diff --git a/Makefile b/Makefile
index dd1858b..767aa28 100644
--- a/Makefile
+++ b/Makefile
@@ -1,12 +1,6 @@
-install:
- mvn -f attribute-endpoints-provider install
-
verify:
mvn -f attribute-endpoints-provider verify
-test:
- mvn -f attribute-endpoints-provider test
-
clean:
mvn -f attribute-endpoints-provider clean
diff --git a/attribute-endpoints-provider/pom.xml b/attribute-endpoints-provider/pom.xml
index c525026..a6d1663 100644
--- a/attribute-endpoints-provider/pom.xml
+++ b/attribute-endpoints-provider/pom.xml
@@ -28,19 +28,6 @@
test
-
- org.mockito
- mockito-core
- 5.23.0
- test
-
-
-
- org.jboss.resteasy
- resteasy-core
- test
-
-
org.keycloak
keycloak-server-spi-private
diff --git a/attribute-endpoints-provider/src/main/java/de/ccc/hamburg/keycloak/attribute_endpoints/AttributeEndpointsResourceProvider.java b/attribute-endpoints-provider/src/main/java/de/ccc/hamburg/keycloak/attribute_endpoints/AttributeEndpointsResourceProvider.java
index 6c069c0..15303dc 100644
--- a/attribute-endpoints-provider/src/main/java/de/ccc/hamburg/keycloak/attribute_endpoints/AttributeEndpointsResourceProvider.java
+++ b/attribute-endpoints-provider/src/main/java/de/ccc/hamburg/keycloak/attribute_endpoints/AttributeEndpointsResourceProvider.java
@@ -1,12 +1,21 @@
package de.ccc.hamburg.keycloak.attribute_endpoints;
-import jakarta.ws.rs.*;
-import jakarta.ws.rs.core.MediaType;
-import jakarta.ws.rs.core.Response;
+import java.util.Collection;
+import java.util.List;
+import java.util.Map;
+import java.util.regex.Matcher;
+import java.util.regex.Pattern;
+import java.util.stream.Stream;
+
import org.jboss.logging.Logger;
import org.keycloak.component.ComponentModel;
-import org.keycloak.models.*;
-import org.keycloak.representations.userprofile.config.UPAttribute;
+import org.keycloak.models.ClientModel;
+import org.keycloak.models.KeycloakContext;
+import org.keycloak.models.KeycloakSession;
+import org.keycloak.models.RealmModel;
+import org.keycloak.models.RoleModel;
+import org.keycloak.models.UserModel;
+import org.keycloak.models.UserProvider;
import org.keycloak.representations.userprofile.config.UPConfig;
import org.keycloak.services.managers.AppAuthManager;
import org.keycloak.services.managers.Auth;
@@ -14,11 +23,16 @@ import org.keycloak.services.managers.AuthenticationManager.AuthResult;
import org.keycloak.services.resource.RealmResourceProvider;
import org.keycloak.userprofile.UserProfileProvider;
-import java.util.Collection;
-import java.util.List;
-import java.util.Map;
-import java.util.regex.Pattern;
-import java.util.stream.Stream;
+import jakarta.ws.rs.ForbiddenException;
+import jakarta.ws.rs.GET;
+import jakarta.ws.rs.NotAuthorizedException;
+import jakarta.ws.rs.NotFoundException;
+import jakarta.ws.rs.Path;
+import jakarta.ws.rs.PathParam;
+import jakarta.ws.rs.Produces;
+import jakarta.ws.rs.ServerErrorException;
+import jakarta.ws.rs.core.MediaType;
+import jakarta.ws.rs.core.Response;
public class AttributeEndpointsResourceProvider implements RealmResourceProvider {
private static final Logger LOG = Logger.getLogger(AttributeEndpointsResourceProvider.class);
@@ -37,21 +51,81 @@ public class AttributeEndpointsResourceProvider implements RealmResourceProvider
public void close() {
}
- /**
- * Returns a list of all attribute values selected by the attribute group attributeGroupName.
- *
- * @param attributeGroupName attribute group name
- * @return a list of attribute values.
