mirror of
https://github.com/google/nomulus
synced 2026-09-08 17:17:02 +00:00
Allow UserAuthInfo to contain either old GAE Users or new console Users (#1744)
This means that LegacyAuthenticationMechanism or a to-be-created OAuth2AuthenticationMechanism) can return a UserAuthInfo object that contains either the GAE User or the console User as appropriate. The goal is that the non-auth flows shouldn't have to know about which user type it is. Note: the registry lock flow (for now) needs to know about the separate types of auth because it is a separate level of auth from the standard AuthenticatedRegistrarAccessor. The AuthenticatedRegistrarAccessor code is a bit odd because the new role system doesn't quite fit neatly into the old registrar -> OWNER,ADMIN system but this is a fine approximation. Basically, any new registrar role will map to the old OWNER role.
This commit is contained in:
@@ -474,7 +474,7 @@ public final class RequestHandlerTest {
|
||||
assertThat(providedAuthResult).isNotNull();
|
||||
assertThat(providedAuthResult.authLevel()).isEqualTo(AuthLevel.USER);
|
||||
assertThat(providedAuthResult.userAuthInfo()).isPresent();
|
||||
assertThat(providedAuthResult.userAuthInfo().get().user()).isEqualTo(testUser);
|
||||
assertThat(providedAuthResult.userAuthInfo().get().appEngineUser()).hasValue(testUser);
|
||||
assertThat(providedAuthResult.userAuthInfo().get().oauthTokenInfo()).isEmpty();
|
||||
assertMetric("/auth/adminUser", GET, AuthLevel.USER, true);
|
||||
}
|
||||
|
||||
+142
-76
@@ -28,11 +28,15 @@ import static org.mockito.Mockito.verifyNoInteractions;
|
||||
import static org.mockito.Mockito.when;
|
||||
|
||||
import com.google.appengine.api.users.User;
|
||||
import com.google.common.collect.ImmutableMap;
|
||||
import com.google.common.collect.ImmutableSetMultimap;
|
||||
import com.google.common.testing.NullPointerTester;
|
||||
import com.google.common.testing.TestLogHandler;
|
||||
import dagger.Lazy;
|
||||
import google.registry.groups.GroupsConnection;
|
||||
import google.registry.model.console.GlobalRole;
|
||||
import google.registry.model.console.RegistrarRole;
|
||||
import google.registry.model.console.UserRoles;
|
||||
import google.registry.model.registrar.Registrar;
|
||||
import google.registry.model.registrar.Registrar.State;
|
||||
import google.registry.request.auth.AuthenticatedRegistrarAccessor.RegistrarAccessDeniedException;
|
||||
@@ -71,14 +75,14 @@ class AuthenticatedRegistrarAccessorTest {
|
||||
private static final AuthResult GAE_ADMIN = createAuthResult(true);
|
||||
private static final AuthResult NO_USER = AuthResult.create(AuthLevel.NONE);
|
||||
private static final Optional<String> SUPPORT_GROUP = Optional.of("support@registry.example");
|
||||
/** Client ID of a REAL registrar with a RegistrarContact for USER and GAE_ADMIN. */
|
||||
private static final String CLIENT_ID_WITH_CONTACT = "TheRegistrar";
|
||||
/** Client ID of a REAL registrar without a RegistrarContact. */
|
||||
private static final String REAL_CLIENT_ID_WITHOUT_CONTACT = "NewRegistrar";
|
||||
/** Client ID of an OTE registrar without a RegistrarContact. */
|
||||
private static final String OTE_CLIENT_ID_WITHOUT_CONTACT = "OteRegistrar";
|
||||
/** Client ID of the Admin registrar without a RegistrarContact. */
|
||||
private static final String ADMIN_CLIENT_ID = "AdminRegistrar";
|
||||
/** Registrar ID of a REAL registrar with a RegistrarContact for USER and GAE_ADMIN. */
|
||||
private static final String REGISTRAR_ID_WITH_CONTACT = "TheRegistrar";
|
||||
/** Registrar ID of a REAL registrar without a RegistrarContact. */
|
||||
private static final String REAL_REGISTRAR_ID_WITHOUT_CONTACT = "NewRegistrar";
|
||||
/** Registrar ID of an OTE registrar without a RegistrarContact. */
|
||||
private static final String OTE_REGISTRAR_ID_WITHOUT_CONTACT = "OteRegistrar";
|
||||
/** Registrar ID of the Admin registrar without a RegistrarContact. */
|
||||
private static final String ADMIN_REGISTRAR_ID = "AdminRegistrar";
|
||||
|
||||
/**
|
||||
* Creates an AuthResult for a fake user.
