ctl_v3_auth_test.go 9.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342
  1. // Copyright 2016 The etcd Authors
  2. //
  3. // Licensed under the Apache License, Version 2.0 (the "License");
  4. // you may not use this file except in compliance with the License.
  5. // You may obtain a copy of the License at
  6. //
  7. // http://www.apache.org/licenses/LICENSE-2.0
  8. //
  9. // Unless required by applicable law or agreed to in writing, software
  10. // distributed under the License is distributed on an "AS IS" BASIS,
  11. // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  12. // See the License for the specific language governing permissions and
  13. // limitations under the License.
  14. package e2e
  15. import (
  16. "fmt"
  17. "testing"
  18. )
  19. func TestCtlV3AuthEnable(t *testing.T) { testCtl(t, authEnableTest) }
  20. func TestCtlV3AuthDisable(t *testing.T) { testCtl(t, authDisableTest) }
  21. func TestCtlV3AuthWriteKey(t *testing.T) { testCtl(t, authCredWriteKeyTest) }
  22. func TestCtlV3AuthRoleUpdate(t *testing.T) { testCtl(t, authRoleUpdateTest) }
  23. func TestCtlV3AuthUserDeleteDuringOps(t *testing.T) { testCtl(t, authUserDeleteDuringOpsTest) }
  24. func TestCtlV3AuthRoleRevokeDuringOps(t *testing.T) { testCtl(t, authRoleRevokeDuringOpsTest) }
  25. func authEnableTest(cx ctlCtx) {
  26. if err := authEnable(cx); err != nil {
  27. cx.t.Fatal(err)
  28. }
  29. }
  30. func authEnable(cx ctlCtx) error {
  31. // create root user with root role
  32. if err := ctlV3User(cx, []string{"add", "root", "--interactive=false"}, "User root created", []string{"root"}); err != nil {
  33. return fmt.Errorf("failed to create root user %v", err)
  34. }
  35. if err := ctlV3User(cx, []string{"grant-role", "root", "root"}, "Role root is granted to user root", nil); err != nil {
  36. return fmt.Errorf("failed to grant root user root role %v", err)
  37. }
  38. if err := ctlV3AuthEnable(cx); err != nil {
  39. return fmt.Errorf("authEnableTest ctlV3AuthEnable error (%v)", err)
  40. }
  41. return nil
  42. }
  43. func ctlV3AuthEnable(cx ctlCtx) error {
  44. cmdArgs := append(cx.PrefixArgs(), "auth", "enable")
  45. return spawnWithExpect(cmdArgs, "Authentication Enabled")
  46. }
  47. func authDisableTest(cx ctlCtx) {
  48. // a key that isn't granted to test-user
  49. if err := ctlV3Put(cx, "hoo", "a", ""); err != nil {
  50. cx.t.Fatal(err)
  51. }
  52. if err := authEnable(cx); err != nil {
  53. cx.t.Fatal(err)
  54. }
  55. cx.user, cx.pass = "root", "root"
  56. authSetupTestUser(cx)
  57. // test-user doesn't have the permission, it must fail
  58. cx.user, cx.pass = "test-user", "pass"
  59. if err := ctlV3PutFailPerm(cx, "hoo", "bar"); err != nil {
  60. cx.t.Fatal(err)
  61. }
  62. cx.user, cx.pass = "root", "root"
  63. if err := ctlV3AuthDisable(cx); err != nil {
  64. cx.t.Fatalf("authDisableTest ctlV3AuthDisable error (%v)", err)
  65. }
  66. // now auth fails unconditionally, note that failed RPC is Authenticate(), not Put()
  67. cx.user, cx.pass = "test-user", "pass"
  68. if err := ctlV3PutFailAuthDisabled(cx, "hoo", "bar"); err != nil {
  69. cx.t.Fatal(err)
  70. }
  71. // now the key can be accessed
  72. cx.user, cx.pass = "", ""
  73. if err := ctlV3Put(cx, "hoo", "bar", ""); err != nil {
  74. cx.t.Fatal(err)
  75. }
  76. // confirm put succeeded
  77. if err := ctlV3Get(cx, []string{"hoo"}, []kv{{"hoo", "bar"}}...); err != nil {
  78. cx.t.Fatal(err)
  79. }
  80. }
  81. func ctlV3AuthDisable(cx ctlCtx) error {
  82. cmdArgs := append(cx.PrefixArgs(), "auth", "disable")
  83. return spawnWithExpect(cmdArgs, "Authentication Disabled")
  84. }
  85. func authCredWriteKeyTest(cx ctlCtx) {
  86. // baseline key to check for failed puts
  87. if err := ctlV3Put(cx, "foo", "a", ""); err != nil {
  88. cx.t.Fatal(err)
  89. }
  90. if err := authEnable(cx); err != nil {
