| # |
| # Licensed to the Apache Software Foundation (ASF) under one or more |
| # contributor license agreements. See the NOTICE file distributed with |
| # this work for additional information regarding copyright ownership. |
| # The ASF licenses this file to You under the Apache License, Version 2.0 |
| # (the "License"); you may not use this file except in compliance with |
| # the License. You may obtain a copy of the License at |
| # |
| # http://www.apache.org/licenses/LICENSE-2.0 |
| # |
| # Unless required by applicable law or agreed to in writing, software |
| # distributed under the License is distributed on an "AS IS" BASIS, |
| # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
| # See the License for the specific language governing permissions and |
| # limitations under the License. |
| # |
| use t::APISIX 'no_plan'; |
| |
| repeat_each(1); |
| no_long_string(); |
| no_root_location(); |
| no_shuffle(); |
| log_level("info"); |
| |
| run_tests; |
| |
| __DATA__ |
| |
| === TEST 1: add consumer with username |
| --- config |
| location /t { |
| content_by_lua_block { |
| local t = require("lib.test_admin").test |
| local code, body = t('/apisix/admin/consumers', |
| ngx.HTTP_PUT, |
| [[{ |
| "username":"jack", |
| "desc": "new consumer" |
| }]], |
| [[{ |
| "value": { |
| "username": "jack", |
| "desc": "new consumer" |
| }, |
| "key": "/apisix/consumers/jack" |
| }]] |
| ) |
| |
| ngx.status = code |
| ngx.say(body) |
| } |
| } |
| --- request |
| GET /t |
| --- response_body |
| passed |
| |
| |
| |
| === TEST 2: update consumer with username and plugins |
| --- config |
| location /t { |
| content_by_lua_block { |
| local t = require("lib.test_admin").test |
| local etcd = require("apisix.core.etcd") |
| local res = assert(etcd.get('/consumers/jack')) |
| local prev_create_time = res.body.node.value.create_time |
| assert(prev_create_time ~= nil, "create_time is nil") |
| local update_time = res.body.node.value.update_time |
| assert(update_time ~= nil, "update_time is nil") |
| ngx.sleep(1) |
| |
| local code, body = t('/apisix/admin/consumers', |
| ngx.HTTP_PUT, |
| [[{ |
| "username": "jack", |
| "desc": "new consumer", |
| "plugins": { |
| "key-auth": { |
| "key": "auth-one" |
| } |
| } |
| }]], |
| [[{ |
| "value": { |
| "username": "jack", |
| "desc": "new consumer", |
| "plugins": { |
| "key-auth": { |
| "key": "4y+JvURBE6ZwRbbgaryrhg==" |
| } |
| } |
| }, |
| "key": "/apisix/consumers/jack" |
| }]] |
| ) |
| |
| ngx.status = code |
| ngx.say(body) |
| |
| local res = assert(etcd.get('/consumers/jack')) |
| local create_time = res.body.node.value.create_time |
| assert(prev_create_time == create_time, "create_time mismatched") |
| local update_time = res.body.node.value.update_time |
| assert(update_time ~= nil, "update_time is nil") |
| } |
| } |
| --- request |
| GET /t |
| --- response_body |
| passed |
| |
| |
| |
| === TEST 3: get consumer |
| --- config |
| location /t { |
| content_by_lua_block { |
| local t = require("lib.test_admin").test |
| local code, body = t('/apisix/admin/consumers/jack', |
| ngx.HTTP_GET, |
| nil, |
| [[{ |
| "value": { |
| "username": "jack", |
| "desc": "new consumer", |
| "plugins": { |
| "key-auth": { |
| "key": "auth-one" |
| } |
| } |
| }, |
| "key": "/apisix/consumers/jack" |
| }]] |
| ) |
| |
| ngx.status = code |
| ngx.say(body) |
| } |
| } |
| --- request |
| GET /t |
| --- response_body |
| passed |
