2015-03-13 17:55:54 +00:00
|
|
|
package vault
|
|
|
|
|
|
|
|
import (
|
|
|
|
"reflect"
|
2015-03-16 21:59:37 +00:00
|
|
|
"sort"
|
2015-03-13 17:55:54 +00:00
|
|
|
"strings"
|
|
|
|
"testing"
|
|
|
|
"time"
|
2015-03-15 21:53:41 +00:00
|
|
|
|
|
|
|
"github.com/hashicorp/vault/logical"
|
2015-03-13 17:55:54 +00:00
|
|
|
)
|
|
|
|
|
|
|
|
// mockExpiration returns a mock expiration manager
|
|
|
|
func mockExpiration(t *testing.T) *ExpirationManager {
|
2015-03-24 22:10:46 +00:00
|
|
|
_, ts, _ := mockTokenStore(t)
|
2015-04-10 21:59:49 +00:00
|
|
|
return ts.expiration
|
2015-03-13 17:55:54 +00:00
|
|
|
}
|
|
|
|
|
2015-03-16 22:11:35 +00:00
|
|
|
func TestExpiration_Restore(t *testing.T) {
|
|
|
|
exp := mockExpiration(t)
|
|
|
|
noop := &NoopBackend{}
|
|
|
|
_, barrier, _ := mockBarrier(t)
|
|
|
|
view := NewBarrierView(barrier, "logical/")
|
2015-04-03 21:42:39 +00:00
|
|
|
exp.router.Mount(noop, "prod/aws/", generateUUID(), view)
|
2015-03-16 22:11:35 +00:00
|
|
|
|
|
|
|
paths := []string{
|
|
|
|
"prod/aws/foo",
|
|
|
|
"prod/aws/sub/bar",
|
|
|
|
"prod/aws/zip",
|
|
|
|
}
|
|
|
|
for _, path := range paths {
|
|
|
|
req := &logical.Request{
|
|
|
|
Operation: logical.ReadOperation,
|
|
|
|
Path: path,
|
|
|
|
}
|
|
|
|
resp := &logical.Response{
|
2015-03-19 22:11:42 +00:00
|
|
|
Secret: &logical.Secret{
|
2015-04-09 19:14:04 +00:00
|
|
|
LeaseOptions: logical.LeaseOptions{
|
|
|
|
Lease: 20 * time.Millisecond,
|
|
|
|
},
|
2015-03-16 22:11:35 +00:00
|
|
|
},
|
|
|
|
Data: map[string]interface{}{
|
|
|
|
"access_key": "xyz",
|
|
|
|
"secret_key": "abcd",
|
|
|
|
},
|
|
|
|
}
|
|
|
|
_, err := exp.Register(req, resp)
|
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("err: %v", err)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
// Stop everything
|
|
|
|
err := exp.Stop()
|
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("err: %v", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
// Restore
|
|
|
|
err = exp.Restore()
|
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("err: %v", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
// Ensure all are reaped
|
|
|
|
start := time.Now()
|
|
|
|
for time.Now().Sub(start) < time.Second {
|
2015-04-29 02:17:45 +00:00
|
|
|
noop.Lock()
|
|
|
|
less := len(noop.Requests) < 3
|
|
|
|
noop.Unlock()
|
|
|
|
|
|
|
|
if less {
|
2015-03-16 22:11:35 +00:00
|
|
|
time.Sleep(5 * time.Millisecond)
|
|
|
|
continue
|
|
|
|
}
|
|
|
|
break
|
|
|
|
}
|
|
|
|
for _, req := range noop.Requests {
|
|
|
|
if req.Operation != logical.RevokeOperation {
|
|
|
|
t.Fatalf("Bad: %v", req)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2015-03-13 17:55:54 +00:00
|
|
|
func TestExpiration_Register(t *testing.T) {
|
|
|
|
exp := mockExpiration(t)
|
2015-03-15 21:53:41 +00:00
|
|
|
req := &logical.Request{
|
|
|
|
Operation: logical.ReadOperation,
|
2015-03-13 17:55:54 +00:00
|
|
|
Path: "prod/aws/foo",
|
|
|
|
}
|
2015-03-15 21:53:41 +00:00
|
|
|
resp := &logical.Response{
|
2015-03-19 22:11:42 +00:00
|
|
|
Secret: &logical.Secret{
|
2015-04-09 19:14:04 +00:00
|
|
|
LeaseOptions: logical.LeaseOptions{
|
|
|
|
Lease: time.Hour,
|
|
|
|
},
|
2015-03-13 17:55:54 +00:00
|
|
|
},
|
|
|
|
Data: map[string]interface{}{
|
|
|
|
"access_key": "xyz",
|
|
|
|
"secret_key": "abcd",
|
|
|
|
},
|
|
|
|
}
|
|
|
|
|
|
|
|
id, err := exp.Register(req, resp)
|
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("err: %v", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
if !strings.HasPrefix(id, req.Path) {
|
|
|
|
t.Fatalf("bad: %s", id)
|
|
|
|
}
|
|
|
|
|
|
|
|
if len(id) <= len(req.Path) {
|
|
|
|
