Merge "Fix sql injection vulnerability"
[portal.git] / ecomp-portal-BE-common / src / test / java / org / onap / portalapp / portal / service / AdminRolesServiceImplTest.java
1 /*-
2  * ============LICENSE_START==========================================
3  * ONAP Portal
4  * ===================================================================
5  * Copyright (C) 2017 AT&T Intellectual Property. All rights reserved.
6  * ===================================================================
7  * Modifications Copyright (c) 2019 Samsung
8  * ===================================================================
9  *
10  * Unless otherwise specified, all software contained herein is licensed
11  * under the Apache License, Version 2.0 (the "License");
12  * you may not use this software except in compliance with the License.
13  * You may obtain a copy of the License at
14  *
15  *             http://www.apache.org/licenses/LICENSE-2.0
16  *
17  * Unless required by applicable law or agreed to in writing, software
18  * distributed under the License is distributed on an "AS IS" BASIS,
19  * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
20  * See the License for the specific language governing permissions and
21  * limitations under the License.
22  *
23  * Unless otherwise specified, all documentation contained herein is licensed
24  * under the Creative Commons License, Attribution 4.0 Intl. (the "License");
25  * you may not use this documentation except in compliance with the License.
26  * You may obtain a copy of the License at
27  *
28  *             https://creativecommons.org/licenses/by/4.0/
29  *
30  * Unless required by applicable law or agreed to in writing, documentation
31  * distributed under the License is distributed on an "AS IS" BASIS,
32  * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
33  * See the License for the specific language governing permissions and
34  * limitations under the License.
35  *
36  * ============LICENSE_END============================================
37  *
38  * 
39  */
40 package org.onap.portalapp.portal.service;
41
42 import static org.junit.Assert.assertEquals;
43 import static org.junit.Assert.assertFalse;
44 import static org.junit.Assert.assertNotNull;
45 import static org.junit.Assert.assertTrue;
46
47 import java.util.ArrayList;
48 import java.util.HashMap;
49 import java.util.List;
50 import java.util.Map;
51 import java.util.SortedSet;
52
53 import org.hibernate.SQLQuery;
54 import org.hibernate.Session;
55 import org.hibernate.SessionFactory;
56 import org.hibernate.Transaction;
57 import org.json.simple.JSONObject;
58 import org.junit.After;
59 import org.junit.Before;
60 import org.junit.Test;
61 import org.junit.runner.RunWith;
62 import org.mockito.InjectMocks;
63 import org.mockito.Matchers;
64 import org.mockito.Mock;
65 import org.mockito.Mockito;
66 import org.mockito.MockitoAnnotations;
67 import org.onap.portalapp.portal.core.MockEPUser;
68 import org.onap.portalapp.portal.domain.EPApp;
69 import org.onap.portalapp.portal.domain.EPRole;
70 import org.onap.portalapp.portal.domain.EPUser;
71 import org.onap.portalapp.portal.domain.EPUserApp;
72 import org.onap.portalapp.portal.domain.UserRole;
73 import org.onap.portalapp.portal.transport.AppNameIdIsAdmin;
74 import org.onap.portalapp.portal.transport.AppsListWithAdminRole;
75 import org.onap.portalapp.portal.utils.EPCommonSystemProperties;
76 import org.onap.portalapp.portal.utils.EcompPortalUtils;
77 import org.onap.portalapp.portal.utils.PortalConstants;
78 import org.onap.portalsdk.core.service.DataAccessService;
79 import org.onap.portalsdk.core.service.DataAccessServiceImpl;
80 import org.onap.portalsdk.core.util.SystemProperties;
81 import org.powermock.api.mockito.PowerMockito;
82 import org.powermock.core.classloader.annotations.PrepareForTest;
83 import org.powermock.modules.junit4.PowerMockRunner;
84 import org.springframework.http.HttpEntity;
85 import org.springframework.http.HttpMethod;
86 import org.springframework.http.HttpStatus;
