,
|
||||
},
|
||||
Auth{
|
||||
Enable: enable,
|
||||
ClientId: validClientID,
|
||||
|
|
@ -433,9 +432,9 @@ func TestConfig_validateAuth(t *testing.T) {
|
|||
}
|
||||
|
||||
for i, e := range errors {
|
||||
if !strings.Contains(e.Error(), test.expErrs[i]) {
|
||||
t.Errorf("expected error to contain %s, but got %s", test.expErrs[i], e.Error())
|
||||
}
|
||||
if !strings.Contains(e.Error(), test.expErrs[i]) {
|
||||
t.Errorf("expected error to contain %s, but got %s", test.expErrs[i], e.Error())
|
||||
}
|
||||
}
|
||||
})
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue