2023-03-28 22:48:58 +00:00
|
|
|
// Copyright (c) HashiCorp, Inc.
|
2023-08-11 13:12:13 +00:00
|
|
|
// SPDX-License-Identifier: BUSL-1.1
|
2023-03-28 22:48:58 +00:00
|
|
|
|
2023-03-27 15:35:39 +00:00
|
|
|
package resource
|
|
|
|
|
|
|
|
import (
|
|
|
|
"context"
|
|
|
|
"testing"
|
|
|
|
|
|
|
|
"github.com/stretchr/testify/mock"
|
|
|
|
"github.com/stretchr/testify/require"
|
|
|
|
"google.golang.org/grpc/codes"
|
|
|
|
"google.golang.org/grpc/metadata"
|
|
|
|
"google.golang.org/grpc/status"
|
2023-08-07 21:37:03 +00:00
|
|
|
"google.golang.org/protobuf/proto"
|
2023-03-27 15:35:39 +00:00
|
|
|
|
2023-04-11 11:10:14 +00:00
|
|
|
"github.com/hashicorp/consul/acl/resolver"
|
2023-03-27 15:35:39 +00:00
|
|
|
"github.com/hashicorp/consul/internal/resource"
|
2023-04-06 09:40:04 +00:00
|
|
|
"github.com/hashicorp/consul/internal/resource/demo"
|
2023-03-27 15:35:39 +00:00
|
|
|
"github.com/hashicorp/consul/internal/storage"
|
|
|
|
"github.com/hashicorp/consul/proto-public/pbresource"
|
|
|
|
"github.com/hashicorp/consul/proto/private/prototest"
|
|
|
|
)
|
|
|
|
|
2023-04-17 21:33:20 +00:00
|
|
|
func TestRead_InputValidation(t *testing.T) {
|
|
|
|
server := testServer(t)
|
|
|
|
client := testClient(t, server)
|
2023-04-25 11:52:35 +00:00
|
|
|
demo.RegisterTypes(server.Registry)
|
2023-04-17 21:33:20 +00:00
|
|
|
|
2023-08-07 21:37:03 +00:00
|
|
|
testCases := map[string]func(artistId, recordlabelId *pbresource.ID) *pbresource.ID{
|
|
|
|
"no id": func(artistId, recordLabelId *pbresource.ID) *pbresource.ID { return nil },
|
|
|
|
"no type": func(artistId, _ *pbresource.ID) *pbresource.ID {
|
|
|
|
artistId.Type = nil
|
|
|
|
return artistId
|
|
|
|
},
|
|
|
|
"no tenancy": func(artistId, _ *pbresource.ID) *pbresource.ID {
|
|
|
|
artistId.Tenancy = nil
|
|
|
|
return artistId
|
2023-04-17 21:33:20 +00:00
|
|
|
},
|
2023-08-07 21:37:03 +00:00
|
|
|
"no name": func(artistId, _ *pbresource.ID) *pbresource.ID {
|
|
|
|
artistId.Name = ""
|
|
|
|
return artistId
|
2023-04-17 21:33:20 +00:00
|
|
|
},
|
2023-08-07 21:37:03 +00:00
|
|
|
"partition scope with non-empty namespace": func(_, recordLabelId *pbresource.ID) *pbresource.ID {
|
|
|
|
recordLabelId.Tenancy.Namespace = "ishouldnothaveanamespace"
|
|
|
|
return recordLabelId
|
2023-04-17 21:33:20 +00:00
|
|
|
},
|
|
|
|
}
|
|
|
|
for desc, modFn := range testCases {
|
|
|
|
t.Run(desc, func(t *testing.T) {
|
2023-08-07 21:37:03 +00:00
|
|
|
artist, err := demo.GenerateV2Artist()
|
2023-04-17 21:33:20 +00:00
|
|
|
require.NoError(t, err)
|
|
|
|
|
2023-08-07 21:37:03 +00:00
|
|
|
recordLabel, err := demo.GenerateV1RecordLabel("LoonyTunes")
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
|
|
|
// Each test case picks which resource to use based on the resource type's scope.
