blob: fd958885d3029450c3e476e97bd09ec66397c755 [file]
#
# Licensed to the Apache Software Foundation (ASF) under one or more
# contributor license agreements. See the NOTICE file distributed with
# this work for additional information regarding copyright ownership.
# The ASF licenses this file to You under the Apache License, Version 2.0
# (the "License"); you may not use this file except in compliance with
# the License. You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
#
use t::APISIX 'no_plan';
repeat_each(1);
no_long_string();
no_root_location();
no_shuffle();
log_level("info");
run_tests;
__DATA__
=== TEST 1: add consumer with username
--- config
location /t {
content_by_lua_block {
local t = require("lib.test_admin").test
local code, body = t('/apisix/admin/consumers',
ngx.HTTP_PUT,
[[{
"username":"jack",
"desc": "new consumer"
}]],
[[{
"value": {
"username": "jack",
"desc": "new consumer"
},
"key": "/apisix/consumers/jack"
}]]
)
ngx.status = code
ngx.say(body)
}
}
--- request
GET /t
--- response_body
passed
=== TEST 2: update consumer with username and plugins
--- config
location /t {
content_by_lua_block {
local t = require("lib.test_admin").test
local etcd = require("apisix.core.etcd")
local res = assert(etcd.get('/consumers/jack'))
local prev_create_time = res.body.node.value.create_time
assert(prev_create_time ~= nil, "create_time is nil")
local update_time = res.body.node.value.update_time
assert(update_time ~= nil, "update_time is nil")
ngx.sleep(1)
local code, body = t('/apisix/admin/consumers',
ngx.HTTP_PUT,
[[{
"username": "jack",
"desc": "new consumer",
"plugins": {
"key-auth": {
"key": "auth-one"
}
}
}]],
[[{
"value": {
"username": "jack",
"desc": "new consumer",
"plugins": {
"key-auth": {
"key": "4y+JvURBE6ZwRbbgaryrhg=="
}
}
},
"key": "/apisix/consumers/jack"
}]]
)
ngx.status = code
ngx.say(body)
local res = assert(etcd.get('/consumers/jack'))
local create_time = res.body.node.value.create_time
assert(prev_create_time == create_time, "create_time mismatched")
local update_time = res.body.node.value.update_time
assert(update_time ~= nil, "update_time is nil")
}
}
--- request
GET /t
--- response_body
passed
=== TEST 3: get consumer
--- config
location /t {
content_by_lua_block {
local t = require("lib.test_admin").test
local code, body = t('/apisix/admin/consumers/jack',
ngx.HTTP_GET,
nil,
[[{
"value": {
"username": "jack",
"desc": "new consumer",
"plugins": {
"key-auth": {
"key": "auth-one"
}
}
},
"key": "/apisix/consumers/jack"
}]]
)
ngx.status = code
ngx.say(body)
}
}
--- request
GET /t
--- response_body
passed
=== TEST 4: delete consumer
--- config
location /t {
content_by_lua_block {
ngx.sleep(0.3)
local t = require("lib.test_admin").test
local code, body = t('/apisix/admin/consumers/jack',
ngx.HTTP_DELETE
)
ngx.status = code
ngx.say(body)
}
}
--- request
GET /t
--- response_body
passed
=== TEST 5: delete consumer(id: not_found)
--- config
location /t {
content_by_lua_block {
local t = require("lib.test_admin").test
local code = t('/apisix/admin/consumers/not_found',
ngx.HTTP_DELETE,
nil
)
ngx.say("[delete] code: ", code)
}
}
--- request
GET /t
--- response_body
[delete] code: 404
=== TEST 6: missing username
--- config
location /t {
content_by_lua_block {
local t = require("lib.test_admin").test
local code, body = t('/apisix/admin/consumers',
ngx.HTTP_PUT,
[[{
"id":"jack"
}]],
[[{
"value": {
"id": "jack"
}
}]]
)
ngx.status = code
