2020-10-14 23:22:58 +00:00
|
|
|
package security
|
|
|
|
|
2022-01-01 01:07:19 +00:00
|
|
|
import (
|
|
|
|
"net/http"
|
|
|
|
"net/http/httptest"
|
|
|
|
"testing"
|
2020-10-14 23:22:58 +00:00
|
|
|
|
2022-01-01 01:07:19 +00:00
|
|
|
"github.com/gorilla/mux"
|
|
|
|
"golang.org/x/oauth2"
|
|
|
|
)
|
|
|
|
|
|
|
|
func TestConfig_IsValid(t *testing.T) {
|
|
|
|
c := &Config{
|
|
|
|
Basic: nil,
|
|
|
|
OIDC: nil,
|
2020-10-14 23:22:58 +00:00
|
|
|
}
|
2022-01-01 01:07:19 +00:00
|
|
|
if c.IsValid() {
|
|
|
|
t.Error("expected empty config to be valid")
|
2020-10-14 23:22:58 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2022-01-01 01:07:19 +00:00
|
|
|
func TestConfig_ApplySecurityMiddleware(t *testing.T) {
|
|
|
|
///////////
|
|
|
|
// BASIC //
|
|
|
|
///////////
|
2022-06-15 03:48:28 +00:00
|
|
|
// Bcrypt
|
2022-01-01 01:07:19 +00:00
|
|
|
c := &Config{Basic: &BasicConfig{
|
2022-06-15 03:48:28 +00:00
|
|
|
Username: "john.doe",
|
|
|
|
PasswordBcryptHashBase64Encoded: "JDJhJDA4JDFoRnpPY1hnaFl1OC9ISlFsa21VS09wOGlPU1ZOTDlHZG1qeTFvb3dIckRBUnlHUmNIRWlT",
|
2022-01-01 01:07:19 +00:00
|
|
|
}}
|
|
|
|
api := mux.NewRouter()
|
|
|
|
api.HandleFunc("/test", func(w http.ResponseWriter, r *http.Request) {
|
|
|
|
w.WriteHeader(http.StatusOK)
|
|
|
|
})
|
2022-01-09 00:52:55 +00:00
|
|
|
if err := c.ApplySecurityMiddleware(api); err != nil {
|
|
|
|
t.Error("expected no error, but was", err)
|
|
|
|
}
|
2022-01-01 01:07:19 +00:00
|
|
|
// Try to access the route without basic auth
|
2022-01-02 23:29:34 +00:00
|
|
|
request, _ := http.NewRequest("GET", "/test", http.NoBody)
|
2022-01-01 01:07:19 +00:00
|
|
|
responseRecorder := httptest.NewRecorder()
|
|
|
|
api.ServeHTTP(responseRecorder, request)
|
2022-01-09 00:52:55 +00:00
|
|
|
if responseRecorder.Code != http.StatusUnauthorized {
|
|
|
|
t.Error("expected code to be 401, but was", responseRecorder.Code)
|
|
|
|
}
|
|
|
|
// Try again, but with basic auth
|
|
|
|
request, _ = http.NewRequest("GET", "/test", http.NoBody)
|
|
|
|
responseRecorder = httptest.NewRecorder()
|
|
|
|
request.SetBasicAuth("john.doe", "hunter2")
|
|
|
|
api.ServeHTTP(responseRecorder, request)
|
|
|
|
if responseRecorder.Code != http.StatusOK {
|
|
|
|
t.Error("expected code to be 200, but was", responseRecorder.Code)
|
|
|
|
}
|
2022-01-01 01:07:19 +00:00
|
|
|
//////////
|
|
|
|
// OIDC //
|
|
|
|
//////////
|
|
|
|
api = mux.NewRouter()
|
|
|
|
api.HandleFunc("/test", func(w http.ResponseWriter, r *http.Request) {
|
|
|
|
w.WriteHeader(http.StatusOK)
|
|
|
|
})
|
|
|
|
c.OIDC = &OIDCConfig{
|
|
|
|
IssuerURL: "https://sso.gatus.io/",
|
|
|
|
RedirectURL: "http://localhost:80/authorization-code/callback",
|
|
|
|
Scopes: []string{"openid"},
|
|
|
|
AllowedSubjects: []string{"user1@example.com"},
|
|
|
|
oauth2Config: oauth2.Config{},
|
|
|
|
verifier: nil,
