2020-07-23 15:05:21 +00:00
|
|
|
/*
|
|
|
|
Copyright 2020 VMware, Inc.
|
|
|
|
SPDX-License-Identifier: Apache-2.0
|
|
|
|
*/
|
|
|
|
|
2020-08-14 14:11:14 +00:00
|
|
|
package credentialrequest
|
2020-07-23 15:05:21 +00:00
|
|
|
|
|
|
|
import (
|
|
|
|
"context"
|
2020-07-27 13:08:39 +00:00
|
|
|
"crypto/x509/pkix"
|
2020-07-23 15:05:21 +00:00
|
|
|
"errors"
|
2020-07-24 16:52:38 +00:00
|
|
|
"fmt"
|
2020-07-23 15:05:21 +00:00
|
|
|
"testing"
|
|
|
|
"time"
|
|
|
|
|
2020-07-27 13:08:39 +00:00
|
|
|
"github.com/golang/mock/gomock"
|
2020-08-06 22:14:30 +00:00
|
|
|
"github.com/sclevine/spec"
|
2020-07-23 15:05:21 +00:00
|
|
|
"github.com/stretchr/testify/require"
|
2020-07-23 16:50:23 +00:00
|
|
|
apierrors "k8s.io/apimachinery/pkg/api/errors"
|
2020-07-23 15:05:21 +00:00
|
|
|
metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
|
|
|
|
"k8s.io/apimachinery/pkg/runtime"
|
|
|
|
"k8s.io/apiserver/pkg/authentication/authenticator"
|
2020-07-24 15:21:36 +00:00
|
|
|
"k8s.io/apiserver/pkg/authentication/user"
|
2020-07-23 15:05:21 +00:00
|
|
|
genericapirequest "k8s.io/apiserver/pkg/endpoints/request"
|
|
|
|
"k8s.io/apiserver/pkg/registry/rest"
|
2020-08-06 22:14:30 +00:00
|
|
|
"k8s.io/klog/v2"
|
2020-07-23 15:05:21 +00:00
|
|
|
|
2020-08-24 19:30:45 +00:00
|
|
|
pinnipedapi "github.com/suzerain-io/pinniped/generated/1.19/apis/pinniped"
|
2020-08-20 17:54:15 +00:00
|
|
|
"github.com/suzerain-io/pinniped/internal/mocks/mockcertissuer"
|
|
|
|
"github.com/suzerain-io/pinniped/internal/testutil"
|
2020-07-23 15:05:21 +00:00
|
|
|
)
|
|
|
|
|
|
|
|
type contextKey struct{}
|
|
|
|
|
|
|
|
type FakeToken struct {
|
|
|
|
calledWithToken string
|
|
|
|
calledWithContext context.Context
|
|
|
|
timeout time.Duration
|
|
|
|
reachedTimeout bool
|
|
|
|
cancelled bool
|
|
|
|
webhookStartedRunningNotificationChan chan bool
|
2020-07-24 15:21:36 +00:00
|
|
|
returnResponse *authenticator.Response
|
2020-07-23 23:01:55 +00:00
|
|
|
returnUnauthenticated bool
|
2020-07-24 15:21:36 +00:00
|
|
|
returnErr error
|
2020-07-23 15:05:21 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
func (f *FakeToken) AuthenticateToken(ctx context.Context, token string) (*authenticator.Response, bool, error) {
|
|
|
|
f.calledWithToken = token
|
|
|
|
f.calledWithContext = ctx
|
|
|
|
if f.webhookStartedRunningNotificationChan != nil {
|
|
|
|
f.webhookStartedRunningNotificationChan <- true
|
|
|
|
}
|
|
|
|
afterCh := time.After(f.timeout)
|
|
|
|
select {
|
|
|
|
case <-afterCh:
|
|
|
|
f.reachedTimeout = true
|
|
|
|
case <-ctx.Done():
|
|
|
|
f.cancelled = true
|
|
|
|
}
|
2020-07-24 15:21:36 +00:00
|
|
|
return f.returnResponse, !f.returnUnauthenticated, f.returnErr
|
2020-07-23 15:05:21 +00:00
|
|
|
}
|
|
|
|
|
2020-08-06 22:14:30 +00:00
|
|
|
func TestCreate(t *testing.T) {
|
|
|
|
spec.Run(t, "create", func(t *testing.T, when spec.G, it spec.S) {
|
|
|
|
var r *require.Assertions
|
|
|
|
var ctrl *gomock.Controller
|
|
|
|
var logger *testutil.TranscriptLogger
|
|
|
|
|
|
|
|
it.Before(func() {
|
|
|
|
r = require.New(t)
|
|
|
|
ctrl = gomock.NewController(t)
|
|
|
|
logger = testutil.NewTranscriptLogger(t)
|
|
|
|
klog.SetLogger(logger) // this is unfortunately a global logger, so can't run these tests in parallel :(
|
|
|
|
})
|
|
|
|
|
|
|
|
it.After(func() {
|
|
|
|
klog.SetLogger(nil)
|
|
|
|
ctrl.Finish()
|
|
|
|
})
|
|
|
|
|
|
|
|
it("CreateSucceedsWhenGivenATokenAndTheWebhookAuthenticatesTheToken", func() {
|
|
|
|
webhook := FakeToken{
|
|
|
|
returnResponse: &authenticator.Response{
|
|
|
|
User: &user.DefaultInfo{
|
|
|
|
Name: "test-user",
|
|
|
|
UID: "test-user-uid",
|
|
|
|
Groups: []string{"test-group-1", "test-group-2"},
|
|
|
|
},
|
|
|
|
},
|
|
|
|
returnUnauthenticated: false,
|
|
|
|
}
|
|
|
|
|
|
|
|
issuer := mockcertissuer.NewMockCertIssuer(ctrl)
|
|
|
|
issuer.EXPECT().IssuePEM(
|
|
|
|
pkix.Name{
|
|
|
|
CommonName: "test-user",
|
|
|
|
Organization: []string{"test-group-1", "test-group-2"}},
|
|
|
|
[]string{},
|
|
|
|
1*time.Hour,
|
|
|
|
).Return([]byte("test-cert"), []byte("test-key"), nil)
|
|
|
|
|
|
|
|
storage := NewREST(&webhook, issuer)
|
|
|
|
requestToken := "a token"
|
|
|
|
|
2020-08-14 14:11:14 +00:00
|
|
|
response, err := callCreate(context.Background(), storage, validCredentialRequestWithToken(requestToken))
|
2020-08-06 22:14:30 +00:00
|
|
|
|
|
|
|
r.NoError(err)
|
2020-08-20 17:54:15 +00:00
|
|
|
r.IsType(&pinnipedapi.CredentialRequest{}, response)
|
2020-08-06 22:14:30 +00:00
|
|
|
|
2020-08-20 17:54:15 +00:00
|
|
|
expires := response.(*pinnipedapi.CredentialRequest).Status.Credential.ExpirationTimestamp
|
2020-08-06 22:14:30 +00:00
|
|
|
r.NotNil(expires)
|
|
|
|
r.InDelta(time.Now().Add(1*time.Hour).Unix(), expires.Unix(), 5)
|
2020-08-20 17:54:15 +00:00
|
|
|
response.(*pinnipedapi.CredentialRequest).Status.Credential.ExpirationTimestamp = metav1.Time{}
|
2020-08-06 22:14:30 +00:00
|
|
|
|
2020-08-20 17:54:15 +00:00
|
|
|
r.Equal(response, &pinnipedapi.CredentialRequest{
|
|
|
|
Status: pinnipedapi.CredentialRequestStatus{
|
|
|
|
Credential: &pinnipedapi.CredentialRequestCredential{
|
2020-08-06 22:14:30 +00:00
|
|
|
ExpirationTimestamp: metav1.Time{},
|
|
|
|
ClientCertificateData: "test-cert",
|
|
|
|
ClientKeyData: "test-key",
|
|
|
|
},
|
|
|
|
},
|
|
|
|
})
|
|
|
|
r.Equal(requestToken, webhook.calledWithToken)
|
|
|
|
requireOneLogStatement(r, logger, `"success" userID:test-user-uid,idpAuthenticated:true`)
|
|
|
|
})
|
|
|
|
|
|
|
|
it("CreateFailsWithValidTokenWhenCertIssuerFails", func() {
|
|
|
|
webhook := FakeToken{
|
|
|
|
returnResponse: &authenticator.Response{
|
|
|
|
User: &user.DefaultInfo{
|
|
|
|
Name: "test-user",
|
|
|
|
Groups: []string{"test-group-1", "test-group-2"},
|
|
|
|
},
|
|
|
|
},
|
|
|
|
returnUnauthenticated: false,
|
|
|
|
}
|
|
|
|
|
|
|
|
issuer := mockcertissuer.NewMockCertIssuer(ctrl)
|
|
|
|
issuer.EXPECT().
|
|
|
|
IssuePEM(gomock.Any(), gomock.Any(), gomock.Any()).
