2019-04-22 21:31:16 +00:00
|
|
|
package authorizer_test
|
2019-01-11 20:09:31 +00:00
|
|
|
|
|
|
|
import (
|
|
|
|
"context"
|
2019-07-26 15:37:45 +00:00
|
|
|
"fmt"
|
2019-07-31 09:46:28 +00:00
|
|
|
"strings"
|
2019-01-11 20:09:31 +00:00
|
|
|
"testing"
|
|
|
|
|
|
|
|
"github.com/influxdata/influxdb"
|
2019-04-22 21:31:16 +00:00
|
|
|
"github.com/influxdata/influxdb/authorizer"
|
2019-01-11 20:09:31 +00:00
|
|
|
pctx "github.com/influxdata/influxdb/context"
|
|
|
|
"github.com/influxdata/influxdb/http"
|
|
|
|
"github.com/influxdata/influxdb/inmem"
|
|
|
|
"github.com/influxdata/influxdb/mock"
|
2019-04-22 21:31:16 +00:00
|
|
|
_ "github.com/influxdata/influxdb/query/builtin"
|
2019-05-30 21:39:51 +00:00
|
|
|
"github.com/influxdata/influxdb/task/backend"
|
2019-07-26 15:37:45 +00:00
|
|
|
"github.com/pkg/errors"
|
2019-03-14 20:26:36 +00:00
|
|
|
"go.uber.org/zap/zaptest"
|
2019-01-11 20:09:31 +00:00
|
|
|
)
|
|
|
|
|
|
|
|
func TestOnboardingValidation(t *testing.T) {
|
2019-04-09 18:24:40 +00:00
|
|
|
svc := inmem.NewService()
|
2019-04-22 21:31:16 +00:00
|
|
|
ts := authorizer.NewTaskService(zaptest.NewLogger(t), mockTaskService(3, 2, 1), svc)
|
2019-01-11 20:09:31 +00:00
|
|
|
|
|
|
|
r, err := svc.Generate(context.Background(), &influxdb.OnboardingRequest{
|
2019-02-19 23:47:19 +00:00
|
|
|
User: "Setec Astronomy",
|
|
|
|
Password: "too many secrets",
|
2019-01-11 20:09:31 +00:00
|
|
|
Org: "thing",
|
|
|
|
Bucket: "holder",
|
|
|
|
RetentionPeriod: 1,
|
|
|
|
})
|
|
|
|
|
|
|
|
if err != nil {
|
|
|
|
t.Fatal(err)
|
|
|
|
}
|
|
|
|
|
|
|
|
ctx := pctx.SetAuthorizer(context.Background(), r.Auth)
|
|
|
|
|
2019-04-22 21:31:16 +00:00
|
|
|
_, err = ts.CreateTask(ctx, influxdb.TaskCreate{
|
2019-01-18 16:10:14 +00:00
|
|
|
OrganizationID: r.Org.ID,
|
2019-08-20 14:42:40 +00:00
|
|
|
OwnerID: r.Auth.GetUserID(),
|
2019-01-11 20:09:31 +00:00
|
|
|
Flux: `option task = {
|
|
|
|
name: "my_task",
|
|
|
|
every: 1s,
|
|
|
|
}
|
|
|
|
from(bucket:"holder") |> range(start:-5m) |> to(bucket:"holder", org:"thing")`,
|
|
|
|
})
|
|
|
|
if err != nil {
|
|
|
|
t.Fatal(err)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2019-02-21 18:31:45 +00:00
|
|
|
func mockTaskService(orgID, taskID, runID influxdb.ID) influxdb.TaskService {
|
2019-01-11 20:09:31 +00:00
|
|
|
task := influxdb.Task{
|
2019-02-21 18:31:45 +00:00
|
|
|
ID: taskID,
|
|
|
|
OrganizationID: orgID,
|
2019-01-18 16:10:14 +00:00
|
|
|
Name: "cows",
|
2019-05-30 21:39:51 +00:00
|
|
|
Status: string(backend.TaskActive),
|
2019-01-11 20:09:31 +00:00
|
|
|
Flux: `option task = {
|
|
|
|
name: "my_task",
|
|
|
|
every: 1s,
|
|
|
|
}
|
|
|
|
from(bucket:"holder") |> range(start:-5m) |> to(bucket:"holder", org:"thing")`,
|
|
|
|
