Search in sources :

Example 56 with Permission

use of org.keycloak.representations.idm.authorization.Permission in project keycloak by keycloak.

the class UmaGrantTypeTest method testObtainRptWithClientCredentials.

@Test
public void testObtainRptWithClientCredentials() throws Exception {
    AuthorizationResponse response = authorize("Resource A", new String[] { "ScopeA", "ScopeB" });
    String rpt = response.getToken();
    assertNotNull(rpt);
    assertFalse(response.isUpgraded());
    AccessToken accessToken = toAccessToken(rpt);
    AccessToken.Authorization authorization = accessToken.getAuthorization();
    assertNotNull(authorization);
    Collection<Permission> permissions = authorization.getPermissions();
    assertNotNull(permissions);
    assertPermissions(permissions, "Resource A", "ScopeA", "ScopeB");
    assertTrue(permissions.isEmpty());
}
Also used : AccessToken(org.keycloak.representations.AccessToken) Permission(org.keycloak.representations.idm.authorization.Permission) AuthorizationResponse(org.keycloak.representations.idm.authorization.AuthorizationResponse) Test(org.junit.Test)

Example 57 with Permission

use of org.keycloak.representations.idm.authorization.Permission in project keycloak by keycloak.

the class UmaGrantTypeTest method testObtainRptWithUpgradeOnlyScopes.

@Test
public void testObtainRptWithUpgradeOnlyScopes() throws Exception {
    AuthorizationResponse response = authorize("marta", "password", null, new String[] { "ScopeA", "ScopeB" });
    String rpt = response.getToken();
    AccessToken.Authorization authorization = toAccessToken(rpt).getAuthorization();
    Collection<Permission> permissions = authorization.getPermissions();
    assertFalse(response.isUpgraded());
    assertNotNull(permissions);
    assertPermissions(permissions, "Resource A", "ScopeA", "ScopeB");
    assertTrue(permissions.isEmpty());
    response = authorize("marta", "password", "Resource A", new String[] { "ScopeC" }, rpt);
    authorization = toAccessToken(response.getToken()).getAuthorization();
    permissions = authorization.getPermissions();
    assertTrue(response.isUpgraded());
    assertNotNull(permissions);
    assertPermissions(permissions, "Resource A", "ScopeA", "ScopeB", "ScopeC");
    assertTrue(permissions.isEmpty());
}
Also used : AccessToken(org.keycloak.representations.AccessToken) Permission(org.keycloak.representations.idm.authorization.Permission) AuthorizationResponse(org.keycloak.representations.idm.authorization.AuthorizationResponse) Test(org.junit.Test)

Example 58 with Permission

use of org.keycloak.representations.idm.authorization.Permission in project keycloak by keycloak.

the class UmaGrantTypeTest method testObtainRptWithUpgrade.

@Test
public void testObtainRptWithUpgrade() throws Exception {
    AuthorizationResponse response = authorize("marta", "password", "Resource A", new String[] { "ScopeA", "ScopeB" });
    String rpt = response.getToken();
    AccessToken.Authorization authorization = toAccessToken(rpt).getAuthorization();
    Collection<Permission> permissions = authorization.getPermissions();
    assertNotNull(permissions);
    assertPermissions(permissions, "Resource A", "ScopeA", "ScopeB");
    assertTrue(permissions.isEmpty());
    response = authorize("marta", "password", "Resource A", new String[] { "ScopeC" }, rpt);
    assertTrue(response.isUpgraded());
    authorization = toAccessToken(response.getToken()).getAuthorization();
    permissions = authorization.getPermissions();
    assertNotNull(permissions);
    assertPermissions(permissions, "Resource A", "ScopeA", "ScopeB", "ScopeC");
    assertTrue(permissions.isEmpty());
}
Also used : AccessToken(org.keycloak.representations.AccessToken) Permission(org.keycloak.representations.idm.authorization.Permission) AuthorizationResponse(org.keycloak.representations.idm.authorization.AuthorizationResponse) Test(org.junit.Test)

Example 59 with Permission

use of org.keycloak.representations.idm.authorization.Permission in project keycloak by keycloak.

the class GroupPermissions method hasPermission.