t.Fatalf("bad: %s", id)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2015-04-03 00:45:42 +00:00
|
|
|
func TestExpiration_RegisterAuth(t *testing.T) {
|
2015-03-24 01:11:15 +00:00
|
|
|
exp := mockExpiration(t)
|
|
|
|
root, err := exp.tokenStore.RootToken()
|
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("err: %v", err)
|
|
|
|
}
|
|
|
|
|
2015-04-03 00:45:42 +00:00
|
|
|
auth := &logical.Auth{
|
|
|
|
ClientToken: root.ID,
|
2015-04-09 19:14:04 +00:00
|
|
|
LeaseOptions: logical.LeaseOptions{
|
|
|
|
Lease: time.Hour,
|
|
|
|
},
|
2015-03-24 01:11:15 +00:00
|
|
|
}
|
|
|
|
|
2015-04-03 00:45:42 +00:00
|
|
|
err = exp.RegisterAuth("auth/github/login", auth)
|
2015-03-24 01:11:15 +00:00
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("err: %v", err)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2015-04-08 22:43:26 +00:00
|
|
|
func TestExpiration_RegisterAuth_NoLease(t *testing.T) {
|
|
|
|
exp := mockExpiration(t)
|
|
|
|
root, err := exp.tokenStore.RootToken()
|
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("err: %v", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
auth := &logical.Auth{
|
|
|
|
ClientToken: root.ID,
|
|
|
|
}
|
|
|
|
|
|
|
|
err = exp.RegisterAuth("auth/github/login", auth)
|
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("err: %v", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
// Should not be able to renew, no expiration
|
2015-04-09 21:23:37 +00:00
|
|
|
_, err = exp.RenewToken("auth/github/login", root.ID, 0)
|
2015-04-08 22:43:26 +00:00
|
|
|
if err.Error() != "lease not found" {
|
|
|
|
t.Fatalf("err: %v", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
// Wait and check token is not invalidated
|
|
|
|
time.Sleep(20 * time.Millisecond)
|
|
|
|
|
|
|
|
// Verify token does not get revoked
|
|
|
|
out, err := exp.tokenStore.Lookup(root.ID)
|
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("err: %v", err)
|
|
|
|
}
|
|
|
|
if out == nil {
|
|
|
|
t.Fatalf("missing token")
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2015-03-16 21:59:37 +00:00
|
|
|
func TestExpiration_Revoke(t *testing.T) {
|
|
|
|
exp := mockExpiration(t)
|
|
|
|
noop := &NoopBackend{}
|
|
|
|
_, barrier, _ := mockBarrier(t)
|
|
|
|
view := NewBarrierView(barrier, "logical/")
|
2015-04-03 21:42:39 +00:00
|
|
|
exp.router.Mount(noop, "prod/aws/", generateUUID(), view)
|
2015-03-16 21:59:37 +00:00
|
|
|
|
|
|
|
req := &logical.Request{
|
|
|
|
Operation: logical.ReadOperation,
|
|
|
|
Path: "prod/aws/foo",
|
|
|
|
}
|
|
|
|
resp := &logical.Response{
|
2015-03-19 22:11:42 +00:00
|
|
|
Secret: &logical.Secret{
|
2015-04-09 19:14:04 +00:00
|
|
|
LeaseOptions: logical.LeaseOptions{
|
|
|
|
Lease: time.Hour,
|
|
|
|
},
|
2015-03-16 21:59:37 +00:00
|
|
|
},
|
|
|
|
Data: map[string]interface{}{
|
|
|
|
"access_key": "xyz",
|
|
|
|
"secret_key": "abcd",
|
|
|
|
},
|
|
|
|
}
|
|
|
|
|
|
|
|
id, err := exp.Register(req, resp)
|
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("err: %v", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
if err := exp.Revoke(id); err != nil {
|
|
|
|
t.Fatalf("err: %v", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
req = noop.Requests[0]
|
|
|
|
if req.Operation != logical.RevokeOperation {
|
|
|
|
t.Fatalf("Bad: %v", req)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func TestExpiration_RevokeOnExpire(t *testing.T) {
|
|
|
|
exp := mockExpiration(t)
|
|
|
|
noop := &NoopBackend{}
|
|
|
|
_, barrier, _ := mockBarrier(t)
|
|
|
|
view := NewBarrierView(barrier, "logical/")
|
2015-04-03 21:42:39 +00:00
|
|
|
exp.router.Mount(noop, "prod/aws/", generateUUID(), view)