Every: "1s",
|
|
|
|
}
|
|
|
|
|
2019-03-05 22:58:33 +00:00
|
|
|
log := influxdb.Log{Message: "howdy partner"}
|
2019-01-11 20:09:31 +00:00
|
|
|
|
|
|
|
run := influxdb.Run{
|
2019-02-21 18:31:45 +00:00
|
|
|
ID: runID,
|
|
|
|
TaskID: taskID,
|
2019-01-11 20:09:31 +00:00
|
|
|
Status: "completed",
|
|
|
|
ScheduledFor: "a while ago",
|
|
|
|
StartedAt: "not so long ago",
|
|
|
|
FinishedAt: "more recently",
|
2019-03-05 22:58:33 +00:00
|
|
|
Log: []influxdb.Log{log},
|
2019-01-11 20:09:31 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
return &mock.TaskService{
|
|
|
|
FindTaskByIDFn: func(context.Context, influxdb.ID) (*influxdb.Task, error) {
|
|
|
|
return &task, nil
|
|
|
|
},
|
|
|
|
FindTasksFn: func(context.Context, influxdb.TaskFilter) ([]*influxdb.Task, int, error) {
|
|
|
|
return []*influxdb.Task{&task}, 1, nil
|
|
|
|
},
|
2019-02-09 01:34:44 +00:00
|
|
|
CreateTaskFn: func(_ context.Context, tc influxdb.TaskCreate) (*influxdb.Task, error) {
|
|
|
|
taskCopy := task
|
|
|
|
return &taskCopy, nil
|
2019-01-11 20:09:31 +00:00
|
|
|
},
|
|
|
|
UpdateTaskFn: func(context.Context, influxdb.ID, influxdb.TaskUpdate) (*influxdb.Task, error) {
|
|
|
|
return &task, nil
|
|
|
|
},
|
|
|
|
DeleteTaskFn: func(context.Context, influxdb.ID) error {
|
|
|
|
return nil
|
|
|
|
},
|
|
|
|
FindLogsFn: func(context.Context, influxdb.LogFilter) ([]*influxdb.Log, int, error) {
|
|
|
|
return []*influxdb.Log{&log}, 1, nil
|
|
|
|
},
|
|
|
|
FindRunsFn: func(context.Context, influxdb.RunFilter) ([]*influxdb.Run, int, error) {
|
|
|
|
return []*influxdb.Run{&run}, 1, nil
|
|
|
|
},
|
|
|
|
FindRunByIDFn: func(context.Context, influxdb.ID, influxdb.ID) (*influxdb.Run, error) {
|
|
|
|
return &run, nil
|
|
|
|
},
|
|
|
|
CancelRunFn: func(context.Context, influxdb.ID, influxdb.ID) error {
|
|
|
|
return nil
|
|
|
|
},
|
|
|
|
RetryRunFn: func(context.Context, influxdb.ID, influxdb.ID) (*influxdb.Run, error) {
|
|
|
|
return &run, nil
|
|
|
|
},
|
|
|
|
ForceRunFn: func(context.Context, influxdb.ID, int64) (*influxdb.Run, error) {
|
|
|
|
return &run, nil
|
|
|
|
},
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func TestValidations(t *testing.T) {
|
2019-02-21 18:31:45 +00:00
|
|
|
var (
|
2019-07-26 15:37:45 +00:00
|
|
|
taskID = influxdb.ID(0x7456)
|
|
|
|
runID = influxdb.ID(0x402)
|
|
|
|
otherOrg = &influxdb.Organization{Name: "other_org"}
|
2019-02-21 18:31:45 +00:00
|
|
|
)
|
|
|
|
|
2019-04-09 18:24:40 +00:00
|
|
|
inmem := inmem.NewService()
|
2019-01-11 20:09:31 +00:00
|
|
|
|
|
|
|
r, err := inmem.Generate(context.Background(), &influxdb.OnboardingRequest{
|
2019-02-19 23:47:19 +00:00
|
|
|
User: "Setec Astronomy",
|
|
|
|
Password: "too many secrets",
|
2019-01-11 20:09:31 +00:00
