use of com.yahoo.athenz.zms.Role in project athenz by yahoo.
the class DataCache method processAssumeRoleAssertion.
void processAssumeRoleAssertion(Assertion assertion, Map<String, Role> roles) {
final String roleName = assertion.getRole();
Role role = roles.get(roleName);
if (role == null) {
return;
}
/* add the resource as a role name for all the members */
processRoleMembers(assertion.getResource(), role.getRoleMembers());
}
use of com.yahoo.athenz.zms.Role in project athenz by yahoo.
the class DataStore method processDomainPolicies.
void processDomainPolicies(DomainData domainData, DataCache domainCache) {
com.yahoo.athenz.zms.SignedPolicies signedPolicies = domainData.getPolicies();
if (signedPolicies == null) {
return;
}
com.yahoo.athenz.zms.DomainPolicies domainPolicies = signedPolicies.getContents();
if (domainPolicies == null) {
return;
}
List<com.yahoo.athenz.zms.Policy> policies = domainPolicies.getPolicies();
if (policies == null) {
return;
}
List<Role> roles = domainData.getRoles();
HashMap<String, Role> roleMap = new HashMap<>();
for (Role role : roles) {
roleMap.put(role.getName(), role);
}
for (com.yahoo.athenz.zms.Policy policy : policies) {
domainCache.processPolicy(domainData.getName(), policy, roleMap);
}
}
use of com.yahoo.athenz.zms.Role in project athenz by yahoo.
the class ZTSImplTest method testMatchPrincipalInRoleDelegatedTrustNoMatch.
@Test
public void testMatchPrincipalInRoleDelegatedTrustNoMatch() {
Role role = createRoleObject("weather", "Role", "coretech_not_present");
assertFalse(authorizer.matchPrincipalInRole(role, "Role", "user_domain.user1", "coretech_not_present"));
}
use of com.yahoo.athenz.zms.Role in project athenz by yahoo.
the class DataCacheTest method testPolicyWithInvalidAssertionRole.
@Test
public void testPolicyWithInvalidAssertionRole() {
Domain domain = new Domain();
domain.setName("testDomain");
Role role1 = new Role();
role1.setName("testDomain.role.role1");
List<RoleMember> members1 = new ArrayList<>();
members1.add(new RoleMember().setMemberName("user_domain.user1"));
members1.add(new RoleMember().setMemberName("user_domain.user2"));
role1.setRoleMembers(members1);
Role role2 = new Role();
role2.setName("testDomain.role.role2");
List<RoleMember> members2 = new ArrayList<>();
members2.add(new RoleMember().setMemberName("user_domain.user2"));
role2.setRoleMembers(members2);
Role role3 = new Role();
role3.setName("testDomain.role.role3");
List<RoleMember> members3 = new ArrayList<>();
members3.add(new RoleMember().setMemberName("user_domain.user3"));
role3.setRoleMembers(members3);
Policy policy = new Policy();
policy.setName("testDomain.policy.policy1");
Assertion assertion = new Assertion();
assertion.setAction("assume_role");
assertion.setEffect(AssertionEffect.ALLOW);
assertion.setResource("testDomain.role");
assertion.setRole("testDomain.role.Invalid");
List<Assertion> assertList = new ArrayList<Assertion>();
assertList.add(assertion);
policy.setAssertions(assertList);
HashMap<String, Role> roleList = new HashMap<>();
roleList.put(role1.getName(), role1);
roleList.put(role2.getName(), role2);
roleList.put(role3.getName(), role3);
DataCache cache = new DataCache();
cache.processRole(role1);
cache.processRole(role2);
cache.processRole(role3);
cache.processPolicy(domain.getName(), policy, roleList);
Set<MemberRole> set1 = cache.getMemberRoleSet("user_domain.user1");
assertNotNull(set1);
assertTrue(set1.contains(new MemberRole("testDomain.role.role1", 0)));
assertEquals(set1.size(), 1);
Set<MemberRole> set2 = cache.getMemberRoleSet("user_domain.user2");
assertNotNull(set2);
assertTrue(set2.contains(new MemberRole("testDomain.role.role1", 0)));
assertTrue(set2.contains(new MemberRole("testDomain.role.role2", 0)));
assertEquals(set2.size(), 2);
Set<MemberRole> set3 = cache.getMemberRoleSet("user_domain.user3");
assertNotNull(set3);
assertTrue(set3.contains(new MemberRole("testDomain.role.role3", 0)));
assertEquals(set3.size(), 1);
}
use of com.yahoo.athenz.zms.Role in project athenz by yahoo.
the class DataCacheTest method testPolicyWithAssertionRoleNoMember.
@Test
public void testPolicyWithAssertionRoleNoMember() {
Domain domain = new Domain();
domain.setName("testDomain");
Role role1 = new Role();
role1.setName("testDomain.role.role1");
Role role2 = new Role();
role2.setName("testDomain.role.role2");
List<RoleMember> members2 = new ArrayList<>();
members2.add(new RoleMember().setMemberName("user_domain.user2"));
role2.setRoleMembers(members2);
Role role3 = new Role();
role3.setName("testDomain.role.role3");
List<RoleMember> members3 = new ArrayList<>();
members3.add(new RoleMember().setMemberName("user_domain.user3"));
role3.setRoleMembers(members3);
Policy policy = new Policy();
policy.setName("testDomain.policy.policy1");
Assertion assertion = new Assertion();
assertion.setAction("assume_role");
assertion.setEffect(AssertionEffect.ALLOW);
assertion.setResource("testDomain.roleA");
assertion.setRole("testDomain.role.role1");
List<Assertion> assertList = new ArrayList<Assertion>();
assertList.add(assertion);
policy.setAssertions(assertList);
HashMap<String, Role> roleList = new HashMap<>();
roleList.put(role1.getName(), role1);
roleList.put(role2.getName(), role2);
roleList.put(role3.getName(), role3);
DataCache cache = new DataCache();
cache.processRole(role1);
cache.processRole(role2);
cache.processRole(role3);
cache.processPolicy(domain.getName(), policy, roleList);
Set<MemberRole> set1 = cache.getMemberRoleSet("user_domain.user1");
assertNull(set1);
Set<MemberRole> set2 = cache.getMemberRoleSet("user_domain.user2");
assertNotNull(set2);
assertTrue(set2.contains(new MemberRole("testDomain.role.role2", 0)));
assertEquals(set2.size(), 1);
Set<MemberRole> set3 = cache.getMemberRoleSet("user_domain.user3");
assertNotNull(set3);
assertTrue(set3.contains(new MemberRole("testDomain.role.role3", 0)));
assertEquals(set3.size(), 1);
}
Aggregations