|
|
|
|
Return(nil, nil, fmt.Errorf("some certificate authority error"))
|
|
|
|
|
|
|
|
storage := NewREST(&webhook, issuer)
|
|
|
|
requestToken := "a token"
|
|
|
|
|
2020-08-14 14:11:14 +00:00
|
|
|
response, err := callCreate(context.Background(), storage, validCredentialRequestWithToken(requestToken))
|
2020-08-06 22:14:30 +00:00
|
|
|
requireSuccessfulResponseWithAuthenticationFailureMessage(t, err, response)
|
|
|
|
r.Equal(requestToken, webhook.calledWithToken)
|
|
|
|
requireOneLogStatement(r, logger, `"failure" failureType:cert issuer,msg:some certificate authority error`)
|
|
|
|
})
|
|
|
|
|
|
|
|
it("CreateSucceedsWithAnUnauthenticatedStatusWhenGivenATokenAndTheWebhookReturnsUnauthenticatedWithUserId", func() {
|
|
|
|
webhook := FakeToken{
|
|
|
|
returnResponse: &authenticator.Response{
|
|
|
|
User: &user.DefaultInfo{UID: "test-user-uid"},
|
|
|
|
},
|
|
|
|
returnUnauthenticated: true,
|
|
|
|
}
|
|
|
|
storage := NewREST(&webhook, nil)
|
|
|
|
requestToken := "a token"
|
|
|
|
|
2020-08-14 14:11:14 +00:00
|
|
|
response, err := callCreate(context.Background(), storage, validCredentialRequestWithToken(requestToken))
|
2020-08-06 22:14:30 +00:00
|
|
|
|
|
|
|
requireSuccessfulResponseWithAuthenticationFailureMessage(t, err, response)
|
|
|
|
r.Equal(requestToken, webhook.calledWithToken)
|
2020-08-20 17:54:15 +00:00
|
|
|
requireOneLogStatement(r, logger, `"success" userID:test-user-uid,idpAuthenticated:false,pinnipedAuthenticated:false`)
|
2020-08-06 22:14:30 +00:00
|
|
|
})
|
|
|
|
|
|
|
|
it("CreateSucceedsWithAnUnauthenticatedStatusWhenGivenATokenAndTheWebhookReturnsUnauthenticatedWithNilUser", func() {
|
|
|
|
webhook := FakeToken{
|
|
|
|
returnResponse: &authenticator.Response{User: nil},
|
|
|
|
returnUnauthenticated: true,
|
|
|
|
}
|
|
|
|
storage := NewREST(&webhook, nil)
|
|
|
|
requestToken := "a token"
|
|
|
|
|
2020-08-14 14:11:14 +00:00
|
|
|
response, err := callCreate(context.Background(), storage, validCredentialRequestWithToken(requestToken))
|
2020-08-06 22:14:30 +00:00
|
|
|
|
|
|
|
requireSuccessfulResponseWithAuthenticationFailureMessage(t, err, response)
|
|
|
|
r.Equal(requestToken, webhook.calledWithToken)
|
2020-08-20 17:54:15 +00:00
|
|
|
requireOneLogStatement(r, logger, `"success" userID:<none>,idpAuthenticated:false,pinnipedAuthenticated:false`)
|
2020-08-06 22:14:30 +00:00
|
|
|
})
|
|
|
|
|
|
|
|
it("CreateSucceedsWithAnUnauthenticatedStatusWhenWebhookFails", func() {
|
|
|
|
webhook := FakeToken{
|
|
|
|
returnErr: errors.New("some webhook error"),
|
|
|
|
}
|
|
|
|
storage := NewREST(&webhook, nil)
|
|
|
|
|
2020-08-14 14:11:14 +00:00
|
|
|
response, err := callCreate(context.Background(), storage, validCredentialRequest())
|
2020-08-06 22:14:30 +00:00
|
|
|
|
|
|
|
requireSuccessfulResponseWithAuthenticationFailureMessage(t, err, response)
|
|
|
|
requireOneLogStatement(r, logger, `"failure" failureType:webhook authentication,msg:some webhook error`)
|
|
|
|
})
|
|
|
|
|
2020-09-11 20:08:54 +00:00
|
|
|
it("CreateSucceedsWithAnUnauthenticatedStatusWhenWebhookReturnsNilResponseWithAuthenticatedFalse", func() {
|
|
|
|
webhook := FakeToken{
|
|
|
|