|
|
|
|
req := &pbresource.ReadRequest{Id: modFn(artist.Id, recordLabel.Id)}
|
2023-04-17 21:33:20 +00:00
|
|
|
|
|
|
|
_, err = client.Read(testContext(t), req)
|
|
|
|
require.Error(t, err)
|
|
|
|
require.Equal(t, codes.InvalidArgument.String(), status.Code(err).String())
|
|
|
|
})
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2023-03-27 15:35:39 +00:00
|
|
|
func TestRead_TypeNotFound(t *testing.T) {
|
2023-04-06 09:40:04 +00:00
|
|
|
server := NewServer(Config{Registry: resource.NewRegistry()})
|
2023-03-27 15:35:39 +00:00
|
|
|
client := testClient(t, server)
|
|
|
|
|
2023-04-06 09:40:04 +00:00
|
|
|
artist, err := demo.GenerateV2Artist()
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
|
|
|
_, err = client.Read(context.Background(), &pbresource.ReadRequest{Id: artist.Id})
|
2023-03-27 15:35:39 +00:00
|
|
|
require.Error(t, err)
|
|
|
|
require.Equal(t, codes.InvalidArgument.String(), status.Code(err).String())
|
2023-06-26 12:25:14 +00:00
|
|
|
require.Contains(t, err.Error(), "resource type demo.v2.Artist not registered")
|
2023-03-27 15:35:39 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
func TestRead_ResourceNotFound(t *testing.T) {
|
|
|
|
for desc, tc := range readTestCases() {
|
|
|
|
t.Run(desc, func(t *testing.T) {
|
2023-08-07 21:37:03 +00:00
|
|
|
tenancyCases := map[string]func(artistId, recordlabelId *pbresource.ID) *pbresource.ID{
|
|
|
|
"resource not found by name": func(artistId, _ *pbresource.ID) *pbresource.ID {
|
|
|
|
artistId.Name = "bogusname"
|
|
|
|
return artistId
|
|
|
|
},
|
|
|
|
"partition not found when namespace scoped": func(artistId, _ *pbresource.ID) *pbresource.ID {
|
|
|
|
id := clone(artistId)
|
|
|
|
id.Tenancy.Partition = "boguspartition"
|
|
|
|
return id
|
|
|
|
},
|
|
|
|
"namespace not found when namespace scoped": func(artistId, _ *pbresource.ID) *pbresource.ID {
|
|
|
|
id := clone(artistId)
|
|
|
|
id.Tenancy.Namespace = "bogusnamespace"
|
|
|
|
return id
|
|
|
|
},
|
|
|
|
"partition not found when partition scoped": func(_, recordLabelId *pbresource.ID) *pbresource.ID {
|
|
|
|
id := clone(recordLabelId)
|
|
|
|
id.Tenancy.Partition = "boguspartition"
|
|
|
|
return id
|
|
|
|
},
|
|
|
|
}
|
|
|
|
for tenancyDesc, modFn := range tenancyCases {
|
|
|
|
t.Run(tenancyDesc, func(t *testing.T) {
|
|
|
|
server := testServer(t)
|
|
|
|
demo.RegisterTypes(server.Registry)
|
|
|
|
client := testClient(t, server)
|
|
|
|
|
|
|
|
recordLabel, err := demo.GenerateV1RecordLabel("LoonyTunes")
|
|
|
|
require.NoError(t, err)
|
|
|
|
recordLabel, err = server.Backend.WriteCAS(tc.ctx, recordLabel)
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
|
|
|
artist, err := demo.GenerateV2Artist()
|
|
|
|
require.NoError(t, err)
|
|
|
|
artist, err = server.Backend.WriteCAS(tc.ctx, artist)
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
|
|
|
// Each tenancy test case picks which resource to use based on the resource type's scope.