|
||||
@@ -104,18 +108,17 @@ class AuthenticatedRegistrarAccessorTest {
|
||||
void beforeEach() {
|
||||
when(lazyGroupsConnection.get()).thenReturn(groupsConnection);
|
||||
JdkLoggerConfig.getConfig(AuthenticatedRegistrarAccessor.class).addHandler(testLogHandler);
|
||||
// persistResource(loadRegistrar(ADMIN_CLIENT_ID));
|
||||
persistResource(
|
||||
loadRegistrar(REAL_CLIENT_ID_WITHOUT_CONTACT)
|
||||
loadRegistrar(REAL_REGISTRAR_ID_WITHOUT_CONTACT)
|
||||
.asBuilder()
|
||||
.setRegistrarId(OTE_CLIENT_ID_WITHOUT_CONTACT)
|
||||
.setRegistrarId(OTE_REGISTRAR_ID_WITHOUT_CONTACT)
|
||||
.setType(Registrar.Type.OTE)
|
||||
.setIanaIdentifier(null)
|
||||
.build());
|
||||
persistResource(
|
||||
loadRegistrar(REAL_CLIENT_ID_WITHOUT_CONTACT)
|
||||
loadRegistrar(REAL_REGISTRAR_ID_WITHOUT_CONTACT)
|
||||
.asBuilder()
|
||||
.setRegistrarId(ADMIN_CLIENT_ID)
|
||||
.setRegistrarId(ADMIN_REGISTRAR_ID)
|
||||
.setType(Registrar.Type.OTE)
|
||||
.setIanaIdentifier(null)
|
||||
.build());
|
||||
@@ -129,24 +132,24 @@ class AuthenticatedRegistrarAccessorTest {
|
||||
|
||||
/** Users are owners for registrars if and only if they are in the contacts for that registrar. */
|
||||
@Test
|
||||
void getAllClientIdWithAccess_user() {
|
||||
void getAllRegistrarIdWithAccess_user() {
|
||||
AuthenticatedRegistrarAccessor registrarAccessor =
|
||||
new AuthenticatedRegistrarAccessor(
|
||||
USER, ADMIN_CLIENT_ID, SUPPORT_GROUP, lazyGroupsConnection);
|
||||
USER, ADMIN_REGISTRAR_ID, SUPPORT_GROUP, lazyGroupsConnection);
|
||||
|
||||
assertThat(registrarAccessor.getAllClientIdWithRoles())
|
||||
.containsExactly(CLIENT_ID_WITH_CONTACT, OWNER);
|
||||
assertThat(registrarAccessor.getAllRegistrarIdsWithRoles())
|
||||
.containsExactly(REGISTRAR_ID_WITH_CONTACT, OWNER);
|
||||
verify(lazyGroupsConnection).get();
|
||||
}
|
||||
|
||||
/** Logged-out users don't have access to anything. */
|
||||
@Test
|
||||
void getAllClientIdWithAccess_loggedOutUser() {
|
||||
void getAllRegistrarIdWithAccess_loggedOutUser() {
|
||||
AuthenticatedRegistrarAccessor registrarAccessor =
|
||||
new AuthenticatedRegistrarAccessor(
|
||||
NO_USER, ADMIN_CLIENT_ID, SUPPORT_GROUP, lazyGroupsConnection);
|
||||
NO_USER, ADMIN_REGISTRAR_ID, SUPPORT_GROUP, lazyGroupsConnection);
|
||||
|
||||
assertThat(registrarAccessor.getAllClientIdWithRoles()).isEmpty();
|
||||
assertThat(registrarAccessor.getAllRegistrarIdsWithRoles()).isEmpty();
|
||||
verifyNoInteractions(lazyGroupsConnection);
|
||||
}
|
||||
|
||||
@@ -162,23 +165,20 @@ class AuthenticatedRegistrarAccessorTest {
|
||||
* <p>(in other words - they don't have OWNER access only to REAL registrars owned by others)
|
||||
*/
|
||||
@Test
|
||||
void getAllClientIdWithAccess_gaeAdmin() {
|
||||
void getAllRegistrarIdWithAccess_gaeAdmin() {
|
||||
AuthenticatedRegistrarAccessor registrarAccessor =
|
||||
new AuthenticatedRegistrarAccessor(
|
||||
GAE_ADMIN, ADMIN_CLIENT_ID, SUPPORT_GROUP, lazyGroupsConnection);
|
||||
GAE_ADMIN, ADMIN_REGISTRAR_ID, SUPPORT_GROUP, lazyGroupsConnection);
|
||||
|
||||
assertThat(registrarAccessor.getAllClientIdWithRoles())
|
||||
assertThat(registrarAccessor.getAllRegistrarIdsWithRoles())
|
||||
.containsExactly(
|
||||
CLIENT_ID_WITH_CONTACT, ADMIN,
|
||||
CLIENT_ID_WITH_CONTACT, OWNER,
|
||||
|
||||
REAL_CLIENT_ID_WITHOUT_CONTACT, ADMIN,
|
||||
|
||||
OTE_CLIENT_ID_WITHOUT_CONTACT, ADMIN,
|
||||
OTE_CLIENT_ID_WITHOUT_CONTACT, OWNER,
|
||||
|
||||
ADMIN_CLIENT_ID, ADMIN,
|
||||
ADMIN_CLIENT_ID, OWNER);
|
||||
REGISTRAR_ID_WITH_CONTACT, ADMIN,
|
||||
REGISTRAR_ID_WITH_CONTACT, OWNER,
|
||||
REAL_REGISTRAR_ID_WITHOUT_CONTACT, ADMIN,
|
||||
OTE_REGISTRAR_ID_WITHOUT_CONTACT, ADMIN,
|
||||
OTE_REGISTRAR_ID_WITHOUT_CONTACT, OWNER,
|
||||
ADMIN_REGISTRAR_ID, ADMIN,
|
||||
ADMIN_REGISTRAR_ID, OWNER);
|
||||
verifyNoInteractions(lazyGroupsConnection);
|
||||
}
|
||||
|
||||
@@ -194,51 +194,48 @@ class AuthenticatedRegistrarAccessorTest {
