OrConditionEvalTest.java revision 6909255a1970175507277a0f2f105979625f76b2
fb63998ce7684bddab24e10c0b593809df1b7bffCraig McDonnell/**
fb63998ce7684bddab24e10c0b593809df1b7bffCraig McDonnell * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS HEADER.
fb63998ce7684bddab24e10c0b593809df1b7bffCraig McDonnell *
fb63998ce7684bddab24e10c0b593809df1b7bffCraig McDonnell * Copyright (c) 2009 Sun Microsystems Inc. All Rights Reserved
fb63998ce7684bddab24e10c0b593809df1b7bffCraig McDonnell *
fb63998ce7684bddab24e10c0b593809df1b7bffCraig McDonnell * The contents of this file are subject to the terms
fb63998ce7684bddab24e10c0b593809df1b7bffCraig McDonnell * of the Common Development and Distribution License
fb63998ce7684bddab24e10c0b593809df1b7bffCraig McDonnell * (the License). You may not use this file except in
fb63998ce7684bddab24e10c0b593809df1b7bffCraig McDonnell * compliance with the License.
fb63998ce7684bddab24e10c0b593809df1b7bffCraig McDonnell *
fb63998ce7684bddab24e10c0b593809df1b7bffCraig McDonnell * You can obtain a copy of the License at
fb63998ce7684bddab24e10c0b593809df1b7bffCraig McDonnell * https://opensso.dev.java.net/public/CDDLv1.0.html or
fb63998ce7684bddab24e10c0b593809df1b7bffCraig McDonnell * opensso/legal/CDDLv1.0.txt
fb63998ce7684bddab24e10c0b593809df1b7bffCraig McDonnell * See the License for the specific language governing
fb63998ce7684bddab24e10c0b593809df1b7bffCraig McDonnell * permission and limitations under the License.
fb63998ce7684bddab24e10c0b593809df1b7bffCraig McDonnell *
fb63998ce7684bddab24e10c0b593809df1b7bffCraig McDonnell * When distributing Covered Code, include this CDDL
fb63998ce7684bddab24e10c0b593809df1b7bffCraig McDonnell * Header Notice in each file and include the License file
fb63998ce7684bddab24e10c0b593809df1b7bffCraig McDonnell * at opensso/legal/CDDLv1.0.txt.
721bb987c406979bcfe705fa1ca8d54497d40fcbRobert Wapshott * If applicable, add the following below the CDDL Header,
721bb987c406979bcfe705fa1ca8d54497d40fcbRobert Wapshott * with the fields enclosed by brackets [] replaced by
fb63998ce7684bddab24e10c0b593809df1b7bffCraig McDonnell * your own identifying information:
415243fbc81341293a852ff6aa14e9608d08685cCraig McDonnell * "Portions Copyrighted [year] [name of copyright owner]"
415243fbc81341293a852ff6aa14e9608d08685cCraig McDonnell *
721bb987c406979bcfe705fa1ca8d54497d40fcbRobert Wapshott * $Id: OrConditionEvalTest.java,v 1.1 2009/09/05 00:24:03 veiming Exp $
6c1420dd55f69d09f39dd213ee6c97ba901b8d92Craig McDonnell *
6c1420dd55f69d09f39dd213ee6c97ba901b8d92Craig McDonnell * Portions Copyrighted 2014 ForgeRock AS
9ebd9a731316dfd624ce3bcc4ea6519d10899936Ken Stubbings */
9ebd9a731316dfd624ce3bcc4ea6519d10899936Ken Stubbings
721bb987c406979bcfe705fa1ca8d54497d40fcbRobert Wapshott/**
721bb987c406979bcfe705fa1ca8d54497d40fcbRobert Wapshott * Portions copyright 2014 ForgeRock AS.
