Search in sources :

Example 6 with OperationPolicyExpression

use of org.nhindirect.policy.OperationPolicyExpression in project nhin-d by DirectProject.

the class StackMachineCompiler_compileTest method testCompile_multipleEmbeddedOperations_extendedKeyUsage_keyUsage_assertEntriesAndEvaluation.

public void testCompile_multipleEmbeddedOperations_extendedKeyUsage_keyUsage_assertEntriesAndEvaluation() throws Exception {
    final X509Certificate cert = TestUtils.loadCertificate("mshost.der");
    // build the expression
    final Integer keyUsage = KeyUsage.nonRepudiation;
    final PolicyValue<Integer> op1 = PolicyValueFactory.getInstance(keyUsage);
    final LiteralPolicyExpression<Integer> expr1 = LiteralPolicyExpressionFactory.getInstance(op1);
    final KeyUsageExtensionField expr2 = new KeyUsageExtensionField(true);
    final Vector<PolicyExpression> operands1 = new Vector<PolicyExpression>();
    operands1.add(expr1);
    operands1.add(expr2);
    final OperationPolicyExpression oper1 = OperationPolicyExpressionFactory.getInstance(PolicyOperator.BITWISE_AND, operands1);
    // build outer expression embedding the first operation as a parameter
    final PolicyValue<Integer> op3 = PolicyValueFactory.getInstance(0);
    final LiteralPolicyExpression<Integer> expr3 = LiteralPolicyExpressionFactory.getInstance(op3);
    final Vector<PolicyExpression> operands2 = new Vector<PolicyExpression>();
    operands2.add(oper1);
    operands2.add(expr3);
    final OperationPolicyExpression oper2 = OperationPolicyExpressionFactory.getInstance(PolicyOperator.GREATER, operands2);
    final StackMachineCompiler compiler = new StackMachineCompiler();
    // build a separate expression for extended key usage
    final ExtendedKeyUsageExtensionField expr4 = new ExtendedKeyUsageExtensionField(true);
    final PolicyValue<String> op5 = PolicyValueFactory.getInstance(ExtendedKeyUsageIdentifier.ID_KP_EMAIL_PROTECTION.getId());
    final LiteralPolicyExpression<String> expr5 = LiteralPolicyExpressionFactory.getInstance(op5);
    final Vector<PolicyExpression> operands3 = new Vector<PolicyExpression>();
    operands3.add(expr4);
    operands3.add(expr5);
    final OperationPolicyExpression oper3 = OperationPolicyExpressionFactory.getInstance(PolicyOperator.CONTAINS, operands3);
    // build an and operator and make sure the cert has all policies met
    final Vector<PolicyExpression> operands4 = new Vector<PolicyExpression>();
    operands4.add(oper2);
    operands4.add(oper3);
    final OperationPolicyExpression oper4 = OperationPolicyExpressionFactory.getInstance(PolicyOperator.LOGICAL_AND, operands4);
    final Vector<Opcode> entries = compiler.compile(cert, oper4);
    assertEquals(9, entries.size());
    assertEquals(op1, ((StackMachineEntry) entries.get(0)).getValue());
    assertEquals(expr2.getPolicyValue().getPolicyValue(), ((StackMachineEntry) entries.get(1)).getValue().getPolicyValue());
    assertEquals(PolicyOperator.BITWISE_AND, ((StackMachineEntry) entries.get(2)).getOperator());
    assertEquals(op3, ((StackMachineEntry) entries.get(3)).getValue());
    assertEquals(PolicyOperator.GREATER, ((StackMachineEntry) entries.get(4)).getOperator());
    assertEquals(expr4.getPolicyValue(), ((StackMachineEntry) entries.get(5)).getValue());
    assertEquals(op5, ((StackMachineEntry) entries.get(6)).getValue());
    assertEquals(PolicyOperator.CONTAINS, ((StackMachineEntry) entries.get(7)).getOperator());
    assertEquals(PolicyOperator.LOGICAL_AND, ((StackMachineEntry) entries.get(8)).getOperator());
    // execute the compiled expression in the stack machine
    final StackMachine machine = new StackMachine();
    final Boolean evalVal = machine.evaluate(entries);
    assertTrue(evalVal);
}
Also used : ExtendedKeyUsageExtensionField(org.nhindirect.policy.x509.ExtendedKeyUsageExtensionField) Opcode(org.nhindirect.policy.Opcode) LiteralPolicyExpression(org.nhindirect.policy.LiteralPolicyExpression) PolicyExpression(org.nhindirect.policy.PolicyExpression) OperationPolicyExpression(org.nhindirect.policy.OperationPolicyExpression) StackMachineCompiler(org.nhindirect.policy.impl.machine.StackMachineCompiler) X509Certificate(java.security.cert.X509Certificate) OperationPolicyExpression(org.nhindirect.policy.OperationPolicyExpression) StackMachine(org.nhindirect.policy.impl.machine.StackMachine) StackMachineEntry(org.nhindirect.policy.impl.machine.StackMachineEntry) KeyUsageExtensionField(org.nhindirect.policy.x509.KeyUsageExtensionField) ExtendedKeyUsageExtensionField(org.nhindirect.policy.x509.ExtendedKeyUsageExtensionField) Vector(java.util.Vector)