- */
@GET
@Path("export/{slug}")
@Produces(MediaType.APPLICATION_JSON)
- public Response exportAttributeValues(@PathParam("slug") String attributeGroupName) {
- AttributeExportContext ctx = new AttributeExportContext(attributeGroupName);
+ public Response exportAttributeValues(@PathParam("slug") String slug) {
+ KeycloakContext context = session.getContext();
+ RealmModel realm = context.getRealm();
- List attribute_list = ctx.users
+ List componentList = realm.getComponentsStream()
+ .filter(c -> c.getProviderId().equals(AdminUiPage.PROVIDER_ID))
+ .filter(c -> c.getConfig().getFirst("slug").equals(slug))
+ .toList();
+
+ Auth auth = AttributeEndpointsResourceProvider.getAuth(session);
+
+ if (componentList.isEmpty()) {
+ throw new NotFoundException("Endpoint not found.");
+ }
+
+ if (componentList.size() > 1) {
+ throw new NotFoundException(
+ "Endpoint Configuration Error - Multiple configurations exist for this endpoint.");
+ }
+
+ ComponentModel component = componentList.get(0);
+
+ String configAuthRole = component.getConfig().getFirst("auth-role");
+ RoleModel authRole = realm.getRole(configAuthRole);
+ if (authRole == null) {
+ throw new ServerErrorException("Endpoint Configuration Error - auth-role does not exist.", 500);
+ }
+
+ String configMatchRole = component.getConfig().getFirst("match-role");
+ RoleModel matchRole = realm.getRole(configMatchRole);
+ if (matchRole == null) {
+ throw new ServerErrorException("Endpoint Configuration Error - match-role does not exist.", 500);
+ }
+
+ UserProfileProvider profileProvider = session.getProvider(UserProfileProvider.class);
+ UPConfig upconfig = profileProvider.getConfiguration();
+ String configAttributeGroup = component.getConfig().getFirst("attribute-group");
+ if (!upconfig.getGroups().stream().anyMatch(g -> g.getName().equals(configAttributeGroup))) {
+ throw new ServerErrorException("Endpoint Configuration Error - attribute-group does not exist.", 500);
+ }
+
+ String configAttributeRegex = component.getConfig().getFirst("attribute-regex");
+ Boolean regexIsBlank = configAttributeRegex == null;
+
+ if (!regexIsBlank) {
+ try {
+ Pattern.compile(configAttributeRegex);
+ } catch (Exception e) {
+ throw new ServerErrorException(
+ "Endpoint Configuration Error - attribute-regex is not a valid regex pattern.", 500);
+ }
+ }
+
+ UserModel authUser = auth.getUser();
+ if (!authUser.hasRole(authRole)) {
+ LOG.info("User " + authUser.getUsername() + " does not have required role " + authRole.getName());
+ throw new ForbiddenException("User does not have required auth role.");
+ }
+
+ List attributeNames = upconfig.getAttributes()
+ .stream()
+ .filter(a -> a.getGroup() != null && a.getGroup().equals(configAttributeGroup))
+ .map(a -> a.getName())
+ .toList();
+
+ UserProvider userProvider = session.users();
+ Stream users = userProvider.searchForUserStream(realm, Map.of())
+ .filter(user -> user.hasRole(matchRole));
+
+ List attribute_list = users
.map(user -> {
- Stream attributeStream = ctx.attributeNames.stream()
+ Stream attributeStream = attributeNames.stream()
.map(attributeName -> user.getAttributeStream(attributeName).toList())
.flatMap(Collection::stream);
@@ -60,83 +134,18 @@ public class AttributeEndpointsResourceProvider implements RealmResourceProvider
.toList();
})
.flatMap(List::stream)
- .filter(ctx.filter::matches)
+ .filter(attribute -> {
+ if (regexIsBlank) {
+ return true;
+ }
+ final Pattern pattern = Pattern.compile(configAttributeRegex);
+ final Matcher matcher = pattern.matcher(attribute);
+ return matcher.find();
+ })
.toList();
return Response.ok(attribute_list).build();
- }
- /**
- * Resolves and validates the configuration and request state needed to export attribute
- * values for a given slug, exposing the results as member variables.