721bb987c406979bcfe705fa1ca8d54497d40fcbRobert Wapshott */
fb63998ce7684bddab24e10c0b593809df1b7bffCraig McDonnell
fb63998ce7684bddab24e10c0b593809df1b7bffCraig McDonnellpackage com.sun.identity.entitlement;
fb63998ce7684bddab24e10c0b593809df1b7bffCraig McDonnell
6c1420dd55f69d09f39dd213ee6c97ba901b8d92Craig McDonnellimport com.iplanet.sso.SSOToken;
6c1420dd55f69d09f39dd213ee6c97ba901b8d92Craig McDonnellimport com.sun.identity.entitlement.opensso.SubjectUtils;
415243fbc81341293a852ff6aa14e9608d08685cCraig McDonnellimport com.sun.identity.security.AdminTokenAction;
fb63998ce7684bddab24e10c0b593809df1b7bffCraig McDonnellimport org.forgerock.openam.entitlement.conditions.environment.IPCondition;
fb63998ce7684bddab24e10c0b593809df1b7bffCraig McDonnellimport java.security.AccessController;
fb63998ce7684bddab24e10c0b593809df1b7bffCraig McDonnellimport java.util.HashMap;
6c1420dd55f69d09f39dd213ee6c97ba901b8d92Craig McDonnellimport java.util.HashSet;
6c1420dd55f69d09f39dd213ee6c97ba901b8d92Craig McDonnellimport java.util.List;
415243fbc81341293a852ff6aa14e9608d08685cCraig McDonnellimport java.util.Map;
fb63998ce7684bddab24e10c0b593809df1b7bffCraig McDonnellimport java.util.Set;
fb63998ce7684bddab24e10c0b593809df1b7bffCraig McDonnellimport javax.security.auth.Subject;
fb63998ce7684bddab24e10c0b593809df1b7bffCraig McDonnellimport org.testng.annotations.AfterClass;
6c1420dd55f69d09f39dd213ee6c97ba901b8d92Craig McDonnellimport org.testng.annotations.BeforeClass;
6c1420dd55f69d09f39dd213ee6c97ba901b8d92Craig McDonnellimport org.testng.annotations.Test;
415243fbc81341293a852ff6aa14e9608d08685cCraig McDonnell
415243fbc81341293a852ff6aa14e9608d08685cCraig McDonnellimport static org.forgerock.openam.entitlement.conditions.environment.ConditionConstants.REQUEST_IP;
415243fbc81341293a852ff6aa14e9608d08685cCraig McDonnell
415243fbc81341293a852ff6aa14e9608d08685cCraig McDonnellpublic class OrConditionEvalTest {
415243fbc81341293a852ff6aa14e9608d08685cCraig McDonnell private static final String PRIVILEGE_NAME = "OrConditionEvalTest";
415243fbc81341293a852ff6aa14e9608d08685cCraig McDonnell private static final String ROOT_RESOURCE_NAME =
415243fbc81341293a852ff6aa14e9608d08685cCraig McDonnell "http://www.OrConditionEvalTest.com";
721bb987c406979bcfe705fa1ca8d54497d40fcbRobert Wapshott private static final String START_IP = "100.100.100.100";
415243fbc81341293a852ff6aa14e9608d08685cCraig McDonnell private static final String END_IP = "200.200.200.200";
721bb987c406979bcfe705fa1ca8d54497d40fcbRobert Wapshott private static final String DNS_MASK = "*.OrConditionEvalTest.com";
721bb987c406979bcfe705fa1ca8d54497d40fcbRobert Wapshott
721bb987c406979bcfe705fa1ca8d54497d40fcbRobert Wapshott private SSOToken adminToken = (SSOToken) AccessController.doPrivileged(
721bb987c406979bcfe705fa1ca8d54497d40fcbRobert Wapshott AdminTokenAction.getInstance());
