store_test.go 8.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360
  1. // Copyright 2016 The etcd Authors
  2. //
  3. // Licensed under the Apache License, Version 2.0 (the "License");
  4. // you may not use this file except in compliance with the License.
  5. // You may obtain a copy of the License at
  6. //
  7. // http://www.apache.org/licenses/LICENSE-2.0
  8. //
  9. // Unless required by applicable law or agreed to in writing, software
  10. // distributed under the License is distributed on an "AS IS" BASIS,
  11. // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  12. // See the License for the specific language governing permissions and
  13. // limitations under the License.
  14. package auth
  15. import (
  16. "os"
  17. "testing"
  18. pb "github.com/coreos/etcd/etcdserver/etcdserverpb"
  19. "github.com/coreos/etcd/mvcc/backend"
  20. "golang.org/x/crypto/bcrypt"
  21. "golang.org/x/net/context"
  22. )
  23. func init() { BcryptCost = bcrypt.MinCost }
  24. func dummyIndexWaiter(index uint64) <-chan struct{} {
  25. ch := make(chan struct{})
  26. go func() {
  27. ch <- struct{}{}
  28. }()
  29. return ch
  30. }
  31. // TestNewAuthStoreRevision ensures newly auth store
  32. // keeps the old revision when there are no changes.
  33. func TestNewAuthStoreRevision(t *testing.T) {
  34. b, tPath := backend.NewDefaultTmpBackend()
  35. defer os.Remove(tPath)
  36. as := NewAuthStore(b, dummyIndexWaiter)
  37. err := enableAuthAndCreateRoot(as)
  38. if err != nil {
  39. t.Fatal(err)
  40. }
  41. old := as.Revision()
  42. b.Close()
  43. as.Close()
  44. // no changes to commit
  45. b2 := backend.NewDefaultBackend(tPath)
  46. as = NewAuthStore(b2, dummyIndexWaiter)
  47. new := as.Revision()
  48. b2.Close()
  49. as.Close()
  50. if old != new {
  51. t.Fatalf("expected revision %d, got %d", old, new)
  52. }
  53. }
  54. func enableAuthAndCreateRoot(as *authStore) error {
  55. _, err := as.UserAdd(&pb.AuthUserAddRequest{Name: "root", Password: "root"})
  56. if err != nil {
  57. return err
  58. }
  59. _, err = as.RoleAdd(&pb.AuthRoleAddRequest{Name: "root"})
  60. if err != nil {
  61. return err
  62. }
  63. _, err = as.UserGrantRole(&pb.AuthUserGrantRoleRequest{User: "root", Role: "root"})
  64. if err != nil {
  65. return err
  66. }
  67. return as.AuthEnable()
  68. }
  69. func TestCheckPassword(t *testing.T) {
  70. b, tPath := backend.NewDefaultTmpBackend()
  71. defer func() {
  72. b.Close()
  73. os.Remove(tPath)
  74. }()
  75. as := NewAuthStore(b, dummyIndexWaiter)
  76. defer as.Close()
  77. err := enableAuthAndCreateRoot(as)
  78. if err != nil {
  79. t.Fatal(err)
  80. }
  81. ua := &pb.AuthUserAddRequest{Name: "foo", Password: "bar"}
  82. _, err = as.UserAdd(ua)
  83. if err != nil {
  84. t.Fatal(err)
  85. }
  86. // auth a non-existing user
  87. _, err = as.CheckPassword("foo-test", "bar")
  88. if err == nil {
  89. t.Fatalf("expected %v, got %v", ErrAuthFailed, err)
  90. }
  91. if err != ErrAuthFailed {
  92. t.Fatalf("expected %v, got %v", ErrAuthFailed, err)
  93. }
  94. // auth an existing user with correct password
  95. _, err = as.CheckPassword("foo", "bar")
  96. if err != nil {
  97. t.Fatal(err)
  98. }
  99. // auth an existing user but with wrong password