87 import org.springframework.http.ResponseEntity;
88 import org.springframework.web.client.RestTemplate;
89
90 @RunWith(PowerMockRunner.class)
91 @PrepareForTest({ EcompPortalUtils.class, PortalConstants.class, SystemProperties.class,
92                 EPCommonSystemProperties.class })
93 public class AdminRolesServiceImplTest {
94
95         @Mock
96         DataAccessService dataAccessService = new DataAccessServiceImpl();
97
98     @Mock
99     ExternalAccessRolesService externalAccessRolesService;
100
101         @Mock
102         EPAppCommonServiceImpl epAppCommonServiceImpl = new EPAppCommonServiceImpl();
103
104         @Mock
105         SearchServiceImpl searchServiceImpl = new SearchServiceImpl();
106
107         @Mock
108         SessionFactory sessionFactory;
109
110         @Mock
111         Session session;
112
113         @Mock
114         Transaction transaction;
115
116         @Mock
117         RestTemplate template = new RestTemplate();
118
119         @Before
120         public void setup() {
121                 MockitoAnnotations.initMocks(this);
122                 Mockito.when(sessionFactory.openSession()).thenReturn(session);
123                 Mockito.when(session.beginTransaction()).thenReturn(transaction);
124         }
125
126         @After
127         public void after() {
128                 session.close();
129         }
130
131         @InjectMocks
132         AdminRolesServiceImpl adminRolesServiceImpl = new AdminRolesServiceImpl();
133
134         private Long ACCOUNT_ADMIN_ROLE_ID = 999L;
135         
136         private Long ECOMP_APP_ID = 1L;
137         
138         public EPApp mockApp() {
139                 EPApp app = new EPApp();
140                 app.setName("Test");
141                 app.setImageUrl("test");
142                 app.setNameSpace("com.test.app");
143                 app.setCentralAuth(true);
144                 app.setDescription("test");
145                 app.setNotes("test");
146                 app.setUrl("test");
147                 app.setId((long) 1);
148                 app.setAppRestEndpoint("test");
149                 app.setAlternateUrl("test");
150                 app.setName("test");
151                 app.setMlAppName("test");
152                 app.setMlAppAdminId("test");
153                 app.setUsername("test");
154                 app.setAppPassword("test");
155                 app.setOpen(false);
156                 app.setEnabled(true);
157                 app.setUebKey("test");
158                 app.setUebSecret("test");
159                 app.setUebTopicName("test");
160                 app.setAppType(1);
161                 return app;
162         }
163
164         MockEPUser mockUser = new MockEPUser();
165
166         @SuppressWarnings("deprecation")
167         @Test
168         public void getAppsWithAdminRoleStateForUserTest() {
169                 EPUser user = mockUser.mockEPUser();
170                 EPApp app = mockApp();
171                 app.setId(1l);
172                 List<EPUser> users = new ArrayList<>();
173                 users.add(user);
174                 Map<String, String> userParams = new HashMap<>();
175                 userParams.put("org_user_id", user.getOrgUserId());
176                 Mockito.when(dataAccessService.executeNamedQuery("getEPUserByOrgUserId", userParams, null)).thenReturn(users);
177                 List<EPUserApp> userAppList = new ArrayList<>();
178                 EPUserApp epUserApp = new EPUserApp();
179                 EPRole role = new EPRole();
180                 role.setActive(true);
181                 role.setId(1l);
182                 role.setName("test role");
183                 epUserApp.setApp(app);
184                 epUserApp.setRole(role);
185                 epUserApp.setUserId(1l);
186                 userAppList.add(epUserApp);
187                 Mockito.when(dataAccessService.getList(EPUserApp.class,
188                                 " where userId = " + user.getId() + " and role.id = " + 999, null, null)).thenReturn(userAppList);
