2019-11-05 21:24:54 +01:00
|
|
|
package client
|
|
|
|
|
|
|
|
|
|
import (
|
|
|
|
|
"fmt"
|
|
|
|
|
"net/http"
|
|
|
|
|
"net/http/httptest"
|
2020-04-12 20:46:18 +02:00
|
|
|
"sort"
|
2019-11-05 21:24:54 +01:00
|
|
|
"testing"
|
2021-05-03 20:52:15 +02:00
|
|
|
|
2022-07-20 17:11:29 +02:00
|
|
|
"github.com/sparetimecoders/goamqp"
|
2021-05-03 20:52:15 +02:00
|
|
|
"github.com/stretchr/testify/assert"
|
2019-11-05 21:24:54 +01:00
|
|
|
)
|
|
|
|
|
|
|
|
|
|
func TestPrivilegeHandler_Process_InvalidType(t *testing.T) {
|
|
|
|
|
handler := New(WithBaseURL("base"))
|
|
|
|
|
|
2021-05-15 14:42:19 +02:00
|
|
|
result, err := handler.Process("abc", goamqp.Headers{})
|
2019-11-05 21:24:54 +01:00
|
|
|
|
2021-05-15 14:42:19 +02:00
|
|
|
assert.Nil(t, result)
|
|
|
|
|
assert.EqualError(t, err, "unexpected event type: 'string'")
|
2019-11-05 21:24:54 +01:00
|
|
|
}
|
|
|
|
|
|
2019-12-31 12:58:20 +01:00
|
|
|
func TestPrivilegeHandler_Process_PrivilegeRemoved(t *testing.T) {
|
|
|
|
|
handler := New(WithBaseURL("base"))
|
|
|
|
|
|
2021-05-15 14:42:19 +02:00
|
|
|
result, err := handler.Process(&PrivilegeAdded{
|
2020-04-12 20:33:35 +02:00
|
|
|
Email: "jim@example.org",
|
|
|
|
|
CompanyID: "abc-123",
|
|
|
|
|
Privilege: PrivilegeAdmin,
|
2021-05-15 14:42:19 +02:00
|
|
|
}, goamqp.Headers{})
|
|
|
|
|
assert.Nil(t, result)
|
|
|
|
|
assert.NoError(t, err)
|
2019-12-31 12:58:20 +01:00
|
|
|
|
|
|
|
|
companies := handler.CompaniesByUser("jim@example.org", func(privileges CompanyPrivileges) bool {
|
|
|
|
|
return privileges.Admin
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
assert.Equal(t, []string{"abc-123"}, companies)
|
|
|
|
|
|
2021-05-15 14:42:19 +02:00
|
|
|
result, err = handler.Process(&PrivilegeRemoved{
|
2020-04-12 20:33:35 +02:00
|
|
|
Email: "jim@example.org",
|
|
|
|
|
CompanyID: "abc-123",
|
|
|
|
|
Privilege: PrivilegeAdmin,
|
2021-05-15 14:42:19 +02:00
|
|
|
}, goamqp.Headers{})
|
|
|
|
|
assert.Nil(t, result)
|
|
|
|
|
assert.NoError(t, err)
|
2019-12-31 12:58:20 +01:00
|
|
|
|
|
|
|
|
companies = handler.CompaniesByUser("jim@example.org", func(privileges CompanyPrivileges) bool {
|
|
|
|
|
return privileges.Admin
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
assert.Empty(t, companies)
|
|
|
|
|
}
|
|
|
|
|
|
2020-04-12 20:33:35 +02:00
|
|
|
func TestPrivilegeHandler_Process_UserAdded_And_UserRemoved(t *testing.T) {
|
|
|
|
|
handler := New(WithBaseURL("base"))
|
|
|
|
|
|
2021-05-15 14:42:19 +02:00
|
|
|
result, err := handler.Process(&UserAdded{
|
2020-04-12 20:33:35 +02:00
|
|
|
Email: "jim@example.org",
|
|
|
|
|
CompanyID: "abc-123",
|
2021-05-15 14:42:19 +02:00
|
|
|
}, goamqp.Headers{})
|
|
|
|
|
assert.Nil(t, result)
|
|
|
|
|
