store_test.go 4.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206
  1. // Copyright 2016 The etcd Authors
  2. //
  3. // Licensed under the Apache License, Version 2.0 (the "License");
  4. // you may not use this file except in compliance with the License.
  5. // You may obtain a copy of the License at
  6. //
  7. // http://www.apache.org/licenses/LICENSE-2.0
  8. //
  9. // Unless required by applicable law or agreed to in writing, software
  10. // distributed under the License is distributed on an "AS IS" BASIS,
  11. // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  12. // See the License for the specific language governing permissions and
  13. // limitations under the License.
  14. package auth
  15. import (
  16. "os"
  17. "testing"
  18. pb "github.com/coreos/etcd/etcdserver/etcdserverpb"
  19. "github.com/coreos/etcd/mvcc/backend"
  20. )
  21. func TestUserAdd(t *testing.T) {
  22. b, tPath := backend.NewDefaultTmpBackend()
  23. defer func() {
  24. b.Close()
  25. os.Remove(tPath)
  26. }()
  27. as := NewAuthStore(b)
  28. ua := &pb.AuthUserAddRequest{Name: "foo"}
  29. _, err := as.UserAdd(ua) // add a non-existing user
  30. if err != nil {
  31. t.Fatal(err)
  32. }
  33. _, err = as.UserAdd(ua) // add an existing user
  34. if err == nil {
  35. t.Fatalf("expected %v, got %v", ErrUserAlreadyExist, err)
  36. }
  37. if err != ErrUserAlreadyExist {
  38. t.Fatalf("expected %v, got %v", ErrUserAlreadyExist, err)
  39. }
  40. }
  41. func TestAuthenticate(t *testing.T) {
  42. b, tPath := backend.NewDefaultTmpBackend()
  43. defer func() {
  44. b.Close()
  45. os.Remove(tPath)
  46. }()
  47. as := NewAuthStore(b)
  48. ua := &pb.AuthUserAddRequest{Name: "foo", Password: "bar"}
  49. _, err := as.UserAdd(ua)
  50. if err != nil {
  51. t.Fatal(err)
  52. }
  53. // auth a non-existing user
  54. _, err = as.Authenticate("foo-test", "bar")
  55. if err == nil {
  56. t.Fatalf("expected %v, got %v", ErrAuthFailed, err)
  57. }
  58. if err != ErrAuthFailed {
  59. t.Fatalf("expected %v, got %v", ErrAuthFailed, err)
  60. }
  61. // auth an existing user with correct password
  62. _, err = as.Authenticate("foo", "bar")
  63. if err != nil {
  64. t.Fatal(err)
  65. }
  66. // auth an existing user but with wrong password
  67. _, err = as.Authenticate("foo", "")
  68. if err == nil {
  69. t.Fatalf("expected %v, got %v", ErrAuthFailed, err)
  70. }
  71. if err != ErrAuthFailed {
  72. t.Fatalf("expected %v, got %v", ErrAuthFailed, err)
  73. }
  74. }
  75. func TestUserDelete(t *testing.T) {
  76. b, tPath := backend.NewDefaultTmpBackend()
  77. defer func() {
  78. b.Close()
  79. os.Remove(tPath)
  80. }()
  81. as := NewAuthStore(b)
  82. ua := &pb.AuthUserAddRequest{Name: "foo"}
  83. _, err := as.UserAdd(ua)
  84. if err != nil {
  85. t.Fatal(err)
  86. }
  87. // delete an existing user
  88. ud := &pb.AuthUserDeleteRequest{Name: "foo"}
  89. _, err = as.UserDelete(ud)
  90. if err != nil {
  91. t.Fatal(err)
  92. }
  93. // delete a non-existing user
  94. _, err = as.UserDelete(ud)
  95. if err == nil {
  96. t.Fatalf("expected %v, got %v", ErrUserNotFound, err)
  97. }
  98. if err != ErrUserNotFound {
  99. t.Fatalf("expected %v, got %v", ErrUserNotFound, err)
  100. }
  101. }
  102. func TestUserChangePassword(t *testing.T) {
  103. b, tPath := backend.NewDefaultTmpBackend()
  104. defer func() {
  105. b.Close()
  106. os.Remove(tPath)
  107. }()
  108. as := NewAuthStore(b)
  109. _, err := as.UserAdd(&pb.AuthUserAddRequest{Name: "foo"})
  110. if err != nil {
  111. t.Fatal(err)
  112. }
  113. _, err = as.Authenticate("foo", "")
  114. if err != nil {
  115. t.Fatal(err)
  116. }
  117. _, err = as.UserChangePassword(&pb.AuthUserChangePasswordRequest{Name: "foo", Password: "bar"})
  118. if err != nil {
  119. t.Fatal(err)
  120. }
  121. _, err = as.Authenticate("foo", "bar")
  122. if err != nil {
  123. t.Fatal(err)
  124. }
  125. // change a non-existing user
  126. _, err = as.UserChangePassword(&pb.AuthUserChangePasswordRequest{Name: "foo-test", Password: "bar"})
  127. if err == nil {
  128. t.Fatalf("expected %v, got %v", ErrUserNotFound, err)
  129. }
  130. if err != ErrUserNotFound {
  131. t.Fatalf("expected %v, got %v", ErrUserNotFound, err)
  132. }
  133. }
  134. func TestRoleAdd(t *testing.T) {
  135. b, tPath := backend.NewDefaultTmpBackend()
  136. defer func() {
  137. b.Close()
  138. os.Remove(tPath)
  139. }()
  140. as := NewAuthStore(b)
  141. // adds a new role
  142. _, err := as.RoleAdd(&pb.AuthRoleAddRequest{Name: "role-test"})
  143. if err != nil {
  144. t.Fatal(err)
  145. }
  146. }
  147. func TestUserGrant(t *testing.T) {
  148. b, tPath := backend.NewDefaultTmpBackend()
  149. defer func() {
  150. b.Close()
  151. os.Remove(tPath)
  152. }()
  153. as := NewAuthStore(b)
  154. _, err := as.UserAdd(&pb.AuthUserAddRequest{Name: "foo"})
  155. if err != nil {
  156. t.Fatal(err)
  157. }
  158. // adds a new role
  159. _, err = as.RoleAdd(&pb.AuthRoleAddRequest{Name: "role-test"})
  160. if err != nil {
  161. t.Fatal(err)
  162. }
  163. // grants a role to the user
  164. _, err = as.UserGrant(&pb.AuthUserGrantRequest{User: "foo", Role: "role-test"})
  165. if err != nil {
  166. t.Fatal(err)
  167. }
  168. // grants a role to a non-existing user
  169. _, err = as.UserGrant(&pb.AuthUserGrantRequest{User: "foo-test", Role: "role-test"})
  170. if err == nil {
  171. t.Fatalf("expected %v, got %v", ErrUserNotFound, err)
  172. }
  173. if err != ErrUserNotFound {
  174. t.Fatalf("expected %v, got %v", ErrUserNotFound, err)
  175. }
  176. }