2 * ============LICENSE_START=======================================================
4 * ================================================================================
5 * Copyright (C) 2019 Nokia Intellectual Property. All rights reserved.
6 * ================================================================================
7 * Licensed under the Apache License, Version 2.0 (the "License");
8 * you may not use this file except in compliance with the License.
9 * You may obtain a copy of the License at
11 * http://www.apache.org/licenses/LICENSE-2.0
13 * Unless required by applicable law or agreed to in writing, software
14 * distributed under the License is distributed on an "AS IS" BASIS,
15 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
16 * See the License for the specific language governing permissions and
17 * limitations under the License.
18 * ============LICENSE_END=========================================================
20 package org.onap.dmaap.dbcapi.resources;
22 import static org.junit.Assert.assertEquals;
23 import static org.junit.Assert.assertNotNull;
24 import static org.junit.Assert.assertNull;
25 import static org.mockito.Matchers.anyString;
26 import static org.mockito.Matchers.eq;
27 import static org.mockito.Mockito.doReturn;
28 import static org.mockito.Mockito.mock;
29 import static org.mockito.Mockito.verify;
30 import static org.mockito.Mockito.verifyNoMoreInteractions;
31 import static org.mockito.Mockito.verifyZeroInteractions;
32 import static org.mockito.Mockito.when;
34 import java.io.PrintWriter;
35 import java.io.StringWriter;
36 import com.sun.security.auth.UserPrincipal;
37 import javax.servlet.FilterChain;
38 import javax.servlet.FilterConfig;
39 import javax.servlet.http.HttpServletRequest;
40 import javax.servlet.http.HttpServletResponse;
41 import org.junit.Before;
42 import org.junit.BeforeClass;
43 import org.junit.Test;
44 import org.junit.runner.RunWith;
45 import org.mockito.Mock;
46 import org.mockito.Spy;
47 import org.mockito.runners.MockitoJUnitRunner;
48 import org.onap.dmaap.dbcapi.model.Dmaap;
49 import org.onap.dmaap.dbcapi.service.DmaapService;
50 import org.onap.dmaap.dbcapi.util.DmaapConfig;
51 import org.onap.dmaap.dbcapi.util.PermissionBuilder;
53 @RunWith(MockitoJUnitRunner.class)
54 public class AAFAuthorizationFilterTest {
57 private AAFAuthorizationFilter filter;
59 private FilterConfig filterConfig;
61 private HttpServletRequest servletRequest;
63 private HttpServletResponse servletResponse;
65 private FilterChain filterChain;
67 private DmaapConfig dmaapConfig;
69 private PermissionBuilder permissionBuilder;
71 private DmaapService dmaapService;
74 public static void setUpClass(){
75 System.setProperty("ConfigFile", "src/test/resources/dmaapbc.properties");
78 public void setUp() throws Exception {
79 filter.setPermissionBuilder(permissionBuilder);
80 doReturn(dmaapConfig).when(filter).getConfig();
81 doReturn(dmaapService).when(filter).getDmaapService();
85 public void init_shouldNotInitializePermissionBuilder_whenAAFnotUsed() throws Exception {
87 filter.setPermissionBuilder(null);
88 configureAAFUsage(false);
91 filter.init(filterConfig);
94 assertNull(filter.getPermissionBuilder());
98 public void init_shouldInitializePermissionBuilder_whenAAFisUsed() throws Exception {
100 filter.setPermissionBuilder(null);
101 configureAAFUsage(true);
102 //doReturn(provideEmptyInstance()).when(dmaapService).getDmaap();
103 when(dmaapService.getDmaap()).thenReturn(mock(Dmaap.class));
106 filter.init(filterConfig);
109 assertNotNull(permissionBuilder);
113 public void doFilter_shouldSkipAuthorization_whenAAFnotUsed() throws Exception {
115 filter.setCadiEnabled(false);
118 filter.doFilter(servletRequest,servletResponse,filterChain);
121 verify(filterChain).doFilter(servletRequest,servletResponse);
122 verifyNoMoreInteractions(filterChain);
123 verifyZeroInteractions(permissionBuilder, servletRequest, servletResponse);
127 public void doFilter_shouldPass_whenUserHasPermissionToResourceEndpoint() throws Exception {
129 String user = "johnny";
130 String permission = "org.onap.dmaap-bc.api.topics|mr|GET";
131 when(permissionBuilder.buildPermission(servletRequest)).thenReturn(permission);
132 configureServletRequest(permission, user, true);
133 filter.setCadiEnabled(true);
136 filter.doFilter(servletRequest,servletResponse,filterChain);
139 verify(filterChain).doFilter(servletRequest,servletResponse);
140 verify(permissionBuilder).updateDmaapInstance();
141 verifyZeroInteractions(servletResponse);
145 public void doFilter_shouldReturnError_whenUserDontHavePermissionToResourceEndpoint() throws Exception {
147 String user = "jack";
148 String permission = "org.onap.dmaap-bc.api.topics|mr|GET";
149 when(permissionBuilder.buildPermission(servletRequest)).thenReturn(permission);
150 configureServletRequest(permission, user, false);
151 filter.setCadiEnabled(true);
153 String errorMsgJson = "{\"code\":403,\"message\":\"User "+user+" does not have permission "
154 + permission +"\",\"fields\":\"Authorization\",\"2xx\":false}";
155 StringWriter sw = new StringWriter();
156 PrintWriter pw = new PrintWriter(sw);
157 when(servletResponse.getWriter()).thenReturn(pw);
160 filter.doFilter(servletRequest,servletResponse,filterChain);
163 verifyZeroInteractions(filterChain);
164 verify(permissionBuilder).updateDmaapInstance();
165 verify(servletResponse).setStatus(403);
166 assertEquals(errorMsgJson, sw.toString());
169 private void configureServletRequest(String permission, String user, boolean isUserInRole) {
170 when(servletRequest.getUserPrincipal()).thenReturn(new UserPrincipal(user));
171 when(servletRequest.isUserInRole(permission)).thenReturn(isUserInRole);
174 private void configureAAFUsage(Boolean isUsed) {
175 doReturn(isUsed.toString()).when(dmaapConfig).getProperty(eq(AAFAuthorizationFilter.CADI_AUTHZ_FLAG), anyString());