|
||||
* <p>(in other words - they don't have OWNER access only to REAL registrars owned by others)
|
||||
*/
|
||||
@Test
|
||||
void getAllClientIdWithAccess_userInSupportGroup() {
|
||||
void getAllRegistrarIdWithAccess_userInSupportGroup() {
|
||||
when(groupsConnection.isMemberOfGroup("user@gmail.com", SUPPORT_GROUP.get())).thenReturn(true);
|
||||
AuthenticatedRegistrarAccessor registrarAccessor =
|
||||
new AuthenticatedRegistrarAccessor(
|
||||
USER, ADMIN_CLIENT_ID, SUPPORT_GROUP, lazyGroupsConnection);
|
||||
USER, ADMIN_REGISTRAR_ID, SUPPORT_GROUP, lazyGroupsConnection);
|
||||
|
||||
assertThat(registrarAccessor.getAllClientIdWithRoles())
|
||||
assertThat(registrarAccessor.getAllRegistrarIdsWithRoles())
|
||||
.containsExactly(
|
||||
CLIENT_ID_WITH_CONTACT, ADMIN,
|
||||
CLIENT_ID_WITH_CONTACT, OWNER,
|
||||
|
||||
REAL_CLIENT_ID_WITHOUT_CONTACT, ADMIN,
|
||||
|
||||
OTE_CLIENT_ID_WITHOUT_CONTACT, ADMIN,
|
||||
OTE_CLIENT_ID_WITHOUT_CONTACT, OWNER,
|
||||
|
||||
ADMIN_CLIENT_ID, ADMIN,
|
||||
ADMIN_CLIENT_ID, OWNER);
|
||||
REGISTRAR_ID_WITH_CONTACT, ADMIN,
|
||||
REGISTRAR_ID_WITH_CONTACT, OWNER,
|
||||
REAL_REGISTRAR_ID_WITHOUT_CONTACT, ADMIN,
|
||||
OTE_REGISTRAR_ID_WITHOUT_CONTACT, ADMIN,
|
||||
OTE_REGISTRAR_ID_WITHOUT_CONTACT, OWNER,
|
||||
ADMIN_REGISTRAR_ID, ADMIN,
|
||||
ADMIN_REGISTRAR_ID, OWNER);
|
||||
verify(lazyGroupsConnection).get();
|
||||
}
|
||||
|
||||
/** Empty Support group email - skips check and doesn't generate the lazy. */
|
||||
@Test
|
||||
void getAllClientIdWithAccess_emptySupportEmail_works() {
|
||||
void getAllRegistrarIdWithAccess_emptySupportEmail_works() {
|
||||
AuthenticatedRegistrarAccessor registrarAccessor =
|
||||
new AuthenticatedRegistrarAccessor(
|
||||
USER, ADMIN_CLIENT_ID, Optional.empty(), lazyGroupsConnection);
|
||||
USER, ADMIN_REGISTRAR_ID, Optional.empty(), lazyGroupsConnection);
|
||||
|
||||
assertThat(registrarAccessor.getAllClientIdWithRoles())
|
||||
.containsExactly(CLIENT_ID_WITH_CONTACT, OWNER);
|
||||
assertThat(registrarAccessor.getAllRegistrarIdsWithRoles())
|
||||
.containsExactly(REGISTRAR_ID_WITH_CONTACT, OWNER);
|
||||
// Make sure we didn't instantiate the lazyGroupsConnection
|
||||
verifyNoInteractions(lazyGroupsConnection);
|
||||
}
|
||||
|
||||
/** Support group check throws - continue anyway. */
|
||||
@Test
|
||||
void getAllClientIdWithAccess_throwingGroupCheck_stillWorks() {
|
||||
void getAllRegistrarIdWithAccess_throwingGroupCheck_stillWorks() {
|
||||
when(groupsConnection.isMemberOfGroup(any(), any())).thenThrow(new RuntimeException("blah"));
|
||||
AuthenticatedRegistrarAccessor registrarAccessor =
|
||||
new AuthenticatedRegistrarAccessor(
|
||||
USER, ADMIN_CLIENT_ID, SUPPORT_GROUP, lazyGroupsConnection);
|
||||
USER, ADMIN_REGISTRAR_ID, SUPPORT_GROUP, lazyGroupsConnection);
|
||||
|
||||
verify(groupsConnection).isMemberOfGroup("user@gmail.com", SUPPORT_GROUP.get());
|
||||
assertThat(registrarAccessor.getAllClientIdWithRoles())
|
||||
.containsExactly(CLIENT_ID_WITH_CONTACT, OWNER);
|
||||
assertThat(registrarAccessor.getAllRegistrarIdsWithRoles())
|
||||
.containsExactly(REGISTRAR_ID_WITH_CONTACT, OWNER);
|
||||
verify(lazyGroupsConnection).get();
|
||||
}
|
||||
|
||||
@@ -246,7 +243,7 @@ class AuthenticatedRegistrarAccessorTest {
|
||||
@Test
|
||||
void testGetRegistrarForUser_noAccess_isNotAdmin() {
|
||||
expectGetRegistrarFailure(
|
||||
REAL_CLIENT_ID_WITHOUT_CONTACT,
|
||||
REAL_REGISTRAR_ID_WITHOUT_CONTACT,
|
||||
USER,
|
||||
"user user@gmail.com doesn't have access to registrar NewRegistrar");
|
||||
verify(lazyGroupsConnection).get();
|
||||
@@ -261,7 +258,7 @@ class AuthenticatedRegistrarAccessorTest {
|
||||
.setState(State.DISABLED)
|
||||
.build());
|
||||
expectGetRegistrarFailure(
|
||||
CLIENT_ID_WITH_CONTACT,
|
||||
REGISTRAR_ID_WITH_CONTACT,
|
||||
USER,
|
||||