private boolean hasPermission(Resource resource, EvaluationContext context, String... scopes) {
    ResourceServer server = root.realmResourceServer();
    Collection<Permission> permissions;
    if (context == null) {
        permissions = root.evaluatePermission(new ResourcePermission(resource, resource.getScopes(), server), server);
    } else {
        permissions = root.evaluatePermission(new ResourcePermission(resource, resource.getScopes(), server), server, context);
    }
    List<String> expectedScopes = Arrays.asList(scopes);
    for (Permission permission : permissions) {
        for (String scope : permission.getScopes()) {
            if (expectedScopes.contains(scope)) {
                return true;
            }
        }
    }
    return false;
}
Also used : ResourcePermission(org.keycloak.authorization.permission.ResourcePermission) Permission(org.keycloak.representations.idm.authorization.Permission) ResourceServer(org.keycloak.authorization.model.ResourceServer) ResourcePermission(org.keycloak.authorization.permission.ResourcePermission)

Example 60 with Permission

use of org.keycloak.representations.idm.authorization.Permission in project keycloak by keycloak.

the class EntitlementAPITest method testObtainAllEntitlementsForResourceType.

@Test
public void testObtainAllEntitlementsForResourceType() throws Exception {
    ClientResource client = getClient(getRealm(), RESOURCE_SERVER_TEST);
    AuthorizationResource authorization = client.authorization();
    JSPolicyRepresentation policy = new JSPolicyRepresentation();
    policy.setName(KeycloakModelUtils.generateId());
    policy.setCode("$evaluation.grant();");
    authorization.policies().js().create(policy).close();
    for (int i = 0; i < 10; i++) {
        ResourceRepresentation resource = new ResourceRepresentation();
        resource.setType("type-one");
        resource.setName(KeycloakModelUtils.generateId());
        authorization.resources().create(resource).close();
    }
    for (int i = 0; i < 10; i++) {
        ResourceRepresentation resource = new ResourceRepresentation();
        resource.setType("type-two");
        resource.setName(KeycloakModelUtils.generateId());
        authorization.resources().create(resource).close();
    }
    for (int i = 0; i < 10; i++) {
        ResourceRepresentation resource = new ResourceRepresentation();
        resource.setType("type-three");
        resource.setName(KeycloakModelUtils.generateId());
        authorization.resources().create(resource).close();
    }
    for (int i = 0; i < 10; i++) {
        ResourceRepresentation resource = new ResourceRepresentation();
        resource.setType("type-four");
        resource.setName(KeycloakModelUtils.generateId());
        resource.addScope("scope:view", "scope:update");
        authorization.resources().create(resource).close();
    }
    for (int i = 0; i < 10; i++) {
        ResourceRepresentation resource = new ResourceRepresentation();
        resource.setType("type-five");
        resource.setName(KeycloakModelUtils.generateId());
        resource.addScope("scope:view");
        authorization.resources().create(resource).close();
    }
    ResourcePermissionRepresentation resourcePermission = new ResourcePermissionRepresentation();
    resourcePermission.setName(KeycloakModelUtils.generateId());
    resourcePermission.setResourceType("type-one");
    resourcePermission.addPolicy(policy.getName());
    authorization.permissions().resource().create(resourcePermission).close();
    resourcePermission = new ResourcePermissionRepresentation();
    resourcePermission.setName(KeycloakModelUtils.generateId());
    resourcePermission.setResourceType("type-two");
    resourcePermission.addPolicy(policy.getName());
    authorization.permissions().resource().create(resourcePermission).close();
    resourcePermission = new ResourcePermissionRepresentation();
    resourcePermission.setName(KeycloakModelUtils.generateId());
    resourcePermission.setResourceType("type-three");
    resourcePermission.addPolicy(policy.getName());
    authorization.permissions().resource().create(resourcePermission).close();
    ScopePermissionRepresentation scopePersmission = new ScopePermissionRepresentation();
    scopePersmission.setName(KeycloakModelUtils.generateId());
    scopePersmission.setResourceType("type-four");
    scopePersmission.addScope("scope:view");
    scopePersmission.addPolicy(policy.getName());
    authorization.permissions().scope().create(scopePersmission).close();
    String accessToken = new OAuthClient().realm("authz-test").clientId(RESOURCE_SERVER_TEST).doGrantAccessTokenRequest("secret", "kolo", "password").getAccessToken();
    AuthzClient authzClient = getAuthzClient(AUTHZ_CLIENT_CONFIG);
    AuthorizationRequest request = new AuthorizationRequest();
    request.addPermission("resource-type:type-one");
    AuthorizationResponse response = authzClient.authorization(accessToken).authorize(request);
    assertNotNull(response.getToken());
    Collection<Permission> permissions = toAccessToken(response.getToken()).getAuthorization().getPermissions();
    assertEquals(10, permissions.size());
    request = new AuthorizationRequest();
    request.addPermission("resource-type:type-three");
    response = authzClient.authorization(accessToken).authorize(request);
    assertNotNull(response.getToken());
    permissions = toAccessToken(response.getToken()).getAuthorization().getPermissions();
    assertEquals(10, permissions.size());
    request = new AuthorizationRequest();
    request.addPermission("resource-type:type-four", "scope:view");
    response = authzClient.authorization(accessToken).authorize(request);
    assertNotNull(response.getToken());
    permissions = toAccessToken(response.getToken()).getAuthorization().getPermissions();
    assertEquals(10, permissions.size());
    for (Permission grantedPermission : permissions) {
        assertEquals(1, grantedPermission.getScopes().size());
        assertTrue(grantedPermission.getScopes().containsAll(Arrays.asList("scope:view")));
    }
    request = new AuthorizationRequest();
    request.addPermission("resource-type:type-five", "scope:view");