|
|
|
Org: "thing",
|
|
|
|
Bucket: "holder",
|
|
|
|
RetentionPeriod: 1,
|
|
|
|
})
|
|
|
|
if err != nil {
|
|
|
|
t.Fatal(err)
|
|
|
|
}
|
2019-07-26 15:37:45 +00:00
|
|
|
|
|
|
|
if err := inmem.CreateOrganization(context.Background(), otherOrg); err != nil {
|
|
|
|
t.Fatal(err)
|
|
|
|
}
|
|
|
|
|
|
|
|
otherBucket := &influxdb.Bucket{
|
|
|
|
Name: "other_bucket",
|
|
|
|
OrgID: otherOrg.ID,
|
|
|
|
}
|
|
|
|
|
|
|
|
if err = inmem.CreateBucket(context.Background(), otherBucket); err != nil {
|
|
|
|
t.Fatal(err)
|
|
|
|
}
|
2019-01-11 20:09:31 +00:00
|
|
|
|
2019-02-21 18:31:45 +00:00
|
|
|
var (
|
2019-07-26 15:37:45 +00:00
|
|
|
orgID = r.Org.ID
|
|
|
|
validTaskService = authorizer.NewTaskService(zaptest.NewLogger(t), mockTaskService(orgID, taskID, runID), inmem)
|
|
|
|
|
2019-02-21 18:31:45 +00:00
|
|
|
// Read all tasks in org.
|
|
|
|
orgReadAllTaskPermissions = []influxdb.Permission{
|
|
|
|
{Action: influxdb.ReadAction, Resource: influxdb.Resource{Type: influxdb.TasksResourceType, OrgID: &orgID}},
|
|
|
|
}
|
|
|
|
|
|
|
|
// Read all tasks in some other org.
|
|
|
|
wrongOrgReadAllTaskPermissions = []influxdb.Permission{
|
|
|
|
{Action: influxdb.ReadAction, Resource: influxdb.Resource{Type: influxdb.TasksResourceType, OrgID: &taskID}},
|
|
|
|
}
|
|
|
|
|
|
|
|
// Write all tasks in org, no specific bucket permissions.
|
|
|
|
orgWriteAllTaskPermissions = []influxdb.Permission{
|
|
|
|
{Action: influxdb.WriteAction, Resource: influxdb.Resource{Type: influxdb.TasksResourceType, OrgID: &orgID}},
|
|
|
|
}
|
|
|
|
|
|
|
|
// Write all tasks in org, and read/write the onboarding bucket.
|
|
|
|
orgWriteAllTaskBucketPermissions = []influxdb.Permission{
|
|
|
|
{Action: influxdb.WriteAction, Resource: influxdb.Resource{Type: influxdb.TasksResourceType, OrgID: &orgID}},
|
|
|
|
{Action: influxdb.WriteAction, Resource: influxdb.Resource{Type: influxdb.BucketsResourceType, OrgID: &orgID, ID: &r.Bucket.ID}},
|
|
|
|
{Action: influxdb.ReadAction, Resource: influxdb.Resource{Type: influxdb.BucketsResourceType, OrgID: &orgID, ID: &r.Bucket.ID}},
|
|
|
|
}
|
|
|
|
|
|
|
|
// Write the specific task, and read/write the onboarding bucket.
|
|
|
|
orgWriteTaskBucketPermissions = []influxdb.Permission{
|
|
|
|
{Action: influxdb.WriteAction, Resource: influxdb.Resource{Type: influxdb.TasksResourceType, OrgID: &orgID, ID: &taskID}},
|
|
|
|
{Action: influxdb.WriteAction, Resource: influxdb.Resource{Type: influxdb.BucketsResourceType, OrgID: &orgID, ID: &r.Bucket.ID}},
|
|
|
|
{Action: influxdb.ReadAction, Resource: influxdb.Resource{Type: influxdb.BucketsResourceType, OrgID: &orgID, ID: &r.Bucket.ID}},
|
|
|
|
}
|
|
|
|
|
|
|
|
// Permission only to specifically write the target task.
