|
|
|
@ -2173,7 +2173,7 @@ func TestAgentConnectAuthorize_idInvalidFormat(t *testing.T) {
|
|
|
|
|
|
|
|
|
|
args := &structs.ConnectAuthorizeRequest{ |
|
|
|
|
Target: "web", |
|
|
|
|
ClientID: "tubes", |
|
|
|
|
ClientCertURI: "tubes", |
|
|
|
|
} |
|
|
|
|
req, _ := http.NewRequest("POST", "/v1/agent/connect/authorize", jsonReader(args)) |
|
|
|
|
resp := httptest.NewRecorder() |
|
|
|
@ -2196,7 +2196,7 @@ func TestAgentConnectAuthorize_idNotService(t *testing.T) {
|
|
|
|
|
|
|
|
|
|
args := &structs.ConnectAuthorizeRequest{ |
|
|
|
|
Target: "web", |
|
|
|
|
ClientID: "spiffe://1234.consul", |
|
|
|
|
ClientCertURI: "spiffe://1234.consul", |
|
|
|
|
} |
|
|
|
|
req, _ := http.NewRequest("POST", "/v1/agent/connect/authorize", jsonReader(args)) |
|
|
|
|
resp := httptest.NewRecorder() |
|
|
|
@ -2238,7 +2238,7 @@ func TestAgentConnectAuthorize_allow(t *testing.T) {
|
|
|
|
|
|
|
|
|
|
args := &structs.ConnectAuthorizeRequest{ |
|
|
|
|
Target: target, |
|
|
|
|
ClientID: connect.TestSpiffeIDService(t, "web").URI().String(), |
|
|
|
|
ClientCertURI: connect.TestSpiffeIDService(t, "web").URI().String(), |
|
|
|
|
} |
|
|
|
|
req, _ := http.NewRequest("POST", "/v1/agent/connect/authorize", jsonReader(args)) |
|
|
|
|
resp := httptest.NewRecorder() |
|
|
|
@ -2280,7 +2280,7 @@ func TestAgentConnectAuthorize_deny(t *testing.T) {
|
|
|
|
|
|
|
|
|
|
args := &structs.ConnectAuthorizeRequest{ |
|
|
|
|
Target: target, |
|
|
|
|
ClientID: connect.TestSpiffeIDService(t, "web").URI().String(), |
|
|
|
|
ClientCertURI: connect.TestSpiffeIDService(t, "web").URI().String(), |
|
|
|
|
} |
|
|
|
|
req, _ := http.NewRequest("POST", "/v1/agent/connect/authorize", jsonReader(args)) |
|
|
|
|
resp := httptest.NewRecorder() |
|
|
|
@ -2321,7 +2321,7 @@ func TestAgentConnectAuthorize_serviceWrite(t *testing.T) {
|
|
|
|
|
|
|
|
|
|
args := &structs.ConnectAuthorizeRequest{ |
|
|
|
|
Target: "foo", |
|
|
|
|
ClientID: connect.TestSpiffeIDService(t, "web").URI().String(), |
|
|
|
|
ClientCertURI: connect.TestSpiffeIDService(t, "web").URI().String(), |
|
|
|
|
} |
|
|
|
|
req, _ := http.NewRequest("POST", |
|
|
|
|
"/v1/agent/connect/authorize?token="+token, jsonReader(args)) |
|
|
|
@ -2340,7 +2340,7 @@ func TestAgentConnectAuthorize_defaultDeny(t *testing.T) {
|
|
|
|
|
|
|
|
|
|
args := &structs.ConnectAuthorizeRequest{ |
|
|
|
|
Target: "foo", |
|
|
|
|
ClientID: connect.TestSpiffeIDService(t, "web").URI().String(), |
|
|
|
|
ClientCertURI: connect.TestSpiffeIDService(t, "web").URI().String(), |
|
|
|
|
} |
|
|
|
|
req, _ := http.NewRequest("POST", "/v1/agent/connect/authorize?token=root", jsonReader(args)) |
|
|
|
|
resp := httptest.NewRecorder() |
|
|
|
@ -2370,7 +2370,7 @@ func TestAgentConnectAuthorize_defaultAllow(t *testing.T) {
|
|
|
|
|
|
|
|
|
|
args := &structs.ConnectAuthorizeRequest{ |
|
|
|
|
Target: "foo", |
|
|
|
|
ClientID: connect.TestSpiffeIDService(t, "web").URI().String(), |
|
|
|
|
ClientCertURI: connect.TestSpiffeIDService(t, "web").URI().String(), |
|
|
|
|
} |
|
|
|
|
req, _ := http.NewRequest("POST", "/v1/agent/connect/authorize?token=root", jsonReader(args)) |
|
|
|
|
resp := httptest.NewRecorder() |
|
|
|
|