diff --git a/Makefile b/Makefile index dd1858b..767aa28 100644 --- a/Makefile +++ b/Makefile @@ -1,12 +1,6 @@ -install: - mvn -f attribute-endpoints-provider install - verify: mvn -f attribute-endpoints-provider verify -test: - mvn -f attribute-endpoints-provider test - clean: mvn -f attribute-endpoints-provider clean diff --git a/attribute-endpoints-provider/pom.xml b/attribute-endpoints-provider/pom.xml index c525026..a6d1663 100644 --- a/attribute-endpoints-provider/pom.xml +++ b/attribute-endpoints-provider/pom.xml @@ -28,19 +28,6 @@ test - - org.mockito - mockito-core - 5.23.0 - test - - - - org.jboss.resteasy - resteasy-core - test - - org.keycloak keycloak-server-spi-private diff --git a/attribute-endpoints-provider/src/main/java/de/ccc/hamburg/keycloak/attribute_endpoints/AttributeEndpointsResourceProvider.java b/attribute-endpoints-provider/src/main/java/de/ccc/hamburg/keycloak/attribute_endpoints/AttributeEndpointsResourceProvider.java index 6c069c0..15303dc 100644 --- a/attribute-endpoints-provider/src/main/java/de/ccc/hamburg/keycloak/attribute_endpoints/AttributeEndpointsResourceProvider.java +++ b/attribute-endpoints-provider/src/main/java/de/ccc/hamburg/keycloak/attribute_endpoints/AttributeEndpointsResourceProvider.java @@ -1,12 +1,21 @@ package de.ccc.hamburg.keycloak.attribute_endpoints; -import jakarta.ws.rs.*; -import jakarta.ws.rs.core.MediaType; -import jakarta.ws.rs.core.Response; +import java.util.Collection; +import java.util.List; +import java.util.Map; +import java.util.regex.Matcher; +import java.util.regex.Pattern; +import java.util.stream.Stream; + import org.jboss.logging.Logger; import org.keycloak.component.ComponentModel; -import org.keycloak.models.*; -import org.keycloak.representations.userprofile.config.UPAttribute; +import org.keycloak.models.ClientModel; +import org.keycloak.models.KeycloakContext; +import org.keycloak.models.KeycloakSession; +import org.keycloak.models.RealmModel; +import org.keycloak.models.RoleModel; +import org.keycloak.models.UserModel; +import org.keycloak.models.UserProvider; import org.keycloak.representations.userprofile.config.UPConfig; import org.keycloak.services.managers.AppAuthManager; import org.keycloak.services.managers.Auth; @@ -14,11 +23,16 @@ import org.keycloak.services.managers.AuthenticationManager.AuthResult; import org.keycloak.services.resource.RealmResourceProvider; import org.keycloak.userprofile.UserProfileProvider; -import java.util.Collection; -import java.util.List; -import java.util.Map; -import java.util.regex.Pattern; -import java.util.stream.Stream; +import jakarta.ws.rs.ForbiddenException; +import jakarta.ws.rs.GET; +import jakarta.ws.rs.NotAuthorizedException; +import jakarta.ws.rs.NotFoundException; +import jakarta.ws.rs.Path; +import jakarta.ws.rs.PathParam; +import jakarta.ws.rs.Produces; +import jakarta.ws.rs.ServerErrorException; +import jakarta.ws.rs.core.MediaType; +import jakarta.ws.rs.core.Response; public class AttributeEndpointsResourceProvider implements RealmResourceProvider { private static final Logger LOG = Logger.getLogger(AttributeEndpointsResourceProvider.class); @@ -37,21 +51,81 @@ public class AttributeEndpointsResourceProvider implements RealmResourceProvider public void close() { } - /** - * Returns a list of all attribute values selected by the attribute group attributeGroupName. - * - * @param attributeGroupName attribute group name - * @return a list of attribute values. - */ @GET @Path("export/{slug}") @Produces(MediaType.APPLICATION_JSON) - public Response exportAttributeValues(@PathParam("slug") String attributeGroupName) { - AttributeExportContext ctx = new AttributeExportContext(attributeGroupName); + public Response exportAttributeValues(@PathParam("slug") String slug) { + KeycloakContext context = session.getContext(); + RealmModel realm = context.getRealm(); - List attribute_list = ctx.users + List componentList = realm.getComponentsStream() + .filter(c -> c.getProviderId().equals(AdminUiPage.PROVIDER_ID)) + .filter(c -> c.getConfig().getFirst("slug").equals(slug)) + .toList(); + + Auth auth = AttributeEndpointsResourceProvider.getAuth(session); + + if (componentList.isEmpty()) { + throw new NotFoundException("Endpoint not found."); + } + + if (componentList.size() > 1) { + throw new NotFoundException( + "Endpoint Configuration Error - Multiple configurations exist for this endpoint."); + } + + ComponentModel component = componentList.get(0); + + String configAuthRole = component.getConfig().getFirst("auth-role"); + RoleModel authRole = realm.getRole(configAuthRole); + if (authRole == null) { + throw new ServerErrorException("Endpoint Configuration Error - auth-role does not exist.", 500); + } + + String configMatchRole = component.getConfig().getFirst("match-role"); + RoleModel matchRole = realm.getRole(configMatchRole); + if (matchRole == null) { + throw new ServerErrorException("Endpoint Configuration Error - match-role does not exist.", 500); + } + + UserProfileProvider profileProvider = session.getProvider(UserProfileProvider.class); + UPConfig upconfig = profileProvider.getConfiguration(); + String configAttributeGroup = component.getConfig().getFirst("attribute-group"); + if (!upconfig.getGroups().stream().anyMatch(g -> g.getName().equals(configAttributeGroup))) { + throw new ServerErrorException("Endpoint Configuration Error - attribute-group does not exist.", 500); + } + + String configAttributeRegex = component.getConfig().getFirst("attribute-regex"); + Boolean regexIsBlank = configAttributeRegex == null; + + if (!regexIsBlank) { + try { + Pattern.compile(configAttributeRegex); + } catch (Exception e) { + throw new ServerErrorException( + "Endpoint Configuration Error - attribute-regex is not a valid regex pattern.", 500); + } + } + + UserModel authUser = auth.getUser(); + if (!authUser.hasRole(authRole)) { + LOG.info("User " + authUser.getUsername() + " does not have required role " + authRole.getName()); + throw new ForbiddenException("User does not have required auth role."); + } + + List attributeNames = upconfig.getAttributes() + .stream() + .filter(a -> a.getGroup() != null && a.getGroup().equals(configAttributeGroup)) + .map(a -> a.getName()) + .toList(); + + UserProvider userProvider = session.users(); + Stream users = userProvider.searchForUserStream(realm, Map.of()) + .filter(user -> user.hasRole(matchRole)); + + List attribute_list = users .map(user -> { - Stream attributeStream = ctx.attributeNames.stream() + Stream attributeStream = attributeNames.stream() .map(attributeName -> user.getAttributeStream(attributeName).toList()) .flatMap(Collection::stream); @@ -60,83 +134,18 @@ public class AttributeEndpointsResourceProvider implements RealmResourceProvider .toList(); }) .flatMap(List::stream) - .filter(ctx.filter::matches) + .filter(attribute -> { + if (regexIsBlank) { + return true; + } + final Pattern pattern = Pattern.compile(configAttributeRegex); + final Matcher matcher = pattern.matcher(attribute); + return matcher.find(); + }) .toList(); return Response.ok(attribute_list).build(); - } - /** - * Resolves and validates the configuration and request state needed to export attribute - * values for a given slug, exposing the results as member variables. - */ - private class AttributeExportContext { - List attributeNames; - UserModel authUser; - String configAttributeGroup; - RegExFilter filter; - UPConfig upconfig; - Stream users; - - AttributeExportContext(String slug) { - RealmModel realm = session.getContext().getRealm(); - - List componentList = realm.getComponentsStream() - .filter(c -> c.getProviderId().equals(AdminUiPage.PROVIDER_ID)) - .filter(c -> c.getConfig().getFirst("slug").equals(slug)) - .toList(); - - if (componentList.isEmpty()) { - throw new NotFoundException("Endpoint not found"); - } - - if (componentList.size() > 1) { - throw new NotFoundException( - "Endpoint Configuration Error - Multiple configurations exist for this endpoint."); - } - - ComponentModel component = componentList.get(0); - - RoleModel authRole = realm.getRole(component.getConfig().getFirst("auth-role")); - if (authRole == null) { - throw new ServerErrorException("Endpoint Configuration Error - auth-role does not exist.", 500); - } - - RoleModel matchRole = realm.getRole(component.getConfig().getFirst("match-role")); - if (matchRole == null) { - throw new ServerErrorException("Endpoint Configuration Error - match-role does not exist.", 500); - } - - upconfig = session.getProvider(UserProfileProvider.class).getConfiguration(); - configAttributeGroup = component.getConfig().getFirst("attribute-group"); - if (upconfig.getGroups().stream().noneMatch(g -> g.getName().equals(configAttributeGroup))) { - throw new ServerErrorException("Endpoint Configuration Error - attribute-group does not exist.", 500); - } - - try { - filter = new RegExFilter(component.getConfig().getFirst("attribute-regex")); - } catch (Exception e) { - throw new ServerErrorException( - "Endpoint Configuration Error - attribute-regex is not a valid regex pattern.", 500); - } - - authUser = AttributeEndpointsResourceProvider.getAuth(session).getUser(); - if (!authUser.hasRole(authRole)) { - LOG.info("User " + authUser.getUsername() + " does not have required role " + authRole.getName() + " for attribute endpoint " + slug); - throw new ForbiddenException("User does not have required auth role."); - } - - // select all attributes that match configAttributeGroup, or that are in a group that matches configAttributeGroup - attributeNames = upconfig.getAttributes() - .stream() - .filter(a -> a.getGroup() != null && a.getGroup().equals(configAttributeGroup)) - .map(UPAttribute::getName) - .toList(); - - UserProvider userProvider = session.users(); - users = userProvider.searchForUserStream(realm, Map.of()) - .filter(user -> user.hasRole(matchRole)); - } } private static Auth getAuth(KeycloakSession session) { @@ -147,25 +156,8 @@ public class AttributeEndpointsResourceProvider implements RealmResourceProvider } RealmModel realm = session.getContext().getRealm(); - ClientModel client = auth.client(); - return new Auth(realm, auth.token(), auth.user(), client, auth.session(), false); - } - - private static class RegExFilter { - Pattern pattern; - - RegExFilter(String regex) { - if (regex == null) - pattern = null; - else - pattern = Pattern.compile(regex); - } - - boolean matches(String input) { - if (pattern == null) - return true; - return pattern.matcher(input).matches(); - } + ClientModel client = auth.getClient(); + return new Auth(realm, auth.getToken(), auth.getUser(), client, auth.getSession(), false); } } diff --git a/attribute-endpoints-provider/src/test/java/de/ccc/hamburg/keycloak/attribute_endpoints/AttributeEndpointsResourceProviderTest.java b/attribute-endpoints-provider/src/test/java/de/ccc/hamburg/keycloak/attribute_endpoints/AttributeEndpointsResourceProviderTest.java deleted file mode 100644 index 7458a1f..0000000 --- a/attribute-endpoints-provider/src/test/java/de/ccc/hamburg/keycloak/attribute_endpoints/AttributeEndpointsResourceProviderTest.java +++ /dev/null @@ -1,313 +0,0 @@ -package de.ccc.hamburg.keycloak.attribute_endpoints; - -import jakarta.ws.rs.ForbiddenException; -import jakarta.ws.rs.NotFoundException; -import jakarta.ws.rs.ServerErrorException; -import jakarta.ws.rs.core.Response; -import org.junit.Before; -import org.junit.Test; -import org.keycloak.component.ComponentModel; -import org.keycloak.models.*; -import org.keycloak.representations.userprofile.config.UPAttribute; -import org.keycloak.representations.userprofile.config.UPConfig; -import org.keycloak.representations.userprofile.config.UPGroup; -import org.keycloak.services.managers.AppAuthManager; -import org.keycloak.services.managers.AuthenticationManager.AuthResult; -import org.keycloak.userprofile.UserProfileProvider; -import org.mockito.MockedConstruction; -import org.mockito.Mockito; - -import java.util.Collections; -import java.util.HashMap; -import java.util.List; -import java.util.Map; -import java.util.function.Supplier; -import java.util.stream.Stream; - -import static org.junit.Assert.*; -import static org.mockito.ArgumentMatchers.