Example 7 with OperationPolicyExpression

use of org.nhindirect.policy.OperationPolicyExpression in project nhin-d by DirectProject.

the class SimpleTextV1LexiconPolicyParser_buildExpressionTest method testBuildExpression_tinaryExpression_literalOperands_validatePolicyExpression.

public void testBuildExpression_tinaryExpression_literalOperands_validatePolicyExpression() throws Exception {
    final SimpleTextV1LexiconPolicyParser parser = new SimpleTextV1LexiconPolicyParser();
    InputStream stream = IOUtils.toInputStream("2 = 1 != true");
    Vector<SimpleTextV1LexiconPolicyParser.TokenTypeAssociation> tokens = parser.parseToTokens(stream);
    // now build expressions
    PolicyExpression expression = parser.buildExpression(tokens.iterator());
    // check that the expression is an equals
    assertNotNull(expression);
    assertEquals(PolicyExpressionType.OPERATION, expression.getExpressionType());
    OperationPolicyExpression operationExpression = (OperationPolicyExpression) expression;
    assertEquals(PolicyOperator.NOT_EQUALS, operationExpression.getPolicyOperator());
    // break down the sub operation parameters... should be an operation and a literal
    expression = operationExpression.getOperands().get(1);
    assertEquals(PolicyExpressionType.LITERAL, expression.getExpressionType());
    assertEquals("true", ((LiteralPolicyExpression<?>) expression).getPolicyValue().getPolicyValue());
    expression = operationExpression.getOperands().get(0);
    assertEquals(PolicyExpressionType.OPERATION, expression.getExpressionType());
    // break down the sub parameters again of this operation
    OperationPolicyExpression subOperation = (OperationPolicyExpression) expression;
    assertEquals(PolicyOperator.EQUALS, subOperation.getPolicyOperator());
    expression = subOperation.getOperands().get(0);
    assertEquals(PolicyExpressionType.LITERAL, expression.getExpressionType());
    assertEquals("2", ((LiteralPolicyExpression<?>) expression).getPolicyValue().getPolicyValue());
    expression = subOperation.getOperands().get(1);
    assertEquals(PolicyExpressionType.LITERAL, expression.getExpressionType());
    assertEquals("1", ((LiteralPolicyExpression<?>) expression).getPolicyValue().getPolicyValue());
}
Also used : LiteralPolicyExpression(org.nhindirect.policy.LiteralPolicyExpression) InputStream(java.io.InputStream) LiteralPolicyExpression(org.nhindirect.policy.LiteralPolicyExpression) PolicyExpression(org.nhindirect.policy.PolicyExpression) OperationPolicyExpression(org.nhindirect.policy.OperationPolicyExpression) OperationPolicyExpression(org.nhindirect.policy.OperationPolicyExpression)

Example 8 with OperationPolicyExpression

use of org.nhindirect.policy.OperationPolicyExpression in project nhin-d by DirectProject.

the class SimpleTextV1LexiconPolicyParser_buildExpressionTest method testBuildExpression_requiredCertField_validateTokens.

