blob: 0f047c0f2e36b5d2630e8de297e26802162c6750 [file] [log] [blame]
<!DOCTYPE HTML>
<html lang="en">
<head>
<!-- Generated by javadoc (17) -->
<title>Source code</title>
<meta name="viewport" content="width=device-width, initial-scale=1">
<meta name="description" content="source: package: org.apache.hadoop.hbase.http, class: TestInfoServersACL">
<meta name="generator" content="javadoc/SourceToHTMLConverter">
<link rel="stylesheet" type="text/css" href="../../../../../../stylesheet.css" title="Style">
</head>
<body class="source-page">
<main role="main">
<div class="source-container">
<pre><span class="source-line-no">001</span><span id="line-1">/*</span>
<span class="source-line-no">002</span><span id="line-2"> * Licensed to the Apache Software Foundation (ASF) under one</span>
<span class="source-line-no">003</span><span id="line-3"> * or more contributor license agreements. See the NOTICE file</span>
<span class="source-line-no">004</span><span id="line-4"> * distributed with this work for additional information</span>
<span class="source-line-no">005</span><span id="line-5"> * regarding copyright ownership. The ASF licenses this file</span>
<span class="source-line-no">006</span><span id="line-6"> * to you under the Apache License, Version 2.0 (the</span>
<span class="source-line-no">007</span><span id="line-7"> * "License"); you may not use this file except in compliance</span>
<span class="source-line-no">008</span><span id="line-8"> * with the License. You may obtain a copy of the License at</span>
<span class="source-line-no">009</span><span id="line-9"> *</span>
<span class="source-line-no">010</span><span id="line-10"> * http://www.apache.org/licenses/LICENSE-2.0</span>
<span class="source-line-no">011</span><span id="line-11"> *</span>
<span class="source-line-no">012</span><span id="line-12"> * Unless required by applicable law or agreed to in writing, software</span>
<span class="source-line-no">013</span><span id="line-13"> * distributed under the License is distributed on an "AS IS" BASIS,</span>
<span class="source-line-no">014</span><span id="line-14"> * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.</span>
<span class="source-line-no">015</span><span id="line-15"> * See the License for the specific language governing permissions and</span>
<span class="source-line-no">016</span><span id="line-16"> * limitations under the License.</span>
<span class="source-line-no">017</span><span id="line-17"> */</span>
<span class="source-line-no">018</span><span id="line-18">package org.apache.hadoop.hbase.http;</span>
<span class="source-line-no">019</span><span id="line-19"></span>
<span class="source-line-no">020</span><span id="line-20">import static org.junit.Assert.assertEquals;</span>
<span class="source-line-no">021</span><span id="line-21">import static org.junit.Assert.assertFalse;</span>
<span class="source-line-no">022</span><span id="line-22">import static org.junit.Assert.assertTrue;</span>
<span class="source-line-no">023</span><span id="line-23"></span>
<span class="source-line-no">024</span><span id="line-24">import java.io.File;</span>
<span class="source-line-no">025</span><span id="line-25">import java.lang.management.ManagementFactory;</span>
<span class="source-line-no">026</span><span id="line-26">import java.net.HttpURLConnection;</span>
<span class="source-line-no">027</span><span id="line-27">import java.net.URL;</span>
<span class="source-line-no">028</span><span id="line-28">import java.security.PrivilegedExceptionAction;</span>
<span class="source-line-no">029</span><span id="line-29">import javax.management.ObjectName;</span>
<span class="source-line-no">030</span><span id="line-30">import org.apache.hadoop.conf.Configuration;</span>
<span class="source-line-no">031</span><span id="line-31">import org.apache.hadoop.fs.CommonConfigurationKeys;</span>
<span class="source-line-no">032</span><span id="line-32">import org.apache.hadoop.fs.Path;</span>
<span class="source-line-no">033</span><span id="line-33">import org.apache.hadoop.hbase.HBaseClassTestRule;</span>
<span class="source-line-no">034</span><span id="line-34">import org.apache.hadoop.hbase.HBaseTestingUtil;</span>
<span class="source-line-no">035</span><span id="line-35">import org.apache.hadoop.hbase.HConstants;</span>
<span class="source-line-no">036</span><span id="line-36">import org.apache.hadoop.hbase.LocalHBaseCluster;</span>
<span class="source-line-no">037</span><span id="line-37">import org.apache.hadoop.hbase.TableName;</span>
<span class="source-line-no">038</span><span id="line-38">import org.apache.hadoop.hbase.Waiter;</span>
<span class="source-line-no">039</span><span id="line-39">import org.apache.hadoop.hbase.coprocessor.CoprocessorHost;</span>
<span class="source-line-no">040</span><span id="line-40">import org.apache.hadoop.hbase.security.HBaseKerberosUtils;</span>
<span class="source-line-no">041</span><span id="line-41">import org.apache.hadoop.hbase.security.token.TokenProvider;</span>
<span class="source-line-no">042</span><span id="line-42">import org.apache.hadoop.hbase.testclassification.MediumTests;</span>
<span class="source-line-no">043</span><span id="line-43">import org.apache.hadoop.hbase.testclassification.MiscTests;</span>
<span class="source-line-no">044</span><span id="line-44">import org.apache.hadoop.hbase.util.CommonFSUtils;</span>
<span class="source-line-no">045</span><span id="line-45">import org.apache.hadoop.hbase.util.Pair;</span>
<span class="source-line-no">046</span><span id="line-46">import org.apache.hadoop.minikdc.MiniKdc;</span>
<span class="source-line-no">047</span><span id="line-47">import org.apache.hadoop.security.UserGroupInformation;</span>
<span class="source-line-no">048</span><span id="line-48">import org.apache.http.auth.AuthSchemeProvider;</span>
<span class="source-line-no">049</span><span id="line-49">import org.apache.http.auth.AuthScope;</span>
<span class="source-line-no">050</span><span id="line-50">import org.apache.http.auth.KerberosCredentials;</span>
<span class="source-line-no">051</span><span id="line-51">import org.apache.http.client.config.AuthSchemes;</span>