"user user@gmail.com doesn't have access to registrar TheRegistrar");
|
||||
verify(lazyGroupsConnection).get();
|
||||
@@ -271,7 +268,7 @@ class AuthenticatedRegistrarAccessorTest {
|
||||
@Test
|
||||
void testGetRegistrarForUser_noAccess_isNotAdmin_notReal() {
|
||||
expectGetRegistrarFailure(
|
||||
OTE_CLIENT_ID_WITHOUT_CONTACT,
|
||||
OTE_REGISTRAR_ID_WITHOUT_CONTACT,
|
||||
USER,
|
||||
"user user@gmail.com doesn't have access to registrar OteRegistrar");
|
||||
verify(lazyGroupsConnection).get();
|
||||
@@ -281,7 +278,7 @@ class AuthenticatedRegistrarAccessorTest {
|
||||
@Test
|
||||
void testGetRegistrarForUser_noUser() {
|
||||
expectGetRegistrarFailure(
|
||||
CLIENT_ID_WITH_CONTACT,
|
||||
REGISTRAR_ID_WITH_CONTACT,
|
||||
NO_USER,
|
||||
"<logged-out user> doesn't have access to registrar TheRegistrar");
|
||||
verifyNoInteractions(lazyGroupsConnection);
|
||||
@@ -291,7 +288,7 @@ class AuthenticatedRegistrarAccessorTest {
|
||||
@Test
|
||||
void testGetRegistrarForUser_inContacts_isNotAdmin() throws Exception {
|
||||
expectGetRegistrarSuccess(
|
||||
CLIENT_ID_WITH_CONTACT,
|
||||
REGISTRAR_ID_WITH_CONTACT,
|
||||
USER,
|
||||
"user user@gmail.com has [OWNER] access to registrar TheRegistrar");
|
||||
verify(lazyGroupsConnection).get();
|
||||
@@ -301,7 +298,7 @@ class AuthenticatedRegistrarAccessorTest {
|
||||
@Test
|
||||
void testGetRegistrarForUser_inContacts_isAdmin() throws Exception {
|
||||
expectGetRegistrarSuccess(
|
||||
CLIENT_ID_WITH_CONTACT,
|
||||
REGISTRAR_ID_WITH_CONTACT,
|
||||
GAE_ADMIN,
|
||||
"admin admin@gmail.com has [OWNER, ADMIN] access to registrar TheRegistrar");
|
||||
verifyNoInteractions(lazyGroupsConnection);
|
||||
@@ -311,7 +308,7 @@ class AuthenticatedRegistrarAccessorTest {
|
||||
@Test
|
||||
void testGetRegistrarForUser_notInContacts_isAdmin() throws Exception {
|
||||
expectGetRegistrarSuccess(
|
||||
REAL_CLIENT_ID_WITHOUT_CONTACT,
|
||||
REAL_REGISTRAR_ID_WITHOUT_CONTACT,
|
||||
GAE_ADMIN,
|
||||
"admin admin@gmail.com has [ADMIN] access to registrar NewRegistrar.");
|
||||
verifyNoInteractions(lazyGroupsConnection);
|
||||
@@ -326,7 +323,7 @@ class AuthenticatedRegistrarAccessorTest {
|
||||
.setState(State.DISABLED)
|
||||
.build());
|
||||
expectGetRegistrarSuccess(
|
||||
REAL_CLIENT_ID_WITHOUT_CONTACT,
|
||||
REAL_REGISTRAR_ID_WITHOUT_CONTACT,
|
||||
GAE_ADMIN,
|
||||
"admin admin@gmail.com has [OWNER, ADMIN] access to registrar NewRegistrar.");
|
||||
verifyNoInteractions(lazyGroupsConnection);
|
||||
@@ -336,7 +333,7 @@ class AuthenticatedRegistrarAccessorTest {
|
||||
@Test
|
||||
void testGetRegistrarForUser_notInContacts_isAdmin_notReal() throws Exception {
|
||||
expectGetRegistrarSuccess(
|
||||
OTE_CLIENT_ID_WITHOUT_CONTACT,
|
||||
OTE_REGISTRAR_ID_WITHOUT_CONTACT,
|
||||
GAE_ADMIN,
|
||||
"admin admin@gmail.com has [OWNER, ADMIN] access to registrar OteRegistrar.");
|
||||
verifyNoInteractions(lazyGroupsConnection);
|
||||
@@ -346,9 +343,7 @@ class AuthenticatedRegistrarAccessorTest {
|
||||
@Test
|
||||
void testGetRegistrarForUser_doesntExist_isAdmin() {
|
||||
expectGetRegistrarFailure(
|
||||
"BadClientId",
|
||||
GAE_ADMIN,
|
||||
"Registrar BadClientId does not exist");
|
||||
"BadRegistrarId", GAE_ADMIN, "Registrar BadRegistrarId does not exist");
|
||||
verifyNoInteractions(lazyGroupsConnection);
|
||||
}
|
||||
|
||||
@@ -356,7 +351,7 @@ class AuthenticatedRegistrarAccessorTest {
|
||||
throws Exception {
|
||||
AuthenticatedRegistrarAccessor registrarAccessor =
|
||||
new AuthenticatedRegistrarAccessor(
|
||||
authResult, ADMIN_CLIENT_ID, SUPPORT_GROUP, lazyGroupsConnection);
|
||||
authResult, ADMIN_REGISTRAR_ID, SUPPORT_GROUP, lazyGroupsConnection);
|
||||
|
||||
// make sure loading the registrar succeeds and returns a value
|
||||
assertThat(registrarAccessor.getRegistrar(registrarId)).isNotNull();
|
||||
@@ -367,7 +362,7 @@ class AuthenticatedRegistrarAccessorTest {
|
||||