- */
- private class AttributeExportContext {
- List attributeNames;
- UserModel authUser;
- String configAttributeGroup;
- RegExFilter filter;
- UPConfig upconfig;
- Stream users;
-
- AttributeExportContext(String slug) {
- RealmModel realm = session.getContext().getRealm();
-
- List componentList = realm.getComponentsStream()
- .filter(c -> c.getProviderId().equals(AdminUiPage.PROVIDER_ID))
- .filter(c -> c.getConfig().getFirst("slug").equals(slug))
- .toList();
-
- if (componentList.isEmpty()) {
- throw new NotFoundException("Endpoint not found");
- }
-
- if (componentList.size() > 1) {
- throw new NotFoundException(
- "Endpoint Configuration Error - Multiple configurations exist for this endpoint.");
- }
-
- ComponentModel component = componentList.get(0);
-
- RoleModel authRole = realm.getRole(component.getConfig().getFirst("auth-role"));
- if (authRole == null) {
- throw new ServerErrorException("Endpoint Configuration Error - auth-role does not exist.", 500);
- }
-
- RoleModel matchRole = realm.getRole(component.getConfig().getFirst("match-role"));
- if (matchRole == null) {
- throw new ServerErrorException("Endpoint Configuration Error - match-role does not exist.", 500);
- }
-
- upconfig = session.getProvider(UserProfileProvider.class).getConfiguration();
- configAttributeGroup = component.getConfig().getFirst("attribute-group");
- if (upconfig.getGroups().stream().noneMatch(g -> g.getName().equals(configAttributeGroup))) {
- throw new ServerErrorException("Endpoint Configuration Error - attribute-group does not exist.", 500);
- }
-
- try {
- filter = new RegExFilter(component.getConfig().getFirst("attribute-regex"));
- } catch (Exception e) {
- throw new ServerErrorException(
- "Endpoint Configuration Error - attribute-regex is not a valid regex pattern.", 500);
- }
-
- authUser = AttributeEndpointsResourceProvider.getAuth(session).getUser();
- if (!authUser.hasRole(authRole)) {
- LOG.info("User " + authUser.getUsername() + " does not have required role " + authRole.getName() + " for attribute endpoint " + slug);
- throw new ForbiddenException("User does not have required auth role.");
- }
-
- // select all attributes that match configAttributeGroup, or that are in a group that matches configAttributeGroup
- attributeNames = upconfig.getAttributes()
- .stream()
- .filter(a -> a.getGroup() != null && a.getGroup().equals(configAttributeGroup))
- .map(UPAttribute::getName)
- .toList();
-
- UserProvider userProvider = session.users();
- users = userProvider.searchForUserStream(realm, Map.of())
- .filter(user -> user.hasRole(matchRole));
- }
}
private static Auth getAuth(KeycloakSession session) {
@@ -147,25 +156,8 @@ public class AttributeEndpointsResourceProvider implements RealmResourceProvider
}
RealmModel realm = session.getContext().getRealm();
- ClientModel client = auth.client();
- return new Auth(realm, auth.token(), auth.user(), client, auth.session(), false);
- }
-
- private static class RegExFilter {
- Pattern pattern;
-
- RegExFilter(String regex) {
- if (regex == null)
- pattern = null;
- else
- pattern = Pattern.compile(regex);
- }
-
- boolean matches(String input) {
- if (pattern == null)
- return true;
- return pattern.matcher(input).matches();
- }
+ ClientModel client = auth.getClient();
+ return new Auth(realm, auth.getToken(), auth.getUser(), client, auth.getSession(), false);
}
}
diff --git a/attribute-endpoints-provider/src/test/java/de/ccc/hamburg/keycloak/attribute_endpoints/AttributeEndpointsResourceProviderTest.java b/attribute-endpoints-provider/src/test/java/de/ccc/hamburg/keycloak/attribute_endpoints/AttributeEndpointsResourceProviderTest.java
deleted file mode 100644
index 7458a1f..0000000
--- a/attribute-endpoints-provider/src/test/java/de/ccc/hamburg/keycloak/attribute_endpoints/AttributeEndpointsResourceProviderTest.java
+++ /dev/null
@@ -1,313 +0,0 @@
-package de.ccc.hamburg.keycloak.attribute_endpoints;
-
-import jakarta.ws.rs.ForbiddenException;
-import jakarta.ws.rs.NotFoundException;
-import jakarta.ws.rs.ServerErrorException;
-import jakarta.ws.rs.core.Response;
-import org.junit.Before;
-import org.junit.Test;
-import org.keycloak.component.ComponentModel;
-import org.keycloak.models.*;
-import org.keycloak.representations.userprofile.config.UPAttribute;
-import org.keycloak.representations.userprofile.config.UPConfig;
-import org.keycloak.representations.userprofile.config.UPGroup;
-import org.keycloak.services.managers.AppAuthManager;
-import org.keycloak.services.managers.AuthenticationManager.AuthResult;
-import org.keycloak.userprofile.UserProfileProvider;
-import org.mockito.MockedConstruction;
-import org.mockito.Mockito;
-
-import java.util.Collections;
-import java.util.HashMap;
-import java.util.List;
-import java.util.Map;
-import java.util.function.Supplier;
-import java.util.stream.Stream;
-
-import static org.junit.Assert.*;
-import static org.mockito.ArgumentMatchers.*;
-import static org.mockito.Mockito.mock;
-import static org.mockito.Mockito.when;
-
-/**
- * Tests the two endpoints of {@link AttributeEndpointsResourceProvider} against the realm
- * configuration and expected results documented in {@code testing/README.md}.