<span class="source-line-no">052</span><span id="line-52">import org.apache.http.client.methods.CloseableHttpResponse;</span>
<span class="source-line-no">053</span><span id="line-53">import org.apache.http.client.methods.HttpGet;</span>
<span class="source-line-no">054</span><span id="line-54">import org.apache.http.config.Lookup;</span>
<span class="source-line-no">055</span><span id="line-55">import org.apache.http.config.RegistryBuilder;</span>
<span class="source-line-no">056</span><span id="line-56">import org.apache.http.impl.auth.SPNegoSchemeFactory;</span>
<span class="source-line-no">057</span><span id="line-57">import org.apache.http.impl.client.BasicCredentialsProvider;</span>
<span class="source-line-no">058</span><span id="line-58">import org.apache.http.impl.client.CloseableHttpClient;</span>
<span class="source-line-no">059</span><span id="line-59">import org.apache.http.impl.client.HttpClients;</span>
<span class="source-line-no">060</span><span id="line-60">import org.apache.http.util.EntityUtils;</span>
<span class="source-line-no">061</span><span id="line-61">import org.ietf.jgss.GSSCredential;</span>
<span class="source-line-no">062</span><span id="line-62">import org.ietf.jgss.GSSManager;</span>
<span class="source-line-no">063</span><span id="line-63">import org.ietf.jgss.GSSName;</span>
<span class="source-line-no">064</span><span id="line-64">import org.ietf.jgss.Oid;</span>
<span class="source-line-no">065</span><span id="line-65">import org.junit.AfterClass;</span>
<span class="source-line-no">066</span><span id="line-66">import org.junit.BeforeClass;</span>
<span class="source-line-no">067</span><span id="line-67">import org.junit.ClassRule;</span>
<span class="source-line-no">068</span><span id="line-68">import org.junit.Rule;</span>
<span class="source-line-no">069</span><span id="line-69">import org.junit.Test;</span>
<span class="source-line-no">070</span><span id="line-70">import org.junit.experimental.categories.Category;</span>
<span class="source-line-no">071</span><span id="line-71">import org.junit.rules.TestName;</span>
<span class="source-line-no">072</span><span id="line-72">import org.slf4j.Logger;</span>
<span class="source-line-no">073</span><span id="line-73">import org.slf4j.LoggerFactory;</span>
<span class="source-line-no">074</span><span id="line-74"></span>
<span class="source-line-no">075</span><span id="line-75">/**</span>
<span class="source-line-no">076</span><span id="line-76"> * Testing info servers for admin acl.</span>
<span class="source-line-no">077</span><span id="line-77"> */</span>
<span class="source-line-no">078</span><span id="line-78">@Category({ MiscTests.class, MediumTests.class })</span>
<span class="source-line-no">079</span><span id="line-79">public class TestInfoServersACL {</span>
<span class="source-line-no">080</span><span id="line-80"></span>
<span class="source-line-no">081</span><span id="line-81"> @ClassRule</span>
<span class="source-line-no">082</span><span id="line-82"> public static final HBaseClassTestRule CLASS_RULE =</span>
<span class="source-line-no">083</span><span id="line-83"> HBaseClassTestRule.forClass(TestInfoServersACL.class);</span>
<span class="source-line-no">084</span><span id="line-84"></span>
<span class="source-line-no">085</span><span id="line-85"> private static final Logger LOG = LoggerFactory.getLogger(TestInfoServersACL.class);</span>
<span class="source-line-no">086</span><span id="line-86"> private final static HBaseTestingUtil UTIL = new HBaseTestingUtil();</span>
<span class="source-line-no">087</span><span id="line-87"> private static Configuration conf;</span>
<span class="source-line-no">088</span><span id="line-88"></span>
<span class="source-line-no">089</span><span id="line-89"> protected static String USERNAME;</span>
<span class="source-line-no">090</span><span id="line-90"> private static LocalHBaseCluster CLUSTER;</span>
<span class="source-line-no">091</span><span id="line-91"> private static final File KEYTAB_FILE = new File(UTIL.getDataTestDir("keytab").toUri().getPath());</span>
<span class="source-line-no">092</span><span id="line-92"> private static MiniKdc KDC;</span>
<span class="source-line-no">093</span><span id="line-93"> private static String HOST = "localhost";</span>
<span class="source-line-no">094</span><span id="line-94"> private static String PRINCIPAL;</span>
<span class="source-line-no">095</span><span id="line-95"> private static String HTTP_PRINCIPAL;</span>
<span class="source-line-no">096</span><span id="line-96"></span>
<span class="source-line-no">097</span><span id="line-97"> @Rule</span>
<span class="source-line-no">098</span><span id="line-98"> public TestName name = new TestName();</span>
<span class="source-line-no">099</span><span id="line-99"></span>
<span class="source-line-no">100</span><span id="line-100"> // user/group present in hbase.admin.acl</span>
<span class="source-line-no">101</span><span id="line-101"> private static final String USER_ADMIN_STR = "admin";</span>
<span class="source-line-no">102</span><span id="line-102"></span>
<span class="source-line-no">103</span><span id="line-103"> // user with no permissions</span>
<span class="source-line-no">104</span><span id="line-104"> private static final String USER_NONE_STR = "none";</span>
<span class="source-line-no">105</span><span id="line-105"></span>
<span class="source-line-no">106</span><span id="line-106"> @BeforeClass</span>
<span class="source-line-no">107</span><span id="line-107"> public static void beforeClass() throws Exception {</span>
<span class="source-line-no">108</span><span id="line-108"> conf = UTIL.getConfiguration();</span>
<span class="source-line-no">109</span><span id="line-109"> KDC = UTIL.setupMiniKdc(KEYTAB_FILE);</span>
<span class="source-line-no">110</span><span id="line-110"> USERNAME = UserGroupInformation.getLoginUser().getShortUserName();</span>
<span class="source-line-no">111</span><span id="line-111"> PRINCIPAL = USERNAME + "/" + HOST;</span>
<span class="source-line-no">112</span><span id="line-112"> HTTP_PRINCIPAL = "HTTP/" + HOST;</span>
<span class="source-line-no">113</span><span id="line-113"> // Create principals for services and the test users</span>
