Move authorizer tests to node-commons
diff --git a/iotdb-core/datanode/pom.xml b/iotdb-core/datanode/pom.xml index 0484076..141b3f7 100644 --- a/iotdb-core/datanode/pom.xml +++ b/iotdb-core/datanode/pom.xml
@@ -290,26 +290,11 @@ <scope>test</scope> </dependency> <dependency> - <groupId>net.minidev</groupId> - <artifactId>json-smart</artifactId> - <scope>test</scope> - </dependency> - <dependency> <groupId>org.apache.ratis</groupId> <artifactId>ratis-thirdparty-misc</artifactId> <scope>runtime</scope> </dependency> <dependency> - <groupId>com.nimbusds</groupId> - <artifactId>oauth2-oidc-sdk</artifactId> - <scope>test</scope> - </dependency> - <dependency> - <groupId>com.nimbusds</groupId> - <artifactId>nimbus-jose-jwt</artifactId> - <scope>test</scope> - </dependency> - <dependency> <groupId>org.powermock</groupId> <artifactId>powermock-core</artifactId> <scope>test</scope>
diff --git a/iotdb-core/datanode/src/test/java/org/apache/iotdb/db/auth/authorizer/OpenIdAuthorizerTest.java b/iotdb-core/datanode/src/test/java/org/apache/iotdb/db/auth/authorizer/OpenIdAuthorizerTest.java deleted file mode 100644 index 61d61c7..0000000 --- a/iotdb-core/datanode/src/test/java/org/apache/iotdb/db/auth/authorizer/OpenIdAuthorizerTest.java +++ /dev/null
@@ -1,154 +0,0 @@ -/* - * Licensed to the Apache Software Foundation (ASF) under one - * or more contributor license agreements. See the NOTICE file - * distributed with this work for additional information - * regarding copyright ownership. The ASF licenses this file - * to you under the Apache License, Version 2.0 (the - * "License"); you may not use this file except in compliance - * with the License. You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, - * software distributed under the License is distributed on an - * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY - * KIND, either express or implied. See the License for the - * specific language governing permissions and limitations - * under the License. - */ -package org.apache.iotdb.db.auth.authorizer; - -import org.apache.iotdb.commons.auth.AuthException; -import org.apache.iotdb.commons.auth.authorizer.OpenIdAuthorizer; -import org.apache.iotdb.commons.conf.CommonConfig; -import org.apache.iotdb.commons.conf.CommonDescriptor; -import org.apache.iotdb.db.utils.EnvironmentUtils; - -import com.nimbusds.jose.JOSEException; -import com.nimbusds.jose.JWSAlgorithm; -import com.nimbusds.jose.JWSHeader; -import com.nimbusds.jose.crypto.RSASSASigner; -import com.nimbusds.jose.jwk.KeyUse; -import com.nimbusds.jose.jwk.RSAKey; -import com.nimbusds.jwt.JWTClaimsSet; -import com.nimbusds.jwt.SignedJWT; -import com.nimbusds.oauth2.sdk.ParseException; -import net.minidev.json.JSONObject; -import org.junit.After; -import org.junit.Before; -import