415243fbc81341293a852ff6aa14e9608d08685cCraig McDonnell private Subject adminSubject = SubjectUtils.createSubject(adminToken);
415243fbc81341293a852ff6aa14e9608d08685cCraig McDonnell private boolean migrated = EntitlementConfiguration.getInstance(
415243fbc81341293a852ff6aa14e9608d08685cCraig McDonnell adminSubject, "/").migratedToEntitlementService();
415243fbc81341293a852ff6aa14e9608d08685cCraig McDonnell
415243fbc81341293a852ff6aa14e9608d08685cCraig McDonnell @BeforeClass
721bb987c406979bcfe705fa1ca8d54497d40fcbRobert Wapshott public void setup() throws Exception {
415243fbc81341293a852ff6aa14e9608d08685cCraig McDonnell if (migrated) {
721bb987c406979bcfe705fa1ca8d54497d40fcbRobert Wapshott Map<String, Boolean> actions = new HashMap<String, Boolean>();
415243fbc81341293a852ff6aa14e9608d08685cCraig McDonnell actions.put("GET", Boolean.TRUE);
6c1420dd55f69d09f39dd213ee6c97ba901b8d92Craig McDonnell Entitlement ent = new Entitlement(
91f0e3cb60de3eba8cbb70c7e36cc0df22d71f5bRobert Wapshott ApplicationTypeManager.URL_APPLICATION_TYPE_NAME,
91f0e3cb60de3eba8cbb70c7e36cc0df22d71f5bRobert Wapshott ROOT_RESOURCE_NAME + "/*", actions);
91f0e3cb60de3eba8cbb70c7e36cc0df22d71f5bRobert Wapshott OrCondition cond = new OrCondition();
9ebd9a731316dfd624ce3bcc4ea6519d10899936Ken Stubbings Set<EntitlementCondition> conditions = new
9ebd9a731316dfd624ce3bcc4ea6519d10899936Ken Stubbings HashSet<EntitlementCondition>();
415243fbc81341293a852ff6aa14e9608d08685cCraig McDonnell IPCondition ipc = new IPCondition();
415243fbc81341293a852ff6aa14e9608d08685cCraig McDonnell ipc.setStartIp(START_IP);
415243fbc81341293a852ff6aa14e9608d08685cCraig McDonnell ipc.setEndIp(END_IP);
415243fbc81341293a852ff6aa14e9608d08685cCraig McDonnell conditions.add(ipc);
9ebd9a731316dfd624ce3bcc4ea6519d10899936Ken Stubbings cond.setEConditions(conditions);
9ebd9a731316dfd624ce3bcc4ea6519d10899936Ken Stubbings
9ebd9a731316dfd624ce3bcc4ea6519d10899936Ken Stubbings Privilege privilege = Privilege.getNewInstance();
9ebd9a731316dfd624ce3bcc4ea6519d10899936Ken Stubbings privilege.setName(PRIVILEGE_NAME);
9ebd9a731316dfd624ce3bcc4ea6519d10899936Ken Stubbings privilege.setEntitlement(ent);
9ebd9a731316dfd624ce3bcc4ea6519d10899936Ken Stubbings privilege.setSubject(new AnyUserSubject());
9ebd9a731316dfd624ce3bcc4ea6519d10899936Ken Stubbings privilege.setCondition(cond);
9ebd9a731316dfd624ce3bcc4ea6519d10899936Ken Stubbings
9ebd9a731316dfd624ce3bcc4ea6519d10899936Ken Stubbings PrivilegeManager pm = PrivilegeManager.getInstance("/",
9ebd9a731316dfd624ce3bcc4ea6519d10899936Ken Stubbings adminSubject);
9ebd9a731316dfd624ce3bcc4ea6519d10899936Ken Stubbings pm.add(privilege);
9ebd9a731316dfd624ce3bcc4ea6519d10899936Ken Stubbings Thread.sleep(1000);
9ebd9a731316dfd624ce3bcc4ea6519d10899936Ken Stubbings }
9ebd9a731316dfd624ce3bcc4ea6519d10899936Ken Stubbings }