<span class="source-line-no">114</span><span id="line-114"> KDC.createPrincipal(KEYTAB_FILE, PRINCIPAL, HTTP_PRINCIPAL, USER_ADMIN_STR, USER_NONE_STR);</span>
<span class="source-line-no">115</span><span id="line-115"> UTIL.startMiniZKCluster();</span>
<span class="source-line-no">116</span><span id="line-116"></span>
<span class="source-line-no">117</span><span id="line-117"> HBaseKerberosUtils.setSecuredConfiguration(conf, PRINCIPAL + "@" + KDC.getRealm(),</span>
<span class="source-line-no">118</span><span id="line-118"> HTTP_PRINCIPAL + "@" + KDC.getRealm());</span>
<span class="source-line-no">119</span><span id="line-119"> HBaseKerberosUtils.setSSLConfiguration(UTIL, TestInfoServersACL.class);</span>
<span class="source-line-no">120</span><span id="line-120"></span>
<span class="source-line-no">121</span><span id="line-121"> conf.setStrings(CoprocessorHost.REGION_COPROCESSOR_CONF_KEY, TokenProvider.class.getName());</span>
<span class="source-line-no">122</span><span id="line-122"> UTIL.startMiniDFSCluster(1);</span>
<span class="source-line-no">123</span><span id="line-123"> Path rootdir = UTIL.getDataTestDirOnTestFS("TestInfoServersACL");</span>
<span class="source-line-no">124</span><span id="line-124"> CommonFSUtils.setRootDir(conf, rootdir);</span>
<span class="source-line-no">125</span><span id="line-125"></span>
<span class="source-line-no">126</span><span id="line-126"> // The info servers do not run in tests by default.</span>
<span class="source-line-no">127</span><span id="line-127"> // Set them to ephemeral ports so they will start</span>
<span class="source-line-no">128</span><span id="line-128"> // setup configuration</span>
<span class="source-line-no">129</span><span id="line-129"> conf.setInt(HConstants.MASTER_INFO_PORT, 0);</span>
<span class="source-line-no">130</span><span id="line-130"> conf.setInt(HConstants.REGIONSERVER_INFO_PORT, 0);</span>
<span class="source-line-no">131</span><span id="line-131"></span>
<span class="source-line-no">132</span><span id="line-132"> conf.set(HttpServer.HTTP_UI_AUTHENTICATION, "kerberos");</span>
<span class="source-line-no">133</span><span id="line-133"> conf.set(HttpServer.HTTP_SPNEGO_AUTHENTICATION_PRINCIPAL_KEY, HTTP_PRINCIPAL);</span>
<span class="source-line-no">134</span><span id="line-134"> conf.set(HttpServer.HTTP_SPNEGO_AUTHENTICATION_KEYTAB_KEY, KEYTAB_FILE.getAbsolutePath());</span>
<span class="source-line-no">135</span><span id="line-135"></span>
<span class="source-line-no">136</span><span id="line-136"> // ACL lists work only when "hadoop.security.authorization" is set to true</span>
<span class="source-line-no">137</span><span id="line-137"> conf.setBoolean(CommonConfigurationKeys.HADOOP_SECURITY_AUTHORIZATION, true);</span>
<span class="source-line-no">138</span><span id="line-138"> // only user admin will have acl access</span>
<span class="source-line-no">139</span><span id="line-139"> conf.set(HttpServer.HTTP_SPNEGO_AUTHENTICATION_ADMIN_USERS_KEY, USER_ADMIN_STR);</span>
<span class="source-line-no">140</span><span id="line-140"> // conf.set(HttpServer.FILTER_INITIALIZERS_PROPERTY, "");</span>
<span class="source-line-no">141</span><span id="line-141"></span>
<span class="source-line-no">142</span><span id="line-142"> CLUSTER = new LocalHBaseCluster(conf, 1);</span>
<span class="source-line-no">143</span><span id="line-143"> CLUSTER.startup();</span>
<span class="source-line-no">144</span><span id="line-144"> CLUSTER.getActiveMaster().waitForMetaOnline();</span>
<span class="source-line-no">145</span><span id="line-145"> }</span>
<span class="source-line-no">146</span><span id="line-146"></span>
<span class="source-line-no">147</span><span id="line-147"> /**</span>
<span class="source-line-no">148</span><span id="line-148"> * Helper method to shut down the cluster (if running)</span>
<span class="source-line-no">149</span><span id="line-149"> */</span>
<span class="source-line-no">150</span><span id="line-150"> @AfterClass</span>
<span class="source-line-no">151</span><span id="line-151"> public static void shutDownMiniCluster() throws Exception {</span>
<span class="source-line-no">152</span><span id="line-152"> if (CLUSTER != null) {</span>
<span class="source-line-no">153</span><span id="line-153"> CLUSTER.shutdown();</span>
<span class="source-line-no">154</span><span id="line-154"> CLUSTER.join();</span>
<span class="source-line-no">155</span><span id="line-155"> }</span>
<span class="source-line-no">156</span><span id="line-156"> if (KDC != null) {</span>
<span class="source-line-no">157</span><span id="line-157"> KDC.stop();</span>
<span class="source-line-no">158</span><span id="line-158"> }</span>
<span class="source-line-no">159</span><span id="line-159"> UTIL.shutdownMiniCluster();</span>
<span class="source-line-no">160</span><span id="line-160"> }</span>
<span class="source-line-no">161</span><span id="line-161"></span>
<span class="source-line-no">162</span><span id="line-162"> @Test</span>
<span class="source-line-no">163</span><span id="line-163"> public void testAuthorizedUser() throws Exception {</span>
<span class="source-line-no">164</span><span id="line-164"> UserGroupInformation admin = UserGroupInformation</span>
<span class="source-line-no">165</span><span id="line-165"> .loginUserFromKeytabAndReturnUGI(USER_ADMIN_STR, KEYTAB_FILE.getAbsolutePath());</span>
<span class="source-line-no">166</span><span id="line-166"> admin.doAs(new PrivilegedExceptionAction&lt;Void&gt;() {</span>
<span class="source-line-no">167</span><span id="line-167"> @Override</span>
<span class="source-line-no">168</span><span id="line-168"> public Void run() throws Exception {</span>
<span class="source-line-no">169</span><span id="line-169"> // Check the expected content is present in the http response</span>
<span class="source-line-no">170</span><span id="line-170"> String expectedContent = "Get Log Level";</span>
<span class="source-line-no">171</span><span id="line-171"> Pair&lt;Integer, String&gt; pair = getLogLevelPage();</span>
<span class="source-line-no">172</span><span id="line-172"> assertEquals(HttpURLConnection.HTTP_OK, pair.getFirst().intValue());</span>