assert.NoError(t, err)
|
2020-04-12 20:33:35 +02:00
|
|
|
|
2021-05-15 14:42:19 +02:00
|
|
|
result, err = handler.Process(&UserAdded{
|
2020-04-12 20:33:35 +02:00
|
|
|
Email: "jim@example.org",
|
|
|
|
|
CompanyID: "abc-456",
|
2021-05-15 14:42:19 +02:00
|
|
|
}, goamqp.Headers{})
|
|
|
|
|
assert.Nil(t, result)
|
|
|
|
|
assert.NoError(t, err)
|
2020-04-12 20:33:35 +02:00
|
|
|
|
|
|
|
|
companies := handler.CompaniesByUser("jim@example.org", func(privileges CompanyPrivileges) bool {
|
|
|
|
|
return true
|
|
|
|
|
})
|
2020-04-12 20:46:18 +02:00
|
|
|
sort.Strings(companies)
|
2020-04-12 20:33:35 +02:00
|
|
|
assert.Equal(t, []string{"abc-123", "abc-456"}, companies)
|
|
|
|
|
|
2021-05-15 14:42:19 +02:00
|
|
|
result, err = handler.Process(&UserRemoved{
|
2020-04-12 20:33:35 +02:00
|
|
|
Email: "jim@example.org",
|
|
|
|
|
CompanyID: "abc-123",
|
2021-05-15 14:42:19 +02:00
|
|
|
}, goamqp.Headers{})
|
|
|
|
|
assert.Nil(t, result)
|
|
|
|
|
assert.NoError(t, err)
|
2020-04-12 20:33:35 +02:00
|
|
|
|
2021-05-15 14:42:19 +02:00
|
|
|
result, err = handler.Process(&UserRemoved{
|
2020-04-12 20:33:35 +02:00
|
|
|
Email: "jim@example.org",
|
|
|
|
|
CompanyID: "abc-456",
|
2021-05-15 14:42:19 +02:00
|
|
|
}, goamqp.Headers{})
|
|
|
|
|
assert.Nil(t, result)
|
|
|
|
|
assert.NoError(t, err)
|
2020-04-12 20:33:35 +02:00
|
|
|
|
|
|
|
|
companies = handler.CompaniesByUser("jim@example.org", func(privileges CompanyPrivileges) bool {
|
|
|
|
|
return true
|
|
|
|
|
})
|
|
|
|
|
assert.Empty(t, companies)
|
|
|
|
|
}
|
|
|
|
|
|
2019-11-05 21:24:54 +01:00
|
|
|
func TestPrivilegeHandler_GetCompanies_Email_Not_Found(t *testing.T) {
|
|
|
|
|
handler := New(WithBaseURL("base"))
|
|
|
|
|
|
|
|
|
|
companies := handler.CompaniesByUser("jim@example.org", func(privileges CompanyPrivileges) bool {
|
|
|
|
|
return true
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
assert.Empty(t, companies)
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
func TestPrivilegeHandler_GetCompanies_No_Companies_Found(t *testing.T) {
|
|
|
|
|
handler := New(WithBaseURL("base"))
|
|
|
|
|
|
2021-05-15 14:42:19 +02:00
|
|
|
result, err := handler.Process(&UserAdded{
|
2020-04-12 20:33:35 +02:00
|
|
|
Email: "jim@example.org",
|
|
|
|
|
CompanyID: "abc-123",
|
2021-05-15 14:42:19 +02:00
|
|
|
}, goamqp.Headers{})
|
|
|
|
|
assert.Nil(t, result)
|
|
|
|
|
assert.NoError(t, err)
|
2019-11-05 21:24:54 +01:00
|
|
|
|
|
|
|
|
companies := handler.CompaniesByUser("jim@example.org", func(privileges CompanyPrivileges) bool {
|
|
|
|
|
return privileges.Admin
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
assert.Empty(t, companies)
|
2020-04-12 20:33:35 +02:00
|
|
|
|
|
|
|
|