|
|
|
|
}
|
|
|
|
c.Basic = nil
|
2022-01-09 00:52:55 +00:00
|
|
|
if err := c.ApplySecurityMiddleware(api); err != nil {
|
|
|
|
t.Error("expected no error, but was", err)
|
|
|
|
}
|
2022-01-01 01:07:19 +00:00
|
|
|
// Try without any session cookie
|
2022-01-02 23:29:34 +00:00
|
|
|
request, _ = http.NewRequest("GET", "/test", http.NoBody)
|
2022-01-01 01:07:19 +00:00
|
|
|
responseRecorder = httptest.NewRecorder()
|
|
|
|
api.ServeHTTP(responseRecorder, request)
|
|
|
|
if responseRecorder.Code != http.StatusUnauthorized {
|
|
|
|
t.Error("expected code to be 401, but was", responseRecorder.Code)
|
|
|
|
}
|
|
|
|
// Try with a session cookie
|
2022-01-02 23:29:34 +00:00
|
|
|
request, _ = http.NewRequest("GET", "/test", http.NoBody)
|
2022-01-01 01:07:19 +00:00
|
|
|
request.AddCookie(&http.Cookie{Name: "session", Value: "123"})
|
|
|
|
responseRecorder = httptest.NewRecorder()
|
|
|
|
api.ServeHTTP(responseRecorder, request)
|
|
|
|
if responseRecorder.Code != http.StatusUnauthorized {
|
|
|
|
t.Error("expected code to be 401, but was", responseRecorder.Code)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func TestConfig_RegisterHandlers(t *testing.T) {
|
|
|
|
c := &Config{}
|
|
|
|
router := mux.NewRouter()
|
|
|
|
c.RegisterHandlers(router)
|
|
|
|
// Try to access the OIDC handler. This should fail, because the security config doesn't have OIDC
|
2022-01-02 23:29:34 +00:00
|
|
|
request, _ := http.NewRequest("GET", "/oidc/login", http.NoBody)
|
2022-01-01 01:07:19 +00:00
|
|
|
responseRecorder := httptest.NewRecorder()
|
|
|
|
router.ServeHTTP(responseRecorder, request)
|
|
|
|
if responseRecorder.Code != http.StatusNotFound {
|
|
|
|
t.Error("expected code to be 404, but was", responseRecorder.Code)
|
|
|
|
}
|
|
|
|
// Set an empty OIDC config. This should fail, because the IssuerURL is required.
|
|
|
|
c.OIDC = &OIDCConfig{}
|
|
|
|
if err := c.RegisterHandlers(router); err == nil {
|
|
|
|
t.Fatal("expected an error, but got none")
|
|
|
|
}
|
|
|
|
// Set the OIDC config and try again
|
|
|
|
c.OIDC = &OIDCConfig{
|
|
|
|
IssuerURL: "https://sso.gatus.io/",
|
|
|
|
RedirectURL: "http://localhost:80/authorization-code/callback",
|
|
|
|
Scopes: []string{"openid"},
|
|
|
|
AllowedSubjects: []string{"user1@example.com"},
|
|
|
|
}
|
|
|
|
if err := c.RegisterHandlers(router); err != nil {
|
|
|
|
t.Fatal("expected no error, but got", err)
|
2020-10-14 23:22:58 +00:00
|
|
|
}
|
2022-01-02 23:29:34 +00:00
|
|
|
request, _ = http.NewRequest("GET", "/oidc/login", http.NoBody)
|
2022-01-01 01:07:19 +00:00
|
|
|
responseRecorder = httptest.NewRecorder()
|
|
|
|
router.ServeHTTP(responseRecorder, request)
|
|
|
|
if responseRecorder.Code != http.StatusFound {
|
|
|
|
t.Error("expected code to be 302, but was", responseRecorder.Code)
|
2020-10-14 23:22:58 +00:00
|
|
|
}
|
|
|
|
}
|