|
2015-03-16 21:59:37 +00:00
|
|
|
|
|
|
|
req := &logical.Request{
|
|
|
|
Operation: logical.ReadOperation,
|
|
|
|
Path: "prod/aws/foo",
|
|
|
|
}
|
|
|
|
resp := &logical.Response{
|
2015-03-19 22:11:42 +00:00
|
|
|
Secret: &logical.Secret{
|
2015-04-09 19:14:04 +00:00
|
|
|
LeaseOptions: logical.LeaseOptions{
|
|
|
|
Lease: 20 * time.Millisecond,
|
|
|
|
},
|
2015-03-16 21:59:37 +00:00
|
|
|
},
|
|
|
|
Data: map[string]interface{}{
|
|
|
|
"access_key": "xyz",
|
|
|
|
"secret_key": "abcd",
|
|
|
|
},
|
|
|
|
}
|
|
|
|
|
|
|
|
_, err := exp.Register(req, resp)
|
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("err: %v", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
start := time.Now()
|
|
|
|
for time.Now().Sub(start) < time.Second {
|
2015-04-29 02:17:45 +00:00
|
|
|
req = nil
|
|
|
|
|
|
|
|
noop.Lock()
|
|
|
|
if len(noop.Requests) > 0 {
|
|
|
|
req = noop.Requests[0]
|
|
|
|
}
|
|
|
|
noop.Unlock()
|
|
|
|
if req == nil {
|
2015-03-16 21:59:37 +00:00
|
|
|
time.Sleep(5 * time.Millisecond)
|
|
|
|
continue
|
|
|
|
}
|
|
|
|
if req.Operation != logical.RevokeOperation {
|
|
|
|
t.Fatalf("Bad: %v", req)
|
|
|
|
}
|
2015-04-29 02:17:45 +00:00
|
|
|
|
2015-03-16 21:59:37 +00:00
|
|
|
break
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func TestExpiration_RevokePrefix(t *testing.T) {
|
|
|
|
exp := mockExpiration(t)
|
|
|
|
noop := &NoopBackend{}
|
|
|
|
_, barrier, _ := mockBarrier(t)
|
|
|
|
view := NewBarrierView(barrier, "logical/")
|
2015-04-03 21:42:39 +00:00
|
|
|
exp.router.Mount(noop, "prod/aws/", generateUUID(), view)
|
2015-03-16 21:59:37 +00:00
|
|
|
|
|
|
|
paths := []string{
|
|
|
|
"prod/aws/foo",
|
|
|
|
"prod/aws/sub/bar",
|
|
|
|
"prod/aws/zip",
|
|
|
|
}
|
|
|
|
for _, path := range paths {
|
|
|
|
req := &logical.Request{
|
|
|
|
Operation: logical.ReadOperation,
|
|
|
|
Path: path,
|
|
|
|
}
|
|
|
|
resp := &logical.Response{
|
2015-03-19 22:11:42 +00:00
|
|
|
Secret: &logical.Secret{
|
2015-04-09 19:14:04 +00:00
|
|
|
LeaseOptions: logical.LeaseOptions{
|
|
|
|
Lease: 20 * time.Millisecond,
|
|
|
|
},
|
2015-03-16 21:59:37 +00:00
|
|
|
},
|
|
|
|
Data: map[string]interface{}{
|
|
|
|
"access_key": "xyz",
|
|
|
|
"secret_key": "abcd",
|
|
|
|
},
|
|
|
|
}
|
|
|
|
_, err := exp.Register(req, resp)
|
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("err: %v", err)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
// Should nuke all the keys
|
|
|
|
if err := exp.RevokePrefix("prod/aws/"); err != nil {
|
|
|
|
t.Fatalf("err: %v", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
if len(noop.Requests) != 3 {
|
2015-04-10 21:48:08 +00:00
|
|
|
t.Fatalf("Bad: %v", noop.Requests)
|
|
|
|
}
|
|
|
|
for _, req := range noop.Requests {
|
|
|
|
if req.Operation != logical.RevokeOperation {
|
|
|
|
t.Fatalf("Bad: %v", req)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
expect := []string{
|
|
|
|
"foo",
|
|
|
|
"sub/bar",
|
|
|
|
"zip",
|
|
|
|
}
|
|
|
|
sort.Strings(noop.Paths)
|
|
|
|
sort.Strings(expect)
|
|
|
|
if !reflect.DeepEqual(noop.Paths, expect) {
|
|
|
|
t.Fatalf("bad: %v", noop.Paths)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func TestExpiration_RevokeByToken(t *testing.T) {
|
|
|
|
exp := mockExpiration(t)
|
|
|
|
noop := &NoopBackend{}
|
|
|
|
_, barrier, _ := mockBarrier(t)
|
|
|
|
view := NewBarrierView(barrier, "logical/")
|
|
|
|
exp.router.Mount(noop, "prod/aws/", generateUUID(), view)
|
|
|
|
|
|
|
|
paths := []string{
|
|
|
|
"prod/aws/foo",
|
|
|
|
"prod/aws/sub/bar",
|
|
|
|
"prod/aws/zip",
|
|
|
|
}
|
|
|
|
for _, path := range paths {
|
|
|
|
