Search in sources :

Example 6 with GrpcAuthHelper

use of io.pravega.controller.server.security.auth.GrpcAuthHelper in project pravega by pravega.

the class InMemoryControllerServiceImplTest method supplierCreatesTokenWithReadForInternalStreamsWhenRequestedIsSame.

@Test
public void supplierCreatesTokenWithReadForInternalStreamsWhenRequestedIsSame() {
    GrpcAuthHelper mockAuthHelper = spy(new GrpcAuthHelper(true, "tokenSigningKey", 600));
    ControllerServiceImpl objectUnderTest = new ControllerServiceImpl(null, mockAuthHelper, requestTracker, true, true, 200);
    String streamResource = new AuthorizationResourceImpl().ofStreamInScope("testScope", "_testStream");
    Controller.StreamInfo request = createStreamInfoProtobufMessage("testScope", "_testStream", AccessOperation.READ);
    doReturn("").when(mockAuthHelper).checkAuthorization(streamResource, AuthHandler.Permissions.READ);
    doReturn("dummy.delegation.token").when(mockAuthHelper).createDelegationToken(streamResource, AuthHandler.Permissions.READ);
    assertEquals("dummy.delegation.token", objectUnderTest.delegationTokenSupplier(request).get());
}
Also used : GrpcAuthHelper(io.pravega.controller.server.security.auth.GrpcAuthHelper) AuthorizationResourceImpl(io.pravega.shared.security.auth.AuthorizationResourceImpl) Controller(io.pravega.controller.stream.api.grpc.v1.Controller) Test(org.junit.Test)

Example 7 with GrpcAuthHelper

use of io.pravega.controller.server.security.auth.GrpcAuthHelper in project pravega by pravega.

the class InMemoryControllerServiceImplTest method supplierCreatesTokenWithRequestedReadPermission.

@Test
public void supplierCreatesTokenWithRequestedReadPermission() {
    GrpcAuthHelper mockAuthHelper = spy(new GrpcAuthHelper(true, "tokenSigningKey", 600));
    ControllerServiceImpl objectUnderTest = new ControllerServiceImpl(null, mockAuthHelper, requestTracker, true, true, 200);
    String streamResource = new AuthorizationResourceImpl().ofStreamInScope("testScope", "testStream");
    Controller.StreamInfo request = createStreamInfoProtobufMessage("testScope", "testStream", AccessOperation.READ);
    doReturn("").when(mockAuthHelper).checkAuthorization(streamResource, AuthHandler.Permissions.READ);
    doReturn("dummy.delegation.token").when(mockAuthHelper).createDelegationToken(streamResource, AuthHandler.Permissions.READ);
    assertEquals("dummy.delegation.token", objectUnderTest.delegationTokenSupplier(request).get());
}
Also used : GrpcAuthHelper(io.pravega.controller.server.security.auth.GrpcAuthHelper) AuthorizationResourceImpl(io.pravega.shared.security.auth.AuthorizationResourceImpl) Controller(io.pravega.controller.stream.api.grpc.v1.Controller) Test(org.junit.Test)

Example 8 with GrpcAuthHelper

use of io.pravega.controller.server.security.auth.GrpcAuthHelper in project pravega by pravega.

the class InMemoryControllerServiceImplTest method supplierCreatesTokenWithReadWritePermissionByDefault.

@Test
public void supplierCreatesTokenWithReadWritePermissionByDefault() {
    GrpcAuthHelper mockAuthHelper = spy(new GrpcAuthHelper(true, "tokenSigningKey", 600));
    ControllerServiceImpl objectUnderTest = new ControllerServiceImpl(null, mockAuthHelper, requestTracker, true, true, 200);
    String streamResource = new AuthorizationResourceImpl().ofStreamInScope("testScope", "testStream");
    Controller.StreamInfo request = createStreamInfoProtobufMessage("testScope", "testStream", null);
    doReturn("").when(mockAuthHelper).checkAuthorization(streamResource, AuthHandler.Permissions.READ_UPDATE);
    doReturn("dummy.delegation.token").when(mockAuthHelper).createDelegationToken(streamResource, AuthHandler.Permissions.READ_UPDATE);
    assertEquals("dummy.delegation.token", objectUnderTest.delegationTokenSupplier(request).get());
}
Also used : GrpcAuthHelper(io.pravega.controller.server.security.auth.GrpcAuthHelper) AuthorizationResourceImpl(io.pravega.shared.security.auth.AuthorizationResourceImpl) Controller(io.pravega.controller.stream.api.grpc.v1.Controller) Test(org.junit.Test)

Example 9 with GrpcAuthHelper

use of io.pravega.controller.server.security.auth.GrpcAuthHelper in project pravega by pravega.

the class InMemoryControllerServiceImplTest method supplierForMarkStreams.

