|
18 | 18 |
|
19 | 19 | import static io.cdap.cdap.common.http.HttpHeaderNames.TASK_WORKER_DECRYPTION_HDR; |
20 | 20 |
|
21 | | -import io.cdap.cdap.common.conf.CConfiguration; |
22 | 21 | import io.cdap.http.internal.HandlerInfo; |
23 | 22 | import io.netty.handler.codec.http.DefaultHttpRequest; |
24 | 23 | import io.netty.handler.codec.http.HttpMethod; |
25 | 24 | import io.netty.handler.codec.http.HttpRequest; |
26 | 25 | import io.netty.handler.codec.http.HttpVersion; |
| 26 | +import java.util.Arrays; |
| 27 | +import java.util.Collection; |
27 | 28 | import org.junit.Assert; |
| 29 | +import org.junit.Before; |
28 | 30 | import org.junit.Test; |
| 31 | +import org.junit.runner.RunWith; |
| 32 | +import org.junit.runners.Parameterized; |
| 33 | +import org.junit.runners.Parameterized.Parameters; |
29 | 34 |
|
| 35 | +/** |
| 36 | + * Tests for {@link EncryptionExemptionHook}. |
| 37 | + */ |
| 38 | +@RunWith(Parameterized.class) |
30 | 39 | public class EncryptionExemptionHookTest { |
31 | | - private static final String TESTSERVICENAME = "test.Service"; |
32 | | - private static final String TESTHANDLERNAME = "test.handler"; |
33 | | - private static final String TESTMETHODNAME = "testMethod"; |
34 | 40 |
|
35 | | - @Test |
36 | | - public void testPatternMatchingSuccessful() { |
37 | | - HttpRequest request = new DefaultHttpRequest(HttpVersion.HTTP_1_1, HttpMethod.GET, |
38 | | - "/v3/namespaces/default/securekeys/personal-token"); |
39 | | - HandlerInfo handlerInfo = new HandlerInfo(TESTHANDLERNAME, TESTMETHODNAME); |
40 | | - EncryptionExemptionHook hook = new EncryptionExemptionHook(CConfiguration.create(), TESTSERVICENAME); |
| 41 | + private HandlerInfo handlerInfo; |
| 42 | + private EncryptionExemptionHook hook; |
41 | 43 |
|
42 | | - hook.preCall(request, null, handlerInfo); |
| 44 | + // Parameters for the test |
| 45 | + private final String uri; |
| 46 | + private final boolean expectedDecryptionHeader; |
| 47 | + private final String testName; |
43 | 48 |
|
44 | | - Assert.assertFalse(Boolean.parseBoolean(request.headers().get(TASK_WORKER_DECRYPTION_HDR))); |
| 49 | + public EncryptionExemptionHookTest(String uri, boolean expectedDecryptionHeader, |
| 50 | + String testName) { |
| 51 | + this.uri = uri; |
| 52 | + this.expectedDecryptionHeader = expectedDecryptionHeader; |
| 53 | + this.testName = testName; |
45 | 54 | } |
46 | 55 |
|
47 | | - @Test |
48 | | - public void testPatternMatchingCredentialsUriWithQueryParamsSuccessful() { |
49 | | - HttpRequest request = new DefaultHttpRequest(HttpVersion.HTTP_1_1, HttpMethod.GET, |
50 | | - "/v3Internal/namespaces/default/credentials/workloadIdentity/" |
51 | | - + "provision?scopes=https://www.test.com/auth/test-platform"); |
52 | | - HandlerInfo handlerInfo = new HandlerInfo(TESTHANDLERNAME, TESTMETHODNAME); |
53 | | - EncryptionExemptionHook hook = new EncryptionExemptionHook(CConfiguration.create(), TESTSERVICENAME); |
54 | | - |
55 | | - hook.preCall(request, null, handlerInfo); |
| 56 | + // Define the data set for the tests |
| 57 | + @Parameters(name = "{2}") |
| 58 | + public static Collection<Object[]> data() { |
| 59 | + return Arrays.asList(new Object[][]{ |
| 60 | + // Successful (Exempt) Tests - Header should be FALSE. |