<span class="source-line-no">173</span><span id="line-173"> assertTrue("expected=" + expectedContent + ", content=" + pair.getSecond(),</span>
<span class="source-line-no">174</span><span id="line-174"> pair.getSecond().contains(expectedContent));</span>
<span class="source-line-no">175</span><span id="line-175"> return null;</span>
<span class="source-line-no">176</span><span id="line-176"> }</span>
<span class="source-line-no">177</span><span id="line-177"> });</span>
<span class="source-line-no">178</span><span id="line-178"> }</span>
<span class="source-line-no">179</span><span id="line-179"></span>
<span class="source-line-no">180</span><span id="line-180"> @Test</span>
<span class="source-line-no">181</span><span id="line-181"> public void testUnauthorizedUser() throws Exception {</span>
<span class="source-line-no">182</span><span id="line-182"> UserGroupInformation nonAdmin = UserGroupInformation</span>
<span class="source-line-no">183</span><span id="line-183"> .loginUserFromKeytabAndReturnUGI(USER_NONE_STR, KEYTAB_FILE.getAbsolutePath());</span>
<span class="source-line-no">184</span><span id="line-184"> nonAdmin.doAs(new PrivilegedExceptionAction&lt;Void&gt;() {</span>
<span class="source-line-no">185</span><span id="line-185"> @Override</span>
<span class="source-line-no">186</span><span id="line-186"> public Void run() throws Exception {</span>
<span class="source-line-no">187</span><span id="line-187"> Pair&lt;Integer, String&gt; pair = getLogLevelPage();</span>
<span class="source-line-no">188</span><span id="line-188"> assertEquals(HttpURLConnection.HTTP_FORBIDDEN, pair.getFirst().intValue());</span>
<span class="source-line-no">189</span><span id="line-189"> return null;</span>
<span class="source-line-no">190</span><span id="line-190"> }</span>
<span class="source-line-no">191</span><span id="line-191"> });</span>
<span class="source-line-no">192</span><span id="line-192"> }</span>
<span class="source-line-no">193</span><span id="line-193"></span>
<span class="source-line-no">194</span><span id="line-194"> @Test</span>
<span class="source-line-no">195</span><span id="line-195"> public void testTableActionsAvailableForAdmins() throws Exception {</span>
<span class="source-line-no">196</span><span id="line-196"> final String expectedAuthorizedContent = "Actions:";</span>
<span class="source-line-no">197</span><span id="line-197"> UserGroupInformation admin = UserGroupInformation</span>
<span class="source-line-no">198</span><span id="line-198"> .loginUserFromKeytabAndReturnUGI(USER_ADMIN_STR, KEYTAB_FILE.getAbsolutePath());</span>
<span class="source-line-no">199</span><span id="line-199"> admin.doAs(new PrivilegedExceptionAction&lt;Void&gt;() {</span>
<span class="source-line-no">200</span><span id="line-200"> @Override</span>
<span class="source-line-no">201</span><span id="line-201"> public Void run() throws Exception {</span>
<span class="source-line-no">202</span><span id="line-202"> // Check the expected content is present in the http response</span>
<span class="source-line-no">203</span><span id="line-203"> Pair&lt;Integer, String&gt; pair = getTablePage(TableName.META_TABLE_NAME);</span>
<span class="source-line-no">204</span><span id="line-204"> assertEquals(HttpURLConnection.HTTP_OK, pair.getFirst().intValue());</span>
<span class="source-line-no">205</span><span id="line-205"> assertTrue("expected=" + expectedAuthorizedContent + ", content=" + pair.getSecond(),</span>
<span class="source-line-no">206</span><span id="line-206"> pair.getSecond().contains(expectedAuthorizedContent));</span>
<span class="source-line-no">207</span><span id="line-207"> return null;</span>
<span class="source-line-no">208</span><span id="line-208"> }</span>
<span class="source-line-no">209</span><span id="line-209"> });</span>
<span class="source-line-no">210</span><span id="line-210"></span>
<span class="source-line-no">211</span><span id="line-211"> UserGroupInformation nonAdmin = UserGroupInformation</span>
<span class="source-line-no">212</span><span id="line-212"> .loginUserFromKeytabAndReturnUGI(USER_NONE_STR, KEYTAB_FILE.getAbsolutePath());</span>
<span class="source-line-no">213</span><span id="line-213"> nonAdmin.doAs(new PrivilegedExceptionAction&lt;Void&gt;() {</span>
<span class="source-line-no">214</span><span id="line-214"> @Override</span>
<span class="source-line-no">215</span><span id="line-215"> public Void run() throws Exception {</span>
<span class="source-line-no">216</span><span id="line-216"> Pair&lt;Integer, String&gt; pair = getTablePage(TableName.META_TABLE_NAME);</span>
<span class="source-line-no">217</span><span id="line-217"> assertEquals(HttpURLConnection.HTTP_OK, pair.getFirst().intValue());</span>
<span class="source-line-no">218</span><span id="line-218"> assertFalse(</span>
<span class="source-line-no">219</span><span id="line-219"> "should not find=" + expectedAuthorizedContent + ", content=" + pair.getSecond(),</span>
<span class="source-line-no">220</span><span id="line-220"> pair.getSecond().contains(expectedAuthorizedContent));</span>
<span class="source-line-no">221</span><span id="line-221"> return null;</span>
<span class="source-line-no">222</span><span id="line-222"> }</span>
<span class="source-line-no">223</span><span id="line-223"> });</span>
<span class="source-line-no">224</span><span id="line-224"> }</span>
<span class="source-line-no">225</span><span id="line-225"></span>
<span class="source-line-no">226</span><span id="line-226"> @Test</span>
<span class="source-line-no">227</span><span id="line-227"> public void testLogsAvailableForAdmins() throws Exception {</span>
<span class="source-line-no">228</span><span id="line-228"> final String expectedAuthorizedContent = "Directory: /logs/";</span>
<span class="source-line-no">229</span><span id="line-229"> UserGroupInformation admin = UserGroupInformation</span>
<span class="source-line-no">230</span><span id="line-230"> .loginUserFromKeytabAndReturnUGI(USER_ADMIN_STR, KEYTAB_FILE.getAbsolutePath());</span>
<span class="source-line-no">231</span><span id="line-231"> admin.doAs(new PrivilegedExceptionAction&lt;Void&gt;() {</span>