- */
-public class AttributeEndpointsResourceProviderTest {
-
- private static final String SSH_KEY_1 = "ssh-key-1";
- private static final String SSH_KEY_2 = "ssh-key-2";
- private static final String MAILING_LIST_CHAOS = "mailing-list-address-chaos";
- private static final String MAILING_LIST_INTERN = "mailing-list-address-intern";
-
- private KeycloakSession session;
- private RealmModel realm;
- private Map roles;
- private UserModel hacker;
- private UserModel tester;
- private UserModel noone;
-
- @Before
- public void setUp() {
- session = mock(KeycloakSession.class);
- KeycloakContext context = mock(KeycloakContext.class);
- when(session.getContext()).thenReturn(context);
-
- realm = mock(RealmModel.class);
- when(context.getRealm()).thenReturn(realm);
-
- roles = new HashMap<>();
- for (String name : List.of("dooris-authorized", "export-dooris-ssh-keys",
- "mailing-list-chaos-member", "mailing-list-intern-member",
- "export-mailing-list-addresses")) {
- roles.put(name, mock(RoleModel.class));
- }
- when(realm.getRole(anyString())).thenAnswer(inv -> roles.get(inv.getArgument(0, String.class)));
-
- List components = List.of(
- attributeEndpointComponent("dooris-ssh-keys",
- "export-dooris-ssh-keys", "dooris-authorized", "dooris-ssh-keys"),
- attributeEndpointComponent("mailing-list-addresses-chaos",
- "export-mailing-list-addresses", "mailing-list-chaos-member", MAILING_LIST_CHAOS),
- attributeEndpointComponent("mailing-list-addresses-intern",
- "export-mailing-list-addresses", "mailing-list-intern-member", MAILING_LIST_INTERN));
- when(realm.getComponentsStream()).thenAnswer(inv -> components.stream());
-
- UserProfileProvider userProfileProvider = mock(UserProfileProvider.class);
- when(session.getProvider(UserProfileProvider.class)).thenReturn(userProfileProvider);
- when(userProfileProvider.getConfiguration()).thenReturn(testUserProfileConfig());
-
- hacker = user("hacker", Map.of(
- SSH_KEY_1, "hacker-ssh-key-1",
- SSH_KEY_2, "hacker-ssh-key-2",
- MAILING_LIST_CHAOS, "hacker+chaos@example.net",
- MAILING_LIST_INTERN, "hacker+intern@example.net"),
- List.of("dooris-authorized", "mailing-list-chaos-member", "mailing-list-intern-member"));
- tester = user("tester", Map.of(
- SSH_KEY_1, "tester-ssh-key-1",
- SSH_KEY_2, "tester-ssh-key-2",
- MAILING_LIST_CHAOS, "tester+chaos@example.com",
- MAILING_LIST_INTERN, "tester+intern@example.com"),
- List.of("mailing-list-chaos-member"));
- noone = user("noone", Map.of(
- SSH_KEY_1, "noone-ssh-key-1",
- SSH_KEY_2, "noone-ssh-key-2",
- MAILING_LIST_CHAOS, "noone+chaos@example.org",
- MAILING_LIST_INTERN, "noone+intern@example.org"),
- Collections.emptyList());
-
- UserProvider userProvider = mock(UserProvider.class);
- when(session.users()).thenReturn(userProvider);
- when(userProvider.searchForUserStream(eq(realm), eq(Map.of())))
- .thenAnswer(inv -> Stream.of(hacker, tester, noone));
- }
-
- @Test
- public void exportAttributeValues_doorisSlug_returnsSshKeysOfMatchingUser() {
- try (Response response = callAuthenticatedAs("export-dooris-ssh-keys",
- () -> new AttributeEndpointsResourceProvider(session).exportAttributeValues("dooris-ssh-keys"))) {
-
- assertEquals(200, response.getStatus());
- assertEquals(List.of("hacker-ssh-key-1", "hacker-ssh-key-2"), response.getEntity());
- }
- }
-
- /* NOTYET
- @Test
- public void exportAttributeValuesMap_doorisSlug_returnsSshKeysPerAttribute() {
- try (Response response = callAuthenticatedAs("export-dooris-ssh-keys",
- () -> new AttributeEndpointsResourceProvider(session).exportAttributeValuesMap("dooris-ssh-keys"))) {
-
- assertEquals(200, response.getStatus());
- assertEquals(Map.of(
- SSH_KEY_1, List.of("hacker-ssh-key-1"),
- SSH_KEY_2, List.of("hacker-ssh-key-2")),
- response.getEntity());
- }
- }
- */
-
- /* NOTYET
- @Test
- public void exportAttributeValues_mailingListChaosSlug_returnsAddressesOfAllMatchingUsers() {
- try (Response response = callAuthenticatedAs("export-mailing-list-addresses",
- () -> new AttributeEndpointsResourceProvider(session)
- .exportAttributeValues("mailing-list-addresses-chaos"))) {
-
- assertEquals(200, response.getStatus());
- assertEquals(List.of("hacker+chaos@example.net", "tester+chaos@example.com"), response.getEntity());
- }
- }
- */
-
- /* NOTYET
- @Test
- public void exportAttributeValues_mailingListInternSlug_returnsAddressOfSingleMatchingUser() {
- try (Response response = callAuthenticatedAs("export-mailing-list-addresses",
- () -> new AttributeEndpointsResourceProvider(session)
- .exportAttributeValues("mailing-list-addresses-intern"))) {
-