  91. cx.t.Fatal(err)
  92. }
  93. cx.user, cx.pass = "root", "root"
  94. authSetupTestUser(cx)
  95. // confirm root role doesn't grant access to all keys
  96. if err := ctlV3PutFailPerm(cx, "foo", "bar"); err != nil {
  97. cx.t.Fatal(err)
  98. }
  99. if err := ctlV3GetFailPerm(cx, "foo"); err != nil {
  100. cx.t.Fatal(err)
  101. }
  102. // try invalid user
  103. cx.user, cx.pass = "a", "b"
  104. if err := ctlV3PutFailAuth(cx, "foo", "bar"); err != nil {
  105. cx.t.Fatal(err)
  106. }
  107. // confirm put failed
  108. cx.user, cx.pass = "test-user", "pass"
  109. if err := ctlV3Get(cx, []string{"foo"}, []kv{{"foo", "a"}}...); err != nil {
  110. cx.t.Fatal(err)
  111. }
  112. // try good user
  113. cx.user, cx.pass = "test-user", "pass"
  114. if err := ctlV3Put(cx, "foo", "bar", ""); err != nil {
  115. cx.t.Fatal(err)
  116. }
  117. // confirm put succeeded
  118. if err := ctlV3Get(cx, []string{"foo"}, []kv{{"foo", "bar"}}...); err != nil {
  119. cx.t.Fatal(err)
  120. }
  121. // try bad password
  122. cx.user, cx.pass = "test-user", "badpass"
  123. if err := ctlV3PutFailAuth(cx, "foo", "baz"); err != nil {
  124. cx.t.Fatal(err)
  125. }
  126. // confirm put failed
  127. cx.user, cx.pass = "test-user", "pass"
  128. if err := ctlV3Get(cx, []string{"foo"}, []kv{{"foo", "bar"}}...); err != nil {
  129. cx.t.Fatal(err)
  130. }
  131. }
  132. func authRoleUpdateTest(cx ctlCtx) {
  133. if err := ctlV3Put(cx, "foo", "bar", ""); err != nil {
  134. cx.t.Fatal(err)
  135. }
  136. if err := authEnable(cx); err != nil {
  137. cx.t.Fatal(err)
  138. }
  139. cx.user, cx.pass = "root", "root"
  140. authSetupTestUser(cx)
  141. // try put to not granted key
  142. cx.user, cx.pass = "test-user", "pass"
  143. if err := ctlV3PutFailPerm(cx, "hoo", "bar"); err != nil {
  144. cx.t.Fatal(err)
  145. }
  146. // grant a new key
  147. cx.user, cx.pass = "root", "root"
  148. if err := ctlV3RoleGrantPermission(cx, "test-role", grantingPerm{true, true, "hoo", ""}); err != nil {
  149. cx.t.Fatal(err)
  150. }
  151. // try a newly granted key
  152. cx.user, cx.pass = "test-user", "pass"
  153. if err := ctlV3Put(cx, "hoo", "bar", ""); err != nil {
  154. cx.t.Fatal(err)
  155. }
  156. // confirm put succeeded
  157. if err := ctlV3Get(cx, []string{"hoo"}, []kv{{"hoo", "bar"}}...); err != nil {
  158. cx.t.Fatal(err)
  159. }
  160. // revoke the newly granted key
  161. cx.user, cx.pass = "root", "root"
  162. if err := ctlV3RoleRevokePermission(cx, "test-role", "hoo", ""); err != nil {
  163. cx.t.Fatal(err)
  164. }
  165. // try put to the revoked key
  166. cx.user, cx.pass = "test-user", "pass"
  167. if err := ctlV3PutFailPerm(cx, "hoo", "bar"); err != nil {
  168. cx.t.Fatal(err)
  169. }
  170. // confirm a key still granted can be accessed
  171. if err := ctlV3Get(cx, []string{"foo"}, []kv{{"foo", "bar"}}...); err != nil {
  172. cx.t.Fatal(err)
  173. }
  174. }
  175. func authUserDeleteDuringOpsTest(cx ctlCtx) {
  176. if err := ctlV3Put(cx, "foo", "bar", ""); err != nil {
  177. cx.t.Fatal(err)
  178. }
  179. if err := authEnable(cx); err != nil {
  180. cx.t.Fatal(err)
  181. }
  182. cx.user, cx.pass = "root", "root"
  183. authSetupTestUser(cx)
  184. // create a key
  185. cx.user, cx.pass = "test-user", "pass"
  186. if err := ctlV3Put(cx, "foo", "bar", ""); err != nil {
  187. cx.t.Fatal(err)
  188. }
  189. // confirm put succeeded
  190. if err := ctlV3Get(cx, []string{"foo"}, []kv{{"foo", "bar"}}...); err != nil {
  191. cx.t.Fatal(err)
  192. }
  193. // delete the user
  194. cx.user, cx.pass = "root", "root"
  195. err := ctlV3User(cx, []string{"delete", "test-user"}, "User test-user deleted", []string{})
  196. if err != nil {
  197. cx.t.Fatal(err)
  198. }
  199. // check the user is deleted
  200. cx.user, cx.pass = "test-user", "pass"
  201. if err := ctlV3PutFailAuth(cx, "foo", "baz"); err != nil {