req := &logical.Request{
|
|
|
|
Operation: logical.ReadOperation,
|
|
|
|
Path: path,
|
|
|
|
ClientToken: "foobarbaz",
|
|
|
|
}
|
|
|
|
resp := &logical.Response{
|
|
|
|
Secret: &logical.Secret{
|
|
|
|
LeaseOptions: logical.LeaseOptions{
|
|
|
|
Lease: 20 * time.Millisecond,
|
|
|
|
},
|
|
|
|
},
|
|
|
|
Data: map[string]interface{}{
|
|
|
|
"access_key": "xyz",
|
|
|
|
"secret_key": "abcd",
|
|
|
|
},
|
|
|
|
}
|
|
|
|
_, err := exp.Register(req, resp)
|
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("err: %v", err)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
// Should nuke all the keys
|
|
|
|
if err := exp.RevokeByToken("foobarbaz"); err != nil {
|
|
|
|
t.Fatalf("err: %v", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
if len(noop.Requests) != 3 {
|
2015-03-16 21:59:37 +00:00
|
|
|
t.Fatalf("Bad: %v", noop.Requests)
|
|
|
|
}
|
|
|
|
for _, req := range noop.Requests {
|
|
|
|
if req.Operation != logical.RevokeOperation {
|
|
|
|
t.Fatalf("Bad: %v", req)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
expect := []string{
|
|
|
|
"foo",
|
|
|
|
"sub/bar",
|
|
|
|
"zip",
|
|
|
|
}
|
|
|
|
sort.Strings(noop.Paths)
|
|
|
|
sort.Strings(expect)
|
|
|
|
if !reflect.DeepEqual(noop.Paths, expect) {
|
|
|
|
t.Fatalf("bad: %v", noop.Paths)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2015-04-03 18:58:10 +00:00
|
|
|
func TestExpiration_RenewToken(t *testing.T) {
|
|
|
|
exp := mockExpiration(t)
|
|
|
|
root, err := exp.tokenStore.RootToken()
|
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("err: %v", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
// Register a token
|
|
|
|
auth := &logical.Auth{
|
|
|
|
ClientToken: root.ID,
|
2015-04-09 19:14:04 +00:00
|
|
|
LeaseOptions: logical.LeaseOptions{
|
|
|
|
Lease: time.Hour,
|
|
|
|
Renewable: true,
|
|
|
|
},
|
2015-04-03 18:58:10 +00:00
|
|
|
}
|
2015-04-09 21:23:37 +00:00
|
|
|
err = exp.RegisterAuth("auth/token/login", auth)
|
2015-04-03 18:58:10 +00:00
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("err: %v", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
// Renew the token
|
2015-04-09 21:23:37 +00:00
|
|
|
out, err := exp.RenewToken("auth/token/login", root.ID, 0)
|
2015-04-03 18:58:10 +00:00
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("err: %v", err)
|
|
|
|
}
|
2015-04-11 04:21:06 +00:00
|
|
|
|
|
|
|
if auth.ClientToken != out.ClientToken {
|
2015-04-06 23:35:39 +00:00
|
|
|
t.Fatalf("Bad: %#v", out)
|
|
|
|
}
|
2015-04-03 18:58:10 +00:00
|
|
|
}
|
|
|
|
|
2015-04-09 00:03:46 +00:00
|
|
|
func TestExpiration_RenewToken_NotRenewable(t *testing.T) {
|
|
|
|
exp := mockExpiration(t)
|
|
|
|
root, err := exp.tokenStore.RootToken()
|
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("err: %v", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
// Register a token
|
|
|
|
auth := &logical.Auth{
|
|
|
|
ClientToken: root.ID,
|
2015-04-09 19:14:04 +00:00
|
|
|
LeaseOptions: logical.LeaseOptions{
|
|
|
|
Lease: time.Hour,
|
|
|
|
Renewable: false,
|
|
|
|
},
|
2015-04-09 00:03:46 +00:00
|
|
|
}
|
|
|
|
err = exp.RegisterAuth("auth/github/login", auth)
|
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("err: %v", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
// Attempt to renew the token
|
2015-04-09 21:23:37 +00:00
|
|
|
_, err = exp.RenewToken("auth/github/login", root.ID, 0)
|
2015-04-09 00:03:46 +00:00
|
|
|
if err.Error() != "lease is not renewable" {
|
|
|
|
t.Fatalf("err: %v", err)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2015-03-16 21:59:37 +00:00
|
|
|
func TestExpiration_Renew(t *testing.T) {
|
|
|
|
