2016-03-03 14:19:17 +00:00
|
|
|
package mssql
|
|
|
|
|
|
|
|
import (
|
2018-01-08 18:31:38 +00:00
|
|
|
"context"
|
2018-04-09 14:46:52 +00:00
|
|
|
"database/sql"
|
2016-03-03 14:19:17 +00:00
|
|
|
"fmt"
|
|
|
|
"log"
|
|
|
|
"os"
|
2016-06-11 15:48:40 +00:00
|
|
|
"reflect"
|
2016-03-03 14:19:17 +00:00
|
|
|
"testing"
|
|
|
|
|
2018-04-09 14:46:52 +00:00
|
|
|
_ "github.com/denisenkom/go-mssqldb"
|
2016-03-03 14:19:17 +00:00
|
|
|
"github.com/hashicorp/vault/logical"
|
|
|
|
logicaltest "github.com/hashicorp/vault/logical/testing"
|
|
|
|
"github.com/mitchellh/mapstructure"
|
2018-07-11 21:49:13 +00:00
|
|
|
"github.com/ory/dockertest"
|
2016-03-03 14:19:17 +00:00
|
|
|
)
|
|
|
|
|
2018-04-09 14:46:52 +00:00
|
|
|
func prepareMSSQLTestContainer(t *testing.T) (func(), string) {
|
|
|
|
if os.Getenv("MSSQL_URL") != "" {
|
|
|
|
return func() {}, os.Getenv("MSSQL_URL")
|
|
|
|
}
|
|
|
|
|
|
|
|
pool, err := dockertest.NewPool("")
|
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("Failed to connect to docker: %s", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
runOpts := &dockertest.RunOptions{
|
|
|
|
Repository: "microsoft/mssql-server-linux",
|
|
|
|
Tag: "2017-latest",
|
|
|
|
Env: []string{"ACCEPT_EULA=Y", "SA_PASSWORD=yourStrong(!)Password"},
|
|
|
|
}
|
|
|
|
resource, err := pool.RunWithOptions(runOpts)
|
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("Could not start local MSSQL docker container: %s", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
cleanup := func() {
|
|
|
|
err := pool.Purge(resource)
|
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("Failed to cleanup local container: %s", err)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
retURL := fmt.Sprintf("sqlserver://sa:yourStrong(!)Password@localhost:%s", resource.GetPort("1433/tcp"))
|
|
|
|
|
|
|
|
// exponential backoff-retry, because the mssql container may not be able to accept connections yet
|
|
|
|
if err = pool.Retry(func() error {
|
|
|
|
var err error
|
|
|
|
var db *sql.DB
|
|
|
|
db, err = sql.Open("mssql", retURL)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
2018-04-26 15:28:58 +00:00
|
|
|
defer db.Close()
|
2018-04-09 14:46:52 +00:00
|
|
|
return db.Ping()
|
|
|
|
}); err != nil {
|
|
|
|
cleanup()
|
|
|
|
t.Fatalf("Could not connect to MSSQL docker container: %s", err)
|
|
|
|
}
|
|
|
|
|
|
|
|
return cleanup, retURL
|
|
|
|
}
|
|
|
|
|
2016-06-11 15:48:40 +00:00
|
|
|
func TestBackend_config_connection(t *testing.T) {
|
|
|
|
var resp *logical.Response
|
|
|
|
var err error
|
|
|
|
config := logical.TestBackendConfig()
|
|
|
|
config.StorageView = &logical.InmemStorage{}
|
2018-01-19 06:44:44 +00:00
|
|
|
b, err := Factory(context.Background(), config)
|
2016-06-11 15:48:40 +00:00
|
|
|
if err != nil {
|
|
|
|
t.Fatal(err)
|
|
|
|
}
|
|
|
|
|
|
|
|
configData := map[string]interface{}{
|
|
|
|
"connection_string": "sample_connection_string",
|
|
|
|
"max_open_connections": 7,
|
|
|
|
"verify_connection": false,
|
|
|
|
}
|
|
|
|
|
|
|
|
configReq := &logical.Request{
|
|
|
|
Operation: logical.UpdateOperation,
|
|
|
|
Path: "config/connection",
|
|
|
|
Storage: config.StorageView,
|
|
|
|
Data: configData,
|
|
|
|
}
|
2018-01-08 18:31:38 +00:00
|
|
|
resp, err = b.HandleRequest(context.Background(), configReq)
|
2016-06-11 15:48:40 +00:00
|
|
|
if err != nil || (resp != nil && resp.IsError()) {
|
|
|
|
t.Fatalf("err:%s resp:%#v\n", err, resp)
|
|
|
|
}
|
|
|
|
|
|
|
|
configReq.Operation = logical.ReadOperation
|
2018-01-08 18:31:38 +00:00
|
|
|
resp, err = b.HandleRequest(context.Background(), configReq)
|
2016-06-11 15:48:40 +00:00
|
|
|