org.junit.Ignore; -import org.junit.Test; - -import java.io.IOException; -import java.net.URISyntaxException; -import java.security.KeyPair; -import java.security.KeyPairGenerator; -import java.security.PrivateKey; -import java.security.interfaces.RSAPublicKey; -import java.time.Instant; -import java.util.Collections; -import java.util.Date; - -import static org.junit.Assert.assertFalse; -import static org.junit.Assert.assertTrue; - -public class OpenIdAuthorizerTest { - - private static final String OPEN_ID_PUBLIC_JWK = - "{\"kty\":\"RSA\",\"x5t#S256\":\"TZFbbj6HsRU28HYvrcVnDs03KreV3DE24-Cxb9EPdS4\",\"e\":\"AQAB\",\"use\":\"sig\",\"x5t\":\"l_N2UlC_a624iu5eYFypnB1Wr20\",\"kid\":\"q1-Wm0ozQ5O0mQH8-SJap2ZcN4MmucWwnQWKYxZJ4ow\",\"x5c\":[\"MIICmTCCAYECBgFyRdXW2DANBgkqhkiG9w0BAQsFADAQMQ4wDAYDVQQDDAVJb1REQjAeFw0yMDA1MjQwODM3MjJaFw0zMDA1MjQwODM5MDJaMBAxDjAMBgNVBAMMBUlvVERCMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAozDCZTVc9946VvhZ6E\\/OP8Yx6tJe0i9GR2Q9jR9S3jQoo0haT\\/P1b\\/zvQK52qA1xj6tBVg64xl3+LUxtCvh3HfAM5Q3PeSa0e2MkZaKCt335lKnKCSuaQGYoHULmg\\/FDOgCA0wJYOonGGJkgWmkzSAzdnHmBATosTl0XkBXHTdFOq5HaKw+bfghYp5097Gkl\\/Dp4sixVjIWLTh5l9diy4D\\/XKxadGumPCmTOS5E7y92jiHE64XFe1Q7v1qD+qKJKFvamAMIFPGBKegIajt42IcOIcIaJZnM1lBZApq1a\\/E6oL24QnP\\/j2e9coseDtGNywaADQdO8PaJadH\\/BV4aPCwIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQBX4rsWPIAwgSK6BEZmtEkh\\/FMfZtkvCFANpwkCX5Pph8yuk\\/8xrvx30yb4fIgqsxxQk6H+Q1qptm1cXs0tNu1yft+t+B2VuVjrWtkCkV0hAy6eZcdW411Pt523pHoOTxg6ehQd5DsvCIlsvWo83ePTKME+092vfs3irfQcRzc5xINdpopSvZlZuQ83tNEJY8gWvspQZr+uj8AP2x6w0BOrPJIiLlV+peNJuD3UgJKlSfOueKbKeM1kIVOG\\/a2AoEkBgqktnaIWzkXbk475\\/0xfGegsSZrxGR3\\/SA3jegS0sHFCY7\\/Ie\\/UvDgqMjd207oT64jxEGrd4mObxOx7aS0tp\"],\"alg\":\"RS256\",\"n\":\"ozDCZTVc9946VvhZ6E_OP8Yx6tJe0i9GR2Q9jR9S3jQoo0haT_P1b_zvQK52qA1xj6tBVg64xl3-LUxtCvh3HfAM5Q3PeSa0e2MkZaKCt335lKnKCSuaQGYoHULmg_FDOgCA0wJYOonGGJkgWmkzSAzdnHmBATosTl0XkBXHTdFOq5HaKw-bfghYp5097Gkl_Dp4sixVjIWLTh5l9diy4D_XKxadGumPCmTOS5E7y92jiHE64XFe1Q7v1qD-qKJKFvamAMIFPGBKegIajt42IcOIcIaJZnM1lBZApq1a_E6oL24QnP_j2e9coseDtGNywaADQdO8PaJadH_BV4aPCw\"}"; - private static CommonConfig config; - private PrivateKey privateKey; - private JSONObject publicJwk; - - @Before - public void setUp() throws Exception { - EnvironmentUtils.envSetUp(); - config = CommonDescriptor.getInstance().getConfig(); - KeyPairGenerator keyPairGenerator = KeyPairGenerator.getInstance("RSA"); - keyPairGenerator.initialize(2048); - KeyPair keyPair = keyPairGenerator.generateKeyPair(); - privateKey = keyPair.getPrivate(); - publicJwk = - new JSONObject( - new RSAKey.Builder((RSAPublicKey) keyPair.getPublic()) - .keyUse(KeyUse.SIGNATURE) - .keyID("datanode-openid-test-key") - .build() - .toJSONObject()); - } - - @After - public void tearDown() throws Exception { - EnvironmentUtils.cleanEnv(); - } - - @Test - public void loginWithJWT() throws Exception { - String jwt = createJwt(false); - - OpenIdAuthorizer authorizer = new OpenIdAuthorizer(publicJwk); - boolean login = authorizer.login(jwt, null, false); - - assertTrue(login); - } - - @Test - public void isAdmin_hasAccess() throws Exception { - String jwt = createJwt(true); - - OpenIdAuthorizer authorizer = new OpenIdAuthorizer(publicJwk); - boolean admin = authorizer.isAdmin(jwt); - - assertTrue(admin); - } - - @Test - public void isAdmin_noAdminClaim() throws Exception { - String jwt = createJwt(false); - - OpenIdAuthorizer authorizer = new OpenIdAuthorizer(publicJwk); - boolean admin = authorizer.isAdmin(jwt); - - assertFalse(admin); - } - - /** Can be run manually as long as the site below is active... */ - @Test - @Ignore("We have to find a way to test this against a defined OIDC Provider") - public void fetchMetadata() - throws ParseException, IOException, URISyntaxException, AuthException { - OpenIdAuthorizer openIdAuthorizer = - new OpenIdAuthorizer("https://auth.demo.pragmaticindustries.de/auth/realms/IoTDB/"); - boolean login = - openIdAuthorizer.login( - "eyJhbGciOiJSUzI1NiIsInR5cCIgOiAiSldUIiwia2lkIiA6ICJxMS1XbTBvelE1TzBtUUg4LVNKYXAyWmNONE1tdWNXd25RV0tZeFpKNG93In0.eyJleHAiOjE1OTAzMTcxNzYsImlhdCI6MTU5MDMxNjg3NiwianRpIjoiY2MyNWQ3MDAtYjc5NC00OTA4LTg0OGUtOTRhNzYzNmM5YzQxIiwiaXNzIjoiaHR0cDovL2F1dGguZGVtby5wcmFnbWF0aWNpbmR1c3RyaWVzLmRlL2F1dGgvcmVhbG1zL0lvVERCIiwiYXVkIjoiYWNjb3VudCIsInN1YiI6Ijg2YWRmNGIzLWE4ZTUtNDc1NC1iNWEwLTQ4OGI0OWY0M2VkMiIsInR5cCI6IkJlYXJlciIsImF6cCI6ImlvdGRiIiwic2Vzc2lvbl9zdGF0ZSI6Ijk0ZmI5NGZjLTg3YTMtNDg4Ny04M2Q3LWE5MmQ1MzMzOTMzMCIsImFjciI6IjEiLCJyZWFsbV9hY2Nlc3MiOnsicm9sZXMiOlsib2ZmbGluZV9hY2Nlc3MiLCJ1bWFfYXV0aG9yaXphdGlvbiJdfSwicmVzb3VyY2VfYWNjZXNzIjp7ImFjY291bnQiOnsicm9sZXMiOlsibWFuYWdlLWFjY291bnQiLCJtYW5hZ2UtYWNjb3VudC1saW5rcyIsInZpZXctcHJvZmlsZSJdfX0sInNjb3BlIjoiZW1haWwgcHJvZmlsZSIsImNsaWVudEhvc3QiOiIxOTIuMTY4LjE2OS4yMSIsImNsaWVudElkIjoiaW90ZGIiLCJlbWFpbF92ZXJpZmllZCI6ZmFsc2UsInByZWZlcnJlZF91c2VybmFtZSI6InNlcnZpY2UtYWNjb3VudC1pb3RkYiIsImNsaWVudEFkZHJlc3MiOiIxOTIuMTY4LjE2OS4yMSJ9.GxQFltm1PrZzVL7rR6K-GpQINFLymjqAxxoDt_DGfQEMt61M6ebmx2oHiP_3G0HDSl7sbamajQbbRrfyTg--emBC2wfhdZ7v_7O0qWC60Yd8cWZ9qxwqwTFKYb8a0Z6_TeH9-vUmsy6kp2BfJZXq3mSy0My21VGUAXRmWTbghiM4RFoHKjAZVhsPHWelFmtLftYPdOGxv-7c9iUOVh_W-nOcCNRJpYY7BEjUYN24TsjvCEwWDQWD9E29LMYfA6LNeG0KdL9Jvqad4bc2FTJn9TaCnJMCiAJ7wEEiotqhXn70uEBWYxGXIVlm3vn3MDe3pTKA2TZy7U5xcrE7S8aGMg", - "", - false); - assertTrue(login); - config.setOpenIdProviderUrl("https://auth.demo.pragmaticindustries.de/auth/realms/IoTDB/"); - OpenIdAuthorizer openIdAuthorizer1 = new OpenIdAuthorizer(); - login = - openIdAuthorizer1.login( - "eyJhbGciOiJSUzI1NiIsInR5cCIgOiAiSldUIiwia2lkIiA6ICJxMS1XbTBvelE1TzBtUUg4LVNKYXAyWmNONE1tdWNXd25RV0tZeFpKNG93In0.eyJleHAiOjE1OTAzMTcxNzYsImlhdCI6MTU5MDMxNjg3NiwianRpIjoiY2MyNWQ3MDAtYjc5NC00OTA4LTg0OGUtOTRhNzYzNmM5YzQxIiwiaXNzIjoiaHR0cDovL2F1dGguZGVtby5wcmFnbWF0aWNpbmR1c3RyaWVzLmRlL2F1dGgvcmVhbG1zL0lvVERCIiwiYXVkIjoiYWNjb3VudCIsInN1YiI6Ijg2YWRmNGIzLWE4ZTUtNDc1NC1iNWEwLTQ4OGI0OWY0M2VkMiIsInR5cCI6IkJlYXJlciIsImF6cCI6ImlvdGRiIiwic2Vzc2lvbl9zdGF0ZSI6Ijk0ZmI5NGZjLTg3YTMtNDg4Ny04M2Q3LWE5MmQ1MzMzOTMzMCIsImFjciI6IjEiLCJyZWFsbV9hY2Nlc3MiOnsicm9sZXMiOlsib2ZmbGluZV9hY2Nlc3MiLCJ1bWFfYXV0aG9yaXphdGlvbiJdfSwicmVzb3VyY2VfYWNjZXNzIjp7ImFjY291bnQiOnsicm9sZXMiOlsibWFuYWdlLWFjY291bnQiLCJtYW5hZ2UtYWNjb3VudC1saW5rcyIsInZpZXctcHJvZmlsZSJdfX0sInNjb3BlIjoiZW1haWwgcHJvZmlsZSIsImNsaWVudEhvc3QiOiIxOTIuMTY4LjE2OS4yMSIsImNsaWVudElkIjoiaW90ZGIiLCJlbWFpbF92ZXJpZmllZCI6ZmFsc2UsInByZWZlcnJlZF91c2VybmFtZSI6InNlcnZpY2UtYWNjb3VudC1pb3RkYiIsImNsaWVudEFkZHJlc3MiOiIxOTIuMTY4LjE2OS4yMSJ9.GxQFltm1PrZzVL7rR6K-GpQINFLymjqAxxoDt_DGfQEMt61M6ebmx2oHiP_3G0HDSl7sbamajQbbRrfyTg--emBC2wfhdZ7v_7O0qWC60Yd8cWZ9qxwqwTFKYb8a0Z6_TeH9-vUmsy6kp2BfJZXq3mSy0My21VGUAXRmWTbghiM4RFoHKjAZVhsPHWelFmtLftYPdOGxv-7c9iUOVh_W-nOcCNRJpYY7BEjUYN24TsjvCEwWDQWD9E29LMYfA6LNeG0KdL9Jvqad4bc2FTJn9TaCnJMCiAJ7wEEiotqhXn70uEBWYxGXIVlm3vn3MDe3pTKA2TZy7U5xcrE7S8aGMg", - "", - false); - assertTrue(login); - } - - private String createJwt(boolean hasAdminRole) throws JOSEException { - JWTClaimsSet.Builder claimsBuilder = - new JWTClaimsSet.Builder() - .subject("datanode-test-user") - .expirationTime(Date.from(Instant.now().plusSeconds(3600))) - .claim( - "realm_access", - Collections.singletonMap( - "roles", - hasAdminRole - ? Collections.singletonList(OpenIdAuthorizer.IOTDB_ADMIN_ROLE_NAME) - : Collections.singletonList("offline_access"))); - SignedJWT signedJwt = new SignedJWT(new JWSHeader(JWSAlgorithm.RS256), claimsBuilder.build()); - signedJwt.sign(new RSASSASigner(privateKey)); - return signedJwt.serialize(); - } -}
diff --git a/iotdb-core/node-commons/src/main/java/org/apache/iotdb/commons/auth/authorizer/OpenIdAuthorizer.java b/iotdb-core/node-commons/src/main/java/org/apache/iotdb/commons/auth/authorizer/OpenIdAuthorizer.java index 2ff888f..f073984 100644 --- a/iotdb-core/node-commons/src/main/java/org/apache/iotdb/commons/auth/authorizer/OpenIdAuthorizer.java +++ b/iotdb-core/node-commons/src/main/java/org/apache/iotdb/commons/auth/authorizer/OpenIdAuthorizer.java
@@ -94,7 +94,6 @@ } this.expectedIssuer = expectedIssuer; this.acceptedAudiences = Collections.unmodifiableSet(new HashSet<>(acceptedAudiences)); - logger.info("Initialized with providerKey: {}", providerKey); } public OpenIdAuthorizer(String providerUrl) @@ -115,8 +114,6 @@ // Fetch Metadata OIDCProviderMetadata providerMetadata = fetchMetadata(providerUrl); - logger.debug("Using Provider Metadata: {}", providerMetadata); - Set<String> acceptedAudiences = parseAudiences(config.getOpenIdAudience()); if (acceptedAudiences.isEmpty()) { throw new AuthException( @@ -133,7 +130,6 @@ try { URL url = new URI(providerMetadata.getJWKSetURI().toString()).toURL(); - logger.debug("Using url {}", url); return new ProviderContext(getProviderRsaJwk(url.openStream()), issuer, acceptedAudiences); } catch (IOException e) { throw new AuthException(TSStatusCode.INIT_AUTH_ERROR, "Unable to start the Auth", e); @@ -194,14 +190,9 @@ try { claims = validateToken(token); } catch (JwtException e) { - logger.error("Unable to login the user with Username (token) {}", token, e); + logger.error("Unable to login the user with Username (token), {}", e.getMessage()); return false; } - logger.debug("JWT was validated successfully!"); - logger.debug("ID: {}", claims.getId()); - logger.debug("Subject: {}", claims.getSubject()); - logger.debug("Issuer: {}", claims.getIssuer()); - logger.debug("Expiration: {}", claims.getExpiration()); // Create User if not exists String iotdbUsername = getUsername(claims); if (!super.listAllUsers().contains(iotdbUsername)) { @@ -308,7 +299,7 @@ try { claims = validateToken(token); } catch (JwtException e) { - logger.warn("Unable to validate token {}!", token, e); + logger.warn("Unable to validate token! {}", e.getMessage()); return false; } }
diff --git a/iotdb-core/datanode/src/test/java/org/apache/iotdb/db/auth/authorizer/LocalFileAuthorizerTest.java b/iotdb-core/node-commons/src/test/java/org/apache/iotdb/commons/auth/authorizer/LocalFileAuthorizerTest.java similarity index 96% rename from iotdb-core/datanode/src/test/java/org/apache/iotdb/db/auth/authorizer/LocalFileAuthorizerTest.java rename to iotdb-core/node-commons/src/test/java/org/apache/iotdb/commons/auth/authorizer/LocalFileAuthorizerTest.java index 194f33e..90ee3af 100644 --- a/iotdb-core/datanode/src/test/java/org/apache/iotdb/db/auth/authorizer/LocalFileAuthorizerTest.java +++ b/iotdb-core/node-commons/src/test/java/org/apache/iotdb/commons/auth/authorizer/LocalFileAuthorizerTest.java
@@ -16,16 +16,13 @@ * specific language governing permissions and limitations * under the License. */ -package org.apache.iotdb.db.auth.authorizer; +package org.apache.iotdb.commons.auth.authorizer; import org.apache.iotdb.commons.auth.AuthException; -import org.apache.iotdb.commons.auth.authorizer.BasicAuthorizer; -import org.apache.iotdb.commons.auth.authorizer.IAuthorizer; import org.apache.iotdb.commons.auth.entity.PrivilegeType; import org.apache.iotdb.commons.auth.entity.PrivilegeUnion; import org.apache.iotdb.commons.conf.CommonDescriptor; import org.apache.iotdb.commons.path.PartialPath; -import org.apache.iotdb.db.utils.EnvironmentUtils; import org.junit.After; import org.junit.Assert; @@ -51,16 +48,13 @@ @Before public void setUp() throws Exception { - EnvironmentUtils.envSetUp(); authorizer = BasicAuthorizer.getInstance(); authorizer.reset(); nodeName = new PartialPath("root.laptop.d1"); } @After - public void tearDown() throws Exception { - EnvironmentUtils.cleanEnv(); - } + public void tearDown() throws Exception {} @Test public void testLogin() throws AuthException {