<span class="source-line-no">232</span><span id="line-232"> @Override</span>
<span class="source-line-no">233</span><span id="line-233"> public Void run() throws Exception {</span>
<span class="source-line-no">234</span><span id="line-234"> // Check the expected content is present in the http response</span>
<span class="source-line-no">235</span><span id="line-235"> Pair&lt;Integer, String&gt; pair = getLogsPage();</span>
<span class="source-line-no">236</span><span id="line-236"> assertEquals(HttpURLConnection.HTTP_OK, pair.getFirst().intValue());</span>
<span class="source-line-no">237</span><span id="line-237"> assertTrue("expected=" + expectedAuthorizedContent + ", content=" + pair.getSecond(),</span>
<span class="source-line-no">238</span><span id="line-238"> pair.getSecond().contains(expectedAuthorizedContent));</span>
<span class="source-line-no">239</span><span id="line-239"> return null;</span>
<span class="source-line-no">240</span><span id="line-240"> }</span>
<span class="source-line-no">241</span><span id="line-241"> });</span>
<span class="source-line-no">242</span><span id="line-242"></span>
<span class="source-line-no">243</span><span id="line-243"> UserGroupInformation nonAdmin = UserGroupInformation</span>
<span class="source-line-no">244</span><span id="line-244"> .loginUserFromKeytabAndReturnUGI(USER_NONE_STR, KEYTAB_FILE.getAbsolutePath());</span>
<span class="source-line-no">245</span><span id="line-245"> nonAdmin.doAs(new PrivilegedExceptionAction&lt;Void&gt;() {</span>
<span class="source-line-no">246</span><span id="line-246"> @Override</span>
<span class="source-line-no">247</span><span id="line-247"> public Void run() throws Exception {</span>
<span class="source-line-no">248</span><span id="line-248"> Pair&lt;Integer, String&gt; pair = getLogsPage();</span>
<span class="source-line-no">249</span><span id="line-249"> assertEquals(HttpURLConnection.HTTP_FORBIDDEN, pair.getFirst().intValue());</span>
<span class="source-line-no">250</span><span id="line-250"> return null;</span>
<span class="source-line-no">251</span><span id="line-251"> }</span>
<span class="source-line-no">252</span><span id="line-252"> });</span>
<span class="source-line-no">253</span><span id="line-253"> }</span>
<span class="source-line-no">254</span><span id="line-254"></span>
<span class="source-line-no">255</span><span id="line-255"> @Test</span>
<span class="source-line-no">256</span><span id="line-256"> public void testDumpActionsAvailableForAdmins() throws Exception {</span>
<span class="source-line-no">257</span><span id="line-257"> final String expectedAuthorizedContent = "Master status for";</span>
<span class="source-line-no">258</span><span id="line-258"> UserGroupInformation admin = UserGroupInformation</span>
<span class="source-line-no">259</span><span id="line-259"> .loginUserFromKeytabAndReturnUGI(USER_ADMIN_STR, KEYTAB_FILE.getAbsolutePath());</span>
<span class="source-line-no">260</span><span id="line-260"> admin.doAs(new PrivilegedExceptionAction&lt;Void&gt;() {</span>
<span class="source-line-no">261</span><span id="line-261"> @Override</span>
<span class="source-line-no">262</span><span id="line-262"> public Void run() throws Exception {</span>
<span class="source-line-no">263</span><span id="line-263"> // Check the expected content is present in the http response</span>
<span class="source-line-no">264</span><span id="line-264"> Pair&lt;Integer, String&gt; pair = getMasterDumpPage();</span>
<span class="source-line-no">265</span><span id="line-265"> assertEquals(HttpURLConnection.HTTP_OK, pair.getFirst().intValue());</span>
<span class="source-line-no">266</span><span id="line-266"> assertTrue("expected=" + expectedAuthorizedContent + ", content=" + pair.getSecond(),</span>
<span class="source-line-no">267</span><span id="line-267"> pair.getSecond().contains(expectedAuthorizedContent));</span>
<span class="source-line-no">268</span><span id="line-268"> return null;</span>
<span class="source-line-no">269</span><span id="line-269"> }</span>
<span class="source-line-no">270</span><span id="line-270"> });</span>
<span class="source-line-no">271</span><span id="line-271"></span>
<span class="source-line-no">272</span><span id="line-272"> UserGroupInformation nonAdmin = UserGroupInformation</span>
<span class="source-line-no">273</span><span id="line-273"> .loginUserFromKeytabAndReturnUGI(USER_NONE_STR, KEYTAB_FILE.getAbsolutePath());</span>
<span class="source-line-no">274</span><span id="line-274"> nonAdmin.doAs(new PrivilegedExceptionAction&lt;Void&gt;() {</span>
<span class="source-line-no">275</span><span id="line-275"> @Override</span>
<span class="source-line-no">276</span><span id="line-276"> public Void run() throws Exception {</span>
<span class="source-line-no">277</span><span id="line-277"> Pair&lt;Integer, String&gt; pair = getMasterDumpPage();</span>
<span class="source-line-no">278</span><span id="line-278"> assertEquals(HttpURLConnection.HTTP_FORBIDDEN, pair.getFirst().intValue());</span>
<span class="source-line-no">279</span><span id="line-279"> return null;</span>
<span class="source-line-no">280</span><span id="line-280"> }</span>
<span class="source-line-no">281</span><span id="line-281"> });</span>
<span class="source-line-no">282</span><span id="line-282"> }</span>
<span class="source-line-no">283</span><span id="line-283"></span>
<span class="source-line-no">284</span><span id="line-284"> @Test</span>
<span class="source-line-no">285</span><span id="line-285"> public void testStackActionsAvailableForAdmins() throws Exception {</span>
<span class="source-line-no">286</span><span id="line-286"> final String expectedAuthorizedContent = "Process Thread Dump";</span>
<span class="source-line-no">287</span><span id="line-287"> UserGroupInformation admin = UserGroupInformation</span>
<span class="source-line-no">288</span><span id="line-288"> .loginUserFromKeytabAndReturnUGI(USER_ADMIN_STR, KEYTAB_FILE.getAbsolutePath());</span>
<span class="source-line-no">289</span><span id="line-289"> admin.doAs(new PrivilegedExceptionAction&lt;Void&gt;() {</span>