if err != nil || (resp != nil && resp.IsError()) {
|
|
|
|
t.Fatalf("err:%s resp:%#v\n", err, resp)
|
|
|
|
}
|
|
|
|
|
2016-07-19 15:55:49 +00:00
|
|
|
delete(configData, "verify_connection")
|
2018-03-30 14:17:39 +00:00
|
|
|
delete(configData, "connection_string")
|
2016-06-11 15:48:40 +00:00
|
|
|
if !reflect.DeepEqual(configData, resp.Data) {
|
|
|
|
t.Fatalf("bad: expected:%#v\nactual:%#v\n", configData, resp.Data)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2016-03-03 14:19:17 +00:00
|
|
|
func TestBackend_basic(t *testing.T) {
|
2018-04-26 16:17:44 +00:00
|
|
|
if os.Getenv(logicaltest.TestEnvVar) == "" {
|
|
|
|
t.Skip(fmt.Sprintf("Acceptance tests skipped unless env '%s' set", logicaltest.TestEnvVar))
|
|
|
|
}
|
|
|
|
|
2018-01-19 06:44:44 +00:00
|
|
|
b, _ := Factory(context.Background(), logical.TestBackendConfig())
|
2016-03-03 14:19:17 +00:00
|
|
|
|
2018-04-09 14:46:52 +00:00
|
|
|
cleanup, connURL := prepareMSSQLTestContainer(t)
|
|
|
|
defer cleanup()
|
|
|
|
|
2016-03-03 14:19:17 +00:00
|
|
|
logicaltest.Test(t, logicaltest.TestCase{
|
2016-04-05 19:10:44 +00:00
|
|
|
AcceptanceTest: true,
|
2018-04-09 14:46:52 +00:00
|
|
|
PreCheck: testAccPreCheckFunc(t, connURL),
|
2018-11-07 01:21:24 +00:00
|
|
|
LogicalBackend: b,
|
2016-03-03 14:19:17 +00:00
|
|
|
Steps: []logicaltest.TestStep{
|
2018-04-09 14:46:52 +00:00
|
|
|
testAccStepConfig(t, connURL),
|
2016-03-03 14:19:17 +00:00
|
|
|
testAccStepRole(t),
|
|
|
|
testAccStepReadCreds(t, "web"),
|
|
|
|
},
|
|
|
|
})
|
|
|
|
}
|
|
|
|
|
|
|
|
func TestBackend_roleCrud(t *testing.T) {
|
2018-04-26 16:17:44 +00:00
|
|
|
if os.Getenv(logicaltest.TestEnvVar) == "" {
|
|
|
|
t.Skip(fmt.Sprintf("Acceptance tests skipped unless env '%s' set", logicaltest.TestEnvVar))
|
|
|
|
}
|
|
|
|
|
2016-03-03 14:19:17 +00:00
|
|
|
b := Backend()
|
|
|
|
|
2018-04-09 14:46:52 +00:00
|
|
|
cleanup, connURL := prepareMSSQLTestContainer(t)
|
|
|
|
defer cleanup()
|
|
|
|
|
2016-03-03 14:19:17 +00:00
|
|
|
logicaltest.Test(t, logicaltest.TestCase{
|
2016-04-05 19:10:44 +00:00
|
|
|
AcceptanceTest: true,
|
2018-04-09 14:46:52 +00:00
|
|
|
PreCheck: testAccPreCheckFunc(t, connURL),
|
2018-11-07 01:21:24 +00:00
|
|
|
LogicalBackend: b,
|
2016-03-03 14:19:17 +00:00
|
|
|
Steps: []logicaltest.TestStep{
|
2018-04-09 14:46:52 +00:00
|
|
|
testAccStepConfig(t, connURL),
|
2016-03-03 14:19:17 +00:00
|
|
|
testAccStepRole(t),
|
|
|
|
testAccStepReadRole(t, "web", testRoleSQL),
|
|
|
|
testAccStepDeleteRole(t, "web"),
|
|
|
|
testAccStepReadRole(t, "web", ""),
|
|
|
|
},
|
|
|
|
})
|
|
|
|
}
|
|
|
|
|
|
|
|
func TestBackend_leaseWriteRead(t *testing.T) {
|
2018-04-26 16:17:44 +00:00
|
|
|
if os.Getenv(logicaltest.TestEnvVar) == "" {
|
|
|
|
t.Skip(fmt.Sprintf("Acceptance tests skipped unless env '%s' set", logicaltest.TestEnvVar))
|
|
|
|
}
|
|
|
|
|
2016-03-03 14:19:17 +00:00
|
|
|
b := Backend()
|
|
|
|
|
2018-04-09 14:46:52 +00:00
|
|
|
cleanup, connURL := prepareMSSQLTestContainer(t)
|
|
|
|
defer cleanup()
|
|
|
|
|
2016-03-03 14:19:17 +00:00
|
|
|
logicaltest.Test(t, logicaltest.TestCase{
|
2016-04-05 19:10:44 +00:00
|
|
|
AcceptanceTest: true,
|
2018-04-09 14:46:52 +00:00
|
|
|
PreCheck: testAccPreCheckFunc(t, connURL),
|
2018-11-07 01:21:24 +00:00
|
|
|
LogicalBackend: b,
|
2016-03-03 14:19:17 +00:00
|
|
|
Steps: []logicaltest.TestStep{
|
2018-04-09 14:46:52 +00:00
|
|
|
testAccStepConfig(t, connURL),
|
2016-03-03 14:19:17 +00:00
|
|
|
testAccStepWriteLease(t),
|
|
|
|
testAccStepReadLease(t),
|
|
|
|
},
|
|
|
|
})
|
|
|
|
|
|
|
|
}
|
|
|
|
|
2018-04-09 14:46:52 +00:00
|
|
|
func testAccPreCheckFunc(t *testing.T, connectionURL string) func() {
|
|
|
|