*; -import static org.mockito.Mockito.mock; -import static org.mockito.Mockito.when; - -/** - * Tests the two endpoints of {@link AttributeEndpointsResourceProvider} against the realm - * configuration and expected results documented in {@code testing/README.md}. - */ -public class AttributeEndpointsResourceProviderTest { - - private static final String SSH_KEY_1 = "ssh-key-1"; - private static final String SSH_KEY_2 = "ssh-key-2"; - private static final String MAILING_LIST_CHAOS = "mailing-list-address-chaos"; - private static final String MAILING_LIST_INTERN = "mailing-list-address-intern"; - - private KeycloakSession session; - private RealmModel realm; - private Map roles; - private UserModel hacker; - private UserModel tester; - private UserModel noone; - - @Before - public void setUp() { - session = mock(KeycloakSession.class); - KeycloakContext context = mock(KeycloakContext.class); - when(session.getContext()).thenReturn(context); - - realm = mock(RealmModel.class); - when(context.getRealm()).thenReturn(realm); - - roles = new HashMap<>(); - for (String name : List.of("dooris-authorized", "export-dooris-ssh-keys", - "mailing-list-chaos-member", "mailing-list-intern-member", - "export-mailing-list-addresses")) { - roles.put(name, mock(RoleModel.class)); - } - when(realm.getRole(anyString())).thenAnswer(inv -> roles.get(inv.getArgument(0, String.class))); - - List components = List.of( - attributeEndpointComponent("dooris-ssh-keys", - "export-dooris-ssh-keys", "dooris-authorized", "dooris-ssh-keys"), - attributeEndpointComponent("mailing-list-addresses-chaos", - "export-mailing-list-addresses", "mailing-list-chaos-member", MAILING_LIST_CHAOS), - attributeEndpointComponent("mailing-list-addresses-intern", - "export-mailing-list-addresses", "mailing-list-intern-member", MAILING_LIST_INTERN)); - when(realm.getComponentsStream()).thenAnswer(inv -> components.stream()); - - UserProfileProvider userProfileProvider = mock(UserProfileProvider.class); - when(session.getProvider(UserProfileProvider.class)).thenReturn(userProfileProvider); - when(userProfileProvider.getConfiguration()).thenReturn(testUserProfileConfig()); - - hacker = user("hacker", Map.of( - SSH_KEY_1, "hacker-ssh-key-1", - SSH_KEY_2, "hacker-ssh-key-2", - MAILING_LIST_CHAOS, "hacker+chaos@example.net", - MAILING_LIST_INTERN, "hacker+intern@example.net"), - List.of("dooris-authorized", "mailing-list-chaos-member", "mailing-list-intern-member")); - tester = user("tester", Map.of( - SSH_KEY_1, "tester-ssh-key-1", - SSH_KEY_2, "tester-ssh-key-2", - MAILING_LIST_CHAOS, "tester+chaos@example.com", - MAILING_LIST_INTERN, "tester+intern@example.com"), - List.of("mailing-list-chaos-member")); - noone = user("noone", Map.of( - SSH_KEY_1, "noone-ssh-key-1", - SSH_KEY_2, "noone-ssh-key-2", - MAILING_LIST_CHAOS, "noone+chaos@example.org", - MAILING_LIST_INTERN, "noone+intern@example.org"), - Collections.emptyList()); - - UserProvider userProvider = mock(UserProvider.class); - when(session.users()).thenReturn(userProvider); - when(userProvider.searchForUserStream(eq(realm), eq(Map.of()))) - .thenAnswer(inv -> Stream.of(hacker, tester, noone)); - } - - @Test - public void exportAttributeValues_doorisSlug_returnsSshKeysOfMatchingUser() { - try (Response response = callAuthenticatedAs("export-dooris-ssh-keys", - () -> new AttributeEndpointsResourceProvider(session).exportAttributeValues("dooris-ssh-keys"))) { - - assertEquals(200, response.getStatus()); - assertEquals(List.of("hacker-ssh-key-1", "hacker-ssh-key-2"), response.getEntity()); - } - } - - /* NOTYET - @Test - public void exportAttributeValuesMap_doorisSlug_returnsSshKeysPerAttribute() { - try (Response response = callAuthenticatedAs("export-dooris-ssh-keys", - () -> new AttributeEndpointsResourceProvider(session).exportAttributeValuesMap("dooris-ssh-keys"))) { - - assertEquals(200, response.getStatus()); - assertEquals(Map.of( - SSH_KEY_1, List.of("hacker-ssh-key-1"), - SSH_KEY_2, List.of("hacker-ssh-key-2")), - response.getEntity()); - } - } - */ - - /* NOTYET - @Test - public void exportAttributeValues_mailingListChaosSlug_returnsAddressesOfAllMatchingUsers() { - try (Response response = callAuthenticatedAs("export-mailing-list-addresses", - () -> new AttributeEndpointsResourceProvider(session) - .exportAttributeValues("mailing-list-addresses-chaos"))) { - - assertEquals(200, response.getStatus()); - assertEquals(List.of("hacker+chaos@example.net", "tester+chaos@example.com"), response.getEntity()); - } - } - */ - - /* NOTYET - @Test - public void exportAttributeValues_mailingListInternSlug_returnsAddressOfSingleMatchingUser() { - try (Response response = callAuthenticatedAs("export-mailing-list-addresses", - () -> new AttributeEndpointsResourceProvider(session) - .exportAttributeValues("mailing-list-addresses-intern"))) { - - assertEquals(200, response.getStatus()); - assertEquals(List.of("hacker+intern@example.net"), response.getEntity()); - } - } - */ - - /* NOTYET - @Test - public void exportAttributeValuesMap_mailingListChaosSlug_returnsAddressesPerAttribute() { - try (Response response = callAuthenticatedAs("export-mailing-list-addresses", - () -> new AttributeEndpointsResourceProvider(session) - .exportAttributeValuesMap("mailing-list-addresses-chaos"))) { - - assertEquals(200, response.getStatus()); - assertEquals(Map.of(MAILING_LIST_CHAOS, - List.of("hacker+chaos@example.net", "tester+chaos@example.com")), - response.getEntity()); - } - } - */ - - @Test - public void exportAttributeValues_unknownSlug_throwsNotFound() { - NotFoundException exception = assertThrows(NotFoundException.class, - () -> callAuthenticatedAs("export-dooris-ssh-keys", - () -> new AttributeEndpointsResourceProvider(session).exportAttributeValues("unknown-slug"))); - - assertEquals(404, exception.getResponse().getStatus()); - assertTrue(exception.getMessage().contains("not found")); - } - - @Test - public void exportAttributeValues_duplicateSlugConfiguration_throwsNotFound() { - List duplicateComponents = List.of( - attributeEndpointComponent("duplicate-slug", - "export-dooris-ssh-keys", "dooris-authorized", "dooris-ssh-keys"), - attributeEndpointComponent("duplicate-slug", - "export-dooris-ssh-keys", "dooris-authorized", "dooris-ssh-keys")); - when(realm.getComponentsStream()).thenAnswer(inv -> duplicateComponents.stream()); - - NotFoundException exception = assertThrows(NotFoundException.class, - () -> callAuthenticatedAs("export-dooris-ssh-keys", - () -> new AttributeEndpointsResourceProvider(session).exportAttributeValues("duplicate-slug"))); - - assertEquals(404, exception.getResponse().getStatus()); - assertTrue(exception.getMessage().contains("Multiple configurations exist")); - } - - @Test - public void exportAttributeValues_missingAuthRole_throwsServerError() { - List components = List.of( - attributeEndpointComponent("bad-auth-role", - "nonexistent-role", "dooris-authorized", "dooris-ssh-keys")); - when(realm.getComponentsStream()).thenAnswer(inv -> components.stream()); - - ServerErrorException exception = assertThrows(ServerErrorException.class, - () -> callAuthenticatedAs("export-dooris-ssh-keys", - () -> new AttributeEndpointsResourceProvider(session).exportAttributeValues("bad-auth-role"))); - - assertEquals(500, exception.getResponse().getStatus()); - assertTrue(exception.getMessage().contains("auth-role does not exist")); - } - - @Test - public void exportAttributeValues_missingMatchRole_throwsServerError() { - List components = List.of( - attributeEndpointComponent("bad-match-role", - "export-dooris-ssh-keys", "nonexistent-role", "dooris-ssh-keys")); - when(realm.getComponentsStream()).thenAnswer(inv -> components.stream()); - - ServerErrorException exception = assertThrows(ServerErrorException.class, - () -> callAuthenticatedAs("export-dooris-ssh-keys", - () -> new AttributeEndpointsResourceProvider(session).exportAttributeValues("bad-match-role"))); - - assertEquals(500, exception.getResponse().getStatus()); - assertTrue(exception.getMessage().contains("match-role does not exist")); - } - - @Test - public void exportAttributeValues_invalidAttributeRegex_throwsServerError() { - ComponentModel component = attributeEndpointComponent("bad-regex", - "export-dooris-ssh-keys", "dooris-authorized", "dooris-ssh-keys"); - component.put("attribute-regex", "["); - when(realm.getComponentsStream()).thenAnswer(inv -> Stream.of(component)); - - ServerErrorException exception = assertThrows(ServerErrorException.class, - () -> callAuthenticatedAs("export-dooris-ssh-keys", - () -> new