Search in sources :

Example 1 with FirewallRule

use of org.apache.qpid.server.security.access.firewall.FirewallRule in project qpid-broker-j by apache.

the class ClientActionTest method testMatches_returnsFalseWhenActionsDontMatch.

public void testMatches_returnsFalseWhenActionsDontMatch() {
    FirewallRule firewallRule = mock(FirewallRule.class);
    when(firewallRule.matches(_addressOfClient)).thenReturn(true);
    when(_action.matches(any(Action.class))).thenReturn(false);
    when(_ruleAction.getFirewallRule()).thenReturn(firewallRule);
    assertFalse(_clientAction.matches(_ruleAction, _addressOfClient));
}
Also used : FirewallRule(org.apache.qpid.server.security.access.firewall.FirewallRule)

Example 2 with FirewallRule

use of org.apache.qpid.server.security.access.firewall.FirewallRule in project qpid-broker-j by apache.

the class ClientActionTest method testMatches_ignoresFirewallRuleIfClientAddressIsNull.

public void testMatches_ignoresFirewallRuleIfClientAddressIsNull() {
    FirewallRule firewallRule = mock(FirewallRule.class);
    when(_action.matches(any(Action.class))).thenReturn(true);
    when(_ruleAction.getFirewallRule()).thenReturn(firewallRule);
    assertTrue(_clientAction.matches(_ruleAction, null));
    verifyZeroInteractions(firewallRule);
}
Also used : FirewallRule(org.apache.qpid.server.security.access.firewall.FirewallRule)

Example 3 with FirewallRule

use of org.apache.qpid.server.security.access.firewall.FirewallRule in project qpid-broker-j by apache.

the class MessagingACLTest method configureACL.

private void configureACL(String... rules) throws Exception {
    EventLoggerProvider eventLoggerProvider = mock(EventLoggerProvider.class);
    EventLogger eventLogger = mock(EventLogger.class);
    when(eventLoggerProvider.getEventLogger()).thenReturn(eventLogger);
    List<AclRule> aclRules = new ArrayList<>();
    try (StringReader stringReader = new StringReader(Arrays.stream(rules).collect(Collectors.joining(LINE_SEPARATOR)))) {
        RuleSet ruleSet = AclFileParser.parse(stringReader, eventLoggerProvider);
        final List<Rule> parsedRules = ruleSet.getAllRules();
        for (final Rule rule : parsedRules) {
            aclRules.add(new AclRule() {

                @Override
                public String getIdentity() {
                    return rule.getIdentity();
                }

                @Override
                public ObjectType getObjectType() {
                    return rule.getAction().getObjectType();
                }

                @Override
                public LegacyOperation getOperation() {
                    return rule.getAction().getOperation();
                }

                @Override
                public Map<ObjectProperties.Property, String> getAttributes() {
                    Map<ObjectProperties.Property, String> attributes = new HashMap<>(rule.getAction().getProperties().asPropertyMap());
                    FirewallRule firewallRule = rule.getAclAction().getFirewallRule();
                    if (firewallRule != null) {
                        if (firewallRule instanceof HostnameFirewallRule) {
                            attributes.put(ObjectProperties.Property.FROM_HOSTNAME, "127.0.0.1");
                        } else if (firewallRule instanceof NetworkFirewallRule) {
                            // tests use only 127.0.0.1 at the moment
                            attributes.put(ObjectProperties.Property.FROM_NETWORK, "127.0.0.1");
                        }
                    }
                    return attributes;
                }

                @Override
                public RuleOutcome getOutcome() {
                    return rule.getRuleOutcome();
                }
            });
        }
    }
    configureACL(aclRules.toArray(new AclRule[aclRules.size()]));
}
Also used : NetworkFirewallRule(org.apache.qpid.server.security.access.firewall.NetworkFirewallRule) RuleSet(org.apache.qpid.server.security.access.config.RuleSet) LegacyOperation(org.apache.qpid.server.security.access.config.LegacyOperation) EventLoggerProvider(org.apache.qpid.server.logging.EventLoggerProvider) EventLogger(org.apache.qpid.server.logging.EventLogger) ArrayList(java.util.ArrayList) ObjectProperties(org.apache.qpid.server.security.access.config.ObjectProperties) ObjectType(org.apache.qpid.server.security.access.config.ObjectType) HostnameFirewallRule(org.apache.qpid.server.security.access.firewall.HostnameFirewallRule) StringReader(java.io.StringReader) RuleOutcome(org.apache.qpid.server.security.access.plugins.RuleOutcome) AclRule(org.apache.qpid.server.security.access.plugins.AclRule) AclRule(org.apache.qpid.server.security.access.plugins.AclRule) NetworkFirewallRule(org.apache.qpid.server.security.access.firewall.NetworkFirewallRule) Rule(org.apache.qpid.server.security.access.config.Rule) FirewallRule(org.apache.qpid.server.security.access.firewall.FirewallRule) HostnameFirewallRule(org.apache.qpid.server.security.access.firewall.HostnameFirewallRule) Map(java.util.Map) HashMap(java.util.HashMap) NetworkFirewallRule(org.apache.qpid.server.security.access.firewall.NetworkFirewallRule) FirewallRule(org.apache.qpid.server.security.access.firewall.FirewallRule) HostnameFirewallRule(org.apache.qpid.server.security.access.firewall.HostnameFirewallRule)

Example 4 with FirewallRule

use of org.apache.qpid.server.security.access.firewall.FirewallRule in project qpid-broker-j by apache.

the class ClientActionTest method testMatches_returnsTrueWhenActionsAndFirewallRuleMatch.

public void testMatches_returnsTrueWhenActionsAndFirewallRuleMatch() {
    FirewallRule firewallRule = mock(FirewallRule.class);
    when(firewallRule.matches(_addressOfClient)).thenReturn(true);
    when(_action.matches(any(Action.class))).thenReturn(true);
    when(_ruleAction.getFirewallRule()).thenReturn(firewallRule);
    assertTrue(_clientAction.matches(_ruleAction, _addressOfClient));
}
Also used : FirewallRule(org.apache.qpid.server.security.access.firewall.FirewallRule)

Aggregations

FirewallRule (org.apache.qpid.server.security.access.firewall.FirewallRule)4 StringReader (java.io.StringReader)1 ArrayList (java.util.ArrayList)1 HashMap (java.util.HashMap)1 Map (java.util.Map)1 EventLogger (org.apache.qpid.server.logging.EventLogger)1 EventLoggerProvider (org.apache.qpid.server.logging.EventLoggerProvider)1 LegacyOperation (org.apache.qpid.server.security.access.config.LegacyOperation)1 ObjectProperties (org.apache.qpid.server.security.access.config.ObjectProperties)1 ObjectType (org.apache.qpid.server.security.access.config.ObjectType)1 Rule (org.apache.qpid.server.security.access.config.Rule)1 RuleSet (org.apache.qpid.server.security.access.config.RuleSet)1 HostnameFirewallRule (org.apache.qpid.server.security.access.firewall.HostnameFirewallRule)1 NetworkFirewallRule (org.apache.qpid.server.security.access.firewall.NetworkFirewallRule)1 AclRule (org.apache.qpid.server.security.access.plugins.AclRule)1 RuleOutcome (org.apache.qpid.server.security.access.plugins.RuleOutcome)1