ngx.print(body)
}
}
--- request
GET /t
--- error_code: 400
--- response_body
{"error_msg":"invalid configuration: property \"username\" is required"}
=== TEST 7: consumer username allows '-' in it
--- config
location /t {
content_by_lua_block {
local t = require("lib.test_admin").test
local code, body = t('/apisix/admin/consumers',
ngx.HTTP_PUT,
[[{
"username":"Jack-and-Rose_123"
}]]
)
ngx.status = code
ngx.print(body)
}
}
--- request
GET /t
--- error_code: 201
=== TEST 8: add consumer with labels
--- config
location /t {
content_by_lua_block {
local t = require("lib.test_admin").test
local code, body = t('/apisix/admin/consumers',
ngx.HTTP_PUT,
[[{
"username":"jack",
"desc": "new consumer",
"labels": {
"build":"16",
"env":"production",
"version":"v2"
}
}]],
[[{
"value": {
"username": "jack",
"desc": "new consumer",
"labels": {
"build":"16",
"env":"production",
"version":"v2"
}
},
"key": "/apisix/consumers/jack"
}]]
)
ngx.status = code
ngx.say(body)
}
}
--- request
GET /t
--- response_body
passed
=== TEST 9: invalid format of label value: set consumer
--- config
location /t {
content_by_lua_block {
local t = require("lib.test_admin").test
local code, body = t('/apisix/admin/consumers',
ngx.HTTP_PUT,
[[{
"username":"jack",
"desc": "new consumer",
"labels": {
"env": ["production", "release"]
}
}]]
)
ngx.status = code
ngx.print(body)
}
}
--- request
GET /t
--- error_code: 400
--- response_body
{"error_msg":"invalid configuration: property \"labels\" validation failed: failed to validate env (matching \".*\"): wrong type: expected string, got table"}
=== TEST 10: post consumers
--- config
location /t {
content_by_lua_block {
local t = require("lib.test_admin").test
local code, body = t('/apisix/admin/consumers',
ngx.HTTP_POST,
""
)
ngx.status = code
ngx.print(body)
}
}
--- request
GET /t
--- error_code: 405
--- response_body
{"error_msg":"not supported `POST` method for consumer"}
=== TEST 11: add consumer with create_time and update_time(pony)
--- config
location /t {
content_by_lua_block {
local t = require("lib.test_admin").test
local code, body = t('/apisix/admin/consumers',
ngx.HTTP_PUT,
[[{
"username":"pony",
"desc": "new consumer",
"create_time": 1602883670,
"update_time": 1602893670
}]],
[[{
"value": {
"username": "pony",
"desc": "new consumer",
"create_time": 1602883670,
"update_time": 1602893670
},
"key": "/apisix/consumers/pony"
}]]
)
ngx.status = code
ngx.say(body)
}
}
--- request
GET /t
--- error_code: 400
--- response_body eval
qr/\{"error_msg":"the property is forbidden:.*"\}/
=== TEST 12: add consumer case_a with key-auth key
--- config
location /t {
content_by_lua_block {
local t = require("lib.test_admin").test
local code, body = t('/apisix/admin/consumers',
ngx.HTTP_PUT,
[[{
"username": "case_a",
"plugins": {
"key-auth": {
"key": "duplicate-check-key-1"
}
}
}]]
)
if code >= 300 then
ngx.status = code
end
ngx.say(body)
}
}
--- request
GET /t
--- response_body
passed
=== TEST 13: add consumer case_b with the same key-auth key, should fail
--- config
location /t {
content_by_lua_block {
local t = require("lib.test_admin").test
-- the duplicate check runs against the locally synced consumer
-- data, wait until the watcher catches up with the previous write
local find_consumer = require("apisix.consumer").find_consumer
for _ = 1, 100 do
if find_consumer("key-auth", "key", "duplicate-check-key-1") then
break
end
ngx.sleep(0.05)
end
local code, body = t('/apisix/admin/consumers',