| |
| |
| |
| === TEST 4: delete consumer |
| --- config |
| location /t { |
| content_by_lua_block { |
| ngx.sleep(0.3) |
| local t = require("lib.test_admin").test |
| local code, body = t('/apisix/admin/consumers/jack', |
| ngx.HTTP_DELETE |
| ) |
| |
| ngx.status = code |
| ngx.say(body) |
| } |
| } |
| --- request |
| GET /t |
| --- response_body |
| passed |
| |
| |
| |
| === TEST 5: delete consumer(id: not_found) |
| --- config |
| location /t { |
| content_by_lua_block { |
| local t = require("lib.test_admin").test |
| local code = t('/apisix/admin/consumers/not_found', |
| ngx.HTTP_DELETE, |
| nil |
| ) |
| ngx.say("[delete] code: ", code) |
| } |
| } |
| --- request |
| GET /t |
| --- response_body |
| [delete] code: 404 |
| |
| |
| |
| === TEST 6: missing username |
| --- config |
| location /t { |
| content_by_lua_block { |
| local t = require("lib.test_admin").test |
| local code, body = t('/apisix/admin/consumers', |
| ngx.HTTP_PUT, |
| [[{ |
| "id":"jack" |
| }]], |
| [[{ |
| "value": { |
| "id": "jack" |
| } |
| }]] |
| ) |
| |
| ngx.status = code |
| ngx.print(body) |
| } |
| } |
| --- request |
| GET /t |
| --- error_code: 400 |
| --- response_body |
| {"error_msg":"invalid configuration: property \"username\" is required"} |
| |
| |
| |
| === TEST 7: consumer username allows '-' in it |
| --- config |
| location /t { |
| content_by_lua_block { |
| local t = require("lib.test_admin").test |
| local code, body = t('/apisix/admin/consumers', |
| ngx.HTTP_PUT, |
| [[{ |
| "username":"Jack-and-Rose_123" |
| }]] |
| ) |
| |
| ngx.status = code |
| ngx.print(body) |
| } |
| } |
| --- request |
| GET /t |
| --- error_code: 201 |
| |
| |
| |
| === TEST 8: add consumer with labels |
| --- config |
| location /t { |
| content_by_lua_block { |
| local t = require("lib.test_admin").test |
| local code, body = t('/apisix/admin/consumers', |
| ngx.HTTP_PUT, |
| [[{ |
| "username":"jack", |
| "desc": "new consumer", |
| "labels": { |
| "build":"16", |
| "env":"production", |
| "version":"v2" |
| } |
| }]], |
| [[{ |
| "value": { |
| "username": "jack", |
| "desc": "new consumer", |
| "labels": { |
| "build":"16", |
| "env":"production", |
| "version":"v2" |
| } |
| }, |
| "key": "/apisix/consumers/jack" |
| }]] |
| ) |
| |
| ngx.status = code |
| ngx.say(body) |
| } |
| } |
| --- request |
| GET /t |
| --- response_body |
| passed |
| |
| |
| |
| === TEST 9: invalid format of label value: set consumer |
| --- config |
| location /t { |
| content_by_lua_block { |
| local t = require("lib.test_admin").test |
| local code, body = t('/apisix/admin/consumers', |
| ngx.HTTP_PUT, |
| [[{ |
| "username":"jack", |
| "desc": "new consumer", |
| "labels": { |
| "env": ["production", "release"] |
| } |
| }]] |
| ) |
| |
| ngx.status = code |
| ngx.print(body) |
| } |
| } |
| --- request |
| GET /t |
| --- error_code: 400 |
| --- response_body |
| {"error_msg":"invalid configuration: property \"labels\" validation failed: failed to validate env (matching \".*\"): wrong type: expected string, got table"} |
| |
| |
| |
| === TEST 10: post consumers |
| --- config |
| location /t { |
| content_by_lua_block { |
| local t = require("lib.test_admin").test |
| local code, body = t('/apisix/admin/consumers', |
| ngx.HTTP_POST, |
| "" |
| ) |
| |
| ngx.status = code |
| ngx.print(body) |
| } |
| } |
| --- request |
| GET /t |
| --- error_code: 405 |
| --- response_body |