|
|
|
|
_, err = client.Read(tc.ctx, &pbresource.ReadRequest{Id: modFn(artist.Id, recordLabel.Id)})
|
|
|
|
require.Error(t, err)
|
|
|
|
require.Equal(t, codes.NotFound.String(), status.Code(err).String())
|
|
|
|
require.Contains(t, err.Error(), "resource not found")
|
|
|
|
})
|
|
|
|
}
|
2023-03-27 15:35:39 +00:00
|
|
|
})
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func TestRead_GroupVersionMismatch(t *testing.T) {
|
|
|
|
for desc, tc := range readTestCases() {
|
|
|
|
t.Run(desc, func(t *testing.T) {
|
|
|
|
server := testServer(t)
|
2023-04-11 11:10:14 +00:00
|
|
|
|
2023-04-25 11:52:35 +00:00
|
|
|
demo.RegisterTypes(server.Registry)
|
2023-03-27 15:35:39 +00:00
|
|
|
client := testClient(t, server)
|
|
|
|
|
2023-04-06 09:40:04 +00:00
|
|
|
artist, err := demo.GenerateV2Artist()
|
2023-03-27 15:35:39 +00:00
|
|
|
require.NoError(t, err)
|
|
|
|
|
2023-04-06 09:40:04 +00:00
|
|
|
_, err = server.Backend.WriteCAS(tc.ctx, artist)
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
|
|
|
id := clone(artist.Id)
|
|
|
|
id.Type = demo.TypeV1Artist
|
|
|
|
|
|
|
|
_, err = client.Read(tc.ctx, &pbresource.ReadRequest{Id: id})
|
2023-03-27 15:35:39 +00:00
|
|
|
require.Error(t, err)
|
|
|
|
require.Equal(t, codes.InvalidArgument.String(), status.Code(err).String())
|
|
|
|
require.Contains(t, err.Error(), "resource was requested with GroupVersion")
|
|
|
|
})
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func TestRead_Success(t *testing.T) {
|
|
|
|
for desc, tc := range readTestCases() {
|
|
|
|
t.Run(desc, func(t *testing.T) {
|
2023-08-16 16:44:10 +00:00
|
|
|
for tenancyDesc, modFn := range tenancyCases() {
|
2023-08-07 21:37:03 +00:00
|
|
|
t.Run(tenancyDesc, func(t *testing.T) {
|
|
|
|
server := testServer(t)
|
|
|
|
demo.RegisterTypes(server.Registry)
|
|
|
|
client := testClient(t, server)
|
|
|
|
|
|
|
|
recordLabel, err := demo.GenerateV1RecordLabel("LoonyTunes")
|
|
|
|
require.NoError(t, err)
|
|
|
|
recordLabel, err = server.Backend.WriteCAS(tc.ctx, recordLabel)
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
|
|
|
artist, err := demo.GenerateV2Artist()
|
|
|
|
require.NoError(t, err)
|
|
|
|
artist, err = server.Backend.WriteCAS(tc.ctx, artist)
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
|
|
|
// Each tenancy test case picks which resource to use based on the resource type's scope.
|
|
|
|
req := &pbresource.ReadRequest{Id: modFn(artist.Id, recordLabel.Id)}
|
|
|
|
rsp, err := client.Read(tc.ctx, req)
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
|
|
|
switch {
|
|
|
|
case proto.Equal(rsp.Resource.Id.Type, demo.TypeV2Artist):
|
|
|
|
prototest.AssertDeepEqual(t, artist, rsp.Resource)
|
|
|
|
case proto.Equal(rsp.Resource.Id.Type, demo.TypeV1RecordLabel):
|
|
|
|
prototest.AssertDeepEqual(t, recordLabel, rsp.Resource)
|
|
|
|
default:
|
|
|
|
require.Fail(t, "unexpected resource type")
|
|
|
|
}
|
|
|
|
})
|
|
|
|
}
|
2023-03-27 15:35:39 +00:00
|
|
|
})
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func TestRead_VerifyReadConsistencyArg(t *testing.T) {
|
|
|
|
// Uses a mockBackend instead of the inmem Backend to verify the ReadConsistency argument is set correctly.