ngx.HTTP_PUT,
[[{
"username": "case_b",
"plugins": {
"key-auth": {
"key": "duplicate-check-key-1"
}
}
}]]
)
ngx.status = code
ngx.print(body)
}
}
--- request
GET /t
--- error_code: 400
--- response_body
{"error_msg":"duplicate key of plugin key-auth found with consumer: case_a"}
=== TEST 14: add consumer case_b with a different key-auth key, should success
--- config
location /t {
content_by_lua_block {
local t = require("lib.test_admin").test
local code, body = t('/apisix/admin/consumers',
ngx.HTTP_PUT,
[[{
"username": "case_b",
"plugins": {
"key-auth": {
"key": "duplicate-check-key-2"
}
}
}]]
)
if code >= 300 then
ngx.status = code
end
ngx.say(body)
}
}
--- request
GET /t
--- response_body
passed
=== TEST 15: update consumer case_a with its own key unchanged, should success
--- config
location /t {
content_by_lua_block {
local t = require("lib.test_admin").test
local code, body = t('/apisix/admin/consumers',
ngx.HTTP_PUT,
[[{
"username": "case_a",
"desc": "updated description",
"plugins": {
"key-auth": {
"key": "duplicate-check-key-1"
}
}
}]]
)
if code >= 300 then
ngx.status = code
end
ngx.say(body)
}
}
--- request
GET /t
--- response_body
passed
=== TEST 16: duplicate basic-auth username between consumers, should fail
--- config
location /t {
content_by_lua_block {
local t = require("lib.test_admin").test
local code, body = t('/apisix/admin/consumers',
ngx.HTTP_PUT,
[[{
"username": "case_c",
"plugins": {
"basic-auth": {
"username": "case-user",
"password": "the-password"
}
}
}]]
)
if code >= 300 then
ngx.status = code
ngx.say(body)
return
end
-- the duplicate check runs against the locally synced consumer
-- data, wait until the watcher catches up with the previous write
local find_consumer = require("apisix.consumer").find_consumer
for _ = 1, 100 do
if find_consumer("basic-auth", "username", "case-user") then
break
end
ngx.sleep(0.05)
end
local code, body = t('/apisix/admin/consumers',
ngx.HTTP_PUT,
[[{
"username": "case_d",
"plugins": {
"basic-auth": {
"username": "case-user",
"password": "another-password"
}
}
}]]
)
ngx.status = code
ngx.print(body)
}
}
--- request
GET /t
--- error_code: 400
--- response_body
{"error_msg":"duplicate username of plugin basic-auth found with consumer: case_c"}
=== TEST 17: store consumer with data_encryption explicitly enabled
--- extra_yaml_config
apisix:
data_encryption:
enable_encrypt_fields: true
keyring:
- qeddd145sfvddff3
--- config
location /t {
content_by_lua_block {
local t = require("lib.test_admin").test
local code, body = t('/apisix/admin/consumers',
ngx.HTTP_PUT,
[[{
"username": "enc_case_a",
"plugins": {
"key-auth": {
"key": "duplicate-check-enc-key"
}
}
}]]
)
if code >= 300 then
ngx.status = code
end
ngx.say(body)
}
}
--- request
GET /t
--- response_body
passed
=== TEST 18: duplicate key against the stored encrypted consumer, should fail
--- extra_yaml_config
apisix:
data_encryption:
enable_encrypt_fields: true
keyring:
- qeddd145sfvddff3
--- config
location /t {
content_by_lua_block {
local t = require("lib.test_admin").test
-- the duplicate check runs against the locally synced consumer
-- data, wait until the watcher catches up with the previous write
local find_consumer = require("apisix.consumer").find_consumer
for _ = 1, 100 do
if find_consumer("key-auth", "key", "duplicate-check-enc-key") then
break
end
ngx.sleep(0.05)
end
local code, body = t('/apisix/admin/consumers',
ngx.HTTP_PUT,
[[{