exp := mockExpiration(t)
|
|
|
|
noop := &NoopBackend{}
|
|
|
|
_, barrier, _ := mockBarrier(t)
|
|
|
|
view := NewBarrierView(barrier, "logical/")
|
2015-04-03 21:42:39 +00:00
|
|
|
exp.router.Mount(noop, "prod/aws/", generateUUID(), view)
|
2015-03-16 21:59:37 +00:00
|
|
|
|
|
|
|
req := &logical.Request{
|
|
|
|
Operation: logical.ReadOperation,
|
|
|
|
Path: "prod/aws/foo",
|
|
|
|
}
|
|
|
|
resp := &logical.Response{
|
2015-03-19 22:11:42 +00:00
|
|
|
Secret: &logical.Secret{
|
2015-04-09 19:14:04 +00:00
|
|
|
LeaseOptions: logical.LeaseOptions{
|
|
|
|
Lease: 20 * time.Millisecond,
|
|
|
|
Renewable: true,
|
|
|
|
},
|
2015-03-16 21:59:37 +00:00
|
|
|
},
|
|
|
|
Data: map[string]interface{}{
|
|
|
|
"access_key": "xyz",
|
|
|
|
"secret_key": "abcd",
|
|
|
|
},
|
|
|
|
}
|
|
|
|
|
|
|
|
id, err := exp.Register(req, resp)
|
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("err: %v", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
noop.Response = &logical.Response{
|
2015-03-19 22:11:42 +00:00
|
|
|
Secret: &logical.Secret{
|
2015-04-09 19:14:04 +00:00
|
|
|
LeaseOptions: logical.LeaseOptions{
|
|
|
|
Lease: 20 * time.Millisecond,
|
|
|
|
},
|
2015-03-16 21:59:37 +00:00
|
|
|
},
|
|
|
|
Data: map[string]interface{}{
|
|
|
|
"access_key": "123",
|
|
|
|
"secret_key": "abcd",
|
|
|
|
},
|
|
|
|
}
|
|
|
|
|
|
|
|
out, err := exp.Renew(id, 0)
|
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("err: %v", err)
|
|
|
|
}
|
|
|
|
|
2015-04-29 02:17:45 +00:00
|
|
|
noop.Lock()
|
|
|
|
defer noop.Unlock()
|
|
|
|
|
2015-03-16 21:59:37 +00:00
|
|
|
if !reflect.DeepEqual(out, noop.Response) {
|
|
|
|
t.Fatalf("Bad: %#v", out)
|
|
|
|
}
|
|
|
|
|
|
|
|
if len(noop.Requests) != 1 {
|
|
|
|
t.Fatalf("Bad: %#v", noop.Requests)
|
|
|
|
}
|
|
|
|
req = noop.Requests[0]
|
|
|
|
if req.Operation != logical.RenewOperation {
|
|
|
|
t.Fatalf("Bad: %v", req)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2015-04-09 00:03:46 +00:00
|
|
|
func TestExpiration_Renew_NotRenewable(t *testing.T) {
|
|
|
|
exp := mockExpiration(t)
|
|
|
|
noop := &NoopBackend{}
|
|
|
|
_, barrier, _ := mockBarrier(t)
|
|
|
|
view := NewBarrierView(barrier, "logical/")
|
|
|
|
exp.router.Mount(noop, "prod/aws/", generateUUID(), view)
|
|
|
|
|
|
|
|
req := &logical.Request{
|
|
|
|
Operation: logical.ReadOperation,
|
|
|
|
Path: "prod/aws/foo",
|
|
|
|
}
|
|
|
|
resp := &logical.Response{
|
|
|
|
Secret: &logical.Secret{
|
2015-04-09 19:14:04 +00:00
|
|
|
LeaseOptions: logical.LeaseOptions{
|
|
|
|
Lease: 20 * time.Millisecond,
|
|
|
|
Renewable: false,
|
|
|
|
},
|
2015-04-09 00:03:46 +00:00
|
|
|
},
|
|
|
|
Data: map[string]interface{}{
|
|
|
|
"access_key": "xyz",
|
|
|
|
"secret_key": "abcd",
|
|
|
|
},
|
|
|
|
}
|
|
|
|
|
|
|
|
id, err := exp.Register(req, resp)
|
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("err: %v", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
_, err = exp.Renew(id, 0)
|
|
|
|
if err.Error() != "lease is not renewable" {
|
|
|
|
t.Fatalf("err: %v", err)
|
|
|
|
}
|
|
|
|
|
2015-04-29 02:17:45 +00:00
|
|
|
noop.Lock()
|
|
|
|
defer noop.Unlock()
|
|
|
|
|
2015-04-09 00:03:46 +00:00
|
|
|
if len(noop.Requests) != 0 {
|
|
|
|
t.Fatalf("Bad: %#v", noop.Requests)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2015-03-16 21:59:37 +00:00
|
|
|
func TestExpiration_Renew_RevokeOnExpire(t *testing.T) {
|
|
|
|
exp := mockExpiration(t)
|
|
|
|
noop := &NoopBackend{}
|
|
|
|
_, barrier, _ := mockBarrier(t)
|
|
|
|
view := NewBarrierView(barrier, "logical/")
|
2015-04-03 21:42:39 +00:00
|
|
|
exp.router.Mount(noop, "prod/aws/", generateUUID(), view)