    try {
        authzClient.authorization(accessToken).authorize(request);
        fail("no type-five resources can be granted since scope permission for scope:view only applies to type-four");
    } catch (RuntimeException expected) {
        assertEquals(403, HttpResponseException.class.cast(expected.getCause()).getStatusCode());
        assertTrue(HttpResponseException.class.cast(expected.getCause()).toString().contains("access_denied"));
    }
    for (int i = 0; i < 5; i++) {
        ResourceRepresentation resource = new ResourceRepresentation();
        resource.setOwner("kolo");
        resource.setType("type-two");
        resource.setName(KeycloakModelUtils.generateId());
        authorization.resources().create(resource).close();
    }
    request = new AuthorizationRequest();
    request.addPermission("resource-type-any:type-two");
    response = authzClient.authorization(accessToken).authorize(request);
    assertNotNull(response.getToken());
    permissions = toAccessToken(response.getToken()).getAuthorization().getPermissions();
    assertEquals(15, permissions.size());
    request = new AuthorizationRequest();
    request.addPermission("resource-type-owner:type-two");
    response = authzClient.authorization(accessToken).authorize(request);
    assertNotNull(response.getToken());
    permissions = toAccessToken(response.getToken()).getAuthorization().getPermissions();
    assertEquals(5, permissions.size());
    request = new AuthorizationRequest();
    request.addPermission("resource-type-instance:type-two");
    response = authzClient.authorization(accessToken).authorize(request);
    assertNotNull(response.getToken());
    permissions = toAccessToken(response.getToken()).getAuthorization().getPermissions();
    assertEquals(5, permissions.size());
    Permission next = permissions.iterator().next();
    ResourceResource resourceMgmt = client.authorization().resources().resource(next.getResourceId());
    ResourceRepresentation representation = resourceMgmt.toRepresentation();
    representation.setType("type-three");
    resourceMgmt.update(representation);
    request = new AuthorizationRequest();
    request.addPermission("resource-type-instance:type-two");
    response = authzClient.authorization(accessToken).authorize(request);
    assertNotNull(response.getToken());
    permissions = toAccessToken(response.getToken()).getAuthorization().getPermissions();
    assertEquals(4, permissions.size());
    request = new AuthorizationRequest();
    request.addPermission("resource-type-instance:type-three");
    response = authzClient.authorization(accessToken).authorize(request);
    assertNotNull(response.getToken());
    permissions = toAccessToken(response.getToken()).getAuthorization().getPermissions();
    assertEquals(1, permissions.size());
    request = new AuthorizationRequest();
    request.addPermission("resource-type-any:type-three");
    response = authzClient.authorization(accessToken).authorize(request);
    assertNotNull(response.getToken());
    permissions = toAccessToken(response.getToken()).getAuthorization().getPermissions();
    assertEquals(11, permissions.size());
    for (int i = 0; i < 2; i++) {
        ResourceRepresentation resource = new ResourceRepresentation();
        resource.setOwner("marta");
        resource.setType("type-one");
        resource.setName(KeycloakModelUtils.generateId());
        authorization.resources().create(resource).close();
    }
    request = new AuthorizationRequest();
    request.addPermission("resource-type:type-one");
    response = authzClient.authorization(accessToken).authorize(request);
    assertNotNull(response.getToken());
    permissions = toAccessToken(response.getToken()).getAuthorization().getPermissions();
    assertEquals(10, permissions.size());
    accessToken = new OAuthClient().realm("authz-test").clientId(RESOURCE_SERVER_TEST).doGrantAccessTokenRequest("secret", "marta", "password").getAccessToken();
    request = new AuthorizationRequest();
    request.addPermission("resource-type-owner:type-one");
    response = authzClient.authorization(accessToken).authorize(request);
    assertNotNull(response.getToken());
    permissions = toAccessToken(response.getToken()).getAuthorization().getPermissions();
    assertEquals(2, permissions.size());
    request = new AuthorizationRequest();
    request.addPermission("resource-type-instance:type-one");
    response = authzClient.authorization(accessToken).authorize(request);
    assertNotNull(response.getToken());
    permissions = toAccessToken(response.getToken()).getAuthorization().getPermissions();
    assertEquals(2, permissions.size());
    request = new AuthorizationRequest();
    request.addPermission("resource-type-any:type-one");
    response = authzClient.authorization(accessToken).authorize(request);
    assertNotNull(response.getToken());
    permissions = toAccessToken(response.getToken()).getAuthorization().getPermissions();
    assertEquals(12, permissions.size());
}
Also used : AuthorizationRequest(org.keycloak.representations.idm.authorization.AuthorizationRequest) OAuthClient(org.keycloak.testsuite.util.OAuthClient) JSPolicyRepresentation(org.keycloak.representations.idm.authorization.JSPolicyRepresentation) HttpResponseException(org.keycloak.authorization.client.util.HttpResponseException) ResourceResource(org.keycloak.admin.client.resource.ResourceResource) AuthorizationResource(org.keycloak.admin.client.resource.AuthorizationResource) ResourceRepresentation(org.keycloak.representations.idm.authorization.ResourceRepresentation) ResourcePermissionRepresentation(org.keycloak.representations.idm.authorization.ResourcePermissionRepresentation) AuthorizationResponse(org.keycloak.representations.idm.authorization.AuthorizationResponse) AuthzClient(org.keycloak.authorization.client.AuthzClient) Permission(org.keycloak.representations.idm.authorization.Permission) ClientResource(org.keycloak.admin.client.resource.ClientResource) ScopePermissionRepresentation(org.keycloak.representations.idm.authorization.ScopePermissionRepresentation) Test(org.junit.Test)