- assertEquals(200, response.getStatus());
- assertEquals(List.of("hacker+intern@example.net"), response.getEntity());
- }
- }
- */
-
- /* NOTYET
- @Test
- public void exportAttributeValuesMap_mailingListChaosSlug_returnsAddressesPerAttribute() {
- try (Response response = callAuthenticatedAs("export-mailing-list-addresses",
- () -> new AttributeEndpointsResourceProvider(session)
- .exportAttributeValuesMap("mailing-list-addresses-chaos"))) {
-
- assertEquals(200, response.getStatus());
- assertEquals(Map.of(MAILING_LIST_CHAOS,
- List.of("hacker+chaos@example.net", "tester+chaos@example.com")),
- response.getEntity());
- }
- }
- */
-
- @Test
- public void exportAttributeValues_unknownSlug_throwsNotFound() {
- NotFoundException exception = assertThrows(NotFoundException.class,
- () -> callAuthenticatedAs("export-dooris-ssh-keys",
- () -> new AttributeEndpointsResourceProvider(session).exportAttributeValues("unknown-slug")));
-
- assertEquals(404, exception.getResponse().getStatus());
- assertTrue(exception.getMessage().contains("not found"));
- }
-
- @Test
- public void exportAttributeValues_duplicateSlugConfiguration_throwsNotFound() {
- List duplicateComponents = List.of(
- attributeEndpointComponent("duplicate-slug",
- "export-dooris-ssh-keys", "dooris-authorized", "dooris-ssh-keys"),
- attributeEndpointComponent("duplicate-slug",
- "export-dooris-ssh-keys", "dooris-authorized", "dooris-ssh-keys"));
- when(realm.getComponentsStream()).thenAnswer(inv -> duplicateComponents.stream());
-
- NotFoundException exception = assertThrows(NotFoundException.class,
- () -> callAuthenticatedAs("export-dooris-ssh-keys",
- () -> new AttributeEndpointsResourceProvider(session).exportAttributeValues("duplicate-slug")));
-
- assertEquals(404, exception.getResponse().getStatus());
- assertTrue(exception.getMessage().contains("Multiple configurations exist"));
- }
-
- @Test
- public void exportAttributeValues_missingAuthRole_throwsServerError() {
- List components = List.of(
- attributeEndpointComponent("bad-auth-role",
- "nonexistent-role", "dooris-authorized", "dooris-ssh-keys"));
- when(realm.getComponentsStream()).thenAnswer(inv -> components.stream());
-
- ServerErrorException exception = assertThrows(ServerErrorException.class,
- () -> callAuthenticatedAs("export-dooris-ssh-keys",
- () -> new AttributeEndpointsResourceProvider(session).exportAttributeValues("bad-auth-role")));
-
- assertEquals(500, exception.getResponse().getStatus());
- assertTrue(exception.getMessage().contains("auth-role does not exist"));
- }
-
- @Test
- public void exportAttributeValues_missingMatchRole_throwsServerError() {
- List components = List.of(
- attributeEndpointComponent("bad-match-role",
- "export-dooris-ssh-keys", "nonexistent-role", "dooris-ssh-keys"));
- when(realm.getComponentsStream()).thenAnswer(inv -> components.stream());
-
- ServerErrorException exception = assertThrows(ServerErrorException.class,
- () -> callAuthenticatedAs("export-dooris-ssh-keys",
- () -> new AttributeEndpointsResourceProvider(session).exportAttributeValues("bad-match-role")));
-
- assertEquals(500, exception.getResponse().getStatus());
- assertTrue(exception.getMessage().contains("match-role does not exist"));
- }
-
- @Test
- public void exportAttributeValues_invalidAttributeRegex_throwsServerError() {
- ComponentModel component = attributeEndpointComponent("bad-regex",
- "export-dooris-ssh-keys", "dooris-authorized", "dooris-ssh-keys");
- component.put("attribute-regex", "[");
- when(realm.getComponentsStream()).thenAnswer(inv -> Stream.of(component));
-
- ServerErrorException exception = assertThrows(ServerErrorException.class,
- () -> callAuthenticatedAs("export-dooris-ssh-keys",
- () -> new AttributeEndpointsResourceProvider(session).exportAttributeValues("bad-regex")));
-
- assertEquals(500, exception.getResponse().getStatus());
- assertTrue(exception.getMessage().contains("attribute-regex is not a valid regex pattern"));
- }
-
- @Test
- public void exportAttributeValues_callerMissingAuthRole_throwsForbidden() {
- ForbiddenException exception = assertThrows(ForbiddenException.class,
- () -> callAuthenticatedAs("not-a-configured-role",
- () -> new AttributeEndpointsResourceProvider(session).exportAttributeValues("dooris-ssh-keys")));
-
- assertEquals(403, exception.getResponse().getStatus());
- }
-
- /**
- * Runs {@code call} as if authenticated by a bearer token belonging to a service account
- * that holds {@code requiredRole}, by intercepting construction of the
- * {@link AppAuthManager.BearerTokenAuthenticator} the provider creates internally.