|
2015-03-16 21:59:37 +00:00
|
|
|
|
|
|
|
req := &logical.Request{
|
|
|
|
Operation: logical.ReadOperation,
|
|
|
|
Path: "prod/aws/foo",
|
|
|
|
}
|
|
|
|
resp := &logical.Response{
|
2015-03-19 22:11:42 +00:00
|
|
|
Secret: &logical.Secret{
|
2015-04-09 19:14:04 +00:00
|
|
|
LeaseOptions: logical.LeaseOptions{
|
|
|
|
Lease: 20 * time.Millisecond,
|
|
|
|
Renewable: true,
|
|
|
|
},
|
2015-03-16 21:59:37 +00:00
|
|
|
},
|
|
|
|
Data: map[string]interface{}{
|
|
|
|
"access_key": "xyz",
|
|
|
|
"secret_key": "abcd",
|
|
|
|
},
|
|
|
|
}
|
|
|
|
|
|
|
|
id, err := exp.Register(req, resp)
|
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("err: %v", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
noop.Response = &logical.Response{
|
2015-03-19 22:11:42 +00:00
|
|
|
Secret: &logical.Secret{
|
2015-04-09 19:14:04 +00:00
|
|
|
LeaseOptions: logical.LeaseOptions{
|
|
|
|
Lease: 20 * time.Millisecond,
|
|
|
|
},
|
2015-03-16 21:59:37 +00:00
|
|
|
},
|
|
|
|
Data: map[string]interface{}{
|
|
|
|
"access_key": "123",
|
|
|
|
"secret_key": "abcd",
|
|
|
|
},
|
|
|
|
}
|
|
|
|
|
|
|
|
_, err = exp.Renew(id, 0)
|
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("err: %v", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
start := time.Now()
|
|
|
|
for time.Now().Sub(start) < time.Second {
|
2015-04-29 02:17:45 +00:00
|
|
|
req = nil
|
|
|
|
|
|
|
|
noop.Lock()
|
|
|
|
if len(noop.Requests) >= 2 {
|
|
|
|
req = noop.Requests[1]
|
|
|
|
}
|
|
|
|
noop.Unlock()
|
|
|
|
|
|
|
|
if req == nil {
|
2015-03-16 21:59:37 +00:00
|
|
|
time.Sleep(5 * time.Millisecond)
|
|
|
|
continue
|
|
|
|
}
|
|
|
|
if req.Operation != logical.RevokeOperation {
|
|
|
|
t.Fatalf("Bad: %v", req)
|
|
|
|
}
|
|
|
|
break
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2015-03-16 20:58:22 +00:00
|
|
|
func TestExpiration_revokeEntry(t *testing.T) {
|
|
|
|
exp := mockExpiration(t)
|
|
|
|
|
|
|
|
noop := &NoopBackend{}
|
|
|
|
_, barrier, _ := mockBarrier(t)
|
|
|
|
view := NewBarrierView(barrier, "logical/")
|
2015-04-03 21:42:39 +00:00
|
|
|
exp.router.Mount(noop, "", generateUUID(), view)
|
2015-03-16 20:58:22 +00:00
|
|
|
|
|
|
|
le := &leaseEntry{
|
2015-04-08 20:35:32 +00:00
|
|
|
LeaseID: "foo/bar/1234",
|
2015-03-16 20:58:22 +00:00
|
|
|
Path: "foo/bar",
|
|
|
|
Data: map[string]interface{}{
|
|
|
|
"testing": true,
|
|
|
|
},
|
2015-03-19 22:11:42 +00:00
|
|
|
Secret: &logical.Secret{
|
2015-04-09 19:14:04 +00:00
|
|
|
LeaseOptions: logical.LeaseOptions{
|
|
|
|
Lease: time.Minute,
|
|
|
|
},
|
2015-03-16 20:58:22 +00:00
|
|
|
},
|
|
|
|
IssueTime: time.Now(),
|
|
|
|
ExpireTime: time.Now(),
|
|
|
|
}
|
|
|
|
|
|
|
|
err := exp.revokeEntry(le)
|
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("err: %v", err)
|
|
|
|
}
|
|
|
|
|
2015-04-29 02:17:45 +00:00
|
|
|
noop.Lock()
|
|
|
|
defer noop.Unlock()
|
|
|
|
|
2015-03-16 20:58:22 +00:00
|
|
|
req := noop.Requests[0]
|
|
|
|
if req.Operation != logical.RevokeOperation {
|
|
|
|
t.Fatalf("Bad: %v", req)
|
|
|
|
}
|
|
|
|
if req.Path != le.Path {
|
|
|
|
t.Fatalf("Bad: %v", req)
|
|
|
|
}
|
2015-03-19 22:11:42 +00:00
|
|
|
if !reflect.DeepEqual(req.Data, le.Data) {
|
2015-03-16 20:58:22 +00:00
|
|
|
t.Fatalf("Bad: %v", req)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2015-03-24 01:11:15 +00:00
|
|
|
func TestExpiration_revokeEntry_token(t *testing.T) {
|
|
|
|
exp := mockExpiration(t)
|
|
|
|
root, err := exp.tokenStore.RootToken()
|
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("err: %v", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
le := &leaseEntry{
|
2015-04-08 20:35:32 +00:00