189                 List<EPApp> appsList = new ArrayList<>();
190                 appsList.add(app);
191                 Mockito.when(dataAccessService.getList(EPApp.class,
192                                 "  where ( enabled = 'Y' or id = " + ECOMP_APP_ID + ")", null, null)).thenReturn(appsList);
193                 AppsListWithAdminRole  actual = adminRolesServiceImpl.getAppsWithAdminRoleStateForUser(user.getOrgUserId());
194                 assertNotNull(actual);
195         }
196         
197         @Test
198         public void getAppsWithAdminRoleStateForUserTestWithException() {
199                 EPUser user = mockUser.mockEPUser();
200                 EPApp app = mockApp();
201                 app.setId(1l);
202                 List<EPUser> users = new ArrayList<>();
203                 users.add(user);
204                 Map<String, String> userParams = new HashMap<>();
205                 userParams.put("org_user_id", user.getOrgUserId());
206                 Mockito.when(dataAccessService.executeNamedQuery("getEPUserByOrgUserId", userParams, null)).thenReturn(users);
207                 AppsListWithAdminRole  actual = adminRolesServiceImpl.getAppsWithAdminRoleStateForUser(user.getOrgUserId());
208
209                 
210         }
211
212         @SuppressWarnings({ "deprecation", "unchecked" })
213         @Test
214         public void setAppsWithAdminRoleStateForUserTest() {
215                 PowerMockito.mockStatic(EPCommonSystemProperties.class);
216                 PowerMockito.mockStatic(EcompPortalUtils.class);
217                 PowerMockito.mockStatic(PortalConstants.class);
218                 PowerMockito.mockStatic(SystemProperties.class);
219                 EPUser user = mockUser.mockEPUser();
220                 EPApp app = mockApp();
221                 app.setId(1l);
222                 EPApp app2 = mockApp();
223                 app2.setName("app2");
224                 app2.setNameSpace("com.test.app2");
225                 app2.setId(2l);
226                 EPApp app3 = mockApp();
227                 app3.setName("app3");
228                 app3.setNameSpace("com.test.app3");
229                 app3.setId(3l);
230                 List<EPApp> apps = new ArrayList<>();
231                 apps.add(app);
232                 apps.add(app2);
233                 apps.add(app3);
234                 Mockito.when(epAppCommonServiceImpl.getAppsFullList()).thenReturn(apps);
235
236                 List<EPUser> localUserList = new ArrayList<>();
237                 localUserList.add(user);
238                 Mockito.when(
239                                 dataAccessService.getList(EPUser.class, " where org_user_id='" + user.getOrgUserId() + "'", null, null))
240                                 .thenReturn(localUserList);
241                 List<EPUserApp> oldAppsWhereUserIsAdmin = new ArrayList<EPUserApp>();
242                 EPUserApp epUserApp = new EPUserApp();
243                 EPRole role = new EPRole();
244                 role.setActive(true);
245                 role.setId(999l);
246                 role.setName("app5");
247                 epUserApp.setApp(app);
248                 epUserApp.setRole(role);
249                 epUserApp.setUserId(1l);
250                 oldAppsWhereUserIsAdmin.add(epUserApp);
251                 Mockito.when(dataAccessService.getList(EPUserApp.class,
252                                 " where userId = " + user.getId() + " and role.id = " + ACCOUNT_ADMIN_ROLE_ID, null,
253                                 null)).thenReturn(oldAppsWhereUserIsAdmin);
254                 Mockito.when(EcompPortalUtils.checkIfRemoteCentralAccessAllowed()).thenReturn(true);
255                 EPApp app4 = mockApp();
256                 app4.setId(6l);
257                 app4.setName("app7");
258                 app4.setNameSpace("com.test.app7");
259                 List<EPApp> apps2 = new ArrayList<>();
260                 apps2.add(app);