return func() {
|
|
|
|
if connectionURL == "" {
|
|
|
|
t.Fatal("connection URL must be set for acceptance tests")
|
|
|
|
}
|
2016-03-03 14:19:17 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2018-04-09 14:46:52 +00:00
|
|
|
func testAccStepConfig(t *testing.T, connURL string) logicaltest.TestStep {
|
2016-03-03 14:19:17 +00:00
|
|
|
return logicaltest.TestStep{
|
|
|
|
Operation: logical.UpdateOperation,
|
|
|
|
Path: "config/connection",
|
|
|
|
Data: map[string]interface{}{
|
2018-04-09 14:46:52 +00:00
|
|
|
"connection_string": connURL,
|
2016-03-03 14:19:17 +00:00
|
|
|
},
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func testAccStepRole(t *testing.T) logicaltest.TestStep {
|
|
|
|
return logicaltest.TestStep{
|
|
|
|
Operation: logical.UpdateOperation,
|
|
|
|
Path: "roles/web",
|
|
|
|
Data: map[string]interface{}{
|
|
|
|
"sql": testRoleSQL,
|
|
|
|
},
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func testAccStepDeleteRole(t *testing.T, n string) logicaltest.TestStep {
|
|
|
|
return logicaltest.TestStep{
|
|
|
|
Operation: logical.DeleteOperation,
|
|
|
|
Path: "roles/" + n,
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func testAccStepReadCreds(t *testing.T, name string) logicaltest.TestStep {
|
|
|
|
return logicaltest.TestStep{
|
|
|
|
Operation: logical.ReadOperation,
|
|
|
|
Path: "creds/" + name,
|
|
|
|
Check: func(resp *logical.Response) error {
|
|
|
|
var d struct {
|
|
|
|
Username string `mapstructure:"username"`
|
|
|
|
Password string `mapstructure:"password"`
|
|
|
|
}
|
|
|
|
if err := mapstructure.Decode(resp.Data, &d); err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
log.Printf("[WARN] Generated credentials: %v", d)
|
|
|
|
|
|
|
|
return nil
|
|
|
|
},
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func testAccStepReadRole(t *testing.T, name, sql string) logicaltest.TestStep {
|
|
|
|
return logicaltest.TestStep{
|
|
|
|
Operation: logical.ReadOperation,
|
|
|
|
Path: "roles/" + name,
|
|
|
|
Check: func(resp *logical.Response) error {
|
|
|
|
if resp == nil {
|
|
|
|
if sql == "" {
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
|
|
|
return fmt.Errorf("bad: %#v", resp)
|
|
|
|
}
|
|
|
|
|
|
|
|
var d struct {
|
|
|
|
SQL string `mapstructure:"sql"`
|
|
|
|
}
|
|
|
|
if err := mapstructure.Decode(resp.Data, &d); err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
if d.SQL != sql {
|
|
|
|
return fmt.Errorf("bad: %#v", resp)
|
|
|
|
}
|
|
|
|
|
|
|
|
return nil
|
|
|
|
},
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func testAccStepWriteLease(t *testing.T) logicaltest.TestStep {
|
|
|
|
return logicaltest.TestStep{
|
|
|
|
Operation: logical.UpdateOperation,
|
|
|
|
Path: "config/lease",
|
|
|
|
Data: map[string]interface{}{
|
2016-03-11 02:15:18 +00:00
|
|
|
"ttl": "1h5m",
|
2016-09-20 16:39:02 +00:00
|
|
|
"max_ttl": "24h",
|
2016-03-03 14:19:17 +00:00
|
|
|
},
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func testAccStepReadLease(t *testing.T) logicaltest.TestStep {
|
|
|
|
return logicaltest.TestStep{
|
|
|
|
Operation: logical.ReadOperation,
|
|
|
|
Path: "config/lease",
|
|
|
|
Check: func(resp *logical.Response) error {
|
2016-09-20 16:39:02 +00:00
|
|
|
if resp.Data["ttl"] != "1h5m0s" || resp.Data["max_ttl"] != "24h0m0s" {
|
2016-03-03 14:19:17 +00:00
|
|
|
return fmt.Errorf("bad: %#v", resp)
|
|
|
|
}
|
|
|
|
|
|
|
|
return nil
|
|
|
|
},
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
const testRoleSQL = `
|
|
|
|
CREATE LOGIN [{{name}}] WITH PASSWORD = '{{password}}';
|
|
|
|
CREATE USER [{{name}}] FOR LOGIN [{{name}}];
|
|
|
|
GRANT SELECT ON SCHEMA::dbo TO [{{name}}]
|
|
|
|
`
|