9ebd9a731316dfd624ce3bcc4ea6519d10899936Ken Stubbings
9ebd9a731316dfd624ce3bcc4ea6519d10899936Ken Stubbings @AfterClass
9ebd9a731316dfd624ce3bcc4ea6519d10899936Ken Stubbings public void clean() throws EntitlementException {
9ebd9a731316dfd624ce3bcc4ea6519d10899936Ken Stubbings if (migrated) {
9ebd9a731316dfd624ce3bcc4ea6519d10899936Ken Stubbings PrivilegeManager pm = PrivilegeManager.getInstance("/",
9ebd9a731316dfd624ce3bcc4ea6519d10899936Ken Stubbings adminSubject);
9ebd9a731316dfd624ce3bcc4ea6519d10899936Ken Stubbings pm.remove(PRIVILEGE_NAME);
9ebd9a731316dfd624ce3bcc4ea6519d10899936Ken Stubbings }
9ebd9a731316dfd624ce3bcc4ea6519d10899936Ken Stubbings }
fb63998ce7684bddab24e10c0b593809df1b7bffCraig McDonnell
fb63998ce7684bddab24e10c0b593809df1b7bffCraig McDonnell @Test
fb63998ce7684bddab24e10c0b593809df1b7bffCraig McDonnell public void positiveTest() throws Exception {
6c1420dd55f69d09f39dd213ee6c97ba901b8d92Craig McDonnell Map<String, Set<String>> environment = getEnvironment(
6c1420dd55f69d09f39dd213ee6c97ba901b8d92Craig McDonnell "100.100.100.200", "www.OrConditionEvalTest.com");
6c1420dd55f69d09f39dd213ee6c97ba901b8d92Craig McDonnell
6c1420dd55f69d09f39dd213ee6c97ba901b8d92Craig McDonnell Evaluator evaluator = new Evaluator(adminSubject,
6c1420dd55f69d09f39dd213ee6c97ba901b8d92Craig McDonnell ApplicationTypeManager.URL_APPLICATION_TYPE_NAME);
fb63998ce7684bddab24e10c0b593809df1b7bffCraig McDonnell List<Entitlement> entitlements = evaluator.evaluate("/", adminSubject,
fb63998ce7684bddab24e10c0b593809df1b7bffCraig McDonnell ROOT_RESOURCE_NAME + "/index.html", environment, false);
fb63998ce7684bddab24e10c0b593809df1b7bffCraig McDonnell
fb63998ce7684bddab24e10c0b593809df1b7bffCraig McDonnell if ((entitlements == null) || entitlements.isEmpty()) {
6c1420dd55f69d09f39dd213ee6c97ba901b8d92Craig McDonnell throw new Exception(
6c1420dd55f69d09f39dd213ee6c97ba901b8d92Craig McDonnell "OrConditionEvalTest.positiveTest: no entitlements returned");
415243fbc81341293a852ff6aa14e9608d08685cCraig McDonnell }
6c1420dd55f69d09f39dd213ee6c97ba901b8d92Craig McDonnell
415243fbc81341293a852ff6aa14e9608d08685cCraig McDonnell Entitlement ent = entitlements.get(0);
6c1420dd55f69d09f39dd213ee6c97ba901b8d92Craig McDonnell Boolean result = ent.getActionValue("GET");
6c1420dd55f69d09f39dd213ee6c97ba901b8d92Craig McDonnell
6c1420dd55f69d09f39dd213ee6c97ba901b8d92Craig McDonnell if ((result == null) || !result) {
6c1420dd55f69d09f39dd213ee6c97ba901b8d92Craig McDonnell throw new Exception(
6c1420dd55f69d09f39dd213ee6c97ba901b8d92Craig McDonnell "OrConditionEvalTest.positiveTest: incorrect decision");
6c1420dd55f69d09f39dd213ee6c97ba901b8d92Craig McDonnell }
6c1420dd55f69d09f39dd213ee6c97ba901b8d92Craig McDonnell
9ebd9a731316dfd624ce3bcc4ea6519d10899936Ken Stubbings Map<String, Set<String>> advice = ent.getAdvices();
6c1420dd55f69d09f39dd213ee6c97ba901b8d92Craig McDonnell if ((advice != null) && !advice.isEmpty()) {