String registrarId, AuthResult authResult, String message) {
|
||||
AuthenticatedRegistrarAccessor registrarAccessor =
|
||||
new AuthenticatedRegistrarAccessor(
|
||||
authResult, ADMIN_CLIENT_ID, SUPPORT_GROUP, lazyGroupsConnection);
|
||||
authResult, ADMIN_REGISTRAR_ID, SUPPORT_GROUP, lazyGroupsConnection);
|
||||
|
||||
// make sure getRegistrar fails
|
||||
RegistrarAccessDeniedException exception =
|
||||
@@ -378,27 +373,27 @@ class AuthenticatedRegistrarAccessorTest {
|
||||
assertThat(exception).hasMessageThat().contains(message);
|
||||
}
|
||||
|
||||
/** guessClientIdForUser returns the first clientId in getAllClientIdWithRoles. */
|
||||
/** guessRegistrarIdForUser returns the first registrarId in getAllRegistrarIdWithRoles. */
|
||||
@Test
|
||||
void testGuessClientIdForUser_hasAccess_returnsFirst() throws Exception {
|
||||
void testGuessRegistrarIdForUser_hasAccess_returnsFirst() throws Exception {
|
||||
AuthenticatedRegistrarAccessor registrarAccessor =
|
||||
AuthenticatedRegistrarAccessor.createForTesting(
|
||||
ImmutableSetMultimap.of(
|
||||
"clientId-1", OWNER,
|
||||
"clientId-2", OWNER,
|
||||
"clientId-2", ADMIN));
|
||||
"registrarId-1", OWNER,
|
||||
"registrarId-2", OWNER,
|
||||
"registrarId-2", ADMIN));
|
||||
|
||||
assertThat(registrarAccessor.guessClientId()).isEqualTo("clientId-1");
|
||||
assertThat(registrarAccessor.guessRegistrarId()).isEqualTo("registrarId-1");
|
||||
}
|
||||
|
||||
/** If a user doesn't have access to any registrars, guess fails. */
|
||||
@Test
|
||||
void testGuessClientIdForUser_noAccess_fails() {
|
||||
void testGuessRegistrarIdForUser_noAccess_fails() {
|
||||
AuthenticatedRegistrarAccessor registrarAccessor =
|
||||
AuthenticatedRegistrarAccessor.createForTesting(ImmutableSetMultimap.of());
|
||||
|
||||
RegistrarAccessDeniedException thrown =
|
||||
assertThrows(RegistrarAccessDeniedException.class, registrarAccessor::guessClientId);
|
||||
assertThrows(RegistrarAccessDeniedException.class, registrarAccessor::guessRegistrarId);
|
||||
assertThat(thrown).hasMessageThat().isEqualTo("TestUserId isn't associated with any registrar");
|
||||
}
|
||||
|
||||
@@ -409,4 +404,75 @@ class AuthenticatedRegistrarAccessorTest {
|
||||
.setDefault(HttpServletResponse.class, rsp)
|
||||
.testAllPublicStaticMethods(AuthenticatedRegistrarAccessor.class);
|
||||
}
|
||||
|
||||
@Test
|
||||
void testConsoleUser_admin() {
|
||||
google.registry.model.console.User consoleUser =
|
||||
new google.registry.model.console.User.Builder()
|
||||
.setGaiaId("gaiaId")
|
||||
.setEmailAddress("email@email.com")
|
||||
.setUserRoles(
|
||||
new UserRoles.Builder().setIsAdmin(true).setGlobalRole(GlobalRole.FTE).build())
|
||||
.build();
|
||||
AuthResult authResult = AuthResult.create(AuthLevel.USER, UserAuthInfo.create(consoleUser));
|
||||
AuthenticatedRegistrarAccessor registrarAccessor =
|
||||
new AuthenticatedRegistrarAccessor(
|
||||
authResult, ADMIN_REGISTRAR_ID, SUPPORT_GROUP, lazyGroupsConnection);
|
||||
|
||||
// Admin access to all, and owner access to the non-real registrar and the admin registrar
|
||||
assertThat(registrarAccessor.getAllRegistrarIdsWithRoles())
|
||||
.containsExactly(
|
||||
REGISTRAR_ID_WITH_CONTACT, ADMIN,
|
||||
REAL_REGISTRAR_ID_WITHOUT_CONTACT, ADMIN,
|
||||
OTE_REGISTRAR_ID_WITHOUT_CONTACT, ADMIN,
|
||||
OTE_REGISTRAR_ID_WITHOUT_CONTACT, OWNER,
|
||||
ADMIN_REGISTRAR_ID, ADMIN,
|
||||
ADMIN_REGISTRAR_ID, OWNER);
|
||||
}
|
||||
|
||||
@Test
|
||||
void testConsoleUser_globalRole() {
|
||||
// Users with global roles shouldn't necessarily have access to specific registrars if they're
|
||||
// not admins
|
||||
google.registry.model.console.User consoleUser =
|
||||
new google.registry.model.console.User.Builder()
|
||||
.setGaiaId("gaiaId")
|
||||
.setEmailAddress("email@email.com")
|
||||
.setUserRoles(new UserRoles.Builder().setGlobalRole(GlobalRole.SUPPORT_AGENT).build())
|
||||