|
|
|
|
orgWriteTaskPermissions = []influxdb.Permission{
|
|
|
|
{Action: influxdb.WriteAction, Resource: influxdb.Resource{Type: influxdb.TasksResourceType, OrgID: &orgID, ID: &taskID}},
|
|
|
|
}
|
|
|
|
|
|
|
|
// Permission only to specifically read the target task.
|
|
|
|
orgReadTaskPermissions = []influxdb.Permission{
|
|
|
|
{Action: influxdb.ReadAction, Resource: influxdb.Resource{Type: influxdb.TasksResourceType, OrgID: &orgID, ID: &taskID}},
|
|
|
|
}
|
|
|
|
)
|
|
|
|
|
2019-01-11 20:09:31 +00:00
|
|
|
tests := []struct {
|
|
|
|
name string
|
|
|
|
check func(context.Context, influxdb.TaskService) error
|
|
|
|
auth *influxdb.Authorization
|
|
|
|
}{
|
|
|
|
{
|
|
|
|
name: "create failure",
|
|
|
|
check: func(ctx context.Context, svc influxdb.TaskService) error {
|
2019-02-09 01:34:44 +00:00
|
|
|
_, err := svc.CreateTask(ctx, influxdb.TaskCreate{
|
2019-01-18 16:10:14 +00:00
|
|
|
OrganizationID: r.Org.ID,
|
2019-01-11 20:09:31 +00:00
|
|
|
Flux: `option task = {
|
|
|
|
name: "my_task",
|
|
|
|
every: 1s,
|
|
|
|
}
|
|
|
|
from(bucket:"holder") |> range(start:-5m) |> to(bucket:"holder", org:"thing")`,
|
|
|
|
})
|
|
|
|
if err == nil {
|
|
|
|
return errors.New("failed to error without permission")
|
|
|
|
}
|
|
|
|
return nil
|
|
|
|
},
|
|
|
|
auth: &influxdb.Authorization{},
|
|
|
|
},
|
|
|
|
{
|
2019-08-06 16:27:52 +00:00
|
|
|
name: "create bad type",
|
|
|
|
check: func(ctx context.Context, svc influxdb.TaskService) error {
|
|
|
|
_, err := svc.CreateTask(ctx, influxdb.TaskCreate{
|
|
|
|
OrganizationID: r.Org.ID,
|
2019-08-20 14:42:40 +00:00
|
|
|
OwnerID: r.Auth.GetUserID(),
|
2019-08-06 16:27:52 +00:00
|
|
|
Type: influxdb.TaskTypeWildcard,
|
|
|
|
Flux: `option task = {
|
|
|
|
name: "my_task",
|
|
|
|
every: 1s,
|
|
|
|
}
|
|
|
|
from(bucket:"holder") |> range(start:-5m) |> to(bucket:"holder", org:"thing")`,
|
|
|
|
})
|
|
|
|
if err != influxdb.ErrInvalidTaskType {
|
|
|
|
return errors.New("failed to error with invalid task type")
|
|
|
|
}
|
|
|
|
return nil
|
|
|
|
},
|
|
|
|
auth: &influxdb.Authorization{},
|
|
|
|
}, {
|
2019-01-11 20:09:31 +00:00
|
|
|
name: "create success",
|
|
|
|
auth: r.Auth,
|
|
|
|
check: func(ctx context.Context, svc influxdb.TaskService) error {
|
2019-02-09 01:34:44 +00:00
|
|
|
_, err := svc.CreateTask(ctx, influxdb.TaskCreate{
|
2019-01-18 16:10:14 +00:00
|
|
|
OrganizationID: r.Org.ID,
|
2019-08-20 14:42:40 +00:00
|
|
|
OwnerID: r.Auth.GetUserID(),
|
2019-01-11 20:09:31 +00:00
|
|
|
Flux: `option task = {
|
|
|
|
name: "my_task",
|
|
|
|
every: 1s,
|
|
|
|
}
|
|
|
|
from(bucket:"holder") |> range(start:-5m) |> to(bucket:"holder", org:"thing")`,
|
|
|
|
})
|
|
|
|
return err
|
|
|
|
},
|
|
|
|
},
|
|
|
|
{
|
2019-08-06 16:27:52 +00:00
|
|
|
name: "create bad bucket",
|
2019-01-11 20:09:31 +00:00
|
|
|
auth: r.Auth,
|
|
|
|
check: func(ctx context.Context, svc influxdb.TaskService) error {
|
2019-07-31 09:46:28 +00:00
|
|
|
var (
|
|
|
|
expMsg = "Failed to create task."