- */
- private Response callAuthenticatedAs(String requiredRole, Supplier call) {
- UserModel serviceAccount = mock(UserModel.class);
- when(serviceAccount.hasRole(roles.get(requiredRole))).thenReturn(true);
-
- try (MockedConstruction ignored = Mockito.mockConstruction(
- AppAuthManager.BearerTokenAuthenticator.class,
- (mock, ctx) -> when(mock.authenticate())
- .thenReturn(new AuthResult(serviceAccount, null, null, null)))) {
- return call.get();
- }
- }
-
- private static ComponentModel attributeEndpointComponent(String slug, String authRole, String matchRole,
- String attributeGroup) {
- ComponentModel component = new ComponentModel();
- component.setProviderId(AdminUiPage.PROVIDER_ID);
- component.put("slug", slug);
- component.put("auth-role", authRole);
- component.put("match-role", matchRole);
- component.put("attribute-group", attributeGroup);
- return component;
- }
-
- /**
- * Mirrors the User Profile configuration in testing.
- */
- private static UPConfig testUserProfileConfig() {
- UPConfig upConfig = new UPConfig();
- upConfig.setGroups(List.of(new UPGroup("dooris-ssh-keys"), new UPGroup("mailing-list-addresses")));
- upConfig.setAttributes(List.of(
- attribute(SSH_KEY_1, "dooris-ssh-keys"),
- attribute(SSH_KEY_2, "dooris-ssh-keys"),
- attribute(MAILING_LIST_CHAOS, "mailing-list-addresses"),
- attribute(MAILING_LIST_INTERN, "mailing-list-addresses")));
- return upConfig;
- }
-
- private static UPAttribute attribute(String name, String group) {
- UPAttribute attribute = new UPAttribute(name);
- attribute.setGroup(group);
- return attribute;
- }
-
- private UserModel user(String username, Map attributes, List roleNames) {
- UserModel user = mock(UserModel.class);
- when(user.getUsername()).thenReturn(username);
-
- when(user.getAttributeStream(anyString())).thenAnswer(inv -> Stream.empty());
- attributes.forEach((name, value) ->
- when(user.getAttributeStream(eq(name))).thenAnswer(inv -> Stream.of(value)));
-
- when(user.hasRole(any(RoleModel.class))).thenReturn(false);
- roleNames.forEach(name -> when(user.hasRole(roles.get(name))).thenReturn(true));
-
- return user;
- }
-}
diff --git a/testing/README.md b/testing/README.md
index 7a16c0e..2c5600e 100644
--- a/testing/README.md
+++ b/testing/README.md
@@ -1,11 +1,9 @@
-# Integration Testing
-
-This directory contains infrastructure and tests to verify end-to-end operation of the provider.
-
-## Creating a Testing Keycloak
+# Creating a Testing Keycloak
The Docker Compose setup in this directory sets up Keycloak and imports a realm `testing`.
+## Starting Keycloak
+
Run `docker compose up -d` to start Keycloak. The admin console will be available at http://localhost:8080/.
You can attach a Java debugger at `localhost:8081`.
@@ -13,7 +11,7 @@ You can attach a Java debugger at `localhost:8081`.
The realm export is in `import/testing.json`.
It will be imported automatically when Keycloak starts.
-### Updating the Realm
+## Updating the Realm
If you want to make changes to the testing realm and persist them, you need to export the realm.
@@ -27,36 +25,16 @@ docker compose exec -it keycloak sh -c "cp -rp /opt/keycloak/data/h2 /tmp && env
## Running Integration Tests
-This directory contains shell scripts that exercise the attribute endpoint.
+This directory also contains shell scripts that exercise the attribute endpoint.
Bring up Keycloak with `docker compose up -d`, then run one of the `client-test-export-`*`.sh` scripts.