.build();
|
||||
AuthResult authResult = AuthResult.create(AuthLevel.USER, UserAuthInfo.create(consoleUser));
|
||||
AuthenticatedRegistrarAccessor registrarAccessor =
|
||||
new AuthenticatedRegistrarAccessor(
|
||||
authResult, ADMIN_REGISTRAR_ID, SUPPORT_GROUP, lazyGroupsConnection);
|
||||
|
||||
// Explicit access to registrars is required for non-admins
|
||||
assertThat(registrarAccessor.getAllRegistrarIdsWithRoles()).isEmpty();
|
||||
}
|
||||
|
||||
@Test
|
||||
void testConsoleUser_registrarRoles() {
|
||||
// Registrar employees should have OWNER access to their registrars
|
||||
google.registry.model.console.User consoleUser =
|
||||
new google.registry.model.console.User.Builder()
|
||||
.setGaiaId("gaiaId")
|
||||
.setEmailAddress("email@email.com")
|
||||
.setUserRoles(
|
||||
new UserRoles.Builder()
|
||||
.setRegistrarRoles(
|
||||
ImmutableMap.of(
|
||||
REGISTRAR_ID_WITH_CONTACT,
|
||||
RegistrarRole.ACCOUNT_MANAGER,
|
||||
REAL_REGISTRAR_ID_WITHOUT_CONTACT,
|
||||
RegistrarRole.ACCOUNT_MANAGER))
|
||||
.build())
|
||||
.build();
|
||||
AuthResult authResult = AuthResult.create(AuthLevel.USER, UserAuthInfo.create(consoleUser));
|
||||
AuthenticatedRegistrarAccessor registrarAccessor =
|
||||
new AuthenticatedRegistrarAccessor(
|
||||
authResult, ADMIN_REGISTRAR_ID, SUPPORT_GROUP, lazyGroupsConnection);
|
||||
assertThat(registrarAccessor.getAllRegistrarIdsWithRoles())
|
||||
.containsExactly(
|
||||
REGISTRAR_ID_WITH_CONTACT, OWNER,
|
||||
REAL_REGISTRAR_ID_WITHOUT_CONTACT, OWNER);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -209,7 +209,7 @@ class RequestAuthenticatorTest {
|
||||
assertThat(authResult).isPresent();
|
||||
assertThat(authResult.get().authLevel()).isEqualTo(AuthLevel.USER);
|
||||
assertThat(authResult.get().userAuthInfo()).isPresent();
|
||||
assertThat(authResult.get().userAuthInfo().get().user()).isEqualTo(testUser);
|
||||
assertThat(authResult.get().userAuthInfo().get().appEngineUser()).hasValue(testUser);
|
||||
assertThat(authResult.get().userAuthInfo().get().isUserAdmin()).isFalse();
|
||||
assertThat(authResult.get().userAuthInfo().get().oauthTokenInfo()).isEmpty();
|
||||
}
|
||||
@@ -224,7 +224,7 @@ class RequestAuthenticatorTest {
|
||||
assertThat(authResult).isPresent();
|
||||
assertThat(authResult.get().authLevel()).isEqualTo(AuthLevel.USER);
|
||||
assertThat(authResult.get().userAuthInfo()).isPresent();
|
||||
assertThat(authResult.get().userAuthInfo().get().user()).isEqualTo(testUser);
|
||||
assertThat(authResult.get().userAuthInfo().get().appEngineUser()).hasValue(testUser);
|
||||
assertThat(authResult.get().userAuthInfo().get().oauthTokenInfo()).isEmpty();
|
||||
}
|
||||
|
||||
@@ -264,7 +264,7 @@ class RequestAuthenticatorTest {
|
||||
assertThat(authResult).isPresent();
|
||||
assertThat(authResult.get().authLevel()).isEqualTo(AuthLevel.USER);
|
||||
assertThat(authResult.get().userAuthInfo()).isPresent();
|
||||
assertThat(authResult.get().userAuthInfo().get().user()).isEqualTo(testUser);
|
||||
assertThat(authResult.get().userAuthInfo().get().appEngineUser()).hasValue(testUser);
|
||||
assertThat(authResult.get().userAuthInfo().get().isUserAdmin()).isTrue();
|
||||
assertThat(authResult.get().userAuthInfo().get().oauthTokenInfo()).isEmpty();
|
||||
}
|
||||
@@ -280,7 +280,7 @@ class RequestAuthenticatorTest {
|
||||
assertThat(authResult).isPresent();
|
||||
assertThat(authResult.get().authLevel()).isEqualTo(AuthLevel.USER);
|
||||
assertThat(authResult.get().userAuthInfo()).isPresent();
|
||||
assertThat(authResult.get().userAuthInfo().get().user()).isEqualTo(testUser);
|
||||
assertThat(authResult.get().userAuthInfo().get().appEngineUser()).hasValue(testUser);
|
||||
assertThat(authResult.get().userAuthInfo().get().isUserAdmin()).isFalse();
|
||||
assertThat(authResult.get().userAuthInfo().get().oauthTokenInfo()).isPresent();
|
||||
