mirror of
https://salsa.debian.org/freeipa-team/freeipa.git
synced 2025-02-25 18:55:28 -06:00
Add option to limit the attributes allowed in an entry.
Kerberos ticket policy can update policy in a user entry. This allowed set/addattr to be used to modify attributes outside of the ticket policy perview, also bypassing all validation/normalization. Likewise the ticket policy was updatable by the user plugin bypassing all validation. Add two new LDAPObject values to control this behavior: limit_object_classes: only attributes in these are allowed disallow_object_classes: attributes in these are disallowed By default both of these lists are empty so are skipped. ticket 744
This commit is contained in:
138
tests/test_xmlrpc/test_krbtpolicy.py
Normal file
138
tests/test_xmlrpc/test_krbtpolicy.py
Normal file
@@ -0,0 +1,138 @@
|
||||
# Authors:
|
||||
# Rob Crittenden <rcritten@redhat.com>
|
||||
#
|
||||
# Copyright (C) 2011 Red Hat
|
||||
# see file 'COPYING' for use and warranty information
|
||||
#
|
||||
# This program is free software; you can redistribute it and/or modify
|
||||
# it under the terms of the GNU General Public License as published by
|
||||
# the Free Software Foundation, either version 3 of the License, or
|
||||
# (at your option) any later version.
|
||||
#
|
||||
# This program is distributed in the hope that it will be useful,
|
||||
# but WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
||||
# GNU General Public License for more details.
|
||||
#
|
||||
# You should have received a copy of the GNU General Public License
|
||||
# along with this program. If not, see <http://www.gnu.org/licenses/>.
|
||||
"""
|
||||
Test kerberos ticket policy
|
||||
"""
|
||||
|
||||
from ipalib import api, errors
|
||||
from tests.test_xmlrpc import objectclasses
|
||||
from xmlrpc_test import Declarative, fuzzy_digits, fuzzy_uuid
|
||||
|
||||
user1 = u'tuser1'
|
||||
|
||||
class test_krbtpolicy(Declarative):
|
||||
cleanup_commands = [
|
||||
('user_del', [user1], {}),
|
||||
]
|
||||
|
||||
tests = [
|
||||
|
||||
|
||||
dict(
|
||||
desc='Reset global policy',
|
||||
command=(
|
||||
'krbtpolicy_reset', [], {}
|
||||
),
|
||||
expected=dict(
|
||||
value=u'',
|
||||
summary=None,
|
||||
result=dict(
|
||||
krbmaxticketlife=[u'86400'],
|
||||
krbmaxrenewableage=[u'604800'],
|
||||
),
|
||||
),
|
||||
),
|
||||
|
||||
|
||||
dict(
|
||||
desc='Show global policy',
|
||||
command=(
|
||||
'krbtpolicy_show', [], {}
|
||||
),
|
||||
expected=dict(
|
||||
value=u'',
|
||||
summary=None,
|
||||
result=dict(
|
||||
dn=u'cn=%s,cn=kerberos,%s' % (api.env.domain, api.env.basedn),
|
||||
krbmaxticketlife=[u'86400'],
|
||||
krbmaxrenewableage=[u'604800'],
|
||||
),
|
||||
),
|
||||
),
|
||||
|
||||
|
||||
dict(
|
||||
desc='Update global policy',
|
||||
command=(
|
||||
'krbtpolicy_mod', [], dict(krbmaxticketlife=3600)
|
||||
),
|
||||
expected=dict(
|
||||
value=u'',
|
||||
summary=None,
|
||||
result=dict(
|
||||
krbmaxticketlife=[u'3600'],
|
||||
krbmaxrenewableage=[u'604800'],
|
||||
),
|
||||
),
|
||||
),
|
||||
|
||||
|
||||
dict(
|
||||
desc='Create %r' % user1,
|
||||
command=(
|
||||
'user_add', [user1], dict(givenname=u'Test', sn=u'User1')
|
||||
),
|
||||
expected=dict(
|
||||
value=user1,
|
||||
summary=u'Added user "%s"' % user1,
|
||||
result=dict(
|
||||
gecos=[u'Test User1'],
|
||||
givenname=[u'Test'],
|
||||
homedirectory=[u'/home/tuser1'],
|
||||
krbprincipalname=[u'tuser1@' + api.env.realm],
|
||||
loginshell=[u'/bin/sh'],
|
||||
objectclass=objectclasses.user,
|
||||
sn=[u'User1'],
|
||||
uid=[user1],
|
||||
uidnumber=[fuzzy_digits],
|
||||
displayname=[u'Test User1'],
|
||||
cn=[u'Test User1'],
|
||||
initials=[u'TU'],
|
||||
ipauniqueid=[fuzzy_uuid],
|
||||
dn=u'uid=%s,cn=users,cn=accounts,%s' % (user1, api.env.basedn)
|
||||
),
|
||||
),
|
||||
),
|
||||
|
||||
|
||||
dict(
|
||||
desc='Update user ticket policy',
|
||||
command=(
|
||||
'krbtpolicy_mod', [user1], dict(krbmaxticketlife=3600)
|
||||
),
|
||||
expected=dict(
|
||||
value=user1,
|
||||
summary=None,
|
||||
result=dict(
|
||||
krbmaxticketlife=[u'3600'],
|
||||
),
|
||||
),
|
||||
),
|
||||
|
||||
|
||||
dict(
|
||||
desc='Try updating other user attribute',
|
||||
command=(
|
||||
'krbtpolicy_mod', [user1], dict(setattr=u'givenname=Pete')
|
||||
),
|
||||
expected=errors.ObjectclassViolation(info='attribute "givenname" not allowed'),
|
||||
),
|
||||
|
||||
|
||||
]
|
||||
@@ -304,6 +304,15 @@ class test_user(Declarative):
|
||||
),
|
||||
|
||||
|
||||
dict(
|
||||
desc='Try updating the krb ticket policy of %r' % user1,
|
||||
command=(
|
||||
'user_mod', [user1], dict(setattr=u'krbmaxticketlife=88000')
|
||||
),
|
||||
expected=errors.ObjectclassViolation(info='attribute "krbmaxticketlife" not allowed'),
|
||||
),
|
||||
|
||||
|
||||
dict(
|
||||
desc='Retrieve %r to verify update' % user1,
|
||||
command=('user_show', [user1], {}),
|
||||
@@ -388,6 +397,17 @@ class test_user(Declarative):
|
||||
),
|
||||
|
||||
|
||||
dict(
|
||||
desc='Create user %r with krb ticket policy' % user1,
|
||||
command=(
|
||||
'user_add', [user1], dict(givenname=u'Test', sn=u'User1',
|
||||
setattr=u'krbmaxticketlife=88000')
|
||||
),
|
||||
expected=errors.ObjectclassViolation(info='attribute "krbmaxticketlife" not allowed'),
|
||||
),
|
||||
|
||||
|
||||
|
||||
dict(
|
||||
desc='Create %r' % user1,
|
||||
command=(
|
||||
|
||||
Reference in New Issue
Block a user