```shell
$ ./client-test-export-dooris.sh
-All attributes collated into a single list
[
"hacker-ssh-key-1",
"hacker-ssh-key-2"
]
-Results mapped per attribute
-{
- "ssh-key-1": [
- "hacker-ssh-key-1"
- ],
- "ssh-key-2": [
- "hacker-ssh-key-2"
- ]
-}
-$ ./client-test-export-mailing-lists.sh
-chaos@
-[
- "hacker+chaos@example.net",
- "tester+chaos@example.com"
-]
-intern@
-[
- "hacker+intern@example.net"
-]
```
## Realm `testing` Configuration
@@ -65,16 +43,16 @@ The realm contains these objects:
* Clients:
* `export-dooris-ssh-keys` with secret `export-dooris-ssh-keys-secret` and user `service-account-export-dooris-ssh-keys`
- * `export-mailing-list-addresses` with secret `export-mailing-list-addresses-secret` and user `service-account-export-mailing-list-addresses`
+ * `export-mailing-list-addresses` with secret `export-mailing-list-addresses-secret` and role `export-mailing-list-addresses`
* Realm Roles:
- * `dooris-authorized` to assign to users whose SSH keys should be exported
- * `mailing-list-chaos-member` to assign to users who are a member of the chaos mailing list
- * `mailing-list-intern-member` to assign to users who are a member of the intern mailing list
- * `export-dooris-ssh-keys` to assign to service account users that should be allowed to use the dooris endpoint config
- * `export-mailing-list-addresses` to assign to service account users that should be allowed to use the mailing list endpoint configs
+ * `dooris-authorized`
+ * `mailing-list-chaos-member`
+ * `mailing-list-intern-member`
+ * `export-dooris-ssh-keys`
+ * `export-mailing-list-addresses`
* Groups:
* `chaos` with role `mailing-list-chaos-member`
- * `ìntern` with roles `dooris-authorized`, `mailing-list-chaos-member` and `mailing-list-intern-member`
+ * `ìntern` with roles `dooris-authorized` and `mailing-list-intern-member`
* Users:
* `tester` (Tony Tester), email `tester@example.com`, member of group `chaos`
* Mailing List Addresses:
@@ -103,7 +81,7 @@ The realm contains these objects:
* `mailing-list-address-chaos`
* Attribute Group `mailing-list-addresses`
* `mailing-list-address-intern`
- * Attribute Group `mailing-list-addresses`
+ * Attribute Group `mailing-list-intern`
* `ssh-key-1`
* Attribute Group `dooris-ssh-keys`
* `ssh-key-2`
diff --git a/testing/client-test-export-dooris.sh b/testing/client-test-export-dooris.sh
index 82f5ad3..b6d4696 100755
--- a/testing/client-test-export-dooris.sh
+++ b/testing/client-test-export-dooris.sh
@@ -7,21 +7,14 @@
set -e
ACCESS_TOKEN="$(curl -s --request POST \
- --url http://localhost:8080/realms/testing/protocol/openid-connect/token \
- --header 'content-type: application/x-www-form-urlencoded' \
- --data scope=openid \
- --data client_id=export-dooris-ssh-keys \
- --data client_secret=export-dooris-ssh-keys-secret \
- --data grant_type=client_credentials | jq --raw-output .access_token -)"
+ --url http://localhost:8080/realms/testing/protocol/openid-connect/token \
+ --header 'content-type: application/x-www-form-urlencoded' \
+ --data scope=openid \
+ --data client_id=export-dooris-ssh-keys \
+ --data client_secret=export-dooris-ssh-keys-secret \
+ --data grant_type=client_credentials | jq --raw-output .access_token -)"
-echo "All attributes collated into a single list"
curl -s --request GET \
- --url http://localhost:8080/realms/testing/attribute-endpoints-provider/export/dooris-ssh-keys \
- --header "authorization: Bearer ${ACCESS_TOKEN}" \
- --header "content-type: application/json" | jq . -
-
-echo "Results mapped per attribute"
-curl -s --request GET \
- --url http://localhost:8080/realms/testing/attribute-endpoints-provider/export/dooris-ssh-keys/map \
- --header "authorization: Bearer ${ACCESS_TOKEN}" \
- --header "content-type: application/json" | jq . -
+ --url http://localhost:8080/realms/testing/attribute-endpoints-provider/export/dooris-ssh-keys \
+ --header "authorization: Bearer ${ACCESS_TOKEN}" \
+ --header "content-type: application/json" | jq . -
\ No newline at end of file
diff --git a/testing/client-test-export-mailing-lists.sh b/testing/client-test-export-mailing-lists.sh