public void testBuildExpression_requiredCertField_validateTokens() throws Exception {
    final SimpleTextV1LexiconPolicyParser parser = new SimpleTextV1LexiconPolicyParser();
    final InputStream stream = IOUtils.toInputStream("X509.TBS.EXTENSION.SubjectKeyIdentifier+ = 1.3.2.3");
    Vector<SimpleTextV1LexiconPolicyParser.TokenTypeAssociation> tokens = parser.parseToTokens(stream);
    // now build expressions
    PolicyExpression expression = parser.buildExpression(tokens.iterator());
    // check that the expression is an equals
    assertNotNull(expression);
    assertEquals(PolicyExpressionType.OPERATION, expression.getExpressionType());
    OperationPolicyExpression operationExpression = (OperationPolicyExpression) expression;
    assertEquals(PolicyOperator.EQUALS, operationExpression.getPolicyOperator());
    // break down the sub operation parameters... should be a literal and an operation
    expression = operationExpression.getOperands().get(0);
    assertEquals(PolicyExpressionType.REFERENCE, expression.getExpressionType());
    assertTrue(expression instanceof SubjectKeyIdentifierExtensionField);
    assertTrue(((SubjectKeyIdentifierExtensionField) expression).isRequired());
    expression = operationExpression.getOperands().get(1);
    assertEquals(PolicyExpressionType.LITERAL, expression.getExpressionType());
    stream.close();
}
Also used : InputStream(java.io.InputStream) LiteralPolicyExpression(org.nhindirect.policy.LiteralPolicyExpression) PolicyExpression(org.nhindirect.policy.PolicyExpression) OperationPolicyExpression(org.nhindirect.policy.OperationPolicyExpression) SubjectKeyIdentifierExtensionField(org.nhindirect.policy.x509.SubjectKeyIdentifierExtensionField) OperationPolicyExpression(org.nhindirect.policy.OperationPolicyExpression)

Example 9 with OperationPolicyExpression

use of org.nhindirect.policy.OperationPolicyExpression in project nhin-d by DirectProject.

the class SimpleTextV1LexiconPolicyParser_buildExpressionTest method testBuildExpression_extensionName_keyUsage_validatePolicyExpression.

public void testBuildExpression_extensionName_keyUsage_validatePolicyExpression() throws Exception {
    final SimpleTextV1LexiconPolicyParser parser = new SimpleTextV1LexiconPolicyParser();
    final InputStream stream = FileUtils.openInputStream(new File("./src/test/resources/policies/lexiconWithKeyUsage.txt"));
    final Vector<SimpleTextV1LexiconPolicyParser.TokenTypeAssociation> tokens = parser.parseToTokens(stream);
    // now build expressions
    PolicyExpression expression = parser.buildExpression(tokens.iterator());
    // check that the expression is an equals
    assertNotNull(expression);
    assertEquals(PolicyExpressionType.OPERATION, expression.getExpressionType());
    OperationPolicyExpression operationExpression = (OperationPolicyExpression) expression;
    assertEquals(PolicyOperator.EQUALS, operationExpression.getPolicyOperator());
    // break down the sub operation parameters... should be a cert reference and a literal
    expression = operationExpression.getOperands().get(0);
    assertEquals(PolicyExpressionType.REFERENCE, expression.getExpressionType());
    assertTrue(expression instanceof KeyUsageExtensionField);
    expression = operationExpression.getOperands().get(1);
    assertEquals(PolicyExpressionType.LITERAL, expression.getExpressionType());
    assertEquals("1", ((LiteralPolicyExpression<?>) expression).getPolicyValue().getPolicyValue());
}
Also used : LiteralPolicyExpression(org.nhindirect.policy.LiteralPolicyExpression) InputStream(java.io.InputStream) LiteralPolicyExpression(org.nhindirect.policy.LiteralPolicyExpression) PolicyExpression(org.nhindirect.policy.PolicyExpression) OperationPolicyExpression(org.nhindirect.policy.OperationPolicyExpression) KeyUsageExtensionField(org.nhindirect.policy.x509.KeyUsageExtensionField) File(java.io.File) OperationPolicyExpression(org.nhindirect.policy.OperationPolicyExpression)

Example 10 with OperationPolicyExpression

use of org.nhindirect.policy.OperationPolicyExpression in project nhin-d by DirectProject.

the class SimpleTextV1LexiconPolicyParser_buildExpressionTest method testBuildExpression_tinaryExpression_operatorExpressionOperands_validatePolicyExpression.