  202. cx.t.Fatal(err)
  203. }
  204. }
  205. func authRoleRevokeDuringOpsTest(cx ctlCtx) {
  206. if err := ctlV3Put(cx, "foo", "bar", ""); err != nil {
  207. cx.t.Fatal(err)
  208. }
  209. if err := authEnable(cx); err != nil {
  210. cx.t.Fatal(err)
  211. }
  212. cx.user, cx.pass = "root", "root"
  213. authSetupTestUser(cx)
  214. // create a key
  215. cx.user, cx.pass = "test-user", "pass"
  216. if err := ctlV3Put(cx, "foo", "bar", ""); err != nil {
  217. cx.t.Fatal(err)
  218. }
  219. // confirm put succeeded
  220. if err := ctlV3Get(cx, []string{"foo"}, []kv{{"foo", "bar"}}...); err != nil {
  221. cx.t.Fatal(err)
  222. }
  223. // create a new role
  224. cx.user, cx.pass = "root", "root"
  225. if err := ctlV3Role(cx, []string{"add", "test-role2"}, "Role test-role2 created"); err != nil {
  226. cx.t.Fatal(err)
  227. }
  228. // grant a new key to the new role
  229. if err := ctlV3RoleGrantPermission(cx, "test-role2", grantingPerm{true, true, "hoo", ""}); err != nil {
  230. cx.t.Fatal(err)
  231. }
  232. // grant the new role to the user
  233. if err := ctlV3User(cx, []string{"grant-role", "test-user", "test-role2"}, "Role test-role2 is granted to user test-user", nil); err != nil {
  234. cx.t.Fatal(err)
  235. }
  236. // try a newly granted key
  237. cx.user, cx.pass = "test-user", "pass"
  238. if err := ctlV3Put(cx, "hoo", "bar", ""); err != nil {
  239. cx.t.Fatal(err)
  240. }
  241. // confirm put succeeded
  242. if err := ctlV3Get(cx, []string{"hoo"}, []kv{{"hoo", "bar"}}...); err != nil {
  243. cx.t.Fatal(err)
  244. }
  245. // revoke a role from the user
  246. cx.user, cx.pass = "root", "root"
  247. err := ctlV3User(cx, []string{"revoke-role", "test-user", "test-role"}, "Role test-role is revoked from user test-user", []string{})
  248. if err != nil {
  249. cx.t.Fatal(err)
  250. }
  251. // check the role is revoked and permission is lost from the user
  252. cx.user, cx.pass = "test-user", "pass"
  253. if err := ctlV3PutFailPerm(cx, "foo", "baz"); err != nil {
  254. cx.t.Fatal(err)
  255. }
  256. // try a key that can be accessed from the remaining role
  257. cx.user, cx.pass = "test-user", "pass"
  258. if err := ctlV3Put(cx, "hoo", "bar2", ""); err != nil {
  259. cx.t.Fatal(err)
  260. }
  261. // confirm put succeeded
  262. if err := ctlV3Get(cx, []string{"hoo"}, []kv{{"hoo", "bar2"}}...); err != nil {
  263. cx.t.Fatal(err)
  264. }
  265. }
  266. func ctlV3PutFailAuth(cx ctlCtx, key, val string) error {
  267. return spawnWithExpect(append(cx.PrefixArgs(), "put", key, val), "authentication failed")
  268. }
  269. func ctlV3PutFailPerm(cx ctlCtx, key, val string) error {
  270. return spawnWithExpect(append(cx.PrefixArgs(), "put", key, val), "permission denied")
  271. }
  272. func ctlV3PutFailAuthDisabled(cx ctlCtx, key, val string) error {
  273. return spawnWithExpect(append(cx.PrefixArgs(), "put", key, val), "authentication is not enabled")
  274. }
  275. func ctlV3GetFailPerm(cx ctlCtx, key string) error {
  276. return spawnWithExpect(append(cx.PrefixArgs(), "get", key), "permission denied")
  277. }
  278. func authSetupTestUser(cx ctlCtx) {
  279. if err := ctlV3User(cx, []string{"add", "test-user", "--interactive=false"}, "User test-user created", []string{"pass"}); err != nil {
  280. cx.t.Fatal(err)
  281. }
  282. if err := spawnWithExpect(append(cx.PrefixArgs(), "role", "add", "test-role"), "Role test-role created"); err != nil {
  283. cx.t.Fatal(err)
  284. }
  285. if err := ctlV3User(cx, []string{"grant-role", "test-user", "test-role"}, "Role test-role is granted to user test-user", nil); err != nil {
  286. cx.t.Fatal(err)
  287. }
  288. cmd := append(cx.PrefixArgs(), "role", "grant-permission", "test-role", "readwrite", "foo")
  289. if err := spawnWithExpect(cmd, "Role test-role updated"); err != nil {
  290. cx.t.Fatal(err)
  291. }
  292. }