returnResponse: nil,
|
|
|
|
returnUnauthenticated: false,
|
|
|
|
}
|
|
|
|
storage := NewREST(&webhook, nil)
|
|
|
|
|
|
|
|
response, err := callCreate(context.Background(), storage, validCredentialRequest())
|
|
|
|
|
|
|
|
requireSuccessfulResponseWithAuthenticationFailureMessage(t, err, response)
|
|
|
|
requireOneLogStatement(r, logger, `"success" userID:<none>,idpAuthenticated:true,pinnipedAuthenticated:false`)
|
|
|
|
})
|
|
|
|
|
2020-08-06 22:14:30 +00:00
|
|
|
it("CreateSucceedsWithAnUnauthenticatedStatusWhenWebhookDoesNotReturnAnyUserInfo", func() {
|
|
|
|
webhook := FakeToken{
|
|
|
|
returnResponse: &authenticator.Response{},
|
|
|
|
returnUnauthenticated: false,
|
|
|
|
}
|
|
|
|
storage := NewREST(&webhook, nil)
|
|
|
|
|
2020-08-14 14:11:14 +00:00
|
|
|
response, err := callCreate(context.Background(), storage, validCredentialRequest())
|
2020-08-06 22:14:30 +00:00
|
|
|
|
|
|
|
requireSuccessfulResponseWithAuthenticationFailureMessage(t, err, response)
|
2020-08-20 17:54:15 +00:00
|
|
|
requireOneLogStatement(r, logger, `"success" userID:<none>,idpAuthenticated:true,pinnipedAuthenticated:false`)
|
2020-08-06 22:14:30 +00:00
|
|
|
})
|
|
|
|
|
|
|
|
it("CreateSucceedsWithAnUnauthenticatedStatusWhenWebhookReturnsAnEmptyUsername", func() {
|
|
|
|
webhook := FakeToken{
|
|
|
|
returnResponse: &authenticator.Response{
|
|
|
|
User: &user.DefaultInfo{
|
|
|
|
Name: "",
|
|
|
|
},
|
|
|
|
},
|
|
|
|
}
|
|
|
|
storage := NewREST(&webhook, nil)
|
|
|
|
|
2020-08-14 14:11:14 +00:00
|
|
|
response, err := callCreate(context.Background(), storage, validCredentialRequest())
|
2020-08-06 22:14:30 +00:00
|
|
|
|
|
|
|
requireSuccessfulResponseWithAuthenticationFailureMessage(t, err, response)
|
2020-08-20 17:54:15 +00:00
|
|
|
requireOneLogStatement(r, logger, `"success" userID:,idpAuthenticated:true,pinnipedAuthenticated:false`)
|
2020-08-06 22:14:30 +00:00
|
|
|
})
|
|
|
|
|
|
|
|
it("CreateDoesNotPassAdditionalContextInfoToTheWebhook", func() {
|
|
|
|
webhook := FakeToken{
|
|
|
|
returnResponse: webhookSuccessResponse(),
|
|
|
|
}
|
|
|
|
storage := NewREST(&webhook, successfulIssuer(ctrl))
|
|
|
|
ctx := context.WithValue(context.Background(), contextKey{}, "context-value")
|
|
|
|
|
2020-08-14 14:11:14 +00:00
|
|
|
_, err := callCreate(ctx, storage, validCredentialRequest())
|
2020-08-06 22:14:30 +00:00
|
|
|
|
|
|
|
r.NoError(err)
|
|
|
|
r.Nil(webhook.calledWithContext.Value("context-key"))
|
|
|
|
})
|
|
|
|
|
|
|
|
it("CreateFailsWhenGivenTheWrongInputType", func() {
|
2020-08-14 14:11:14 +00:00
|
|
|
notACredentialRequest := runtime.Unknown{}
|
2020-08-06 22:14:30 +00:00
|
|
|
response, err := NewREST(&FakeToken{}, nil).Create(
|
|
|
|
genericapirequest.NewContext(),
|
2020-08-14 14:11:14 +00:00
|
|
|
¬ACredentialRequest,
|
2020-08-06 22:14:30 +00:00
|
|
|
rest.ValidateAllObjectFunc,
|
|
|
|
&metav1.CreateOptions{})
|
|
|
|
|
2020-08-14 14:11:14 +00:00
|
|
|
requireAPIError(t, response, err, apierrors.IsBadRequest, "not a CredentialRequest")
|
|
|
|
requireOneLogStatement(r, logger, `"failure" failureType:request validation,msg:not a CredentialRequest`)
|
2020-08-06 22:14:30 +00:00
|
|
|
})
|
|
|
|
|