6c1420dd55f69d09f39dd213ee6c97ba901b8d92Craig McDonnell throw new Exception(
6c1420dd55f69d09f39dd213ee6c97ba901b8d92Craig McDonnell "OrConditionEvalTest.positiveTest: do not expect advices.");
b3a21de0a0e0a5dea71bece7e5c0356700136fbcDiego Colantoni }
b3a21de0a0e0a5dea71bece7e5c0356700136fbcDiego Colantoni }
b3a21de0a0e0a5dea71bece7e5c0356700136fbcDiego Colantoni
b3a21de0a0e0a5dea71bece7e5c0356700136fbcDiego Colantoni @Test
b3a21de0a0e0a5dea71bece7e5c0356700136fbcDiego Colantoni public void negativeTest() throws Exception {
6c1420dd55f69d09f39dd213ee6c97ba901b8d92Craig McDonnell Map<String, Set<String>> environment = getEnvironment(
721bb987c406979bcfe705fa1ca8d54497d40fcbRobert Wapshott "210.100.100.200", "www.OrConditionEvalTest1.com");
721bb987c406979bcfe705fa1ca8d54497d40fcbRobert Wapshott
721bb987c406979bcfe705fa1ca8d54497d40fcbRobert Wapshott Evaluator evaluator = new Evaluator(adminSubject,
721bb987c406979bcfe705fa1ca8d54497d40fcbRobert Wapshott ApplicationTypeManager.URL_APPLICATION_TYPE_NAME);
721bb987c406979bcfe705fa1ca8d54497d40fcbRobert Wapshott List<Entitlement> entitlements = evaluator.evaluate("/", adminSubject,
721bb987c406979bcfe705fa1ca8d54497d40fcbRobert Wapshott ROOT_RESOURCE_NAME + "/index.html", environment, false);
721bb987c406979bcfe705fa1ca8d54497d40fcbRobert Wapshott
721bb987c406979bcfe705fa1ca8d54497d40fcbRobert Wapshott if ((entitlements == null) || entitlements.isEmpty()) {
721bb987c406979bcfe705fa1ca8d54497d40fcbRobert Wapshott throw new Exception(
721bb987c406979bcfe705fa1ca8d54497d40fcbRobert Wapshott "OrConditionEvalTest.negativeTest: no entitlements returned");
fb63998ce7684bddab24e10c0b593809df1b7bffCraig McDonnell }
Entitlement ent = entitlements.get(0);
Boolean result = ent.getActionValue("GET");
if ((result != null) && result) {
throw new Exception(
"OrConditionEvalTest.negativeTest: incorrect decision");
}
Map<String, Set<String>> advices = ent.getAdvices();
if ((advices == null) || advices.isEmpty()) {
throw new Exception(
"OrConditionEvalTest.negativeTest: no advices.");
}
Set<String> ipAdvice = advices.get(IPCondition.class.getName());
if ((ipAdvice == null) || ipAdvice.isEmpty()) {
throw new Exception(
"OrConditionEvalTest.negativeTest: no advice for IPCondition.");
}
String adv = ipAdvice.iterator().next();
if (!adv.equals(REQUEST_IP + "=" + START_IP + "-" + END_IP)
) {
throw new Exception(
"OrConditionEvalTest.negativeTest: incorrect decision for IPCondition");
}
}
private Map<String, Set<String>> getEnvironment(String ipAddr, String dns) {
Map<String, Set<String>> environment =
new HashMap<String, Set<String>>();
Set<String> dnsMask = new HashSet<String>();
dnsMask.add(dns);
environment.put("requestDnsName", dnsMask);
Set<String> ip = new HashSet<String>();
ip.add(ipAddr);
environment.put(REQUEST_IP, ip);
return environment;
}
}