869a36e2649ae064c98063cf1e55198488d78d12Allan Foster * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS HEADER.
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster * Copyright (c) 2009 Sun Microsystems Inc. All Rights Reserved
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster * The contents of this file are subject to the terms
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster * of the Common Development and Distribution License
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster * (the License). You may not use this file except in
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster * compliance with the License.
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster * You can obtain a copy of the License at
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster * https://opensso.dev.java.net/public/CDDLv1.0.html or
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster * See the License for the specific language governing
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster * permission and limitations under the License.
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster * When distributing Covered Code, include this CDDL
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster * Header Notice in each file and include the License file
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster * If applicable, add the following below the CDDL Header,
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster * with the fields enclosed by brackets [] replaced by
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster * your own identifying information:
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster * "Portions Copyrighted [year] [name of copyright owner]"
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster * $Id: DelegationIsAllowedSubResourceTest.java,v 1.3 2009/12/22 18:00:24 veiming Exp $
a4544a5a0e622ef69e38641f87ab1b5685e05911Phill Cunnington * Portions Copyrighted 2014-2015 ForgeRock AS.
ba07e74da87b2caf40d3397e50523632daeb4cacAndrew Forrestimport com.sun.identity.delegation.DelegationEvaluator;
abd4d5547d40141d956adbbd8ac2e0efd5f025e1Andrew Forrestimport com.sun.identity.delegation.DelegationEvaluatorImpl;
869a36e2649ae064c98063cf1e55198488d78d12Allan Fosterimport com.sun.identity.delegation.DelegationPermission;
869a36e2649ae064c98063cf1e55198488d78d12Allan Fosterimport com.sun.identity.entitlement.opensso.OpenSSOUserSubject;
869a36e2649ae064c98063cf1e55198488d78d12Allan Fosterimport com.sun.identity.entitlement.opensso.SubjectUtils;
869a36e2649ae064c98063cf1e55198488d78d12Allan Fosterimport com.sun.identity.entitlement.util.AuthUtils;
869a36e2649ae064c98063cf1e55198488d78d12Allan Fosterimport com.sun.identity.entitlement.util.IdRepoUtils;
869a36e2649ae064c98063cf1e55198488d78d12Allan Fosterimport com.sun.identity.security.AdminTokenAction;
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster * @author dennis
869a36e2649ae064c98063cf1e55198488d78d12Allan Fosterpublic class DelegationIsAllowedSubResourceTest {
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster "DelegationIsAllowedSubResourceTest";
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster "DelegationIsAllowedSubResourceTestUser1";
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster "DelegationIsAllowedSubResourceTestPrivilege";
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster private static final String PRIVILEGE_NAME1 = PRIVILEGE_NAME + "1";
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster private static final String DELEGATE_PRIVILEGE_NAME =
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster "DelegationIsAllowedSubResourceTestDelegationPrivilege";
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster private static final String DELEGATED_RESOURCE_BASE =
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster "http://www.www.delegationisallowedsubresourcetest.com.com";
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster private static final String DELEGATED_RESOURCE = DELEGATED_RESOURCE_BASE +
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster private SSOToken adminToken = (SSOToken) AccessController.doPrivileged(
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster private Subject adminSubject = SubjectUtils.createSubject(adminToken);
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster private boolean migrated = EntitlementConfiguration.getInstance(
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster adminSubject, "/").migratedToEntitlementService();
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster ApplicationTypeManager.getAppplicationType(adminSubject,
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster ApplicationTypeManager.URL_APPLICATION_TYPE_NAME));
74dca04245920444925c2544c591c3da5dad607eAndrew Forrest // Test disabled, unable to fix model change
74dca04245920444925c2544c591c3da5dad607eAndrew Forrest // Set<String> appResources = new HashSet<String>();
74dca04245920444925c2544c591c3da5dad607eAndrew Forrest // appResources.add(DELEGATED_RESOURCE_BASE);
74dca04245920444925c2544c591c3da5dad607eAndrew Forrest // appl.addResources(appResources);
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster appl.setEntitlementCombiner(DenyOverride.class);
ba3008548cd047b233fcd32bb3c5d69926eed22fAndrew Forrest ApplicationManager.saveApplication(adminSubject, "/", appl);
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster PrivilegeManager pm = PrivilegeManager.getInstance("/", adminSubject);
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster ApplicationPrivilegeManager.getInstance("/", adminSubject);
ba3008548cd047b233fcd32bb3c5d69926eed22fAndrew Forrest ApplicationManager.deleteApplication(adminSubject, "/",
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster private void createPrivilege() throws EntitlementException {
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster PrivilegeManager pm = PrivilegeManager.getInstance("/", adminSubject);
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster Map<String, Boolean> actionValues = new HashMap<String, Boolean>();
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster Entitlement entitlement = new Entitlement(APPL_NAME,
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster OpenSSOUserSubject subject = new OpenSSOUserSubject(
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster "id=isallowedtestdummy,ou=user," + SMSEntry.getRootSuffix());
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster Privilege privilege1 = Privilege.getNewInstance();
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster throws SMSException, EntitlementException, SSOException,
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster ApplicationPrivilege ap = new ApplicationPrivilege(
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster OpenSSOUserSubject sbj = new OpenSSOUserSubject();
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster Set<SubjectImplementation> subjects = new HashSet<SubjectImplementation>();
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster Map<String, Set<String>> appRes = new HashMap<String, Set<String>>();
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster ap.setActionValues(ApplicationPrivilege.PossibleAction.READ);
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster ApplicationPrivilegeManager.getInstance("/", adminSubject);
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster SSOToken token = AuthUtils.authenticate("/", USER1, USER1);
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster DelegationPermission dp = new DelegationPermission("/",
ba07e74da87b2caf40d3397e50523632daeb4cacAndrew Forrest DelegationEvaluator de = new DelegationEvaluatorImpl();
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster if (!de.isAllowed(token, dp, Collections.EMPTY_MAP, true)) {
869a36e2649ae064c98063cf1e55198488d78d12Allan Foster "DelegationIsAllowedSubResourceTest.test: failed");