|
|
|
LeaseID: "foo/bar/1234",
|
2015-04-03 18:58:10 +00:00
|
|
|
Auth: &logical.Auth{
|
|
|
|
ClientToken: root.ID,
|
2015-04-09 19:14:04 +00:00
|
|
|
LeaseOptions: logical.LeaseOptions{
|
|
|
|
Lease: time.Minute,
|
|
|
|
},
|
2015-03-24 01:11:15 +00:00
|
|
|
},
|
2015-04-03 18:58:10 +00:00
|
|
|
Path: "foo/bar",
|
2015-03-24 01:11:15 +00:00
|
|
|
IssueTime: time.Now(),
|
|
|
|
ExpireTime: time.Now(),
|
|
|
|
}
|
|
|
|
|
|
|
|
err = exp.revokeEntry(le)
|
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("err: %v", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
out, err := exp.tokenStore.Lookup(root.ID)
|
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("err: %v", err)
|
|
|
|
}
|
|
|
|
if out != nil {
|
|
|
|
t.Fatalf("bad: %v", out)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2015-03-16 20:58:22 +00:00
|
|
|
func TestExpiration_renewEntry(t *testing.T) {
|
|
|
|
exp := mockExpiration(t)
|
|
|
|
|
|
|
|
noop := &NoopBackend{
|
|
|
|
Response: &logical.Response{
|
2015-03-19 22:11:42 +00:00
|
|
|
Secret: &logical.Secret{
|
2015-04-09 19:14:04 +00:00
|
|
|
LeaseOptions: logical.LeaseOptions{
|
|
|
|
Renewable: true,
|
|
|
|
Lease: time.Hour,
|
|
|
|
},
|
2015-03-16 20:58:22 +00:00
|
|
|
},
|
|
|
|
Data: map[string]interface{}{
|
|
|
|
"testing": false,
|
|
|
|
},
|
|
|
|
},
|
|
|
|
}
|
|
|
|
_, barrier, _ := mockBarrier(t)
|
|
|
|
view := NewBarrierView(barrier, "logical/")
|
2015-04-03 21:42:39 +00:00
|
|
|
exp.router.Mount(noop, "", generateUUID(), view)
|
2015-03-16 20:58:22 +00:00
|
|
|
|
|
|
|
le := &leaseEntry{
|
2015-04-08 20:35:32 +00:00
|
|
|
LeaseID: "foo/bar/1234",
|
2015-03-16 20:58:22 +00:00
|
|
|
Path: "foo/bar",
|
|
|
|
Data: map[string]interface{}{
|
|
|
|
"testing": true,
|
|
|
|
},
|
2015-03-19 22:11:42 +00:00
|
|
|
Secret: &logical.Secret{
|
2015-04-09 19:14:04 +00:00
|
|
|
LeaseOptions: logical.LeaseOptions{
|
|
|
|
Lease: time.Minute,
|
|
|
|
},
|
2015-03-16 20:58:22 +00:00
|
|
|
},
|
|
|
|
IssueTime: time.Now(),
|
|
|
|
ExpireTime: time.Now(),
|
|
|
|
}
|
|
|
|
|
2015-03-16 21:59:37 +00:00
|
|
|
resp, err := exp.renewEntry(le, time.Second)
|
2015-03-16 20:58:22 +00:00
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("err: %v", err)
|
|
|
|
}
|
|
|
|
|
2015-04-29 02:17:45 +00:00
|
|
|
noop.Lock()
|
|
|
|
defer noop.Unlock()
|
|
|
|
|
2015-03-16 20:58:22 +00:00
|
|
|
if !reflect.DeepEqual(resp, noop.Response) {
|
|
|
|
t.Fatalf("bad: %#v", resp)
|
|
|
|
}
|
|
|
|
|
|
|
|
req := noop.Requests[0]
|
|
|
|
if req.Operation != logical.RenewOperation {
|
|
|
|
t.Fatalf("Bad: %v", req)
|
|
|
|
}
|
|
|
|
if req.Path != le.Path {
|
|
|
|
t.Fatalf("Bad: %v", req)
|
|
|
|
}
|
2015-03-19 22:11:42 +00:00
|
|
|
if !reflect.DeepEqual(req.Data, le.Data) {
|
2015-03-16 21:59:37 +00:00
|
|
|
t.Fatalf("Bad: %v", req)
|
|
|
|
}
|
2015-03-19 22:11:42 +00:00
|
|
|
if req.Secret.LeaseIncrement != time.Second {
|
2015-03-16 20:58:22 +00:00
|
|
|
t.Fatalf("Bad: %v", req)
|
|
|
|
}
|
2015-04-09 18:54:32 +00:00
|
|
|
if req.Secret.LeaseIssue.IsZero() {
|
|
|
|
t.Fatalf("Bad: %v", req)
|
|
|
|
}
|
2015-03-16 20:58:22 +00:00
|
|
|
}
|
|
|
|
|
2015-04-10 21:07:06 +00:00
|
|
|
func TestExpiration_renewAuthEntry(t *testing.T) {
|
|
|
|
exp := mockExpiration(t)
|
|
|
|
|
|
|
|
noop := &NoopBackend{
|
|
|
|
Response: &logical.Response{
|
|
|
|
Auth: &logical.Auth{
|
|
|
|
LeaseOptions: logical.LeaseOptions{
|
|
|
|
Renewable: true,
|
|
|
|
Lease: time.Hour,
|
|
|
|
},
|
|
|
|
},
|
|
|
|
},
|
|
|
|
}
|
|
|
|
_, barrier, _ := mockBarrier(t)
|
|
|
|
view := NewBarrierView(barrier, "auth/foo/")
|
|
|
|