| {"error_msg":"not supported `POST` method for consumer"} |
| |
| |
| |
| === TEST 11: add consumer with create_time and update_time(pony) |
| --- config |
| location /t { |
| content_by_lua_block { |
| local t = require("lib.test_admin").test |
| local code, body = t('/apisix/admin/consumers', |
| ngx.HTTP_PUT, |
| [[{ |
| "username":"pony", |
| "desc": "new consumer", |
| "create_time": 1602883670, |
| "update_time": 1602893670 |
| }]], |
| [[{ |
| "value": { |
| "username": "pony", |
| "desc": "new consumer", |
| "create_time": 1602883670, |
| "update_time": 1602893670 |
| }, |
| "key": "/apisix/consumers/pony" |
| }]] |
| ) |
| |
| ngx.status = code |
| ngx.say(body) |
| } |
| } |
| --- request |
| GET /t |
| --- error_code: 400 |
| --- response_body eval |
| qr/\{"error_msg":"the property is forbidden:.*"\}/ |
| |
| |
| |
| === TEST 12: add consumer case_a with key-auth key |
| --- config |
| location /t { |
| content_by_lua_block { |
| local t = require("lib.test_admin").test |
| local code, body = t('/apisix/admin/consumers', |
| ngx.HTTP_PUT, |
| [[{ |
| "username": "case_a", |
| "plugins": { |
| "key-auth": { |
| "key": "duplicate-check-key-1" |
| } |
| } |
| }]] |
| ) |
| |
| if code >= 300 then |
| ngx.status = code |
| end |
| ngx.say(body) |
| } |
| } |
| --- request |
| GET /t |
| --- response_body |
| passed |
| |
| |
| |
| === TEST 13: add consumer case_b with the same key-auth key, should fail |
| --- config |
| location /t { |
| content_by_lua_block { |
| local t = require("lib.test_admin").test |
| -- the duplicate check runs against the locally synced consumer |
| -- data, wait until the watcher catches up with the previous write |
| local find_consumer = require("apisix.consumer").find_consumer |
| for _ = 1, 100 do |
| if find_consumer("key-auth", "key", "duplicate-check-key-1") then |
| break |
| end |
| ngx.sleep(0.05) |
| end |
| |
| local code, body = t('/apisix/admin/consumers', |
| ngx.HTTP_PUT, |
| [[{ |
| "username": "case_b", |
| "plugins": { |
| "key-auth": { |
| "key": "duplicate-check-key-1" |
| } |
| } |
| }]] |
| ) |
| |
| ngx.status = code |
| ngx.print(body) |
| } |
| } |
| --- request |
| GET /t |
| --- error_code: 400 |
| --- response_body |
| {"error_msg":"duplicate key of plugin key-auth found with consumer: case_a"} |
| |
| |
| |
| === TEST 14: add consumer case_b with a different key-auth key, should success |
| --- config |
| location /t { |
| content_by_lua_block { |
| local t = require("lib.test_admin").test |
| local code, body = t('/apisix/admin/consumers', |
| ngx.HTTP_PUT, |
| [[{ |
| "username": "case_b", |
| "plugins": { |
| "key-auth": { |
| "key": "duplicate-check-key-2" |
| } |
| } |
| }]] |
| ) |
| |
| if code >= 300 then |
| ngx.status = code |
| end |
| ngx.say(body) |
| } |
| } |
| --- request |
| GET /t |
| --- response_body |
| passed |
| |
| |
| |
| === TEST 15: update consumer case_a with its own key unchanged, should success |
| --- config |
| location /t { |
| content_by_lua_block { |
| local t = require("lib.test_admin").test |
| local code, body = t('/apisix/admin/consumers', |
| ngx.HTTP_PUT, |
| [[{ |
| "username": "case_a", |
| "desc": "updated description", |
| "plugins": { |
| "key-auth": { |
| "key": "duplicate-check-key-1" |
| } |
| } |
| }]] |
| ) |
| |
| if code >= 300 then |
| ngx.status = code |
| end |
| ngx.say(body) |
| } |
| } |
| --- request |
| GET /t |
| --- response_body |
| passed |
| |
| |
| |