<span class="source-line-no">290</span><span id="line-290"> @Override</span>
<span class="source-line-no">291</span><span id="line-291"> public Void run() throws Exception {</span>
<span class="source-line-no">292</span><span id="line-292"> // Check the expected content is present in the http response</span>
<span class="source-line-no">293</span><span id="line-293"> Pair&lt;Integer, String&gt; pair = getStacksPage();</span>
<span class="source-line-no">294</span><span id="line-294"> assertEquals(HttpURLConnection.HTTP_OK, pair.getFirst().intValue());</span>
<span class="source-line-no">295</span><span id="line-295"> assertTrue("expected=" + expectedAuthorizedContent + ", content=" + pair.getSecond(),</span>
<span class="source-line-no">296</span><span id="line-296"> pair.getSecond().contains(expectedAuthorizedContent));</span>
<span class="source-line-no">297</span><span id="line-297"> return null;</span>
<span class="source-line-no">298</span><span id="line-298"> }</span>
<span class="source-line-no">299</span><span id="line-299"> });</span>
<span class="source-line-no">300</span><span id="line-300"></span>
<span class="source-line-no">301</span><span id="line-301"> UserGroupInformation nonAdmin = UserGroupInformation</span>
<span class="source-line-no">302</span><span id="line-302"> .loginUserFromKeytabAndReturnUGI(USER_NONE_STR, KEYTAB_FILE.getAbsolutePath());</span>
<span class="source-line-no">303</span><span id="line-303"> nonAdmin.doAs(new PrivilegedExceptionAction&lt;Void&gt;() {</span>
<span class="source-line-no">304</span><span id="line-304"> @Override</span>
<span class="source-line-no">305</span><span id="line-305"> public Void run() throws Exception {</span>
<span class="source-line-no">306</span><span id="line-306"> Pair&lt;Integer, String&gt; pair = getStacksPage();</span>
<span class="source-line-no">307</span><span id="line-307"> assertEquals(HttpURLConnection.HTTP_FORBIDDEN, pair.getFirst().intValue());</span>
<span class="source-line-no">308</span><span id="line-308"> return null;</span>
<span class="source-line-no">309</span><span id="line-309"> }</span>
<span class="source-line-no">310</span><span id="line-310"> });</span>
<span class="source-line-no">311</span><span id="line-311"> }</span>
<span class="source-line-no">312</span><span id="line-312"></span>
<span class="source-line-no">313</span><span id="line-313"> @Test</span>
<span class="source-line-no">314</span><span id="line-314"> public void testJmxAvailableForAdmins() throws Exception {</span>
<span class="source-line-no">315</span><span id="line-315"> final String expectedAuthorizedContent = "Hadoop:service=HBase";</span>
<span class="source-line-no">316</span><span id="line-316"> UTIL.waitFor(30000, new Waiter.Predicate&lt;Exception&gt;() {</span>
<span class="source-line-no">317</span><span id="line-317"> @Override</span>
<span class="source-line-no">318</span><span id="line-318"> public boolean evaluate() throws Exception {</span>
<span class="source-line-no">319</span><span id="line-319"> for (ObjectName name : ManagementFactory.getPlatformMBeanServer()</span>
<span class="source-line-no">320</span><span id="line-320"> .queryNames(new ObjectName("*:*"), null)) {</span>
<span class="source-line-no">321</span><span id="line-321"> if (name.toString().contains(expectedAuthorizedContent)) {</span>
<span class="source-line-no">322</span><span id="line-322"> LOG.info("{}", name);</span>
<span class="source-line-no">323</span><span id="line-323"> return true;</span>
<span class="source-line-no">324</span><span id="line-324"> }</span>
<span class="source-line-no">325</span><span id="line-325"> }</span>
<span class="source-line-no">326</span><span id="line-326"> return false;</span>
<span class="source-line-no">327</span><span id="line-327"> }</span>
<span class="source-line-no">328</span><span id="line-328"> });</span>
<span class="source-line-no">329</span><span id="line-329"> UserGroupInformation admin = UserGroupInformation</span>
<span class="source-line-no">330</span><span id="line-330"> .loginUserFromKeytabAndReturnUGI(USER_ADMIN_STR, KEYTAB_FILE.getAbsolutePath());</span>
<span class="source-line-no">331</span><span id="line-331"> admin.doAs(new PrivilegedExceptionAction&lt;Void&gt;() {</span>
<span class="source-line-no">332</span><span id="line-332"> @Override</span>
<span class="source-line-no">333</span><span id="line-333"> public Void run() throws Exception {</span>
<span class="source-line-no">334</span><span id="line-334"> // Check the expected content is present in the http response</span>
<span class="source-line-no">335</span><span id="line-335"> Pair&lt;Integer, String&gt; pair = getJmxPage();</span>
<span class="source-line-no">336</span><span id="line-336"> assertEquals(HttpURLConnection.HTTP_OK, pair.getFirst().intValue());</span>
<span class="source-line-no">337</span><span id="line-337"> assertTrue("expected=" + expectedAuthorizedContent + ", content=" + pair.getSecond(),</span>
<span class="source-line-no">338</span><span id="line-338"> pair.getSecond().contains(expectedAuthorizedContent));</span>
<span class="source-line-no">339</span><span id="line-339"> return null;</span>
<span class="source-line-no">340</span><span id="line-340"> }</span>
<span class="source-line-no">341</span><span id="line-341"> });</span>
<span class="source-line-no">342</span><span id="line-342"></span>
<span class="source-line-no">343</span><span id="line-343"> UserGroupInformation nonAdmin = UserGroupInformation</span>
<span class="source-line-no">344</span><span id="line-344"> .loginUserFromKeytabAndReturnUGI(USER_NONE_STR, KEYTAB_FILE.getAbsolutePath());</span>
<span class="source-line-no">345</span><span id="line-345"> nonAdmin.doAs(new PrivilegedExceptionAction&lt;Void&gt;() {</span>
<span class="source-line-no">346</span><span id="line-346"> @Override</span>
<span class="source-line-no">347</span><span id="line-347"> public Void run() throws Exception {</span>
<span class="source-line-no">348</span><span id="line-348"> Pair&lt;Integer, String&gt; pair = getJmxPage();</span>
<span class="source-line-no">349</span><span id="line-349"> assertEquals(HttpURLConnection.HTTP_FORBIDDEN, pair.getFirst().intValue());</span>