|
|
|
it("CreateFailsWhenTokenIsNilInRequest", func() {
|
|
|
|
storage := NewREST(&FakeToken{}, nil)
|
2020-08-20 17:54:15 +00:00
|
|
|
response, err := callCreate(context.Background(), storage, credentialRequest(pinnipedapi.CredentialRequestSpec{
|
|
|
|
Type: pinnipedapi.TokenCredentialType,
|
2020-08-06 22:14:30 +00:00
|
|
|
Token: nil,
|
|
|
|
}))
|
|
|
|
|
|
|
|
requireAPIError(t, response, err, apierrors.IsInvalid,
|
2020-08-20 17:54:15 +00:00
|
|
|
`.pinniped.dev "request name" is invalid: spec.token.value: Required value: token must be supplied`)
|
2020-08-06 22:14:30 +00:00
|
|
|
requireOneLogStatement(r, logger, `"failure" failureType:request validation,msg:token must be supplied`)
|
|
|
|
})
|
|
|
|
|
|
|
|
it("CreateFailsWhenTypeInRequestIsMissing", func() {
|
|
|
|
storage := NewREST(&FakeToken{}, nil)
|
2020-08-20 17:54:15 +00:00
|
|
|
response, err := callCreate(context.Background(), storage, credentialRequest(pinnipedapi.CredentialRequestSpec{
|
2020-08-06 22:14:30 +00:00
|
|
|
Type: "",
|
2020-08-20 17:54:15 +00:00
|
|
|
Token: &pinnipedapi.CredentialRequestTokenCredential{Value: "a token"},
|
2020-08-06 22:14:30 +00:00
|
|
|
}))
|
|
|
|
|
|
|
|
requireAPIError(t, response, err, apierrors.IsInvalid,
|
2020-08-20 17:54:15 +00:00
|
|
|
`.pinniped.dev "request name" is invalid: spec.type: Required value: type must be supplied`)
|
2020-08-06 22:14:30 +00:00
|
|
|
requireOneLogStatement(r, logger, `"failure" failureType:request validation,msg:type must be supplied`)
|
|
|
|
})
|
|
|
|
|
|
|
|
it("CreateFailsWhenTypeInRequestIsNotLegal", func() {
|
|
|
|
storage := NewREST(&FakeToken{}, nil)
|
2020-08-20 17:54:15 +00:00
|
|
|
response, err := callCreate(context.Background(), storage, credentialRequest(pinnipedapi.CredentialRequestSpec{
|
2020-08-06 22:14:30 +00:00
|
|
|
Type: "this in an invalid type",
|
2020-08-20 17:54:15 +00:00
|
|
|
Token: &pinnipedapi.CredentialRequestTokenCredential{Value: "a token"},
|
2020-08-06 22:14:30 +00:00
|
|
|
}))
|
|
|
|
|
|
|
|
requireAPIError(t, response, err, apierrors.IsInvalid,
|
2020-08-20 17:54:15 +00:00
|
|
|
`.pinniped.dev "request name" is invalid: spec.type: Invalid value: "this in an invalid type": unrecognized type`)
|
2020-08-06 22:14:30 +00:00
|
|
|
requireOneLogStatement(r, logger, `"failure" failureType:request validation,msg:unrecognized type`)
|
|
|
|
})
|
|
|
|
|
|
|
|
it("CreateFailsWhenTokenValueIsEmptyInRequest", func() {
|
|
|
|
storage := NewREST(&FakeToken{}, nil)
|
2020-08-20 17:54:15 +00:00
|
|
|
response, err := callCreate(context.Background(), storage, credentialRequest(pinnipedapi.CredentialRequestSpec{
|
|
|
|
Type: pinnipedapi.TokenCredentialType,
|
|
|
|
Token: &pinnipedapi.CredentialRequestTokenCredential{Value: ""},
|
2020-08-06 22:14:30 +00:00
|
|
|
}))
|
|
|
|
|
|
|
|
requireAPIError(t, response, err, apierrors.IsInvalid,
|
2020-08-20 17:54:15 +00:00
|
|
|
`.pinniped.dev "request name" is invalid: spec.token.value: Required value: token must be supplied`)
|
2020-08-06 22:14:30 +00:00
|
|
|
requireOneLogStatement(r, logger, `"failure" failureType:request validation,msg:token must be supplied`)
|
|
|
|
})
|
|
|
|
|
|
|
|