|
|
|
|
for desc, tc := range readTestCases() {
|
|
|
|
t.Run(desc, func(t *testing.T) {
|
2023-04-11 11:10:14 +00:00
|
|
|
server := testServer(t)
|
2023-03-27 15:35:39 +00:00
|
|
|
mockBackend := NewMockBackend(t)
|
2023-04-11 11:10:14 +00:00
|
|
|
server.Backend = mockBackend
|
2023-04-25 11:52:35 +00:00
|
|
|
demo.RegisterTypes(server.Registry)
|
2023-04-06 09:40:04 +00:00
|
|
|
|
|
|
|
artist, err := demo.GenerateV2Artist()
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
|
|
|
mockBackend.On("Read", mock.Anything, mock.Anything, mock.Anything).Return(artist, nil)
|
2023-03-27 15:35:39 +00:00
|
|
|
client := testClient(t, server)
|
|
|
|
|
2023-04-06 09:40:04 +00:00
|
|
|
rsp, err := client.Read(tc.ctx, &pbresource.ReadRequest{Id: artist.Id})
|
2023-03-27 15:35:39 +00:00
|
|
|
require.NoError(t, err)
|
2023-04-06 09:40:04 +00:00
|
|
|
prototest.AssertDeepEqual(t, artist, rsp.Resource)
|
2023-03-27 15:35:39 +00:00
|
|
|
mockBackend.AssertCalled(t, "Read", mock.Anything, tc.consistency, mock.Anything)
|
|
|
|
})
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2023-04-25 11:52:35 +00:00
|
|
|
// N.B. Uses key ACLs for now. See demo.RegisterTypes()
|
2023-04-11 11:10:14 +00:00
|
|
|
func TestRead_ACLs(t *testing.T) {
|
|
|
|
type testCase struct {
|
|
|
|
authz resolver.Result
|
|
|
|
code codes.Code
|
|
|
|
}
|
|
|
|
testcases := map[string]testCase{
|
|
|
|
"read hook denied": {
|
|
|
|
authz: AuthorizerFrom(t, demo.ArtistV1ReadPolicy),
|
|
|
|
code: codes.PermissionDenied,
|
|
|
|
},
|
|
|
|
"read hook allowed": {
|
|
|
|
authz: AuthorizerFrom(t, demo.ArtistV2ReadPolicy),
|
|
|
|
code: codes.NotFound,
|
|
|
|
},
|
|
|
|
}
|
|
|
|
|
|
|
|
for desc, tc := range testcases {
|
|
|
|
t.Run(desc, func(t *testing.T) {
|
|
|
|
server := testServer(t)
|
|
|
|
client := testClient(t, server)
|
|
|
|
|
|
|
|
mockACLResolver := &MockACLResolver{}
|
|
|
|
mockACLResolver.On("ResolveTokenAndDefaultMeta", mock.Anything, mock.Anything, mock.Anything).
|
|
|
|
Return(tc.authz, nil)
|
|
|
|
server.ACLResolver = mockACLResolver
|
2023-04-25 11:52:35 +00:00
|
|
|
demo.RegisterTypes(server.Registry)
|
2023-04-11 11:10:14 +00:00
|
|
|
|
|
|
|
artist, err := demo.GenerateV2Artist()
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
|
|
|
// exercise ACL
|
|
|
|
_, err = client.Read(testContext(t), &pbresource.ReadRequest{Id: artist.Id})
|
|
|
|
require.Error(t, err)
|
|
|
|
require.Equal(t, tc.code.String(), status.Code(err).String())
|
|
|
|
})
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2023-03-27 15:35:39 +00:00
|
|
|
type readTestCase struct {
|
|
|
|
consistency storage.ReadConsistency
|
|
|
|
ctx context.Context
|
|
|
|
}
|
|
|
|
|
|
|
|
func readTestCases() map[string]readTestCase {
|
|
|
|
return map[string]readTestCase{
|
|
|
|
"eventually consistent read": {
|
|
|
|
consistency: storage.EventualConsistency,
|
|
|
|
ctx: context.Background(),
|
|
|
|
},
|
|
|
|
"strongly consistent read": {
|
|
|
|
consistency: storage.StrongConsistency,
|
|
|
|
ctx: metadata.NewOutgoingContext(
|
|
|
|
context.Background(),
|
|
|
|
metadata.New(map[string]string{"x-consul-consistency-mode": "consistent"}),
|
|
|
|
),
|
|
|
|
},
|
|
|
|
}
|
|
|
|
}
|