<span class="source-line-no">350</span><span id="line-350"> return null;</span>
<span class="source-line-no">351</span><span id="line-351"> }</span>
<span class="source-line-no">352</span><span id="line-352"> });</span>
<span class="source-line-no">353</span><span id="line-353"> }</span>
<span class="source-line-no">354</span><span id="line-354"></span>
<span class="source-line-no">355</span><span id="line-355"> @Test</span>
<span class="source-line-no">356</span><span id="line-356"> public void testMetricsAvailableForAdmins() throws Exception {</span>
<span class="source-line-no">357</span><span id="line-357"> // Looks like there's nothing exported to this, but leave it since</span>
<span class="source-line-no">358</span><span id="line-358"> // it's Hadoop2 only and will eventually be removed due to that.</span>
<span class="source-line-no">359</span><span id="line-359"> final String expectedAuthorizedContent = "";</span>
<span class="source-line-no">360</span><span id="line-360"> UserGroupInformation admin = UserGroupInformation</span>
<span class="source-line-no">361</span><span id="line-361"> .loginUserFromKeytabAndReturnUGI(USER_ADMIN_STR, KEYTAB_FILE.getAbsolutePath());</span>
<span class="source-line-no">362</span><span id="line-362"> admin.doAs(new PrivilegedExceptionAction&lt;Void&gt;() {</span>
<span class="source-line-no">363</span><span id="line-363"> @Override</span>
<span class="source-line-no">364</span><span id="line-364"> public Void run() throws Exception {</span>
<span class="source-line-no">365</span><span id="line-365"> // Check the expected content is present in the http response</span>
<span class="source-line-no">366</span><span id="line-366"> Pair&lt;Integer, String&gt; pair = getMetricsPage();</span>
<span class="source-line-no">367</span><span id="line-367"> if (HttpURLConnection.HTTP_NOT_FOUND == pair.getFirst()) {</span>
<span class="source-line-no">368</span><span id="line-368"> // Not on hadoop 2</span>
<span class="source-line-no">369</span><span id="line-369"> return null;</span>
<span class="source-line-no">370</span><span id="line-370"> }</span>
<span class="source-line-no">371</span><span id="line-371"> assertEquals(HttpURLConnection.HTTP_OK, pair.getFirst().intValue());</span>
<span class="source-line-no">372</span><span id="line-372"> assertTrue("expected=" + expectedAuthorizedContent + ", content=" + pair.getSecond(),</span>
<span class="source-line-no">373</span><span id="line-373"> pair.getSecond().contains(expectedAuthorizedContent));</span>
<span class="source-line-no">374</span><span id="line-374"> return null;</span>
<span class="source-line-no">375</span><span id="line-375"> }</span>
<span class="source-line-no">376</span><span id="line-376"> });</span>
<span class="source-line-no">377</span><span id="line-377"></span>
<span class="source-line-no">378</span><span id="line-378"> UserGroupInformation nonAdmin = UserGroupInformation</span>
<span class="source-line-no">379</span><span id="line-379"> .loginUserFromKeytabAndReturnUGI(USER_NONE_STR, KEYTAB_FILE.getAbsolutePath());</span>
<span class="source-line-no">380</span><span id="line-380"> nonAdmin.doAs(new PrivilegedExceptionAction&lt;Void&gt;() {</span>
<span class="source-line-no">381</span><span id="line-381"> @Override</span>
<span class="source-line-no">382</span><span id="line-382"> public Void run() throws Exception {</span>
<span class="source-line-no">383</span><span id="line-383"> Pair&lt;Integer, String&gt; pair = getMetricsPage();</span>
<span class="source-line-no">384</span><span id="line-384"> if (HttpURLConnection.HTTP_NOT_FOUND == pair.getFirst()) {</span>
<span class="source-line-no">385</span><span id="line-385"> // Not on hadoop 2</span>
<span class="source-line-no">386</span><span id="line-386"> return null;</span>
<span class="source-line-no">387</span><span id="line-387"> }</span>
<span class="source-line-no">388</span><span id="line-388"> assertEquals(HttpURLConnection.HTTP_FORBIDDEN, pair.getFirst().intValue());</span>
<span class="source-line-no">389</span><span id="line-389"> return null;</span>
<span class="source-line-no">390</span><span id="line-390"> }</span>
<span class="source-line-no">391</span><span id="line-391"> });</span>
<span class="source-line-no">392</span><span id="line-392"> }</span>
<span class="source-line-no">393</span><span id="line-393"></span>
<span class="source-line-no">394</span><span id="line-394"> private String getInfoServerHostAndPort() {</span>
<span class="source-line-no">395</span><span id="line-395"> return "http://localhost:" + CLUSTER.getActiveMaster().getInfoServer().getPort();</span>
<span class="source-line-no">396</span><span id="line-396"> }</span>
<span class="source-line-no">397</span><span id="line-397"></span>
<span class="source-line-no">398</span><span id="line-398"> private Pair&lt;Integer, String&gt; getLogLevelPage() throws Exception {</span>
<span class="source-line-no">399</span><span id="line-399"> // Build the url which we want to connect to</span>
<span class="source-line-no">400</span><span id="line-400"> URL url = new URL(getInfoServerHostAndPort() + "/logLevel");</span>
<span class="source-line-no">401</span><span id="line-401"> return getUrlContent(url);</span>
<span class="source-line-no">402</span><span id="line-402"> }</span>
<span class="source-line-no">403</span><span id="line-403"></span>
<span class="source-line-no">404</span><span id="line-404"> private Pair&lt;Integer, String&gt; getTablePage(TableName tn) throws Exception {</span>
<span class="source-line-no">405</span><span id="line-405"> URL url = new URL(getInfoServerHostAndPort() + "/table.jsp?name=" + tn.getNameAsString());</span>
<span class="source-line-no">406</span><span id="line-406"> return getUrlContent(url);</span>
<span class="source-line-no">407</span><span id="line-407"> }</span>
<span class="source-line-no">408</span><span id="line-408"></span>
<span class="source-line-no">409</span><span id="line-409"> private Pair&lt;Integer, String&gt; getLogsPage() throws Exception {</span>
<span class="source-line-no">410</span><span id="line-410"> URL url = new URL(getInfoServerHostAndPort() + "/logs/");</span>