exp.router.Mount(noop, "auth/foo/", generateUUID(), view)
|
|
|
|
|
|
|
|
le := &leaseEntry{
|
|
|
|
LeaseID: "auth/foo/1234",
|
|
|
|
Path: "auth/foo/login",
|
|
|
|
Auth: &logical.Auth{
|
|
|
|
LeaseOptions: logical.LeaseOptions{
|
|
|
|
Renewable: true,
|
|
|
|
Lease: time.Minute,
|
|
|
|
},
|
|
|
|
},
|
|
|
|
IssueTime: time.Now(),
|
|
|
|
ExpireTime: time.Now().Add(time.Minute),
|
|
|
|
}
|
|
|
|
|
|
|
|
resp, err := exp.renewAuthEntry(le, time.Second)
|
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("err: %v", err)
|
|
|
|
}
|
|
|
|
|
2015-04-29 02:17:45 +00:00
|
|
|
noop.Lock()
|
|
|
|
defer noop.Unlock()
|
|
|
|
|
2015-04-10 21:07:06 +00:00
|
|
|
if !reflect.DeepEqual(resp, noop.Response) {
|
|
|
|
t.Fatalf("bad: %#v", resp)
|
|
|
|
}
|
|
|
|
|
|
|
|
req := noop.Requests[0]
|
|
|
|
if req.Operation != logical.RenewOperation {
|
|
|
|
t.Fatalf("Bad: %v", req)
|
|
|
|
}
|
|
|
|
if req.Path != "login" {
|
|
|
|
t.Fatalf("Bad: %v", req)
|
|
|
|
}
|
|
|
|
if req.Auth.LeaseIncrement != time.Second {
|
|
|
|
t.Fatalf("Bad: %v", req)
|
|
|
|
}
|
|
|
|
if req.Auth.LeaseIssue.IsZero() {
|
|
|
|
t.Fatalf("Bad: %v", req)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2015-03-16 20:40:03 +00:00
|
|
|
func TestExpiration_PersistLoadDelete(t *testing.T) {
|
|
|
|
exp := mockExpiration(t)
|
|
|
|
le := &leaseEntry{
|
2015-04-08 20:35:32 +00:00
|
|
|
LeaseID: "foo/bar/1234",
|
2015-03-16 20:40:03 +00:00
|
|
|
Path: "foo/bar",
|
|
|
|
Data: map[string]interface{}{
|
|
|
|
"testing": true,
|
|
|
|
},
|
2015-03-19 22:11:42 +00:00
|
|
|
Secret: &logical.Secret{
|
2015-04-09 19:14:04 +00:00
|
|
|
LeaseOptions: logical.LeaseOptions{
|
|
|
|
Lease: time.Minute,
|
|
|
|
},
|
2015-03-16 20:40:03 +00:00
|
|
|
},
|
|
|
|
IssueTime: time.Now(),
|
|
|
|
ExpireTime: time.Now(),
|
|
|
|
}
|
|
|
|
if err := exp.persistEntry(le); err != nil {
|
|
|
|
t.Fatalf("err: %v", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
out, err := exp.loadEntry("foo/bar/1234")
|
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("err: %v", err)
|
|
|
|
}
|
|
|
|
if !reflect.DeepEqual(out, le) {
|
|
|
|
t.Fatalf("out: %#v expect: %#v", out, le)
|
|
|
|
}
|
|
|
|
|
|
|
|
err = exp.deleteEntry("foo/bar/1234")
|
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("err: %v", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
out, err = exp.loadEntry("foo/bar/1234")
|
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("err: %v", err)
|
|
|
|
}
|
|
|
|
if out != nil {
|
|
|
|
t.Fatalf("out: %#v", out)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2015-03-13 17:55:54 +00:00
|
|
|
func TestLeaseEntry(t *testing.T) {
|
|
|
|
le := &leaseEntry{
|
2015-04-08 20:35:32 +00:00
|
|
|
LeaseID: "foo/bar/1234",
|
2015-03-13 17:55:54 +00:00
|
|
|
Path: "foo/bar",
|
|
|
|
Data: map[string]interface{}{
|
|
|
|
"testing": true,
|
|
|
|
},
|
2015-03-19 22:11:42 +00:00
|
|
|
Secret: &logical.Secret{
|
2015-04-09 19:14:04 +00:00
|
|
|
LeaseOptions: logical.LeaseOptions{
|
|
|
|
Lease: time.Minute,
|
|
|
|
},
|
2015-03-13 17:55:54 +00:00
|
|
|
},
|
2015-03-16 18:33:59 +00:00
|
|
|
IssueTime: time.Now(),
|
|
|
|
ExpireTime: time.Now(),
|
2015-03-13 17:55:54 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
enc, err := le.encode()
|
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("err: %v", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
out, err := decodeLeaseEntry(enc)
|
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("err: %v", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
if !reflect.DeepEqual(out.Data, le.Data) {
|
|
|
|
t.Fatalf("got: %#v, expect %#v", out, le)
|
|
|
|
}
|
|
|
|
}
|