it("CreateFailsWhenValidationFails", func() {
|
|
|
|
storage := NewREST(&FakeToken{}, nil)
|
|
|
|
response, err := storage.Create(
|
|
|
|
context.Background(),
|
2020-08-14 14:11:14 +00:00
|
|
|
validCredentialRequest(),
|
2020-08-06 22:14:30 +00:00
|
|
|
func(ctx context.Context, obj runtime.Object) error {
|
|
|
|
return fmt.Errorf("some validation error")
|
|
|
|
},
|
|
|
|
&metav1.CreateOptions{})
|
|
|
|
r.Nil(response)
|
|
|
|
r.EqualError(err, "some validation error")
|
|
|
|
requireOneLogStatement(r, logger, `"failure" failureType:validation webhook,msg:some validation error`)
|
|
|
|
})
|
|
|
|
|
|
|
|
it("CreateDoesNotAllowValidationFunctionToMutateRequest", func() {
|
|
|
|
webhook := FakeToken{
|
|
|
|
returnResponse: webhookSuccessResponse(),
|
|
|
|
}
|
|
|
|
storage := NewREST(&webhook, successfulIssuer(ctrl))
|
|
|
|
requestToken := "a token"
|
|
|
|
response, err := storage.Create(
|
|
|
|
context.Background(),
|
2020-08-14 14:11:14 +00:00
|
|
|
validCredentialRequestWithToken(requestToken),
|
2020-08-06 22:14:30 +00:00
|
|
|
func(ctx context.Context, obj runtime.Object) error {
|
2020-08-20 17:54:15 +00:00
|
|
|
credentialRequest, _ := obj.(*pinnipedapi.CredentialRequest)
|
2020-08-14 14:11:14 +00:00
|
|
|
credentialRequest.Spec.Token.Value = "foobaz"
|
2020-08-06 22:14:30 +00:00
|
|
|
return nil
|
|
|
|
},
|
|
|
|
&metav1.CreateOptions{})
|
|
|
|
r.NoError(err)
|
|
|
|
r.NotEmpty(response)
|
|
|
|
r.Equal(requestToken, webhook.calledWithToken) // i.e. not called with foobaz
|
|
|
|
})
|
|
|
|
|
|
|
|
it("CreateDoesNotAllowValidationFunctionToSeeTheActualRequestToken", func() {
|
|
|
|
webhook := FakeToken{
|
|
|
|
returnResponse: webhookSuccessResponse(),
|
|
|
|
}
|
|
|
|
|
|
|
|
storage := NewREST(&webhook, successfulIssuer(ctrl))
|
|
|
|
validationFunctionWasCalled := false
|
|
|
|
var validationFunctionSawTokenValue string
|
|
|
|
response, err := storage.Create(
|
|
|
|
context.Background(),
|
2020-08-14 14:11:14 +00:00
|
|
|
validCredentialRequest(),
|
2020-08-06 22:14:30 +00:00
|
|
|
func(ctx context.Context, obj runtime.Object) error {
|
2020-08-20 17:54:15 +00:00
|
|
|
credentialRequest, _ := obj.(*pinnipedapi.CredentialRequest)
|
2020-08-06 22:14:30 +00:00
|
|
|
validationFunctionWasCalled = true
|
2020-08-14 14:11:14 +00:00
|
|
|
validationFunctionSawTokenValue = credentialRequest.Spec.Token.Value
|
2020-08-06 22:14:30 +00:00
|
|
|
return nil
|
|
|
|
},
|
|
|
|
&metav1.CreateOptions{})
|
|
|
|
r.NoError(err)
|
|
|
|
r.NotEmpty(response)
|
|
|
|
r.True(validationFunctionWasCalled)
|
|
|
|
r.Empty(validationFunctionSawTokenValue)
|
|
|
|
})
|
|
|
|
|
|
|
|
it("CreateFailsWhenRequestOptionsDryRunIsNotEmpty", func() {
|
|
|
|
response, err := NewREST(&FakeToken{}, nil).Create(
|
|
|
|
genericapirequest.NewContext(),
|
2020-08-14 14:11:14 +00:00
|
|
|
validCredentialRequest(),
|
2020-08-06 22:14:30 +00:00
|
|
|
rest.ValidateAllObjectFunc,
|
|
|
|
&metav1.CreateOptions{
|
|
|
|
DryRun: []string{"some dry run flag"},
|
|
|
|
})
|
|
|
|
|
|
|
|
requireAPIError(t, response, err, apierrors.IsInvalid,
|
2020-08-20 17:54:15 +00:00
|
|
|
`.pinniped.dev "request name" is invalid: dryRun: Unsupported value: []string{"some dry run flag"}`)
