2019-08-03 14:50:05 -05:00
|
|
|
package middleware
|
|
|
|
|
|
|
|
import (
|
2021-05-18 11:24:42 -05:00
|
|
|
"context"
|
2019-08-03 14:50:05 -05:00
|
|
|
"encoding/json"
|
|
|
|
"testing"
|
|
|
|
|
|
|
|
"github.com/grafana/grafana/pkg/bus"
|
2020-12-04 04:09:32 -06:00
|
|
|
"github.com/grafana/grafana/pkg/login"
|
2019-08-03 14:50:05 -05:00
|
|
|
"github.com/grafana/grafana/pkg/models"
|
2020-12-11 04:44:44 -06:00
|
|
|
"github.com/grafana/grafana/pkg/services/contexthandler"
|
2019-08-03 14:50:05 -05:00
|
|
|
"github.com/grafana/grafana/pkg/setting"
|
|
|
|
"github.com/grafana/grafana/pkg/util"
|
2020-12-03 01:28:54 -06:00
|
|
|
"github.com/stretchr/testify/assert"
|
|
|
|
"github.com/stretchr/testify/require"
|
2019-08-03 14:50:05 -05:00
|
|
|
)
|
|
|
|
|
|
|
|
func TestMiddlewareBasicAuth(t *testing.T) {
|
2020-12-03 01:28:54 -06:00
|
|
|
const id int64 = 12
|
2019-08-03 14:50:05 -05:00
|
|
|
|
2020-12-11 04:44:44 -06:00
|
|
|
configure := func(cfg *setting.Cfg) {
|
|
|
|
cfg.BasicAuthEnabled = true
|
|
|
|
cfg.DisableBruteForceLoginProtection = true
|
|
|
|
}
|
|
|
|
|
2020-12-04 04:09:32 -06:00
|
|
|
middlewareScenario(t, "Valid API key", func(t *testing.T, sc *scenarioContext) {
|
2020-12-03 01:28:54 -06:00
|
|
|
const orgID int64 = 2
|
|
|
|
keyhash, err := util.EncodePassword("v5nAwpMafFP6znaS4urhdWDLS5511M42", "asd")
|
|
|
|
require.NoError(t, err)
|
2019-08-03 14:50:05 -05:00
|
|
|
|
2020-12-03 01:28:54 -06:00
|
|
|
bus.AddHandler("test", func(query *models.GetApiKeyByNameQuery) error {
|
|
|
|
query.Result = &models.ApiKey{OrgId: orgID, Role: models.ROLE_EDITOR, Key: keyhash}
|
|
|
|
return nil
|
2019-08-03 14:50:05 -05:00
|
|
|
})
|
|
|
|
|
2020-12-03 01:28:54 -06:00
|
|
|
authHeader := util.GetBasicAuthHeader("api_key", "eyJrIjoidjVuQXdwTWFmRlA2em5hUzR1cmhkV0RMUzU1MTFNNDIiLCJuIjoiYXNkIiwiaWQiOjF9")
|
|
|
|
sc.fakeReq("GET", "/").withAuthorizationHeader(authHeader).exec()
|
|
|
|
|
|
|
|
assert.Equal(t, 200, sc.resp.Code)
|
|
|
|
assert.True(t, sc.context.IsSignedIn)
|
|
|
|
assert.Equal(t, orgID, sc.context.OrgId)
|
|
|
|
assert.Equal(t, models.ROLE_EDITOR, sc.context.OrgRole)
|
2020-12-11 04:44:44 -06:00
|
|
|
}, configure)
|
2020-12-03 01:28:54 -06:00
|
|
|
|
2020-12-04 04:09:32 -06:00
|
|
|
middlewareScenario(t, "Handle auth", func(t *testing.T, sc *scenarioContext) {
|
2020-12-03 01:28:54 -06:00
|
|
|
const password = "MyPass"
|
|
|
|
const salt = "Salt"
|
|
|
|
const orgID int64 = 2
|
|
|
|
|
|
|
|
bus.AddHandler("grafana-auth", func(query *models.LoginUserQuery) error {
|
2020-12-11 04:44:44 -06:00
|
|
|
t.Log("Handling LoginUserQuery")
|
2020-12-03 01:28:54 -06:00
|
|
|
encoded, err := util.EncodePassword(password, salt)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
query.User = &models.User{
|
|
|
|
Password: encoded,
|
|
|
|
Salt: salt,
|
|
|
|
}
|
|
|
|
return nil
|
2019-08-03 14:50:05 -05:00
|
|
|
})
|
|
|
|
|
2021-05-18 11:24:42 -05:00
|
|
|
bus.AddHandlerCtx("get-sign-user", func(ctx context.Context, query *models.GetSignedInUserQuery) error {
|
2020-12-11 04:44:44 -06:00
|
|
|
t.Log("Handling GetSignedInUserQuery")
|
2020-12-03 01:28:54 -06:00
|
|
|
query.Result = &models.SignedInUser{OrgId: orgID, UserId: id}
|
|
|
|
return nil
|
2019-08-03 14:50:05 -05:00
|
|
|
})
|
|
|
|