|
2019-08-22 02:08:51 +00:00
|
|
|
expCode = influxdb.EUnauthorized
|
2019-07-31 09:46:28 +00:00
|
|
|
errfmt = "expected %q, got %q"
|
|
|
|
_, err = svc.CreateTask(ctx, influxdb.TaskCreate{
|
|
|
|
OrganizationID: r.Org.ID,
|
2019-08-20 14:42:40 +00:00
|
|
|
OwnerID: r.Auth.GetUserID(),
|
2019-07-31 09:46:28 +00:00
|
|
|
Flux: `option task = {
|
2019-01-11 20:09:31 +00:00
|
|
|
name: "my_task",
|
|
|
|
every: 1s,
|
|
|
|
}
|
|
|
|
from(bucket:"bad") |> range(start:-5m) |> to(bucket:"bad", org:"thing")`,
|
2019-07-31 09:46:28 +00:00
|
|
|
})
|
|
|
|
)
|
|
|
|
|
|
|
|
if err == nil {
|
|
|
|
return errors.New("created task without bucket permission")
|
|
|
|
}
|
|
|
|
|
|
|
|
perr, ok := err.(*influxdb.Error)
|
|
|
|
if !ok {
|
2019-08-22 02:08:51 +00:00
|
|
|
return fmt.Errorf(errfmt, &influxdb.Error{}, err)
|
2019-07-31 09:46:28 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
if perr.Code != expCode {
|
|
|
|
return fmt.Errorf(errfmt, expCode, perr.Code)
|
|
|
|
}
|
|
|
|
|
|
|
|
if perr.Err == nil {
|
|
|
|
return fmt.Errorf(errfmt, "platform.Error.Err to be present", perr.Err)
|
|
|
|
}
|
|
|
|
|
2019-09-19 15:06:47 +00:00
|
|
|
if !strings.Contains(perr.Err.Error(), "bucket \"bad\" not found") {
|
2019-07-31 09:46:28 +00:00
|
|
|
return fmt.Errorf(errfmt, "to container bucket not found", perr.Err)
|
|
|
|
}
|
|
|
|
|
|
|
|
if perr.Msg != expMsg {
|
|
|
|
return fmt.Errorf(errfmt, expMsg, perr.Msg)
|
|
|
|
}
|
|
|
|
|
|
|
|
return nil
|
|
|
|
},
|
|
|
|
},
|
2019-01-11 20:09:31 +00:00
|
|
|
{
|
|
|
|
name: "FindTaskByID missing auth",
|
|
|
|
auth: &influxdb.Authorization{Permissions: []influxdb.Permission{}},
|
|
|
|
check: func(ctx context.Context, svc influxdb.TaskService) error {
|
|
|
|
_, err := svc.FindTaskByID(ctx, taskID)
|
|
|
|
if err == nil {
|
|
|
|
return errors.New("returned without error without permission")
|
|
|
|
}
|
|
|
|
return nil
|
|
|
|
},
|
|
|
|
},
|
|
|
|
{
|
2019-02-21 18:31:45 +00:00
|
|
|
name: "FindTaskByID with org auth",
|
|
|
|
auth: &influxdb.Authorization{Status: "active", Permissions: orgReadAllTaskPermissions},
|
|
|
|
check: func(ctx context.Context, svc influxdb.TaskService) error {
|
|
|
|
_, err := svc.FindTaskByID(ctx, taskID)
|
|
|
|
return err
|
|
|
|
},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
name: "FindTaskByID with task auth",
|
|
|
|
auth: &influxdb.Authorization{Status: "active", Permissions: orgReadTaskPermissions},
|
2019-01-11 20:09:31 +00:00
|
|
|
check: func(ctx context.Context, svc influxdb.TaskService) error {
|
|
|
|
_, err := svc.FindTaskByID(ctx, taskID)
|
|
|
|
return err
|
|
|
|
},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
name: "FindTasks with bad auth",
|
2019-02-21 18:31:45 +00:00
|
|
|
auth: &influxdb.Authorization{Status: "active", Permissions: wrongOrgReadAllTaskPermissions},