261                 apps2.add(app2);
262                 apps2.add(app3);
263                 apps2.add(app4);
264                 Mockito.when(dataAccessService.executeNamedQuery("getCentralizedApps", null, null)).thenReturn(apps2);
265                 Mockito.when(
266                                 EPCommonSystemProperties.containsProperty(EPCommonSystemProperties.EXTERNAL_CENTRAL_ACCESS_USER_DOMAIN))
267                                 .thenReturn(true);
268                 Mockito.when(SystemProperties.getProperty(EPCommonSystemProperties.EXTERNAL_CENTRAL_ACCESS_USER_DOMAIN))
269                                 .thenReturn("@test.com");
270                 JSONObject getUserRoles = new JSONObject();
271                 ResponseEntity<String> getResponse = new ResponseEntity<>(getUserRoles.toString(), HttpStatus.OK);
272                 Mockito.when(template.exchange(Matchers.anyString(), Matchers.eq(HttpMethod.GET),
273                                 Matchers.<HttpEntity<String>>any(), Matchers.eq(String.class))).thenReturn(getResponse);
274                 ResponseEntity<String> addResponse = new ResponseEntity<>(HttpStatus.CREATED);
275                 Mockito.when(template.exchange(Matchers.anyString(), Matchers.eq(HttpMethod.POST),
276                                 Matchers.<HttpEntity<String>>any(), Matchers.eq(String.class))).thenReturn(addResponse);
277                 
278                 AppsListWithAdminRole newAppsListWithAdminRoles = new AppsListWithAdminRole();
279                 ArrayList<AppNameIdIsAdmin> appsRoles = new ArrayList<>();
280                 AppNameIdIsAdmin appNameIdIsAdmin = new AppNameIdIsAdmin();
281                 appNameIdIsAdmin.setAppName("app1");
282                 appNameIdIsAdmin.setId(2l);
283                 appNameIdIsAdmin.setIsAdmin(true);
284                 appNameIdIsAdmin.setRestrictedApp(false);
285                 AppNameIdIsAdmin appNameIdIsAdmin2 = new AppNameIdIsAdmin();
286                 appNameIdIsAdmin2.setAppName("app2");
287                 appNameIdIsAdmin2.setId(3l);
288                 appNameIdIsAdmin2.setIsAdmin(true);
289                 appNameIdIsAdmin2.setRestrictedApp(false);
290                 appsRoles.add(appNameIdIsAdmin);
291                 appsRoles.add(appNameIdIsAdmin2);
292                 newAppsListWithAdminRoles.setOrgUserId(user.getOrgUserId());
293                 newAppsListWithAdminRoles.setAppsRoles(appsRoles);
294                 Mockito.when((EPApp) session.get(EPApp.class, appNameIdIsAdmin.id)).thenReturn(app2);
295                 Mockito.when((EPApp) session.get(EPApp.class, appNameIdIsAdmin2.id)).thenReturn(app3);
296                 JSONObject getUserRoles2 = new JSONObject();
297                 JSONObject getUserRoles3 = new JSONObject();
298                 JSONObject getUserRoles4 = new JSONObject();
299                 JSONObject finalUserRoles = new JSONObject();
300                 getUserRoles2.put("role", "com.test.app3.Account_Administrator");
301                 getUserRoles3.put("role", "com.test.app3.admin");
302                 getUserRoles4.put("role", "com.test.app3.owner");
303                 List<JSONObject> userRoles =  new ArrayList<>();
304                 userRoles.add(getUserRoles2);
305                 userRoles.add(getUserRoles3);
306                 userRoles.add(getUserRoles4);
307                 finalUserRoles.put("userRole", userRoles);
308                 ResponseEntity<String> getResponse2 = new ResponseEntity<>(finalUserRoles.toString(), HttpStatus.OK);
309                 Mockito.when(template.exchange(Matchers.anyString(), Matchers.eq(HttpMethod.GET),
310                                 Matchers.<HttpEntity<String>>any(), Matchers.eq(String.class))).thenReturn(getResponse2);
311                 boolean actual = adminRolesServiceImpl.setAppsWithAdminRoleStateForUser(newAppsListWithAdminRoles);
312                 assertTrue(actual);
313         }
314
315         @Test
316         public void isSuperAdminTest() {
