From 6425fc50fcf1f29224636317cb514ceef2f6024a Mon Sep 17 00:00:00 2001 From: Souhaila Noor Date: Fri, 3 Dec 2021 11:24:18 -0600 Subject: [PATCH] added identity provider scope url as parameter --- auth/auth.go | 3 + ctl/server.go | 1 + server/config.go | 1 + server/config_internal_test.go | 100 +++++++++++++++++---------------- 4 files changed, 58 insertions(+), 47 deletions(-) diff --git a/auth/auth.go b/auth/auth.go index de7ed303d..4e617c998 100644 --- a/auth/auth.go +++ b/auth/auth.go @@ -32,4 +32,7 @@ type Auth struct { // Group Endpoint URL GroupEndpointURL string `toml:"group-endpoint-url"` + + // Scope URL + ScopeURL string `toml:"scope-url"` } diff --git a/ctl/server.go b/ctl/server.go index a368637e3..c5d43a937 100644 --- a/ctl/server.go +++ b/ctl/server.go @@ -129,5 +129,6 @@ func BuildServerFlags(cmd *cobra.Command, srv *server.Command) { flags.StringVar(&srv.Config.Auth.AuthorizeURL, "auth.authorize-url", srv.Config.Auth.AuthorizeURL, "Identity Provider's Authorize URL.") flags.StringVar(&srv.Config.Auth.TokenURL, "auth.token-url", srv.Config.Auth.TokenURL, "Identity Provider's Token URL.") flags.StringVar(&srv.Config.Auth.GroupEndpointURL, "auth.group-endpoint-url", srv.Config.Auth.GroupEndpointURL, "Identity Provider's Group endpoint URL.") + flags.StringVar(&srv.Config.Auth.ScopeURL, "auth.scope-url", srv.Config.Auth.ScopeURL, "Identity Provider's Scope URL.") } diff --git a/server/config.go b/server/config.go index 79ae314ad..4d69521a1 100644 --- a/server/config.go +++ b/server/config.go @@ -616,6 +616,7 @@ func (c *Config) ValidateAuth() ([]error, error) { "AuthorizeURL": c.Auth.AuthorizeURL, "TokenURL": c.Auth.TokenURL, "GroupEndpointURL": c.Auth.GroupEndpointURL, + "ScopeURL": c.Auth.ScopeURL, } errors := make([]error, 0) diff --git a/server/config_internal_test.go b/server/config_internal_test.go index 927f65327..8917d0fc2 100644 --- a/server/config_internal_test.go +++ b/server/config_internal_test.go @@ -315,6 +315,7 @@ func TestConfig_validateAuth(t *testing.T) { errorMesgEmpty, errorMesgEmpty, errorMesgEmpty, + errorMesgEmpty, }, auth.Auth{ Enable: enable, @@ -323,6 +324,45 @@ func TestConfig_validateAuth(t *testing.T) { AuthorizeURL: emptyString, TokenURL: emptyString, GroupEndpointURL: emptyString, + ScopeURL: emptyString, + }, + }, + { + // Auth enabled, some configs are set to empty string + []string{ + errorMesgEmpty, + errorMesgEmpty, + errorMesgEmpty, + errorMesgEmpty, + errorMesgEmpty, + }, + auth.Auth{ + Enable: enable, + ClientId: validClientID, + ClientSecret: emptyString, + AuthorizeURL: emptyString, + TokenURL: emptyString, + GroupEndpointURL: emptyString, + ScopeURL: emptyString, + }, + }, + { + // Auth enabled, some configs are set to empty string + []string{ + errorMesgEmpty, + errorMesgEmpty, + errorMesgEmpty, + errorMesgEmpty, + errorMesgEmpty, + }, + auth.Auth{ + Enable: enable, + ClientId: emptyString, + ClientSecret: validClientSecret, + AuthorizeURL: emptyString, + TokenURL: emptyString, + GroupEndpointURL: emptyString, + ScopeURL: emptyString, }, }, { @@ -336,27 +376,11 @@ func TestConfig_validateAuth(t *testing.T) { auth.Auth{ Enable: enable, ClientId: validClientID, - ClientSecret: emptyString, - AuthorizeURL: emptyString, - TokenURL: emptyString, - GroupEndpointURL: emptyString, - }, - }, - { - // Auth enabled, some configs are set to empty string - []string{ - errorMesgEmpty, - errorMesgEmpty, - errorMesgEmpty, - errorMesgEmpty, - }, - auth.Auth{ - Enable: enable, - ClientId: emptyString, ClientSecret: validClientSecret, AuthorizeURL: emptyString, TokenURL: emptyString, GroupEndpointURL: emptyString, + ScopeURL: emptyString, }, }, { @@ -366,21 +390,6 @@ func TestConfig_validateAuth(t *testing.T) { errorMesgEmpty, errorMesgEmpty, }, - auth.Auth{ - Enable: enable, - ClientId: validClientID, - ClientSecret: validClientSecret, - AuthorizeURL: emptyString, - TokenURL: emptyString, - GroupEndpointURL: emptyString, - }, - }, - { - // Auth enabled, some configs are set to empty string - []string{ - errorMesgEmpty, - errorMesgEmpty, - }, auth.Auth{ Enable: enable, ClientId: validClientID, @@ -388,12 +397,14 @@ func TestConfig_validateAuth(t *testing.T) { AuthorizeURL: validTestURL, TokenURL: emptyString, GroupEndpointURL: emptyString, + ScopeURL: emptyString, }, }, { // Auth enabled, some configs are set to empty string []string{ errorMesgEmpty, + errorMesgEmpty, }, auth.Auth{ Enable: enable, @@ -402,10 +413,11 @@ func TestConfig_validateAuth(t *testing.T) { AuthorizeURL: validTestURL, TokenURL: validTestURL, GroupEndpointURL: emptyString, + ScopeURL: emptyString, }, }, { - // Auth enabled, + // Auth enabled, some strings are set to invalid URL []string{ errorMesgURL, }, @@ -416,9 +428,11 @@ func TestConfig_validateAuth(t *testing.T) { AuthorizeURL: notValidURL, TokenURL: validTestURL, GroupEndpointURL: validTestURL, + ScopeURL: validTestURL, }, }, { + // Auth enabled, some strings are set to invalid URL []string{ errorMesgURL, errorMesgURL, @@ -430,23 +444,11 @@ func TestConfig_validateAuth(t *testing.T) { AuthorizeURL: validTestURL, TokenURL: notValidURL, GroupEndpointURL: notValidURL, + ScopeURL: validTestURL, }, }, { - []string{ - errorMesgEmpty, - errorMesgURL, - }, - auth.Auth{ - Enable: enable, - ClientId: validClientID, - ClientSecret: emptyString, - AuthorizeURL: validTestURL, - TokenURL: validTestURL, - GroupEndpointURL: notValidURL, - }, - }, - { + // Auth enabled, all configs are set properly []string{}, auth.Auth{ Enable: enable, @@ -455,15 +457,18 @@ func TestConfig_validateAuth(t *testing.T) { AuthorizeURL: validTestURL, TokenURL: validTestURL, GroupEndpointURL: validTestURL, + ScopeURL: validTestURL, }, }, { + // Auth disabled, all configs are set to empty string []string{ errorMesgEmpty, errorMesgEmpty, errorMesgEmpty, errorMesgEmpty, errorMesgEmpty, + errorMesgEmpty, }, auth.Auth{ Enable: disable, @@ -472,6 +477,7 @@ func TestConfig_validateAuth(t *testing.T) { AuthorizeURL: emptyString, TokenURL: emptyString, GroupEndpointURL: emptyString, + ScopeURL: emptyString, }, }, }