| === TEST 16: duplicate basic-auth username between consumers, should fail |
| --- config |
| location /t { |
| content_by_lua_block { |
| local t = require("lib.test_admin").test |
| local code, body = t('/apisix/admin/consumers', |
| ngx.HTTP_PUT, |
| [[{ |
| "username": "case_c", |
| "plugins": { |
| "basic-auth": { |
| "username": "case-user", |
| "password": "the-password" |
| } |
| } |
| }]] |
| ) |
| if code >= 300 then |
| ngx.status = code |
| ngx.say(body) |
| return |
| end |
| |
| -- the duplicate check runs against the locally synced consumer |
| -- data, wait until the watcher catches up with the previous write |
| local find_consumer = require("apisix.consumer").find_consumer |
| for _ = 1, 100 do |
| if find_consumer("basic-auth", "username", "case-user") then |
| break |
| end |
| ngx.sleep(0.05) |
| end |
| |
| local code, body = t('/apisix/admin/consumers', |
| ngx.HTTP_PUT, |
| [[{ |
| "username": "case_d", |
| "plugins": { |
| "basic-auth": { |
| "username": "case-user", |
| "password": "another-password" |
| } |
| } |
| }]] |
| ) |
| |
| ngx.status = code |
| ngx.print(body) |
| } |
| } |
| --- request |
| GET /t |
| --- error_code: 400 |
| --- response_body |
| {"error_msg":"duplicate username of plugin basic-auth found with consumer: case_c"} |
| |
| |
| |
| === TEST 17: store consumer with data_encryption explicitly enabled |
| --- extra_yaml_config |
| apisix: |
| data_encryption: |
| enable_encrypt_fields: true |
| keyring: |
| - qeddd145sfvddff3 |
| --- config |
| location /t { |
| content_by_lua_block { |
| local t = require("lib.test_admin").test |
| local code, body = t('/apisix/admin/consumers', |
| ngx.HTTP_PUT, |
| [[{ |
| "username": "enc_case_a", |
| "plugins": { |
| "key-auth": { |
| "key": "duplicate-check-enc-key" |
| } |
| } |
| }]] |
| ) |
| |
| if code >= 300 then |
| ngx.status = code |
| end |
| ngx.say(body) |
| } |
| } |
| --- request |
| GET /t |
| --- response_body |
| passed |
| |
| |
| |
| === TEST 18: duplicate key against the stored encrypted consumer, should fail |
| --- extra_yaml_config |
| apisix: |
| data_encryption: |
| enable_encrypt_fields: true |
| keyring: |
| - qeddd145sfvddff3 |
| --- config |
| location /t { |
| content_by_lua_block { |
| local t = require("lib.test_admin").test |
| -- the duplicate check runs against the locally synced consumer |
| -- data, wait until the watcher catches up with the previous write |
| local find_consumer = require("apisix.consumer").find_consumer |
| for _ = 1, 100 do |
| if find_consumer("key-auth", "key", "duplicate-check-enc-key") then |
| break |
| end |
| ngx.sleep(0.05) |
| end |
| |
| local code, body = t('/apisix/admin/consumers', |
| ngx.HTTP_PUT, |
| [[{ |
| "username": "enc_case_b", |
| "plugins": { |
| "key-auth": { |
| "key": "duplicate-check-enc-key" |
| } |
| } |
| }]] |
| ) |
| |
| ngx.status = code |
| ngx.print(body) |
| } |
| } |
| --- request |
| GET /t |
| --- error_code: 400 |
| --- response_body |
| {"error_msg":"duplicate key of plugin key-auth found with consumer: enc_case_a"} |
| |
| |
| |
| === TEST 19: add consumer ldap_case_a with ldap-auth user_dn |
| --- config |
| location /t { |
| content_by_lua_block { |
| local t = require("lib.test_admin").test |
| local code, body = t('/apisix/admin/consumers', |
| ngx.HTTP_PUT, |
| [[{ |
| "username": "ldap_case_a", |
| "plugins": { |
| "ldap-auth": { |
| "user_dn": "cn=duplicate-check,ou=users,dc=example,dc=org" |