317                 EPUser user = mockUser.mockEPUser();
318                 user.setId(1l);
319                 SQLQuery SqlQuery = Mockito.mock(SQLQuery.class);
320                 Mockito.when(session.createSQLQuery(Matchers.anyString())).thenReturn(SqlQuery);
321                 List<UserRole> userRoleList = new ArrayList<>();
322                 UserRole userRole = new UserRole();
323                 userRole.setFirstName("Hello");
324                 userRole.setLastName("World");
325                 userRole.setRoleId(1l);
326                 userRole.setRoleName("test");
327                 userRole.setUser_Id(1l);
328                 userRoleList.add(userRole);
329                 Mockito.when(dataAccessService.executeSQLQuery(Matchers.anyString(), Matchers.any(), Matchers.anyMap()))
330                                 .thenReturn(userRoleList);
331                 boolean actual = adminRolesServiceImpl.isSuperAdmin(user);
332                 assertTrue(actual);
333         }
334
335         @Test
336         public void isSuperAdminExceptionTest() {
337                 EPUser user = mockUser.mockEPUser();
338                 user.setId(1l);
339                 SQLQuery SqlQuery = Mockito.mock(SQLQuery.class);
340                 Mockito.when(session.createSQLQuery(Matchers.anyString())).thenReturn(SqlQuery);
341                 Mockito.doThrow(new NullPointerException()).when(dataAccessService).executeSQLQuery(Matchers.anyString(),
342                                 Matchers.any(), Matchers.anyMap());
343                 boolean actual = adminRolesServiceImpl.isSuperAdmin(user);
344                 assertFalse(actual);
345         }
346
347         @Test
348         public void isAccountAdminTest() {
349                 EPUser user = mockUser.mockEPUser();
350                 EPApp app = mockApp();
351                 app.setId(2l);
352                 SortedSet<EPUserApp> userApps = user.getEPUserApps();
353                 EPUserApp epUserApp = new EPUserApp();
354                 EPRole role = new EPRole();
355                 role.setActive(true);
356                 role.setId(999l);
357                 role.setName("test role");
358                 epUserApp.setApp(app);
359                 epUserApp.setRole(role);
360                 epUserApp.setUserId(1l);
361                 userApps.add(epUserApp);
362                 user.setUserApps(userApps);
363                 Mockito.when((EPUser) dataAccessService.getDomainObject(Matchers.any(), Matchers.anyLong(), Matchers.anyMap()))
364                                 .thenReturn(user);
365                 boolean actual = adminRolesServiceImpl.isAccountAdmin(user);
366                 assertTrue(actual);
367         }
368
369         @Test
370         public void isAccountAdminExceptionTest() {
371                 EPUser user = mockUser.mockEPUser();
372                 Mockito.doThrow(new NullPointerException()).when(dataAccessService).getDomainObject(Matchers.any(),
373                                 Matchers.anyLong(), Matchers.anyMap());
374                 boolean actual = adminRolesServiceImpl.isAccountAdmin(user);
375                 assertFalse(actual);
376         }
377
378     @Test
379     public void isAccountAdminUserNull() {
380         boolean actual = adminRolesServiceImpl.isAccountAdmin(null);
381         assertFalse(actual);
382     }
383
384     @Test
385     public void isRoleAdminTest() {
386         EPUser user = mockUser.mockEPUser();
387         List<String> roles = new ArrayList<>();
388         roles.add("approver\\|");
389         Mockito.when(dataAccessService.executeNamedQuery(
390             Matchers.eq("getRoleFunctionsOfUserforAlltheApplications"), Matchers.any(), Matchers.any()))
391                 .thenReturn(roles);
392         Mockito.when(externalAccessRolesService.getFunctionCodeType(Matchers.anyString())).thenReturn("approver");
393         boolean actual = adminRolesServiceImpl.isRoleAdmin(user);
394         assertTrue(actual);
395     }
396
397         @Test