Aggregations

Permission (org.keycloak.representations.idm.authorization.Permission)73 Test (org.junit.Test)50 AuthorizationResponse (org.keycloak.representations.idm.authorization.AuthorizationResponse)44 AccessToken (org.keycloak.representations.AccessToken)36 AuthorizationRequest (org.keycloak.representations.idm.authorization.AuthorizationRequest)29 ResourceRepresentation (org.keycloak.representations.idm.authorization.ResourceRepresentation)27 AuthorizationResource (org.keycloak.admin.client.resource.AuthorizationResource)23 AuthzClient (org.keycloak.authorization.client.AuthzClient)22 ClientResource (org.keycloak.admin.client.resource.ClientResource)20 ArrayList (java.util.ArrayList)19 ResourcePermissionRepresentation (org.keycloak.representations.idm.authorization.ResourcePermissionRepresentation)19 OAuthClient (org.keycloak.testsuite.util.OAuthClient)15 ScopePermissionRepresentation (org.keycloak.representations.idm.authorization.ScopePermissionRepresentation)14 JSPolicyRepresentation (org.keycloak.representations.idm.authorization.JSPolicyRepresentation)13 Response (javax.ws.rs.core.Response)12 AuthorizationDeniedException (org.keycloak.authorization.client.AuthorizationDeniedException)12 AccessTokenResponse (org.keycloak.representations.AccessTokenResponse)12 PermissionRequest (org.keycloak.representations.idm.authorization.PermissionRequest)12 PermissionResponse (org.keycloak.representations.idm.authorization.PermissionResponse)12 Authorization (org.keycloak.representations.AccessToken.Authorization)11