<span class="source-line-no">411</span><span id="line-411"> return getUrlContent(url);</span>
<span class="source-line-no">412</span><span id="line-412"> }</span>
<span class="source-line-no">413</span><span id="line-413"></span>
<span class="source-line-no">414</span><span id="line-414"> private Pair&lt;Integer, String&gt; getMasterDumpPage() throws Exception {</span>
<span class="source-line-no">415</span><span id="line-415"> URL url = new URL(getInfoServerHostAndPort() + "/dump");</span>
<span class="source-line-no">416</span><span id="line-416"> return getUrlContent(url);</span>
<span class="source-line-no">417</span><span id="line-417"> }</span>
<span class="source-line-no">418</span><span id="line-418"></span>
<span class="source-line-no">419</span><span id="line-419"> private Pair&lt;Integer, String&gt; getStacksPage() throws Exception {</span>
<span class="source-line-no">420</span><span id="line-420"> URL url = new URL(getInfoServerHostAndPort() + "/stacks");</span>
<span class="source-line-no">421</span><span id="line-421"> return getUrlContent(url);</span>
<span class="source-line-no">422</span><span id="line-422"> }</span>
<span class="source-line-no">423</span><span id="line-423"></span>
<span class="source-line-no">424</span><span id="line-424"> private Pair&lt;Integer, String&gt; getJmxPage() throws Exception {</span>
<span class="source-line-no">425</span><span id="line-425"> URL url = new URL(getInfoServerHostAndPort() + "/jmx");</span>
<span class="source-line-no">426</span><span id="line-426"> return getUrlContent(url);</span>
<span class="source-line-no">427</span><span id="line-427"> }</span>
<span class="source-line-no">428</span><span id="line-428"></span>
<span class="source-line-no">429</span><span id="line-429"> private Pair&lt;Integer, String&gt; getMetricsPage() throws Exception {</span>
<span class="source-line-no">430</span><span id="line-430"> URL url = new URL(getInfoServerHostAndPort() + "/metrics");</span>
<span class="source-line-no">431</span><span id="line-431"> return getUrlContent(url);</span>
<span class="source-line-no">432</span><span id="line-432"> }</span>
<span class="source-line-no">433</span><span id="line-433"></span>
<span class="source-line-no">434</span><span id="line-434"> /**</span>
<span class="source-line-no">435</span><span id="line-435"> * Retrieves the content of the specified URL. The content will only be returned if the status</span>
<span class="source-line-no">436</span><span id="line-436"> * code for the operation was HTTP 200/OK.</span>
<span class="source-line-no">437</span><span id="line-437"> */</span>
<span class="source-line-no">438</span><span id="line-438"> private Pair&lt;Integer, String&gt; getUrlContent(URL url) throws Exception {</span>
<span class="source-line-no">439</span><span id="line-439"> try (CloseableHttpClient client =</span>
<span class="source-line-no">440</span><span id="line-440"> createHttpClient(UserGroupInformation.getCurrentUser().getUserName())) {</span>
<span class="source-line-no">441</span><span id="line-441"> CloseableHttpResponse resp = client.execute(new HttpGet(url.toURI()));</span>
<span class="source-line-no">442</span><span id="line-442"> int code = resp.getStatusLine().getStatusCode();</span>
<span class="source-line-no">443</span><span id="line-443"> if (code == HttpURLConnection.HTTP_OK) {</span>
<span class="source-line-no">444</span><span id="line-444"> return new Pair&lt;&gt;(code, EntityUtils.toString(resp.getEntity()));</span>
<span class="source-line-no">445</span><span id="line-445"> }</span>
<span class="source-line-no">446</span><span id="line-446"> return new Pair&lt;&gt;(code, null);</span>
<span class="source-line-no">447</span><span id="line-447"> }</span>
<span class="source-line-no">448</span><span id="line-448"> }</span>
<span class="source-line-no">449</span><span id="line-449"></span>
<span class="source-line-no">450</span><span id="line-450"> private CloseableHttpClient createHttpClient(String clientPrincipal) throws Exception {</span>
<span class="source-line-no">451</span><span id="line-451"> // Logs in with Kerberos via GSS</span>
<span class="source-line-no">452</span><span id="line-452"> GSSManager gssManager = GSSManager.getInstance();</span>
<span class="source-line-no">453</span><span id="line-453"> // jGSS Kerberos login constant</span>
<span class="source-line-no">454</span><span id="line-454"> Oid oid = new Oid("1.2.840.113554.1.2.2");</span>
<span class="source-line-no">455</span><span id="line-455"> GSSName gssClient = gssManager.createName(clientPrincipal, GSSName.NT_USER_NAME);</span>
<span class="source-line-no">456</span><span id="line-456"> GSSCredential credential = gssManager.createCredential(gssClient,</span>
<span class="source-line-no">457</span><span id="line-457"> GSSCredential.DEFAULT_LIFETIME, oid, GSSCredential.INITIATE_ONLY);</span>
<span class="source-line-no">458</span><span id="line-458"></span>
<span class="source-line-no">459</span><span id="line-459"> Lookup&lt;AuthSchemeProvider&gt; authRegistry = RegistryBuilder.&lt;AuthSchemeProvider&gt; create()</span>
<span class="source-line-no">460</span><span id="line-460"> .register(AuthSchemes.SPNEGO, new SPNegoSchemeFactory(true, true)).build();</span>
<span class="source-line-no">461</span><span id="line-461"></span>
<span class="source-line-no">462</span><span id="line-462"> BasicCredentialsProvider credentialsProvider = new BasicCredentialsProvider();</span>
<span class="source-line-no">463</span><span id="line-463"> credentialsProvider.setCredentials(AuthScope.ANY, new KerberosCredentials(credential));</span>
<span class="source-line-no">464</span><span id="line-464"></span>
<span class="source-line-no">465</span><span id="line-465"> return HttpClients.custom().setDefaultAuthSchemeRegistry(authRegistry)</span>
<span class="source-line-no">466</span><span id="line-466"> .setDefaultCredentialsProvider(credentialsProvider).build();</span>
<span class="source-line-no">467</span><span id="line-467"> }</span>
<span class="source-line-no">468</span><span id="line-468">}</span>
</pre>
</div>
</main>
</body>
</html>