398         public void isUserTest() {
399                 EPUser user = mockUser.mockEPUser();
400                 EPApp app = mockApp();
401                 app.setId(2l);
402                 SortedSet<EPUserApp> userApps = user.getEPUserApps();
403                 EPUserApp epUserApp = new EPUserApp();
404                 EPRole role = new EPRole();
405                 role.setActive(true);
406                 role.setId(2l);
407                 role.setName("test role");
408                 epUserApp.setApp(app);
409                 epUserApp.setRole(role);
410                 epUserApp.setUserId(1l);
411                 userApps.add(epUserApp);
412                 user.setUserApps(userApps);
413                 Mockito.when((EPUser) dataAccessService.getDomainObject(Matchers.any(), Matchers.anyLong(), Matchers.anyMap()))
414                                 .thenReturn(user);
415                 boolean actual = adminRolesServiceImpl.isUser(user);
416                 assertTrue(actual);
417         }
418
419         @Test
420         public void isUserExceptionTest() {
421                 EPUser user = mockUser.mockEPUser();
422                 Mockito.doThrow(new NullPointerException()).when(dataAccessService).getDomainObject(Matchers.any(),
423                                 Matchers.anyLong(), Matchers.anyMap());
424                 boolean actual = adminRolesServiceImpl.isUser(user);
425                 assertFalse(actual);
426         }
427
428         @Test
429         public void getRolesByAppTest() {
430                 EPUser user = mockUser.mockEPUser();
431                 EPApp app = mockApp();
432                 List<EPRole> expected = new ArrayList<>();
433                 EPRole role = new EPRole();
434                 role.setActive(true);
435                 role.setId(1l);
436                 role.setName("test role");
437                 expected.add(role);
438                 Mockito.when(dataAccessService.executeSQLQuery(Matchers.anyString(), Matchers.any(), Matchers.anyMap()))
439                                 .thenReturn(expected);
440                 List<EPRole> actual = adminRolesServiceImpl.getRolesByApp(user, app.getId());
441                 assertEquals(expected, actual);
442         }
443
444         @Test
445         public void isAccountAdminOfApplicationTest() {
446                 EPUser user = mockUser.mockEPUser();
447                 EPApp app = mockApp();
448                 SortedSet<EPUserApp> userApps = user.getEPUserApps();
449                 EPUserApp epUserApp = new EPUserApp();
450                 EPRole role = new EPRole();
451                 role.setActive(true);
452                 role.setId(999l);
453                 role.setName("test role");
454                 epUserApp.setApp(app);
455                 epUserApp.setRole(role);
456                 epUserApp.setUserId(1l);
457                 userApps.add(epUserApp);
458                 user.setUserApps(userApps);
459                 List<Integer> userAdminApps =  new ArrayList<>();
460                 userAdminApps.add(1);
461                 userAdminApps.add(2);
462                 Mockito.when(dataAccessService.executeNamedQuery(Matchers.anyString(), Matchers.anyMap(), Matchers.anyMap()))
463                                 .thenReturn(userAdminApps);
464                 boolean actual = adminRolesServiceImpl.isAccountAdminOfApplication(user, app);
465                 assertTrue(actual);
466         }
467
468         @Test
469         public void isAccountAdminOfApplicationExceptionTest() {
470                 EPUser user = mockUser.mockEPUser();
471                 EPApp app = mockApp();
472                 Mockito.doThrow(new NullPointerException()).when(dataAccessService).getDomainObject(Matchers.any(),
473                                 Matchers.anyLong(), Matchers.anyMap());
474                 boolean actual = adminRolesServiceImpl.isAccountAdminOfApplication(user, app);
475                 assertFalse(actual);
476         }
477 }