assertThat(authResult.get().userAuthInfo().get().oauthTokenInfo().get().authorizedScopes())
|
||||
@@ -303,7 +303,7 @@ class RequestAuthenticatorTest {
|
||||
assertThat(authResult).isPresent();
|
||||
assertThat(authResult.get().authLevel()).isEqualTo(AuthLevel.USER);
|
||||
assertThat(authResult.get().userAuthInfo()).isPresent();
|
||||
assertThat(authResult.get().userAuthInfo().get().user()).isEqualTo(testUser);
|
||||
assertThat(authResult.get().userAuthInfo().get().appEngineUser()).hasValue(testUser);
|
||||
assertThat(authResult.get().userAuthInfo().get().isUserAdmin()).isTrue();
|
||||
assertThat(authResult.get().userAuthInfo().get().oauthTokenInfo()).isPresent();
|
||||
assertThat(authResult.get().userAuthInfo().get().oauthTokenInfo().get().authorizedScopes())
|
||||
@@ -372,7 +372,7 @@ class RequestAuthenticatorTest {
|
||||
assertThat(authResult).isPresent();
|
||||
assertThat(authResult.get().authLevel()).isEqualTo(AuthLevel.USER);
|
||||
assertThat(authResult.get().userAuthInfo()).isPresent();
|
||||
assertThat(authResult.get().userAuthInfo().get().user()).isEqualTo(testUser);
|
||||
assertThat(authResult.get().userAuthInfo().get().appEngineUser()).hasValue(testUser);
|
||||
assertThat(authResult.get().userAuthInfo().get().isUserAdmin()).isFalse();
|
||||
assertThat(authResult.get().userAuthInfo().get().oauthTokenInfo()).isPresent();
|
||||
assertThat(authResult.get().userAuthInfo().get().oauthTokenInfo().get().authorizedScopes())
|
||||
|
||||
@@ -32,6 +32,8 @@ import com.google.common.collect.ImmutableList;
|
||||
import com.google.common.collect.ImmutableMap;
|
||||
import com.google.common.collect.ImmutableSetMultimap;
|
||||
import com.google.gson.Gson;
|
||||
import google.registry.model.console.RegistrarRole;
|
||||
import google.registry.model.console.UserRoles;
|
||||
import google.registry.model.domain.RegistryLock;
|
||||
import google.registry.model.registrar.RegistrarPoc;
|
||||
import google.registry.request.Action.Method;
|
||||
@@ -83,6 +85,60 @@ final class RegistryLockGetActionTest {
|
||||
Method.GET, response, accessor, authResult, Optional.of("TheRegistrar"));
|
||||
}
|
||||
|
||||
@Test
|
||||
void testSuccess_newConsoleUser() {
|
||||
RegistryLock regularLock =
|
||||
new RegistryLock.Builder()
|
||||
.setRepoId("repoId")
|
||||
.setDomainName("example.test")
|
||||
.setRegistrarId("TheRegistrar")
|
||||
.setVerificationCode("123456789ABCDEFGHJKLMNPQRSTUVWXY")
|
||||
.setRegistrarPocId("johndoe@theregistrar.com")
|
||||
.setLockCompletionTime(fakeClock.nowUtc())
|
||||
.build();
|
||||
saveRegistryLock(regularLock);
|
||||
google.registry.model.console.User consoleUser =
|
||||
new google.registry.model.console.User.Builder()
|
||||
.setEmailAddress("johndoe@theregistrar.com")
|
||||
.setGaiaId("gaiaId")
|
||||
.setUserRoles(
|
||||
new UserRoles.Builder()
|
||||
.setRegistrarRoles(
|
||||
ImmutableMap.of(
|
||||
"TheRegistrar", RegistrarRole.ACCOUNT_MANAGER_WITH_REGISTRY_LOCK))
|
||||
.build())
|
||||
.build();
|
||||
|
||||
action.authResult = AuthResult.create(AuthLevel.USER, UserAuthInfo.create(consoleUser));
|
||||
action.run();
|
||||
assertThat(response.getStatus()).isEqualTo(HttpStatusCodes.STATUS_CODE_OK);
|
||||
assertThat(GSON.fromJson(response.getPayload(), Map.class))
|
||||
.containsExactly(
|
||||
"status",
|
||||
"SUCCESS",
|
||||
"message",
|
||||
"Successful locks retrieval",
|
||||
"results",
|
||||
ImmutableList.of(
|
||||
ImmutableMap.of(
|
||||
"lockEnabledForContact",
|
||||
true,
|
||||
"email",
|
||||
"johndoe@theregistrar.com",
|
||||
"clientId",
|
||||
"TheRegistrar",
|
||||
"locks",
|
||||
ImmutableList.of(
|
||||
new ImmutableMap.Builder<>()
|
||||
.put("domainName", "example.test")
|
||||
.put("lockedTime", "2000-06-08T22:00:00.000Z")
|
||||
.put("lockedBy", "johndoe@theregistrar.com")
|
||||
.put("isLockPending", false)
|
||||
.put("isUnlockPending", false)
|
||||
.put("userCanUnlock", true)
|
||||
.build()))));
|
||||