|
2020-08-06 22:14:30 +00:00
|
|
|
requireOneLogStatement(r, logger, `"failure" failureType:request validation,msg:dryRun not supported`)
|
|
|
|
})
|
|
|
|
|
|
|
|
it("CreateCancelsTheWebhookInvocationWhenTheCallToCreateIsCancelledItself", func() {
|
|
|
|
webhookStartedRunningNotificationChan := make(chan bool)
|
|
|
|
webhook := FakeToken{
|
|
|
|
timeout: time.Second * 2,
|
|
|
|
webhookStartedRunningNotificationChan: webhookStartedRunningNotificationChan,
|
|
|
|
returnResponse: webhookSuccessResponse(),
|
|
|
|
}
|
|
|
|
storage := NewREST(&webhook, successfulIssuer(ctrl))
|
|
|
|
ctx, cancel := context.WithCancel(context.Background())
|
|
|
|
|
|
|
|
c := make(chan bool)
|
|
|
|
go func() {
|
2020-08-14 14:11:14 +00:00
|
|
|
_, err := callCreate(ctx, storage, validCredentialRequest())
|
2020-08-06 22:14:30 +00:00
|
|
|
c <- true
|
|
|
|
r.NoError(err)
|
|
|
|
}()
|
|
|
|
|
|
|
|
r.False(webhook.cancelled)
|
|
|
|
r.False(webhook.reachedTimeout)
|
|
|
|
<-webhookStartedRunningNotificationChan // wait long enough to make sure that the webhook has started
|
|
|
|
cancel() // cancel the context that was passed to storage.Create() above
|
|
|
|
<-c // wait for the above call to storage.Create() to be finished
|
|
|
|
r.True(webhook.cancelled)
|
|
|
|
r.False(webhook.reachedTimeout)
|
|
|
|
r.Equal(context.Canceled, webhook.calledWithContext.Err()) // the inner context is cancelled
|
|
|
|
})
|
|
|
|
|
|
|
|
it("CreateAllowsTheWebhookInvocationToFinishWhenTheCallToCreateIsNotCancelledItself", func() {
|
|
|
|
webhookStartedRunningNotificationChan := make(chan bool)
|
|
|
|
webhook := FakeToken{
|
|
|
|
timeout: 0,
|
|
|
|
webhookStartedRunningNotificationChan: webhookStartedRunningNotificationChan,
|
|
|
|
returnResponse: webhookSuccessResponse(),
|
|
|
|
}
|
|
|
|
storage := NewREST(&webhook, successfulIssuer(ctrl))
|
|
|
|
ctx, cancel := context.WithCancel(context.Background())
|
|
|
|
defer cancel()
|
|
|
|
|
|
|
|
c := make(chan bool)
|
|
|
|
go func() {
|
2020-08-14 14:11:14 +00:00
|
|
|
_, err := callCreate(ctx, storage, validCredentialRequest())
|
2020-08-06 22:14:30 +00:00
|
|
|
c <- true
|
|
|
|
r.NoError(err)
|
|
|
|
}()
|
|
|
|
|
|
|
|
r.False(webhook.cancelled)
|
|
|
|
r.False(webhook.reachedTimeout)
|
|
|
|
<-webhookStartedRunningNotificationChan // wait long enough to make sure that the webhook has started
|
|
|
|
<-c // wait for the above call to storage.Create() to be finished
|
|
|
|
r.False(webhook.cancelled)
|
|
|
|
r.True(webhook.reachedTimeout)
|
|
|
|
r.Equal(context.Canceled, webhook.calledWithContext.Err()) // the inner context is cancelled (in this case by the "defer")
|
|
|
|
})
|
|
|
|
}, spec.Sequential())
|
|
|
|
}
|
|
|
|
|
|
|
|
func requireOneLogStatement(r *require.Assertions, logger *testutil.TranscriptLogger, messageContains string) {
|
2020-08-19 18:21:07 +00:00
|
|
|
transcript := logger.Transcript()
|
|
|
|
r.Len(transcript, 1)
|
|
|
|
r.Equal("info", transcript[0].Level)
|
|
|
|
r.Contains(transcript[0].Message, messageContains)
|
2020-08-06 22:14:30 +00:00
|
|
|
}
|
|
|
|
|
2020-08-20 17:54:15 +00:00
|
|
|