AttributeEndpointsResourceProvider(session).exportAttributeValues("bad-regex"))); - - assertEquals(500, exception.getResponse().getStatus()); - assertTrue(exception.getMessage().contains("attribute-regex is not a valid regex pattern")); - } - - @Test - public void exportAttributeValues_callerMissingAuthRole_throwsForbidden() { - ForbiddenException exception = assertThrows(ForbiddenException.class, - () -> callAuthenticatedAs("not-a-configured-role", - () -> new AttributeEndpointsResourceProvider(session).exportAttributeValues("dooris-ssh-keys"))); - - assertEquals(403, exception.getResponse().getStatus()); - } - - /** - * Runs {@code call} as if authenticated by a bearer token belonging to a service account - * that holds {@code requiredRole}, by intercepting construction of the - * {@link AppAuthManager.BearerTokenAuthenticator} the provider creates internally. - */ - private Response callAuthenticatedAs(String requiredRole, Supplier call) { - UserModel serviceAccount = mock(UserModel.class); - when(serviceAccount.hasRole(roles.get(requiredRole))).thenReturn(true); - - try (MockedConstruction ignored = Mockito.mockConstruction( - AppAuthManager.BearerTokenAuthenticator.class, - (mock, ctx) -> when(mock.authenticate()) - .thenReturn(new AuthResult(serviceAccount, null, null, null)))) { - return call.get(); - } - } - - private static ComponentModel attributeEndpointComponent(String slug, String authRole, String matchRole, - String attributeGroup) { - ComponentModel component = new ComponentModel(); - component.setProviderId(AdminUiPage.PROVIDER_ID); - component.put("slug", slug); - component.put("auth-role", authRole); - component.put("match-role", matchRole); - component.put("attribute-group", attributeGroup); - return component; - } - - /** - * Mirrors the User Profile configuration in testing. - */ - private static UPConfig testUserProfileConfig() { - UPConfig upConfig = new UPConfig(); - upConfig.setGroups(List.of(new UPGroup("dooris-ssh-keys"), new UPGroup("mailing-list-addresses"))); - upConfig.setAttributes(List.of( - attribute(SSH_KEY_1, "dooris-ssh-keys"), - attribute(SSH_KEY_2, "dooris-ssh-keys"), - attribute(MAILING_LIST_CHAOS, "mailing-list-addresses"), - attribute(MAILING_LIST_INTERN, "mailing-list-addresses"))); - return upConfig; - } - - private static UPAttribute attribute(String name, String group) { - UPAttribute attribute = new UPAttribute(name); - attribute.setGroup(group); - return attribute; - } - - private UserModel user(String username, Map attributes, List roleNames) { - UserModel user = mock(UserModel.class); - when(user.getUsername()).thenReturn(username); - - when(user.getAttributeStream(anyString())).thenAnswer(inv -> Stream.empty()); - attributes.forEach((name, value) -> - when(user.getAttributeStream(eq(name))).thenAnswer(inv -> Stream.of(value))); - - when(user.hasRole(any(RoleModel.class))).thenReturn(false); - roleNames.forEach(name -> when(user.hasRole(roles.get(name))).thenReturn(true)); - - return user; - } -} diff --git a/testing/README.md b/testing/README.md index 7a16c0e..2c5600e 100644 --- a/testing/README.md +++ b/testing/README.md @@ -1,11 +1,9 @@ -# Integration Testing - -This directory contains infrastructure and tests to verify end-to-end operation of the provider. - -## Creating a Testing Keycloak +# Creating a Testing Keycloak The Docker Compose setup in this directory sets up Keycloak and imports a realm `testing`. +## Starting Keycloak + Run `docker compose up -d` to start Keycloak. The admin console will be available at http://localhost:8080/. You can attach a Java debugger at `localhost:8081`. @@ -13,7 +11,7 @@ You can attach a Java debugger at `localhost:8081`. The realm export is in `import/testing.json`. It will be imported automatically when Keycloak starts. -### Updating the Realm +## Updating the Realm If you want to make changes to the testing realm and persist them, you need to export the realm. @@ -27,36 +25,16 @@ docker compose exec -it keycloak sh -c "cp -rp /opt/keycloak/data/h2 /tmp && env ## Running Integration Tests -This directory contains shell scripts that exercise the attribute endpoint. +This directory also contains shell scripts