public void testBuildExpression_tinaryExpression_operatorExpressionOperands_validatePolicyExpression() throws Exception {
    final SimpleTextV1LexiconPolicyParser parser = new SimpleTextV1LexiconPolicyParser();
    InputStream stream = IOUtils.toInputStream("false = !true && !false");
    Vector<SimpleTextV1LexiconPolicyParser.TokenTypeAssociation> tokens = parser.parseToTokens(stream);
    // now build expressions
    PolicyExpression expression = parser.buildExpression(tokens.iterator());
    // check that the expression is an equals
    assertNotNull(expression);
    assertEquals(PolicyExpressionType.OPERATION, expression.getExpressionType());
    OperationPolicyExpression operationExpression = (OperationPolicyExpression) expression;
    assertEquals(PolicyOperator.LOGICAL_AND, operationExpression.getPolicyOperator());
    // break down the sub operation parameters... should be two operations
    OperationPolicyExpression subOperation = (OperationPolicyExpression) operationExpression.getOperands().get(0);
    assertEquals(PolicyExpressionType.OPERATION, subOperation.getExpressionType());
    assertEquals(PolicyOperator.EQUALS, subOperation.getPolicyOperator());
    expression = subOperation.getOperands().get(0);
    assertEquals(PolicyExpressionType.LITERAL, expression.getExpressionType());
    assertEquals("false", ((LiteralPolicyExpression<?>) expression).getPolicyValue().getPolicyValue());
    OperationPolicyExpression subSubOperation = (OperationPolicyExpression) subOperation.getOperands().get(1);
    assertEquals(PolicyExpressionType.OPERATION, subSubOperation.getExpressionType());
    assertEquals(PolicyOperator.LOGICAL_NOT, subSubOperation.getPolicyOperator());
    subOperation = (OperationPolicyExpression) operationExpression.getOperands().get(1);
    assertEquals(PolicyExpressionType.OPERATION, subOperation.getExpressionType());
    assertEquals(PolicyOperator.LOGICAL_NOT, subOperation.getPolicyOperator());
    expression = subOperation.getOperands().get(0);
    assertEquals(PolicyExpressionType.LITERAL, expression.getExpressionType());
    assertEquals("false", ((LiteralPolicyExpression<?>) expression).getPolicyValue().getPolicyValue());
}
Also used : LiteralPolicyExpression(org.nhindirect.policy.LiteralPolicyExpression) InputStream(java.io.InputStream) LiteralPolicyExpression(org.nhindirect.policy.LiteralPolicyExpression) PolicyExpression(org.nhindirect.policy.PolicyExpression) OperationPolicyExpression(org.nhindirect.policy.OperationPolicyExpression) OperationPolicyExpression(org.nhindirect.policy.OperationPolicyExpression)

Aggregations

LiteralPolicyExpression (org.nhindirect.policy.LiteralPolicyExpression)16 OperationPolicyExpression (org.nhindirect.policy.OperationPolicyExpression)16 PolicyExpression (org.nhindirect.policy.PolicyExpression)16 Vector (java.util.Vector)9 InputStream (java.io.InputStream)7 KeyUsageExtensionField (org.nhindirect.policy.x509.KeyUsageExtensionField)7 ExtendedKeyUsageExtensionField (org.nhindirect.policy.x509.ExtendedKeyUsageExtensionField)6 Opcode (org.nhindirect.policy.Opcode)5 StackMachine (org.nhindirect.policy.impl.machine.StackMachine)5 StackMachineCompiler (org.nhindirect.policy.impl.machine.StackMachineCompiler)5 ByteArrayOutputStream (java.io.ByteArrayOutputStream)4 File (java.io.File)4 ByteArrayInputStream (java.io.ByteArrayInputStream)3 X509Certificate (java.security.cert.X509Certificate)3 StackMachineEntry (org.nhindirect.policy.impl.machine.StackMachineEntry)3 XMLLexiconPolicyParser (org.nhindirect.policy.impl.XMLLexiconPolicyParser)2 SubjectAttributeField (org.nhindirect.policy.x509.SubjectAttributeField)1 SubjectKeyIdentifierExtensionField (org.nhindirect.policy.x509.SubjectKeyIdentifierExtensionField)1 X509Field (org.nhindirect.policy.x509.X509Field)1