deleted file mode 100755
index 4f15d76..0000000
--- a/testing/client-test-export-mailing-lists.sh
+++ /dev/null
@@ -1,27 +0,0 @@
-#!/bin/sh
-
-#
-# Use curl to run a test export of Dooris ssh keys
-#
-
-set -e
-
-ACCESS_TOKEN="$(curl -s --request POST \
- --url http://localhost:8080/realms/testing/protocol/openid-connect/token \
- --header 'content-type: application/x-www-form-urlencoded' \
- --data scope=openid \
- --data client_id=export-mailing-list-addresses \
- --data client_secret=export-mailing-list-addresses-secret \
- --data grant_type=client_credentials | jq --raw-output .access_token -)"
-
-echo "chaos@"
-curl -s --request GET \
- --url http://localhost:8080/realms/testing/attribute-endpoints-provider/export/mailing-list-addresses-chaos \
- --header "authorization: Bearer ${ACCESS_TOKEN}" \
- --header "content-type: application/json" | jq . -
-
-echo "intern@"
-curl -s --request GET \
- --url http://localhost:8080/realms/testing/attribute-endpoints-provider/export/mailing-list-addresses-intern \
- --header "authorization: Bearer ${ACCESS_TOKEN}" \
- --header "content-type: application/json" | jq . -
diff --git a/testing/compose.yaml b/testing/compose.yaml
index 3f73478..0311532 100644
--- a/testing/compose.yaml
+++ b/testing/compose.yaml
@@ -12,17 +12,6 @@ services:
ports:
- "8080:8080"
- "8081:8081"
- networks:
- - keycloak
volumes:
- ./import:/opt/keycloak/data/import/
- - ../attribute-endpoints-provider/target/attribute-endpoints-provider-1.0-SNAPSHOT.jar:/opt/keycloak/providers/attribute-endpoints-provider.jar
-
-networks:
- # force a "local" IP address that Keycloak accepts HTTP (not HTTPS) requests from
- keycloak:
- driver: bridge
- ipam:
- config:
- - subnet: 192.168.231.128/29
- gateway: 192.168.231.129
+ - ../attribute-endpoints-provider/target/attribute-endpoints-provider-1.0-SNAPSHOT.jar:/opt/keycloak/providers/attribute-endpoints-provider.jar
\ No newline at end of file
diff --git a/testing/import/testing.json b/testing/import/testing.json
index dfa0fa7..3744ff8 100644
--- a/testing/import/testing.json
+++ b/testing/import/testing.json
@@ -1478,7 +1478,7 @@
"subType" : "authenticated",
"subComponents" : { },
"config" : {
- "allowed-protocol-mapper-types" : [ "saml-user-property-mapper", "oidc-usermodel-property-mapper", "saml-role-list-mapper", "oidc-full-name-mapper", "saml-user-attribute-mapper", "oidc-address-mapper", "oidc-usermodel-attribute-mapper", "oidc-sha256-pairwise-sub-mapper" ]
+ "allowed-protocol-mapper-types" : [ "oidc-sha256-pairwise-sub-mapper", "saml-user-attribute-mapper", "saml-user-property-mapper", "oidc-full-name-mapper", "saml-role-list-mapper", "oidc-address-mapper", "oidc-usermodel-attribute-mapper", "oidc-usermodel-property-mapper" ]
}
}, {
"id" : "a49de9bf-462b-4c61-bb52-0373732f4b1b",
@@ -1538,7 +1538,7 @@
"subType" : "anonymous",
"subComponents" : { },
"config" : {
- "allowed-protocol-mapper-types" : [ "saml-role-list-mapper", "saml-user-attribute-mapper", "oidc-usermodel-attribute-mapper", "oidc-usermodel-property-mapper", "saml-user-property-mapper", "oidc-full-name-mapper", "oidc-address-mapper", "oidc-sha256-pairwise-sub-mapper" ]
+ "allowed-protocol-mapper-types" : [ "saml-role-list-mapper", "oidc-address-mapper", "oidc-sha256-pairwise-sub-mapper", "oidc-usermodel-attribute-mapper", "oidc-full-name-mapper", "oidc-usermodel-property-mapper", "saml-user-property-mapper", "saml-user-attribute-mapper" ]
}
}, {
"id" : "dd4024e9-f080-4319-aeb7-7f9906c345c5",
@@ -1605,8 +1605,8 @@
"subComponents" : { },
"config" : {
"match-role" : [ "mailing-list-intern-member" ],
- "attribute-group" : [ "mailing-list-addresses" ],
"auth-role" : [ "export-mailing-list-addresses" ],
+ "attribute-group" : [ "mailing-list-addresses" ],
"slug" : [ "mailing-list-addresses-intern" ]
}
}, {
@@ -1615,8 +1615,8 @@
"subComponents" : { },
"config" : {
"match-role" : [ "dooris-authorized" ],
- "attribute-group" : [ "dooris-ssh-keys" ],
"auth-role" : [ "export-dooris-ssh-keys" ],
+ "attribute-group" : [ "dooris-ssh-keys" ],
"slug" : [ "dooris-ssh-keys" ]
}
}, {