that exercise the attribute endpoint. Bring up Keycloak with `docker compose up -d`, then run one of the `client-test-export-`*`.sh` scripts. ```shell $ ./client-test-export-dooris.sh -All attributes collated into a single list [ "hacker-ssh-key-1", "hacker-ssh-key-2" ] -Results mapped per attribute -{ - "ssh-key-1": [ - "hacker-ssh-key-1" - ], - "ssh-key-2": [ - "hacker-ssh-key-2" - ] -} -$ ./client-test-export-mailing-lists.sh -chaos@ -[ - "hacker+chaos@example.net", - "tester+chaos@example.com" -] -intern@ -[ - "hacker+intern@example.net" -] ``` ## Realm `testing` Configuration @@ -65,16 +43,16 @@ The realm contains these objects: * Clients: * `export-dooris-ssh-keys` with secret `export-dooris-ssh-keys-secret` and user `service-account-export-dooris-ssh-keys` - * `export-mailing-list-addresses` with secret `export-mailing-list-addresses-secret` and user `service-account-export-mailing-list-addresses` + * `export-mailing-list-addresses` with secret `export-mailing-list-addresses-secret` and role `export-mailing-list-addresses` * Realm Roles: - * `dooris-authorized` to assign to users whose SSH keys should be exported - * `mailing-list-chaos-member` to assign to users who are a member of the chaos mailing list - * `mailing-list-intern-member` to assign to users who are a member of the intern mailing list - * `export-dooris-ssh-keys` to assign to service account users that should be allowed to use the dooris endpoint config - * `export-mailing-list-addresses` to assign to service account users that should be allowed to use the mailing list endpoint configs + * `dooris-authorized` + * `mailing-list-chaos-member` + * `mailing-list-intern-member` + * `export-dooris-ssh-keys` + * `export-mailing-list-addresses` * Groups: * `chaos` with role `mailing-list-chaos-member` - * `ìntern` with roles `dooris-authorized`, `mailing-list-chaos-member` and `mailing-list-intern-member` + * `ìntern` with roles `dooris-authorized` and `mailing-list-intern-member` * Users: * `tester` (Tony Tester), email `tester@example.com`, member of group `chaos` * Mailing List Addresses: @@ -103,7 +81,7 @@ The realm contains these objects: * `mailing-list-address-chaos` * Attribute Group `mailing-list-addresses` * `mailing-list-address-intern` - * Attribute Group `mailing-list-addresses` + * Attribute Group `mailing-list-intern` * `ssh-key-1` * Attribute Group `dooris-ssh-keys` * `ssh-key-2` diff --git a/testing/client-test-export-dooris.sh b/testing/client-test-export-dooris.sh index 82f5ad3..b6d4696 100755 --- a/testing/client-test-export-dooris.sh +++ b/testing/client-test-export-dooris.sh @@ -7,21 +7,14 @@ set -e ACCESS_TOKEN="$(curl -s --request POST \ - --url http://localhost:8080/realms/testing/protocol/openid-connect/token \ - --header 'content-type: application/x-www-form-urlencoded' \ - --data scope=openid \ - --data client_id=export-dooris-ssh-keys \ - --data client_secret=export-dooris-ssh-keys-secret \ - --data grant_type=client_credentials | jq --raw-output .access_token -)" + --url http://localhost:8080/realms/testing/protocol/openid-connect/token \ + --header 'content-type: application/x-www-form-urlencoded' \ + --data scope=openid \ + --data client_id=export-dooris-ssh-keys \ + --data client_secret=export-dooris-ssh-keys-secret \ + --data grant_type=client_credentials | jq --raw-output .access_token -)" -echo "All attributes collated into a single list" curl -s --request GET \ - --url http://localhost:8080/realms/testing/attribute-endpoints-provider/export/dooris-ssh-keys \ - --header "authorization: Bearer ${ACCESS_TOKEN}" \ - --header "content-type: application/json" | jq . - - -echo "Results mapped per attribute" -curl -s --request GET \ - --url http://localhost:8080/realms/testing/attribute-endpoints-provider/export/dooris-ssh-keys/map \ - --header "authorization: Bearer ${ACCESS_TOKEN}" \ - --header "content-type: application/json" | jq . - + --url http://localhost:8080/realms/testing/attribute-endpoints-provider/export/dooris-ssh-keys \ + --header "authorization: Bearer ${ACCESS_TOKEN}" \ + --header "content-type: application/json" | jq . - \ No newline at end of file diff --git a/testing/client-test-export-mailing-lists.sh b/testing/client-test-export-mailing-lists.sh deleted file mode 100755 index 4f15d76..0000000 --- a/testing/client-test-export-mailing-lists.sh +++ /dev/null @@ -1,27 +0,0 @@ -#!