func callCreate(ctx context.Context, storage *REST, credentialRequest *pinnipedapi.CredentialRequest) (runtime.Object, error) {
|
2020-07-23 15:05:21 +00:00
|
|
|
return storage.Create(
|
|
|
|
ctx,
|
2020-08-14 14:11:14 +00:00
|
|
|
credentialRequest,
|
2020-07-23 15:05:21 +00:00
|
|
|
rest.ValidateAllObjectFunc,
|
|
|
|
&metav1.CreateOptions{
|
|
|
|
DryRun: []string{},
|
|
|
|
})
|
|
|
|
}
|
|
|
|
|
2020-08-20 17:54:15 +00:00
|
|
|
func validCredentialRequest() *pinnipedapi.CredentialRequest {
|
2020-08-14 14:11:14 +00:00
|
|
|
return validCredentialRequestWithToken("some token")
|
2020-07-23 23:01:55 +00:00
|
|
|
}
|
|
|
|
|
2020-08-20 17:54:15 +00:00
|
|
|
func validCredentialRequestWithToken(token string) *pinnipedapi.CredentialRequest {
|
|
|
|
return credentialRequest(pinnipedapi.CredentialRequestSpec{
|
|
|
|
Type: pinnipedapi.TokenCredentialType,
|
|
|
|
Token: &pinnipedapi.CredentialRequestTokenCredential{Value: token},
|
2020-07-23 15:05:21 +00:00
|
|
|
})
|
|
|
|
}
|
|
|
|
|
2020-08-20 17:54:15 +00:00
|
|
|
func credentialRequest(spec pinnipedapi.CredentialRequestSpec) *pinnipedapi.CredentialRequest {
|
|
|
|
return &pinnipedapi.CredentialRequest{
|
2020-07-23 15:05:21 +00:00
|
|
|
TypeMeta: metav1.TypeMeta{},
|
|
|
|
ObjectMeta: metav1.ObjectMeta{
|
|
|
|
Name: "request name",
|
|
|
|
},
|
|
|
|
Spec: spec,
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2020-07-24 18:00:29 +00:00
|
|
|
func webhookSuccessResponse() *authenticator.Response {
|
|
|
|
return &authenticator.Response{User: &user.DefaultInfo{
|
|
|
|
Name: "some-user",
|
|
|
|
UID: "",
|
|
|
|
Groups: []string{},
|
|
|
|
Extra: nil,
|
|
|
|
}}
|
|
|
|
}
|
|
|
|
|
2020-07-23 16:50:23 +00:00
|
|
|
func requireAPIError(t *testing.T, response runtime.Object, err error, expectedErrorTypeChecker func(err error) bool, expectedErrorMessage string) {
|
|
|
|
t.Helper()
|
|
|
|
require.Nil(t, response)
|
|
|
|
require.True(t, expectedErrorTypeChecker(err))
|
|
|
|
var status apierrors.APIStatus
|
|
|
|
errors.As(err, &status)
|
|
|
|
require.Contains(t, status.Status().Message, expectedErrorMessage)
|
|
|
|
}
|
|
|
|
|
2020-07-24 18:00:29 +00:00
|
|
|
func requireSuccessfulResponseWithAuthenticationFailureMessage(t *testing.T, err error, response runtime.Object) {
|
2020-08-06 22:14:30 +00:00
|
|
|
t.Helper()
|
2020-07-24 18:00:29 +00:00
|
|
|
require.NoError(t, err)
|
2020-08-20 17:54:15 +00:00
|
|
|
require.Equal(t, response, &pinnipedapi.CredentialRequest{
|
|
|
|
Status: pinnipedapi.CredentialRequestStatus{
|
2020-07-24 18:00:29 +00:00
|
|
|
Credential: nil,
|
2020-08-14 13:18:31 +00:00
|
|
|
Message: stringPtr("authentication failed"),
|
2020-07-24 18:00:29 +00:00
|
|
|
},
|
|
|
|
})
|
2020-07-24 15:21:36 +00:00
|
|
|
}
|
|
|
|
|
2020-07-27 13:08:39 +00:00
|
|
|
func successfulIssuer(ctrl *gomock.Controller) CertIssuer {
|
|
|
|
issuer := mockcertissuer.NewMockCertIssuer(ctrl)
|
|
|
|
issuer.EXPECT().
|
|
|
|
IssuePEM(gomock.Any(), gomock.Any(), gomock.Any()).
|
|
|
|
Return([]byte("test-cert"), []byte("test-key"), nil)
|
|
|
|
return issuer
|
|
|
|
}
|
2020-08-14 13:18:31 +00:00
|
|
|
|
|
|
|
func stringPtr(s string) *string {
|
|
|
|
return &s
|
|
|
|
}
|