companies = handler.CompaniesByUser("jim@example.org", func(privileges CompanyPrivileges) bool {
|
|
|
|
|
return true
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
assert.Equal(t, []string{"abc-123"}, companies)
|
|
|
|
|
|
2021-05-15 14:42:19 +02:00
|
|
|
result, err = handler.Process(&UserRemoved{
|
2020-04-12 20:33:35 +02:00
|
|
|
Email: "jim@example.org",
|
|
|
|
|
CompanyID: "abc-123",
|
2021-05-15 14:42:19 +02:00
|
|
|
}, goamqp.Headers{})
|
|
|
|
|
assert.Nil(t, result)
|
|
|
|
|
assert.NoError(t, err)
|
2020-04-12 20:33:35 +02:00
|
|
|
|
|
|
|
|
companies = handler.CompaniesByUser("jim@example.org", func(privileges CompanyPrivileges) bool {
|
|
|
|
|
return true
|
|
|
|
|
})
|
|
|
|
|
assert.Empty(t, companies)
|
2019-11-05 21:24:54 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
func TestPrivilegeHandler_GetCompanies_Company_With_Company_Access_Found(t *testing.T) {
|
|
|
|
|
handler := New(WithBaseURL("base"))
|
|
|
|
|
|
2021-05-15 14:42:19 +02:00
|
|
|
result, err := handler.Process(&PrivilegeAdded{
|
2020-04-12 20:33:35 +02:00
|
|
|
Email: "jim@example.org",
|
|
|
|
|
CompanyID: "abc-123",
|
|
|
|
|
Privilege: PrivilegeCompany,
|
2021-05-15 14:42:19 +02:00
|
|
|
}, goamqp.Headers{})
|
|
|
|
|
assert.Nil(t, result)
|
|
|
|
|
assert.NoError(t, err)
|
2019-11-05 21:24:54 +01:00
|
|
|
|
|
|
|
|
companies := handler.CompaniesByUser("jim@example.org", func(privileges CompanyPrivileges) bool {
|
|
|
|
|
return privileges.Company
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
assert.Equal(t, []string{"abc-123"}, companies)
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
func TestPrivilegeHandler_GetCompanies_Company_With_Admin_Access_Found(t *testing.T) {
|
|
|
|
|
handler := New(WithBaseURL("base"))
|
|
|
|
|
|
2021-05-15 14:42:19 +02:00
|
|
|
result, err := handler.Process(&PrivilegeAdded{
|
2020-04-12 20:33:35 +02:00
|
|
|
Email: "jim@example.org",
|
|
|
|
|
CompanyID: "abc-123",
|
|
|
|
|
Privilege: PrivilegeConsumer,
|
2021-05-15 14:42:19 +02:00
|
|
|
}, goamqp.Headers{})
|
|
|
|
|
assert.Nil(t, result)
|
|
|
|
|
assert.NoError(t, err)
|
2019-11-05 21:24:54 +01:00
|
|
|
|
|
|
|
|
companies := handler.CompaniesByUser("jim@example.org", func(privileges CompanyPrivileges) bool {
|
2020-04-12 20:33:35 +02:00
|
|
|
return privileges.Consumer
|
2019-11-05 21:24:54 +01:00
|
|
|
})
|
|
|
|
|
|
|
|
|
|
assert.Equal(t, []string{"abc-123"}, companies)
|
|
|
|
|
}
|
|
|
|
|
|
2019-12-31 12:58:20 +01:00
|
|
|
func TestPrivilegeHandler_IsAllowed_Return_False_If_No_Privileges(t *testing.T) {
|
|
|
|
|
handler := New(WithBaseURL("base"))
|
|
|
|
|
|
|
|
|
|
result := handler.IsAllowed("jim@example.org", "abc-123", func(privileges CompanyPrivileges) bool {
|
|
|
|
|
return privileges.Company