|
2020-12-03 01:28:54 -06:00
|
|
|
authHeader := util.GetBasicAuthHeader("myUser", password)
|
|
|
|
sc.fakeReq("GET", "/").withAuthorizationHeader(authHeader).exec()
|
2019-08-03 14:50:05 -05:00
|
|
|
|
2020-12-03 01:28:54 -06:00
|
|
|
assert.True(t, sc.context.IsSignedIn)
|
|
|
|
assert.Equal(t, orgID, sc.context.OrgId)
|
|
|
|
assert.Equal(t, id, sc.context.UserId)
|
2020-12-11 04:44:44 -06:00
|
|
|
}, configure)
|
2019-08-03 14:50:05 -05:00
|
|
|
|
2020-12-04 04:09:32 -06:00
|
|
|
middlewareScenario(t, "Auth sequence", func(t *testing.T, sc *scenarioContext) {
|
2020-12-03 01:28:54 -06:00
|
|
|
const password = "MyPass"
|
|
|
|
const salt = "Salt"
|
|
|
|
|
2020-12-04 04:09:32 -06:00
|
|
|
login.Init()
|
2020-12-03 01:28:54 -06:00
|
|
|
|
|
|
|
bus.AddHandler("user-query", func(query *models.GetUserByLoginQuery) error {
|
|
|
|
encoded, err := util.EncodePassword(password, salt)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
query.Result = &models.User{
|
|
|
|
Password: encoded,
|
|
|
|
Id: id,
|
|
|
|
Salt: salt,
|
|
|
|
}
|
|
|
|
return nil
|
2019-08-03 14:50:05 -05:00
|
|
|
})
|
|
|
|
|
2021-05-18 11:24:42 -05:00
|
|
|
bus.AddHandlerCtx("get-sign-user", func(ctx context.Context, query *models.GetSignedInUserQuery) error {
|
2020-12-03 01:28:54 -06:00
|
|
|
query.Result = &models.SignedInUser{UserId: query.UserId}
|
|
|
|
return nil
|
|
|
|
})
|
2019-08-03 14:50:05 -05:00
|
|
|
|
2020-12-03 01:28:54 -06:00
|
|
|
authHeader := util.GetBasicAuthHeader("myUser", password)
|
|
|
|
sc.fakeReq("GET", "/").withAuthorizationHeader(authHeader).exec()
|
2020-12-11 04:44:44 -06:00
|
|
|
require.NotNil(t, sc.context)
|
2019-08-03 14:50:05 -05:00
|
|
|
|
2020-12-03 01:28:54 -06:00
|
|
|
assert.True(t, sc.context.IsSignedIn)
|
|
|
|
assert.Equal(t, id, sc.context.UserId)
|
2020-12-11 04:44:44 -06:00
|
|
|
}, configure)
|
2019-08-03 14:50:05 -05:00
|
|
|
|
2020-12-04 04:09:32 -06:00
|
|
|
middlewareScenario(t, "Should return error if user is not found", func(t *testing.T, sc *scenarioContext) {
|
2020-12-03 01:28:54 -06:00
|
|
|
sc.fakeReq("GET", "/")
|
|
|
|
sc.req.SetBasicAuth("user", "password")
|
|
|
|
sc.exec()
|
|
|
|
|
|
|
|
err := json.NewDecoder(sc.resp.Body).Decode(&sc.respJson)
|
|
|
|
require.Error(t, err)
|
|
|
|
|
|
|
|
assert.Equal(t, 401, sc.resp.Code)
|
2020-12-11 04:44:44 -06:00
|
|
|
assert.Equal(t, contexthandler.InvalidUsernamePassword, sc.respJson["message"])
|
|
|
|
}, configure)
|
2019-08-03 14:50:05 -05:00
|
|
|
|
2020-12-04 04:09:32 -06:00
|
|
|
middlewareScenario(t, "Should return error if user & password do not match", func(t *testing.T, sc *scenarioContext) {
|
2020-12-03 01:28:54 -06:00
|
|
|
bus.AddHandler("user-query", func(loginUserQuery *models.GetUserByLoginQuery) error {
|
|
|
|
return nil
|
2019-08-03 14:50:05 -05:00
|
|
|
})
|
2020-12-03 01:28:54 -06:00
|
|
|
|
|
|
|
sc.fakeReq("GET", "/")
|
|
|
|
sc.req.SetBasicAuth("killa", "gorilla")
|
|
|
|
sc.exec()
|
|
|
|
|
|
|
|
err := json.NewDecoder(sc.resp.Body).Decode(&sc.respJson)
|
|
|
|
require.Error(t, err)
|
|
|
|
|
|
|
|
assert.Equal(t, 401, sc.resp.Code)
|
2020-12-11 04:44:44 -06:00
|
|
|
assert.Equal(t, contexthandler.InvalidUsernamePassword, sc.respJson["message"])
|
|
|
|
}, configure)
|
2019-08-03 14:50:05 -05:00
|
|
|
}
|