  100. _, err = as.CheckPassword("foo", "")
  101. if err == nil {
  102. t.Fatalf("expected %v, got %v", ErrAuthFailed, err)
  103. }
  104. if err != ErrAuthFailed {
  105. t.Fatalf("expected %v, got %v", ErrAuthFailed, err)
  106. }
  107. }
  108. func TestUserDelete(t *testing.T) {
  109. b, tPath := backend.NewDefaultTmpBackend()
  110. defer func() {
  111. b.Close()
  112. os.Remove(tPath)
  113. }()
  114. as := NewAuthStore(b, dummyIndexWaiter)
  115. defer as.Close()
  116. err := enableAuthAndCreateRoot(as)
  117. if err != nil {
  118. t.Fatal(err)
  119. }
  120. ua := &pb.AuthUserAddRequest{Name: "foo"}
  121. _, err = as.UserAdd(ua)
  122. if err != nil {
  123. t.Fatal(err)
  124. }
  125. // delete an existing user
  126. ud := &pb.AuthUserDeleteRequest{Name: "foo"}
  127. _, err = as.UserDelete(ud)
  128. if err != nil {
  129. t.Fatal(err)
  130. }
  131. // delete a non-existing user
  132. _, err = as.UserDelete(ud)
  133. if err == nil {
  134. t.Fatalf("expected %v, got %v", ErrUserNotFound, err)
  135. }
  136. if err != ErrUserNotFound {
  137. t.Fatalf("expected %v, got %v", ErrUserNotFound, err)
  138. }
  139. }
  140. func TestUserChangePassword(t *testing.T) {
  141. b, tPath := backend.NewDefaultTmpBackend()
  142. defer func() {
  143. b.Close()
  144. os.Remove(tPath)
  145. }()
  146. as := NewAuthStore(b, dummyIndexWaiter)
  147. defer as.Close()
  148. err := enableAuthAndCreateRoot(as)
  149. if err != nil {
  150. t.Fatal(err)
  151. }
  152. _, err = as.UserAdd(&pb.AuthUserAddRequest{Name: "foo"})
  153. if err != nil {
  154. t.Fatal(err)
  155. }
  156. ctx1 := context.WithValue(context.WithValue(context.TODO(), "index", uint64(1)), "simpleToken", "dummy")
  157. _, err = as.Authenticate(ctx1, "foo", "")
  158. if err != nil {
  159. t.Fatal(err)
  160. }
  161. _, err = as.UserChangePassword(&pb.AuthUserChangePasswordRequest{Name: "foo", Password: "bar"})
  162. if err != nil {
  163. t.Fatal(err)
  164. }
  165. ctx2 := context.WithValue(context.WithValue(context.TODO(), "index", uint64(2)), "simpleToken", "dummy")
  166. _, err = as.Authenticate(ctx2, "foo", "bar")
  167. if err != nil {
  168. t.Fatal(err)
  169. }
  170. // change a non-existing user
  171. _, err = as.UserChangePassword(&pb.AuthUserChangePasswordRequest{Name: "foo-test", Password: "bar"})
  172. if err == nil {
  173. t.Fatalf("expected %v, got %v", ErrUserNotFound, err)
  174. }
  175. if err != ErrUserNotFound {
  176. t.Fatalf("expected %v, got %v", ErrUserNotFound, err)
  177. }
  178. }
  179. func TestRoleAdd(t *testing.T) {
  180. b, tPath := backend.NewDefaultTmpBackend()
  181. defer func() {
  182. b.Close()
  183. os.Remove(tPath)
  184. }()
  185. as := NewAuthStore(b, dummyIndexWaiter)
  186. defer as.Close()
  187. err := enableAuthAndCreateRoot(as)
  188. if err != nil {
  189. t.Fatal(err)
  190. }
  191. // adds a new role
  192. _, err = as.RoleAdd(&pb.AuthRoleAddRequest{Name: "role-test"})
  193. if err != nil {
  194. t.Fatal(err)
  195. }
  196. }
  197. func TestUserGrant(t *testing.T) {
  198. b, tPath := backend.NewDefaultTmpBackend()
  199. defer func() {
  200. b.Close()
  201. os.Remove(tPath)
  202. }()
  203. as := NewAuthStore(b, dummyIndexWaiter)
  204. defer as.Close()