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
assert.False(t, result)
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
func TestPrivilegeHandler_IsAllowed_Return_True_If_Privilege_Exists(t *testing.T) {
|
|
|
|
|
handler := New(WithBaseURL("base"))
|
|
|
|
|
|
2021-05-15 14:42:19 +02:00
|
|
|
_, _ = handler.Process(&PrivilegeAdded{
|
2020-04-12 20:33:35 +02:00
|
|
|
Email: "jim@example.org",
|
|
|
|
|
CompanyID: "abc-123",
|
|
|
|
|
Privilege: PrivilegeTime,
|
2021-05-15 14:42:19 +02:00
|
|
|
}, goamqp.Headers{})
|
2019-12-31 12:58:20 +01:00
|
|
|
|
|
|
|
|
result := handler.IsAllowed("jim@example.org", "abc-123", func(privileges CompanyPrivileges) bool {
|
2020-04-12 20:33:35 +02:00
|
|
|
return privileges.Time
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
assert.True(t, result)
|
|
|
|
|
|
2021-05-15 14:42:19 +02:00
|
|
|
_, _ = handler.Process(&PrivilegeAdded{
|
2020-04-12 20:33:35 +02:00
|
|
|
Email: "jim@example.org",
|
|
|
|
|
CompanyID: "abc-123",
|
|
|
|
|
Privilege: PrivilegeInvoicing,
|
2021-05-15 14:42:19 +02:00
|
|
|
}, goamqp.Headers{})
|
2020-04-12 20:33:35 +02:00
|
|
|
|
|
|
|
|
result = handler.IsAllowed("jim@example.org", "abc-123", func(privileges CompanyPrivileges) bool {
|
|
|
|
|
return privileges.Invoicing
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
assert.True(t, result)
|
|
|
|
|
|
2021-05-15 14:42:19 +02:00
|
|
|
_, _ = handler.Process(&PrivilegeAdded{
|
2020-04-12 20:33:35 +02:00
|
|
|
Email: "jim@example.org",
|
|
|
|
|
CompanyID: "abc-123",
|
|
|
|
|
Privilege: PrivilegeAccounting,
|
2021-05-15 14:42:19 +02:00
|
|
|
}, goamqp.Headers{})
|
2020-04-12 20:33:35 +02:00
|
|
|
|
|
|
|
|
result = handler.IsAllowed("jim@example.org", "abc-123", func(privileges CompanyPrivileges) bool {
|
|
|
|
|
return privileges.Accounting
|
|
|
|
|
})
|
|
|
|
|
|
|
|
|
|
assert.True(t, result)
|
|
|
|
|
|
2021-05-15 14:42:19 +02:00
|
|
|
_, _ = handler.Process(&PrivilegeAdded{
|
2020-04-12 20:33:35 +02:00
|
|
|
Email: "jim@example.org",
|
|
|
|
|
CompanyID: "abc-123",
|
|
|
|
|
Privilege: PrivilegeSupplier,
|
2021-05-15 14:42:19 +02:00
|
|
|
}, goamqp.Headers{})
|
2020-04-12 20:33:35 +02:00
|
|
|
|
|
|
|
|
result = handler.IsAllowed("jim@example.org", "abc-123", func(privileges CompanyPrivileges) bool {
|
|
|
|
|
return privileges.Supplier
|
2019-12-31 12:58:20 +01:00
|
|
|
})
|
|
|
|
|
|
|
|
|
|
assert.True(t, result)
|
|
|
|
|
}
|
|
|
|
|
|
2019-11-05 21:24:54 +01:00
|
|
|
func TestPrivilegeHandler_Fetch_Error_Response(t *testing.T) {
|
|
|
|
|
server := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
|
|
|
w.WriteHeader(500)
|
|
|
|
|
}))
|
|
|
|
|
|
|
|
|
|
baseURL := server.Listener.Addr().String()
|
|
|
|
|
