added more authz functionality

This commit is contained in:
Souhaila Noor 2021-12-17 15:51:30 -06:00
parent 44b855d50b
commit f05f1d0de2
3 changed files with 151 additions and 4 deletions

View file

@ -91,7 +91,7 @@ func (p *GroupPermissions) GetPermissions(groups []Group, index string) (permiss
if perm, ok := p.Permissions[group.GroupID][index]; ok {
allPermissions[perm] = true
} else {
return "", fmt.Errorf("User %s is NOT allowed access to index %s", group.UserID, index)
return "", fmt.Errorf("User %s does not have permission to index %s", group.UserID, index)
}
} else {
groupsDenied = append(groupsDenied, group.GroupID)
@ -99,7 +99,7 @@ func (p *GroupPermissions) GetPermissions(groups []Group, index string) (permiss
}
if len(groupsDenied) == len(groups) {
return "", fmt.Errorf("group(s) %s are NOT allowed access to FeatureBase", groupsDenied)
return "", fmt.Errorf("group(s) %s does not have permission to FeatureBase", groupsDenied)
}
if allPermissions["admin"] {
@ -112,3 +112,30 @@ func (p *GroupPermissions) GetPermissions(groups []Group, index string) (permiss
return "", fmt.Errorf("no permissions found")
}
}
func (p *GroupPermissions) IsAdmin(groups []Group) bool {
for _, group := range groups {
if _, ok := p.Permissions[group.GroupID]; ok {
for _, permission := range p.Permissions[group.GroupID] {
if permission == "admin" {
return true
}
}
}
}
return false
}
func (p *GroupPermissions) GetAuthorizedIndexList(groups []Group, desiredPermission string) (indexList []string) {
for _, group := range groups {
if _, ok := p.Permissions[group.GroupID]; ok {
for index, permission := range p.Permissions[group.GroupID] {
if permission == desiredPermission {
indexList = append(indexList, index)
}
}
}
}
return indexList
}

View file

@ -23,6 +23,7 @@ import (
)
func TestAuth_ReadPermissionsFile(t *testing.T) {
singleInput := `"dca35310-ecda-4f23-86cd-876aee55906b":
"test": "read"`
@ -67,6 +68,7 @@ func TestAuth_ReadPermissionsFile(t *testing.T) {
}
func TestAuth_GetPermissions(t *testing.T) {
// initializes different example of permissions file in yaml
permissions1 := `"dca35310-ecda-4f23-86cd-876aee55906b":
"test": "read"`
@ -112,14 +114,14 @@ func TestAuth_GetPermissions(t *testing.T) {
groupsList3,
"test1",
"",
"NOT allowed access to index",
"does not have permission to index",
},
{
permissions2,
groupsList2,
"test",
"",
"NOT allowed access to FeatureBase",
"does not have permission to FeatureBase",
},
{
permissions1,
@ -176,3 +178,90 @@ func TestAuth_GetPermissions(t *testing.T) {
})
}
}
func TestAuth_IsAdmin(t *testing.T) {
group := []authz.Group{
{"user-is", "dca35310-ecda-4f23-86cd-876aee55906b", "group-name"},
}
groupPermissions1 := map[string]map[string]string{
"dca35310-ecda-4f23-86cd-876aee55906b": {"test": "admin"},
}
groupPermissions2 := map[string]map[string]string{
"dca35310-ecda-4f23-86cd-876aee55906b": {"test": "read"},
}
tests := []struct {
groups []authz.Group
groupPermissions map[string]map[string]string
output bool
}{
{
group, groupPermissions1, true,
},
{
group, groupPermissions2, false,
},
}
for i, test := range tests {
t.Run(fmt.Sprintf("%d", i), func(t *testing.T) {
p := authz.GroupPermissions{test.groupPermissions}
resp := p.IsAdmin(test.groups)
if resp != test.output {
t.Errorf("expected %t, but got %t", test.output, resp)
}
})
}
}
func TestAuth_GetAuthorizedIndexList(t *testing.T) {
group := []authz.Group{
{"user-is", "dca35310-ecda-4f23-86cd-876aee55906b", "group-name"},
}
p := authz.GroupPermissions{map[string]map[string]string{
"dca35310-ecda-4f23-86cd-876aee55906b": {
"test1": "admin",
"test2": "read",
"test3": "read",
},
}}
tests := []struct {
groups []authz.Group
permission string
output []string
}{
{
group,
"read",
[]string{"test2", "test3"},
},
{
group,
"admin",
[]string{"test1"},
},
{
group,
"write",
nil,
},
}
for i, test := range tests {
t.Run(fmt.Sprintf("%d", i), func(t *testing.T) {
indexList := p.GetAuthorizedIndexList(test.groups, test.permission)
if !reflect.DeepEqual(indexList, test.output) {
t.Errorf("expected %s, but got %s", test.output, indexList)
}
})
}
}

View file

@ -237,6 +237,37 @@ func (m *Command) Start() (err error) {
if err = p.ReadPermissionsFile(permsFile); err != nil {
return err
}
groups := []authz.Group{
{
UserID: "user-id",
GroupID: "dca35310-ecda-4f23-86cd-876aee55906b",
GroupName: "group-name",
},
// {
// UserID: "user-id",
// GroupID: "dca35310-ecda-4f23-86cd-876aee559900",
// GroupName: "group-name",
// },
}
index := "test"
perm, err := p.GetPermissions(groups, index)
fmt.Printf("\nuser has %s access to index %s\n", perm, index)
if err != nil {
fmt.Printf("\np: %s, err: %s\n", perm, err.Error())
}
adminAccess := p.IsAdmin(groups)
fmt.Printf("\nAdminAccess: %t\n", adminAccess)
accessList := []string{"read", "write", "admin"}
for _, a := range accessList {
indexList := p.GetAuthorizedIndexList(groups, a)
fmt.Printf("\nPermission requested: %s, Index List: %s\n", a, indexList)
}
}
// Initialize server.