/bin/sh - -# -# Use curl to run a test export of Dooris ssh keys -# - -set -e - -ACCESS_TOKEN="$(curl -s --request POST \ - --url http://localhost:8080/realms/testing/protocol/openid-connect/token \ - --header 'content-type: application/x-www-form-urlencoded' \ - --data scope=openid \ - --data client_id=export-mailing-list-addresses \ - --data client_secret=export-mailing-list-addresses-secret \ - --data grant_type=client_credentials | jq --raw-output .access_token -)" - -echo "chaos@" -curl -s --request GET \ - --url http://localhost:8080/realms/testing/attribute-endpoints-provider/export/mailing-list-addresses-chaos \ - --header "authorization: Bearer ${ACCESS_TOKEN}" \ - --header "content-type: application/json" | jq . - - -echo "intern@" -curl -s --request GET \ - --url http://localhost:8080/realms/testing/attribute-endpoints-provider/export/mailing-list-addresses-intern \ - --header "authorization: Bearer ${ACCESS_TOKEN}" \ - --header "content-type: application/json" | jq . - diff --git a/testing/compose.yaml b/testing/compose.yaml index 3f73478..0311532 100644 --- a/testing/compose.yaml +++ b/testing/compose.yaml @@ -12,17 +12,6 @@ services: ports: - "8080:8080" - "8081:8081" - networks: - - keycloak volumes: - ./import:/opt/keycloak/data/import/ - - ../attribute-endpoints-provider/target/attribute-endpoints-provider-1.0-SNAPSHOT.jar:/opt/keycloak/providers/attribute-endpoints-provider.jar - -networks: - # force a "local" IP address that Keycloak accepts HTTP (not HTTPS) requests from - keycloak: - driver: bridge - ipam: - config: - - subnet: 192.168.231.128/29 - gateway: 192.168.231.129 + - ../attribute-endpoints-provider/target/attribute-endpoints-provider-1.0-SNAPSHOT.jar:/opt/keycloak/providers/attribute-endpoints-provider.jar \ No newline at end of file diff --git a/testing/import/testing.json b/testing/import/testing.json index dfa0fa7..3744ff8 100644 --- a/testing/import/testing.json +++ b/testing/import/testing.json @@ -1478,7 +1478,7 @@ "subType" : "authenticated", "subComponents" : { }, "config" : { - "allowed-protocol-mapper-types" : [ "saml-user-property-mapper", "oidc-usermodel-property-mapper", "saml-role-list-mapper", "oidc-full-name-mapper", "saml-user-attribute-mapper", "oidc-address-mapper", "oidc-usermodel-attribute-mapper", "oidc-sha256-pairwise-sub-mapper" ] + "allowed-protocol-mapper-types" : [ "oidc-sha256-pairwise-sub-mapper", "saml-user-attribute-mapper", "saml-user-property-mapper", "oidc-full-name-mapper", "saml-role-list-mapper", "oidc-address-mapper", "oidc-usermodel-attribute-mapper", "oidc-usermodel-property-mapper" ] } }, { "id" : "a49de9bf-462b-4c61-bb52-0373732f4b1b", @@ -1538,7 +1538,7 @@ "subType" : "anonymous", "subComponents" : { }, "config" : { - "allowed-protocol-mapper-types" : [ "saml-role-list-mapper", "saml-user-attribute-mapper", "oidc-usermodel-attribute-mapper", "oidc-usermodel-property-mapper", "saml-user-property-mapper", "oidc-full-name-mapper", "oidc-address-mapper", "oidc-sha256-pairwise-sub-mapper" ] + "allowed-protocol-mapper-types" : [ "saml-role-list-mapper", "oidc-address-mapper", "oidc-sha256-pairwise-sub-mapper", "oidc-usermodel-attribute-mapper", "oidc-full-name-mapper", "oidc-usermodel-property-mapper", "saml-user-property-mapper", "saml-user-attribute-mapper" ] } }, { "id" : "dd4024e9-f080-4319-aeb7-7f9906c345c5", @@ -1605,8 +1605,8 @@ "subComponents" : { }, "config" : { "match-role" : [ "mailing-list-intern-member" ], - "attribute-group" : [ "mailing-list-addresses" ], "auth-role" : [ "export-mailing-list-addresses" ], + "attribute-group" : [ "mailing-list-addresses" ], "slug" : [ "mailing-list-addresses-intern" ] } }, { @@ -1615,8 +1615,8 @@ "subComponents" : { }, "config" : { "match-role" : [ "dooris-authorized" ], - "attribute-group" : [ "dooris-ssh-keys" ], "auth-role" : [ "export-dooris-ssh-keys" ], + "attribute-group" : [ "dooris-ssh-keys" ], "slug" : [ "dooris-ssh-keys" ] } }, {