handler := New(WithBaseURL(fmt.Sprintf("http://%s", baseURL)))
|
|
|
|
|
|
|
|
|
|
server.Close()
|
|
|
|
|
|
|
|
|
|
err := handler.Fetch()
|
2020-04-12 20:33:35 +02:00
|
|
|
assert.EqualError(t, err, fmt.Sprintf("Get \"http://%s/authz\": dial tcp %s: connect: connection refused", baseURL, baseURL))
|
2019-11-05 21:24:54 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
func TestPrivilegeHandler_Fetch_Error_Unreadable_Body(t *testing.T) {
|
|
|
|
|
server := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
|
|
|
w.Header().Set("Content-Length", "1")
|
|
|
|
|
}))
|
|
|
|
|
defer server.Close()
|
|
|
|
|
|
|
|
|
|
baseURL := server.Listener.Addr().String()
|
|
|
|
|
handler := New(WithBaseURL(fmt.Sprintf("http://%s", baseURL)))
|
|
|
|
|
|
|
|
|
|
err := handler.Fetch()
|
|
|
|
|
assert.EqualError(t, err, "unexpected EOF")
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
func TestPrivilegeHandler_Fetch_Error_Broken_JSON(t *testing.T) {
|
|
|
|
|
server := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
|
|
|
_, _ = w.Write([]byte("{abc"))
|
|
|
|
|
}))
|
|
|
|
|
defer server.Close()
|
|
|
|
|
|
|
|
|
|
baseURL := server.Listener.Addr().String()
|
|
|
|
|
handler := New(WithBaseURL(fmt.Sprintf("http://%s", baseURL)))
|
|
|
|
|
|
|
|
|
|
err := handler.Fetch()
|
|
|
|
|
assert.EqualError(t, err, "invalid character 'a' looking for beginning of object key string")
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
func TestPrivilegeHandler_Fetch_Valid(t *testing.T) {
|
|
|
|
|
privileges := `
|
|
|
|
|
{
|
|
|
|
|
"jim@example.org": {
|
|
|
|
|
"00010203-0405-4607-8809-0a0b0c0d0e0f": {
|
|
|
|
|
"admin": false,
|
|
|
|
|
"company": true,
|
|
|
|
|
"consumer": false,
|
|
|
|
|
"time": true,
|
|
|
|
|
"invoicing": true,
|
|
|
|
|
"accounting": false,
|
|
|
|
|
"supplier": false
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
}`
|
|
|
|
|
server := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
|
|
|
_, _ = w.Write([]byte(privileges))
|
|
|
|
|
}))
|
|
|
|
|
defer server.Close()
|
|
|
|
|
|
|
|
|
|
baseURL := server.Listener.Addr().String()
|
|
|
|
|
handler := New(WithBaseURL(fmt.Sprintf("http://%s", baseURL)))
|
|
|
|
|
|
|
|
|
|
err := handler.Fetch()
|
|
|
|
|
assert.NoError(t, err)
|
2020-04-12 20:33:35 +02:00
|
|
|
expectedPrivileges := map[string]map[string]*CompanyPrivileges{
|
2019-11-05 21:24:54 +01:00
|
|
|
"jim@example.org": {
|
|
|
|
|
"00010203-0405-4607-8809-0a0b0c0d0e0f": {
|
|
|
|
|
Admin: false,
|
|
|
|
|
Company: true,
|
|
|
|
|
Consumer: false,
|
|
|
|
|
Time: true,
|
|
|
|
|
Invoicing: true,
|
|
|
|
|
Accounting: false,
|
|
|
|
|
Supplier: false,
|
|
|
|
|
},
|
|
|
|
|
},
|
|
|
|
|
}
|
|
|
|
|
assert.Equal(t, expectedPrivileges, handler.privileges)
|
|
|
|
|
}
|