| 61 | + {"/v3/namespaces/default/securekeys/personal-token", false, "SecureKeysExempt"}, |
| 62 | + {"/v3Internal/namespaces/default/credentials/workloadIdentity/provision" |
| 63 | + + "?scopes=https://www.test.com/auth/test-platform", |
| 64 | + false, "CredentialsWithQueryParamsExempt"}, |
| 65 | + {"/v3Internal/namespaces/default/credentials/workloadIdentity/provision", false, |
| 66 | + "CredentialsWithoutQueryParamsExempt"}, |
| 67 | + {"/v3/namespaces/system/apps/pipeline/services/studio/methods" |
| 68 | + + "/v1/contexts/default/connections/testing", |
| 69 | + false, "ConnectionValidationExempt"}, |
| 70 | + {"/v3/namespaces/system/apps/pipeline/services/studio/methods" |
| 71 | + + "/v1/oauth/provider/provider/credential/REUSE_PROV_FALSE", |
| 72 | + false, "OAuthMacroEvaluatorExempt"}, |
| 73 | + // Unsuccessful (Non-Exempt) Test - Header should be TRUE. |
| 74 | + {"testing", true, "NonExempt"}}); |
| 75 | + } |
56 | 76 |
|
57 | | - Assert.assertFalse(Boolean.parseBoolean(request.headers().get(TASK_WORKER_DECRYPTION_HDR))); |
| 77 | + @Before |
| 78 | + public void setup() { |
| 79 | + handlerInfo = new HandlerInfo("test.handler", "testMethod"); |
| 80 | + hook = new EncryptionExemptionHook(); |
58 | 81 | } |
59 | 82 |
|
60 | 83 | @Test |
61 | | - public void testPatternMatchingCredentialsUriWithoutQueryParamsSuccessful() { |
62 | | - HttpRequest request = new DefaultHttpRequest(HttpVersion.HTTP_1_1, HttpMethod.GET, |
63 | | - "/v3Internal/namespaces/default/credentials/workloadIdentity/provision"); |
64 | | - HandlerInfo handlerInfo = new HandlerInfo(TESTHANDLERNAME, TESTMETHODNAME); |
65 | | - EncryptionExemptionHook hook = new EncryptionExemptionHook(CConfiguration.create(), TESTSERVICENAME); |
| 84 | + public void testPreCall() { |
| 85 | + HttpRequest request = new DefaultHttpRequest(HttpVersion.HTTP_1_1, HttpMethod.GET, this.uri); |
66 | 86 |
|
67 | 87 | hook.preCall(request, null, handlerInfo); |
68 | 88 |
|
69 | | - Assert.assertFalse(Boolean.parseBoolean(request.headers().get(TASK_WORKER_DECRYPTION_HDR))); |
70 | | - } |
71 | | - |
72 | | - @Test |
73 | | - public void testPatternMatchingUnsuccessful() { |
74 | | - HttpRequest request = new DefaultHttpRequest(HttpVersion.HTTP_1_1, HttpMethod.GET, "testingUri"); |
75 | | - HandlerInfo handlerInfo = new HandlerInfo(TESTHANDLERNAME, TESTMETHODNAME); |
76 | | - EncryptionExemptionHook hook = new EncryptionExemptionHook(CConfiguration.create(), TESTSERVICENAME); |
| 89 | + String message = String.format("Test case '%s' failed for URI: %s. Expected header value: %s.", |
| 90 | + this.testName, this.uri, this.expectedDecryptionHeader); |
77 | 91 |
|
78 | | - hook.preCall(request, null, handlerInfo); |
| 92 | + Assert.assertEquals(message, this.expectedDecryptionHeader, isDecryptionHeaderSet(request)); |
| 93 | + } |
79 | 94 |
|
80 | | - Assert.assertTrue(Boolean.parseBoolean(request.headers().get(TASK_WORKER_DECRYPTION_HDR))); |
| 95 | + private boolean isDecryptionHeaderSet(HttpRequest request) { |
| 96 | + String headerValue = request.headers().get(TASK_WORKER_DECRYPTION_HDR); |
| 97 | + return Boolean.parseBoolean(headerValue); |
81 | 98 | } |
82 | 99 | } |
0 commit comments