@Test
public void supplierForMarkStreams() {
    GrpcAuthHelper mockAuthHelper = spy(new GrpcAuthHelper(true, "tokenSigningKey", 600));
    ControllerServiceImpl objectUnderTest = new ControllerServiceImpl(null, mockAuthHelper, requestTracker, true, true, 200);
    AuthorizationResource authResource = new AuthorizationResourceImpl();
    String markStreamResource = authResource.ofStreamInScope("testScope", "_MARKtestStream");
    String streamResource = authResource.ofStreamInScope("testScope", "testStream");
    Controller.StreamInfo readRequest = createStreamInfoProtobufMessage("testScope", "_MARKtestStream", AccessOperation.READ);
    Controller.StreamInfo writeRequest = createStreamInfoProtobufMessage("testScope", "_MARKtestStream", AccessOperation.READ_WRITE);
    // For mark streams, authorization is done against the corresponding stream
    doReturn("").when(mockAuthHelper).checkAuthorization(streamResource, AuthHandler.Permissions.READ);
    doReturn("").when(mockAuthHelper).checkAuthorization(streamResource, AuthHandler.Permissions.READ_UPDATE);
    doReturn("dummy.delegation.token").when(mockAuthHelper).createDelegationToken(markStreamResource, AuthHandler.Permissions.READ);
    doReturn("dummy.delegation.token").when(mockAuthHelper).createDelegationToken(markStreamResource, AuthHandler.Permissions.READ_UPDATE);
    assertEquals("dummy.delegation.token", objectUnderTest.delegationTokenSupplier(readRequest).get());
    assertEquals("dummy.delegation.token", objectUnderTest.delegationTokenSupplier(writeRequest).get());
}
Also used : GrpcAuthHelper(io.pravega.controller.server.security.auth.GrpcAuthHelper) AuthorizationResourceImpl(io.pravega.shared.security.auth.AuthorizationResourceImpl) Controller(io.pravega.controller.stream.api.grpc.v1.Controller) AuthorizationResource(io.pravega.shared.security.auth.AuthorizationResource) Test(org.junit.Test)

Example 10 with GrpcAuthHelper

use of io.pravega.controller.server.security.auth.GrpcAuthHelper in project pravega by pravega.

the class PravegaTablesScopeTest method testDeleteScopeRecursive.

@Test
public void testDeleteScopeRecursive() {
    GrpcAuthHelper authHelper = mock(GrpcAuthHelper.class);
    when(authHelper.retrieveMasterToken()).thenReturn("");
    SegmentHelper segmentHelper = mock(SegmentHelper.class);
    PravegaTablesStoreHelper storeHelper = new PravegaTablesStoreHelper(segmentHelper, authHelper, executorService());
    PravegaTablesScope tablesScope = spy(new PravegaTablesScope(scope, storeHelper));
    tablesScope.deleteScopeRecursive(context);
    verify(tablesScope, times(1)).getStreamsInScopeTableName(true, context);
    verify(tablesScope, times(1)).getReaderGroupsInScopeTableName(context);
    verify(tablesScope, times(1)).getKVTablesInScopeTableName(context);
    verify(tablesScope, times(1)).getAllStreamTagsInScopeTableNames(context);
    tablesScope.sealScope(scope, context);
    verify(tablesScope, times(5)).getId(context);
}
Also used : GrpcAuthHelper(io.pravega.controller.server.security.auth.GrpcAuthHelper) SegmentHelper(io.pravega.controller.server.SegmentHelper) Test(org.junit.Test)

Aggregations

GrpcAuthHelper (io.pravega.controller.server.security.auth.GrpcAuthHelper)28 Test (org.junit.Test)22 SegmentHelper (io.pravega.controller.server.SegmentHelper)10 Controller (io.pravega.controller.stream.api.grpc.v1.Controller)10 StreamMetadataStore (io.pravega.controller.store.stream.StreamMetadataStore)9 StreamConfiguration (io.pravega.client.stream.StreamConfiguration)8 AuthorizationResourceImpl (io.pravega.shared.security.auth.AuthorizationResourceImpl)8 UUID (java.util.UUID)8 TaskMetadataStore (io.pravega.controller.store.task.TaskMetadataStore)7 ArrayList (java.util.ArrayList)7 EventStreamWriterMock (io.pravega.controller.mocks.EventStreamWriterMock)6 EventHelper (io.pravega.controller.task.EventHelper)6 List (java.util.List)6 ScalingPolicy (io.pravega.client.stream.ScalingPolicy)5 AbortEvent (io.pravega.shared.controller.event.AbortEvent)5 CommitEvent (io.pravega.shared.controller.event.CommitEvent)5 ControllerEventStreamWriterMock (io.pravega.controller.mocks.ControllerEventStreamWriterMock)4 BucketStore (io.pravega.controller.store.stream.BucketStore)4 TableMetadataTasks (io.pravega.controller.task.KeyValueTable.TableMetadataTasks)4 StreamMetadataTasks (io.pravega.controller.task.Stream.StreamMetadataTasks)4