|
|
|
@ -2173,7 +2173,7 @@ func TestAgentConnectAuthorize_idInvalidFormat(t *testing.T) {
|
|
|
|
|
|
|
|
|
|
args := &structs.ConnectAuthorizeRequest{
|
|
|
|
|
Target: "web",
|
|
|
|
|
ClientID: "tubes",
|
|
|
|
|
ClientCertURI: "tubes",
|
|
|
|
|
}
|
|
|
|
|
req, _ := http.NewRequest("POST", "/v1/agent/connect/authorize", jsonReader(args))
|
|
|
|
|
resp := httptest.NewRecorder()
|
|
|
|
@ -2196,7 +2196,7 @@ func TestAgentConnectAuthorize_idNotService(t *testing.T) {
|
|
|
|
|
|
|
|
|
|
args := &structs.ConnectAuthorizeRequest{
|
|
|
|
|
Target: "web",
|
|
|
|
|
ClientID: "spiffe://1234.consul",
|
|
|
|
|
ClientCertURI: "spiffe://1234.consul",
|
|
|
|
|
}
|
|
|
|
|
req, _ := http.NewRequest("POST", "/v1/agent/connect/authorize", jsonReader(args))
|
|
|
|
|
resp := httptest.NewRecorder()
|
|
|
|
@ -2238,7 +2238,7 @@ func TestAgentConnectAuthorize_allow(t *testing.T) {
|
|
|
|
|
|
|
|
|
|
args := &structs.ConnectAuthorizeRequest{
|
|
|
|
|
Target: target,
|
|
|
|
|
ClientID: connect.TestSpiffeIDService(t, "web").URI().String(),
|
|
|
|
|
ClientCertURI: connect.TestSpiffeIDService(t, "web").URI().String(),
|
|
|
|
|
}
|
|
|
|
|
req, _ := http.NewRequest("POST", "/v1/agent/connect/authorize", jsonReader(args))
|
|
|
|
|
resp := httptest.NewRecorder()
|
|
|
|
@ -2280,7 +2280,7 @@ func TestAgentConnectAuthorize_deny(t *testing.T) {
|
|
|
|
|
|
|
|
|
|
args := &structs.ConnectAuthorizeRequest{
|
|
|
|
|
Target: target,
|
|
|
|
|
ClientID: connect.TestSpiffeIDService(t, "web").URI().String(),
|
|
|
|
|
ClientCertURI: connect.TestSpiffeIDService(t, "web").URI().String(),
|
|
|
|
|
}
|
|
|
|
|
req, _ := http.NewRequest("POST", "/v1/agent/connect/authorize", jsonReader(args))
|
|
|
|
|
resp := httptest.NewRecorder()
|
|
|
|
@ -2321,7 +2321,7 @@ func TestAgentConnectAuthorize_serviceWrite(t *testing.T) {
|
|
|
|
|
|
|
|
|
|
args := &structs.ConnectAuthorizeRequest{
|
|
|
|
|
Target: "foo",
|
|
|
|
|
ClientID: connect.TestSpiffeIDService(t, "web").URI().String(),
|
|
|
|
|
ClientCertURI: connect.TestSpiffeIDService(t, "web").URI().String(),
|
|
|
|
|
}
|
|
|
|
|
req, _ := http.NewRequest("POST",
|
|
|
|
|
"/v1/agent/connect/authorize?token="+token, jsonReader(args))
|
|
|
|
@ -2340,7 +2340,7 @@ func TestAgentConnectAuthorize_defaultDeny(t *testing.T) {
|
|
|
|
|
|
|
|
|
|
args := &structs.ConnectAuthorizeRequest{
|
|
|
|
|
Target: "foo",
|
|
|
|
|
ClientID: connect.TestSpiffeIDService(t, "web").URI().String(),
|
|
|
|
|
ClientCertURI: connect.TestSpiffeIDService(t, "web").URI().String(),
|
|
|
|
|
}
|
|
|
|
|
req, _ := http.NewRequest("POST", "/v1/agent/connect/authorize?token=root", jsonReader(args))
|
|
|
|
|
resp := httptest.NewRecorder()
|
|
|
|
@ -2370,7 +2370,7 @@ func TestAgentConnectAuthorize_defaultAllow(t *testing.T) {
|
|
|
|
|
|
|
|
|
|
args := &structs.ConnectAuthorizeRequest{
|
|
|
|
|
Target: "foo",
|
|
|
|
|
ClientID: connect.TestSpiffeIDService(t, "web").URI().String(),
|
|
|
|
|
ClientCertURI: connect.TestSpiffeIDService(t, "web").URI().String(),
|
|
|
|
|
}
|
|
|
|
|
req, _ := http.NewRequest("POST", "/v1/agent/connect/authorize?token=root", jsonReader(args))
|
|
|
|
|
resp := httptest.NewRecorder()
|
|
|
|
|