  205. err := enableAuthAndCreateRoot(as)
  206. if err != nil {
  207. t.Fatal(err)
  208. }
  209. _, err = as.UserAdd(&pb.AuthUserAddRequest{Name: "foo"})
  210. if err != nil {
  211. t.Fatal(err)
  212. }
  213. // adds a new role
  214. _, err = as.RoleAdd(&pb.AuthRoleAddRequest{Name: "role-test"})
  215. if err != nil {
  216. t.Fatal(err)
  217. }
  218. // grants a role to the user
  219. _, err = as.UserGrantRole(&pb.AuthUserGrantRoleRequest{User: "foo", Role: "role-test"})
  220. if err != nil {
  221. t.Fatal(err)
  222. }
  223. // grants a role to a non-existing user
  224. _, err = as.UserGrantRole(&pb.AuthUserGrantRoleRequest{User: "foo-test", Role: "role-test"})
  225. if err == nil {
  226. t.Fatalf("expected %v, got %v", ErrUserNotFound, err)
  227. }
  228. if err != ErrUserNotFound {
  229. t.Fatalf("expected %v, got %v", ErrUserNotFound, err)
  230. }
  231. // non-admin user
  232. err = as.IsAdminPermitted(&AuthInfo{Username: "foo", Revision: 1})
  233. if err != ErrPermissionDenied {
  234. t.Errorf("expected %v, got %v", ErrPermissionDenied, err)
  235. }
  236. // disabled auth should return nil
  237. as.AuthDisable()
  238. err = as.IsAdminPermitted(&AuthInfo{Username: "root", Revision: 1})
  239. if err != nil {
  240. t.Errorf("expected nil, got %v", err)
  241. }
  242. }
  243. func TestRecoverFromSnapshot(t *testing.T) {
  244. as, _ := setupAuthStore(t)
  245. ua := &pb.AuthUserAddRequest{Name: "foo"}
  246. _, err := as.UserAdd(ua) // add an existing user
  247. if err == nil {
  248. t.Fatalf("expected %v, got %v", ErrUserAlreadyExist, err)
  249. }
  250. if err != ErrUserAlreadyExist {
  251. t.Fatalf("expected %v, got %v", ErrUserAlreadyExist, err)
  252. }
  253. ua = &pb.AuthUserAddRequest{Name: ""}
  254. _, err = as.UserAdd(ua) // add a user with empty name
  255. if err != ErrUserEmpty {
  256. t.Fatal(err)
  257. }
  258. as.Close()
  259. as2 := NewAuthStore(as.be, dummyIndexWaiter)
  260. defer func(a *authStore) {
  261. a.Close()
  262. }(as2)
  263. if !as2.isAuthEnabled() {
  264. t.Fatal("recovering authStore from existing backend failed")
  265. }
  266. ul, err := as.UserList(&pb.AuthUserListRequest{})
  267. if err != nil {
  268. t.Fatal(err)
  269. }
  270. if !contains(ul.Users, "root") {
  271. t.Errorf("expected %v in %v", "root", ul.Users)
  272. }
  273. }
  274. func contains(array []string, str string) bool {
  275. for _, s := range array {
  276. if s == str {
  277. return true
  278. }
  279. }
  280. return false
  281. }
  282. func setupAuthStore(t *testing.T) (store *authStore, teardownfunc func(t *testing.T)) {
  283. b, tPath := backend.NewDefaultTmpBackend()
  284. as := NewAuthStore(b, dummyIndexWaiter)
  285. err := enableAuthAndCreateRoot(as)
  286. if err != nil {
  287. t.Fatal(err)
  288. }
  289. // adds a new role
  290. _, err = as.RoleAdd(&pb.AuthRoleAddRequest{Name: "role-test"})
  291. if err != nil {
  292. t.Fatal(err)
  293. }
  294. ua := &pb.AuthUserAddRequest{Name: "foo", Password: "bar"}
  295. _, err = as.UserAdd(ua) // add a non-existing user
  296. if err != nil {
  297. t.Fatal(err)
  298. }
  299. tearDown := func(t *testing.T) {
  300. b.Close()
  301. os.Remove(tPath)
  302. as.Close()
  303. }
  304. return as, tearDown
  305. }