diff --git a/iotdb-core/node-commons/src/test/java/org/apache/iotdb/commons/auth/authorizer/OpenIdAuthorizerTest.java b/iotdb-core/node-commons/src/test/java/org/apache/iotdb/commons/auth/authorizer/OpenIdAuthorizerTest.java index 1951a68..cf7fb53 100644 --- a/iotdb-core/node-commons/src/test/java/org/apache/iotdb/commons/auth/authorizer/OpenIdAuthorizerTest.java +++ b/iotdb-core/node-commons/src/test/java/org/apache/iotdb/commons/auth/authorizer/OpenIdAuthorizerTest.java
@@ -34,55 +34,66 @@ import com.sun.net.httpserver.HttpServer; import net.minidev.json.JSONObject; import org.junit.After; -import org.junit.Assert; import org.junit.Before; import org.junit.Test; import java.io.IOException; import java.io.OutputStream; import java.net.InetSocketAddress; -import java.nio.file.Files; -import java.nio.file.Path; import java.security.KeyPair; import java.security.KeyPairGenerator; import java.security.PrivateKey; import java.security.interfaces.RSAPublicKey; import java.time.Instant; import java.util.Collections; -import java.util.Comparator; import java.util.Date; +import static org.junit.Assert.assertFalse; +import static org.junit.Assert.assertTrue; + public class OpenIdAuthorizerTest { private final CommonConfig config = CommonDescriptor.getInstance().getConfig(); - - private String originalUserFolder; - private String originalRoleFolder; - private String originalOpenIdAudience; - private Path baseDir; + private PrivateKey privateKey; + private JSONObject publicJwk; @Before - public void setUp() throws IOException { - originalUserFolder = config.getUserFolder(); - originalRoleFolder = config.getRoleFolder(); - originalOpenIdAudience = config.getOpenIdAudience(); - - baseDir = Files.createTempDirectory("openid-authorizer-test-"); - config.setUserFolder(Files.createDirectories(baseDir.resolve("users")).toString()); - config.setRoleFolder(Files.createDirectories(baseDir.resolve("roles")).toString()); + public void setUp() throws Exception { + KeyPairGenerator keyPairGenerator = KeyPairGenerator.getInstance("RSA"); + keyPairGenerator.initialize(2048); + KeyPair keyPair = keyPairGenerator.generateKeyPair(); + privateKey = keyPair.getPrivate(); + publicJwk = + new JSONObject( + new RSAKey.Builder((RSAPublicKey) keyPair.getPublic()) + .keyUse(KeyUse.SIGNATURE) + .keyID("datanode-openid-test-key") + .build() + .toJSONObject()); } @After - public void tearDown() throws IOException { - config.setUserFolder(originalUserFolder); - config.setRoleFolder(originalRoleFolder); - config.setOpenIdAudience(originalOpenIdAudience); + public void tearDown() throws IOException {} - if (baseDir != null) { - try (java.util.stream.Stream<Path> stream = Files.walk(baseDir)) { - stream.sorted(Comparator.reverseOrder()).forEach(this::deleteIfExists); - } - } + @Test + public void loginWithJWT() throws Exception { + String jwt = createJwt(false); + OpenIdAuthorizer authorizer = new OpenIdAuthorizer(publicJwk); + assertTrue(authorizer.login(jwt, null, false)); + } + + @Test + public void isAdmin_hasAccess() throws Exception { + String jwt = createJwt(true); + OpenIdAuthorizer authorizer = new OpenIdAuthorizer(publicJwk); + assertTrue(authorizer.isAdmin(jwt)); + } + + @Test + public void isAdmin_noAdminClaim() throws Exception { + String jwt = createJwt(false); + OpenIdAuthorizer authorizer = new OpenIdAuthorizer(publicJwk); + assertFalse(authorizer.isAdmin(jwt)); } @Test @@ -113,8 +124,8 @@ "roles", Collections.singletonList(OpenIdAuthorizer.IOTDB_ADMIN_ROLE_NAME)))); - Assert.assertFalse(authorizer.login(expiredToken, "", false)); - Assert.assertFalse(authorizer.isAdmin(expiredToken)); + assertFalse(authorizer.login(expiredToken, "", false)); + assertFalse(authorizer.isAdmin(expiredToken)); } @Test @@ -140,8 +151,8 @@ "roles", Collections.singletonList(OpenIdAuthorizer.IOTDB_ADMIN_ROLE_NAME)))); - Assert.assertFalse(authorizer.login(token, "", false)); - Assert.assertFalse(authorizer.isAdmin(token)); + assertFalse(authorizer.login(token, "", false)); + assertFalse(authorizer.isAdmin(token)); } finally { server.stop(0); } @@ -170,8 +181,8 @@ "roles", Collections.singletonList(OpenIdAuthorizer.IOTDB_ADMIN_ROLE_NAME)))); - Assert.assertFalse(authorizer.login(token, "", false)); - Assert.assertFalse(authorizer.isAdmin(token)); + assertFalse(authorizer.login(token, "", false)); + assertFalse(authorizer.isAdmin(token)); } finally { server.stop(0); } @@ -231,11 +242,20 @@ } } - private void deleteIfExists(Path path) { - try { - Files.deleteIfExists(path); - } catch (IOException e) { - throw new RuntimeException("Failed to delete test path " + path, e); - } + private String createJwt(boolean hasAdminRole) throws JOSEException { + JWTClaimsSet.Builder claimsBuilder = + new JWTClaimsSet.Builder() + .subject("datanode-test-user") + .expirationTime(Date.from(Instant.now().plusSeconds(3600))) + .claim( + "realm_access", + Collections.singletonMap( + "roles", + hasAdminRole + ? Collections.singletonList(OpenIdAuthorizer.IOTDB_ADMIN_ROLE_NAME) + : Collections.singletonList("offline_access"))); + SignedJWT signedJwt = new SignedJWT(new JWSHeader(JWSAlgorithm.RS256), claimsBuilder.build()); + signedJwt.sign(new RSASSASigner(privateKey)); + return signedJwt.serialize(); } }