}
|
||||
|
||||
@Test
|
||||
void testSuccess_retrievesLocks() {
|
||||
RegistryLock expiredLock =
|
||||
|
||||
+70
@@ -33,6 +33,8 @@ import com.google.appengine.api.users.User;
|
||||
import com.google.common.collect.ImmutableList;
|
||||
import com.google.common.collect.ImmutableMap;
|
||||
import com.google.common.collect.ImmutableSet;
|
||||
import google.registry.model.console.RegistrarRole;
|
||||
import google.registry.model.console.UserRoles;
|
||||
import google.registry.model.domain.Domain;
|
||||
import google.registry.model.domain.RegistryLock;
|
||||
import google.registry.request.JsonActionRunner;
|
||||
@@ -222,6 +224,47 @@ final class RegistryLockPostActionTest {
|
||||
assertSuccess(response, "lock", "johndoe@theregistrar.com");
|
||||
}
|
||||
|
||||
@Test
|
||||
void testSuccess_consoleUser() throws Exception {
|
||||
google.registry.model.console.User consoleUser =
|
||||
new google.registry.model.console.User.Builder()
|
||||
.setEmailAddress("johndoe@theregistrar.com")
|
||||
.setGaiaId("gaiaId")
|
||||
.setUserRoles(
|
||||
new UserRoles.Builder()
|
||||
.setRegistrarRoles(
|
||||
ImmutableMap.of(
|
||||
"TheRegistrar", RegistrarRole.ACCOUNT_MANAGER_WITH_REGISTRY_LOCK))
|
||||
.build())
|
||||
.setRegistryLockPassword("hi")
|
||||
.build();
|
||||
AuthResult consoleAuthResult =
|
||||
AuthResult.create(AuthLevel.USER, UserAuthInfo.create(consoleUser));
|
||||
action = createAction(consoleAuthResult);
|
||||
Map<String, ?> response = action.handleJsonRequest(lockRequest());
|
||||
assertSuccess(response, "lock", "johndoe@theregistrar.com");
|
||||
}
|
||||
|
||||
@Test
|
||||
void testSuccess_consoleUser_admin() throws Exception {
|
||||
google.registry.model.console.User consoleUser =
|
||||
new google.registry.model.console.User.Builder()
|
||||
.setEmailAddress("johndoe@theregistrar.com")
|
||||
.setGaiaId("gaiaId")
|
||||
.setUserRoles(new UserRoles.Builder().setIsAdmin(true).build())
|
||||
.build();
|
||||
AuthResult consoleAuthResult =
|
||||
AuthResult.create(AuthLevel.USER, UserAuthInfo.create(consoleUser));
|
||||
action = createAction(consoleAuthResult);
|
||||
Map<String, Object> requestMapWithoutPassword =
|
||||
ImmutableMap.of(
|
||||
"isLock", true,
|
||||
"registrarId", "TheRegistrar",
|
||||
"domainName", "example.tld");
|
||||
Map<String, ?> response = action.handleJsonRequest(requestMapWithoutPassword);
|
||||
assertSuccess(response, "lock", "johndoe@theregistrar.com");
|
||||
}
|
||||
|
||||
@Test
|
||||
void testFailure_noInput() {
|
||||
Map<String, ?> response = action.handleJsonRequest(null);
|
||||
@@ -397,6 +440,33 @@ final class RegistryLockPostActionTest {
|
||||
assertFailureWithMessage(response, "Domain example.tld is already unlocked");
|
||||
}
|
||||
|
||||
@Test
|
||||
void testFailure_consoleUser_wrongPassword_noAdmin() {
|
||||
google.registry.model.console.User consoleUser =
|
||||
new google.registry.model.console.User.Builder()
|
||||
.setEmailAddress("johndoe@theregistrar.com")
|
||||
.setGaiaId("gaiaId")
|
||||
.setUserRoles(
|
||||
new UserRoles.Builder()
|
||||
.setRegistrarRoles(
|
||||
ImmutableMap.of(
|
||||
"TheRegistrar", RegistrarRole.ACCOUNT_MANAGER_WITH_REGISTRY_LOCK))
|
||||
.build())
|
||||
.setRegistryLockPassword("hi")
|
||||
.build();
|
||||
AuthResult consoleAuthResult =
|
||||
AuthResult.create(AuthLevel.USER, UserAuthInfo.create(consoleUser));
|
||||
action = createAction(consoleAuthResult);
|
||||
Map<String, ?> response =
|
||||
action.handleJsonRequest(
|
||||
ImmutableMap.of(
|
||||
"registrarId", "TheRegistrar",
|
||||
"domainName", "example.tld",
|
||||
"isLock", true,
|
||||
"password", "badPassword"));
|
||||
assertFailureWithMessage(response, "Incorrect registry lock password for user");
|
||||
}
|
||||
|
||||
private ImmutableMap<String, Object> lockRequest() {
|
||||
return fullRequest(true);
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user