| } |
| } |
| }]] |
| ) |
| |
| if code >= 300 then |
| ngx.status = code |
| end |
| ngx.say(body) |
| } |
| } |
| --- request |
| GET /t |
| --- response_body |
| passed |
| |
| |
| |
| === TEST 20: add consumer ldap_case_b with the same ldap-auth user_dn, should fail |
| --- config |
| location /t { |
| content_by_lua_block { |
| local t = require("lib.test_admin").test |
| -- the duplicate check runs against the locally synced consumer |
| -- data, wait until the watcher catches up with the previous write |
| local find_consumer = require("apisix.consumer").find_consumer |
| for _ = 1, 100 do |
| if find_consumer("ldap-auth", "user_dn", |
| "cn=duplicate-check,ou=users,dc=example,dc=org") then |
| break |
| end |
| ngx.sleep(0.05) |
| end |
| |
| local code, body = t('/apisix/admin/consumers', |
| ngx.HTTP_PUT, |
| [[{ |
| "username": "ldap_case_b", |
| "plugins": { |
| "ldap-auth": { |
| "user_dn": "cn=duplicate-check,ou=users,dc=example,dc=org" |
| } |
| } |
| }]] |
| ) |
| |
| ngx.status = code |
| ngx.print(body) |
| } |
| } |
| --- request |
| GET /t |
| --- error_code: 400 |
| --- response_body |
| {"error_msg":"duplicate user_dn of plugin ldap-auth found with consumer: ldap_case_a"} |
| |
| |
| |
| === TEST 21: add consumer adv_case_a with ldap-auth-advanced user_dn |
| --- config |
| location /t { |
| content_by_lua_block { |
| local t = require("lib.test_admin").test |
| local code, body = t('/apisix/admin/consumers', |
| ngx.HTTP_PUT, |
| [[{ |
| "username": "adv_case_a", |
| "plugins": { |
| "ldap-auth-advanced": { |
| "user_dn": "cn=adv-duplicate-check,ou=users,dc=example,dc=org" |
| } |
| } |
| }]] |
| ) |
| |
| if code >= 300 then |
| ngx.status = code |
| end |
| ngx.say(body) |
| } |
| } |
| --- request |
| GET /t |
| --- response_body |
| passed |
| |
| |
| |
| === TEST 22: add consumer adv_case_b with the same ldap-auth-advanced user_dn, should fail |
| --- config |
| location /t { |
| content_by_lua_block { |
| local t = require("lib.test_admin").test |
| -- the duplicate check runs against the locally synced consumer |
| -- data, wait until the watcher catches up with the previous write |
| local find_consumer = require("apisix.consumer").find_consumer |
| for _ = 1, 100 do |
| if find_consumer("ldap-auth-advanced", "user_dn", |
| "cn=adv-duplicate-check,ou=users,dc=example,dc=org") then |
| break |
| end |
| ngx.sleep(0.05) |
| end |
| |
| local code, body = t('/apisix/admin/consumers', |
| ngx.HTTP_PUT, |
| [[{ |
| "username": "adv_case_b", |
| "plugins": { |
| "ldap-auth-advanced": { |
| "user_dn": "cn=adv-duplicate-check,ou=users,dc=example,dc=org" |
| } |
| } |
| }]] |
| ) |
| |
| ngx.status = code |
| ngx.print(body) |
| } |
| } |
| --- request |
| GET /t |
| --- error_code: 400 |
| --- response_body |
| {"error_msg":"duplicate user_dn of plugin ldap-auth-advanced found with consumer: adv_case_a"} |
| |
| |
| |
| === TEST 23: clean up consumers |
| --- config |
| location /t { |
| content_by_lua_block { |
| local t = require("lib.test_admin").test |
| for _, name in ipairs({"case_a", "case_b", "case_c", "enc_case_a", "ldap_case_a", |
| "adv_case_a"}) do |
| local code, body = t('/apisix/admin/consumers/' .. name, ngx.HTTP_DELETE) |
| if code >= 300 then |
| ngx.say("failed to delete consumer ", name, ": ", body) |
| return |
| end |
| end |
| ngx.say("passed") |
| } |
| } |
| --- request |
| GET /t |
| --- response_body |
| passed |