"username": "enc_case_b",
"plugins": {
"key-auth": {
"key": "duplicate-check-enc-key"
}
}
}]]
)
ngx.status = code
ngx.print(body)
}
}
--- request
GET /t
--- error_code: 400
--- response_body
{"error_msg":"duplicate key of plugin key-auth found with consumer: enc_case_a"}
=== TEST 19: add consumer ldap_case_a with ldap-auth user_dn
--- config
location /t {
content_by_lua_block {
local t = require("lib.test_admin").test
local code, body = t('/apisix/admin/consumers',
ngx.HTTP_PUT,
[[{
"username": "ldap_case_a",
"plugins": {
"ldap-auth": {
"user_dn": "cn=duplicate-check,ou=users,dc=example,dc=org"
}
}
}]]
)
if code >= 300 then
ngx.status = code
end
ngx.say(body)
}
}
--- request
GET /t
--- response_body
passed
=== TEST 20: add consumer ldap_case_b with the same ldap-auth user_dn, should fail
--- config
location /t {
content_by_lua_block {
local t = require("lib.test_admin").test
-- the duplicate check runs against the locally synced consumer
-- data, wait until the watcher catches up with the previous write
local find_consumer = require("apisix.consumer").find_consumer
for _ = 1, 100 do
if find_consumer("ldap-auth", "user_dn",
"cn=duplicate-check,ou=users,dc=example,dc=org") then
break
end
ngx.sleep(0.05)
end
local code, body = t('/apisix/admin/consumers',
ngx.HTTP_PUT,
[[{
"username": "ldap_case_b",
"plugins": {
"ldap-auth": {
"user_dn": "cn=duplicate-check,ou=users,dc=example,dc=org"
}
}
}]]
)
ngx.status = code
ngx.print(body)
}
}
--- request
GET /t
--- error_code: 400
--- response_body
{"error_msg":"duplicate user_dn of plugin ldap-auth found with consumer: ldap_case_a"}
=== TEST 21: add consumer adv_case_a with ldap-auth-advanced user_dn
--- config
location /t {
content_by_lua_block {
local t = require("lib.test_admin").test
local code, body = t('/apisix/admin/consumers',
ngx.HTTP_PUT,
[[{
"username": "adv_case_a",
"plugins": {
"ldap-auth-advanced": {
"user_dn": "cn=adv-duplicate-check,ou=users,dc=example,dc=org"
}
}
}]]
)
if code >= 300 then
ngx.status = code
end
ngx.say(body)
}
}
--- request
GET /t
--- response_body
passed
=== TEST 22: add consumer adv_case_b with the same ldap-auth-advanced user_dn, should fail
--- config
location /t {
content_by_lua_block {
local t = require("lib.test_admin").test
-- the duplicate check runs against the locally synced consumer
-- data, wait until the watcher catches up with the previous write
local find_consumer = require("apisix.consumer").find_consumer
for _ = 1, 100 do
if find_consumer("ldap-auth-advanced", "user_dn",
"cn=adv-duplicate-check,ou=users,dc=example,dc=org") then
break
end
ngx.sleep(0.05)
end
local code, body = t('/apisix/admin/consumers',
ngx.HTTP_PUT,
[[{
"username": "adv_case_b",
"plugins": {
"ldap-auth-advanced": {
"user_dn": "cn=adv-duplicate-check,ou=users,dc=example,dc=org"
}
}
}]]
)
ngx.status = code
ngx.print(body)
}
}
--- request
GET /t
--- error_code: 400
--- response_body
{"error_msg":"duplicate user_dn of plugin ldap-auth-advanced found with consumer: adv_case_a"}
=== TEST 23: clean up consumers
--- config
location /t {
content_by_lua_block {
local t = require("lib.test_admin").test
for _, name in ipairs({"case_a", "case_b", "case_c", "enc_case_a", "ldap_case_a",
"adv_case_a"}) do
local code, body = t('/apisix/admin/consumers/' .. name, ngx.HTTP_DELETE)
if code >= 300 then
ngx.say("failed to delete consumer ", name, ": ", body)
return
end
end
ngx.say("passed")
}
}
--- request
GET /t
--- response_body
passed