|
2019-01-11 20:09:31 +00:00
|
|
|
check: func(ctx context.Context, svc influxdb.TaskService) error {
|
2019-02-21 18:31:45 +00:00
|
|
|
ts, _, err := svc.FindTasks(ctx, influxdb.TaskFilter{
|
2019-02-27 15:56:32 +00:00
|
|
|
OrganizationID: &orgID,
|
2019-01-11 20:09:31 +00:00
|
|
|
})
|
2019-02-21 18:31:45 +00:00
|
|
|
if err == nil && len(ts) > 0 {
|
2019-01-11 20:09:31 +00:00
|
|
|
return errors.New("returned no error with a invalid auth")
|
|
|
|
}
|
|
|
|
return nil
|
|
|
|
},
|
|
|
|
},
|
|
|
|
{
|
2019-02-21 18:31:45 +00:00
|
|
|
name: "FindTasks with org auth",
|
|
|
|
auth: &influxdb.Authorization{Status: "active", Permissions: orgReadAllTaskPermissions},
|
2019-01-11 20:09:31 +00:00
|
|
|
check: func(ctx context.Context, svc influxdb.TaskService) error {
|
|
|
|
_, _, err := svc.FindTasks(ctx, influxdb.TaskFilter{
|
2019-02-27 15:56:32 +00:00
|
|
|
OrganizationID: &orgID,
|
2019-01-11 20:09:31 +00:00
|
|
|
})
|
|
|
|
return err
|
|
|
|
},
|
|
|
|
},
|
|
|
|
{
|
2019-02-21 18:31:45 +00:00
|
|
|
name: "FindTasks with task auth",
|
|
|
|
auth: &influxdb.Authorization{Status: "active", Permissions: orgReadTaskPermissions},
|
|
|
|
check: func(ctx context.Context, svc influxdb.TaskService) error {
|
|
|
|
_, _, err := svc.FindTasks(ctx, influxdb.TaskFilter{
|
2019-02-27 15:56:32 +00:00
|
|
|
OrganizationID: &orgID,
|
2019-02-21 18:31:45 +00:00
|
|
|
})
|
|
|
|
return err
|
|
|
|
},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
name: "FindTasks without org filter",
|
|
|
|
auth: &influxdb.Authorization{Status: "active", Permissions: orgReadAllTaskPermissions},
|
2019-01-11 20:09:31 +00:00
|
|
|
check: func(ctx context.Context, svc influxdb.TaskService) error {
|
|
|
|
_, _, err := svc.FindTasks(ctx, influxdb.TaskFilter{})
|
|
|
|
return err
|
|
|
|
},
|
|
|
|
},
|
|
|
|
{
|
2019-02-21 18:31:45 +00:00
|
|
|
name: "UpdateTask with readonly auth",
|
|
|
|
auth: &influxdb.Authorization{Status: "active", Permissions: orgReadAllTaskPermissions},
|
2019-01-11 20:09:31 +00:00
|
|
|
check: func(ctx context.Context, svc influxdb.TaskService) error {
|
|
|
|
flux := `option task = {
|
|
|
|
name: "my_task",
|
|
|
|
every: 1s,
|
|
|
|
}
|
|
|
|
from(bucket:"holder") |> range(start:-5m) |> to(bucket:"holder", org:"thing")`
|
2019-02-21 18:31:45 +00:00
|
|
|
_, err := svc.UpdateTask(ctx, taskID, influxdb.TaskUpdate{
|
2019-01-11 20:09:31 +00:00
|
|
|
Flux: &flux,
|
|
|
|
})
|
|
|
|
if err == nil {
|
|
|
|
return errors.New("returned no error with a invalid auth")
|
|
|
|
}
|
|
|
|
return nil
|
|
|
|
},
|
|
|
|
},
|
|
|
|
{
|
2019-02-21 18:31:45 +00:00
|
|
|
name: "UpdateTask with org auth",
|
|
|
|
auth: &influxdb.Authorization{Status: "active", Permissions: orgWriteAllTaskBucketPermissions},
|
|
|
|
check: func(ctx context.Context, svc influxdb.TaskService) error {
|
|
|
|
flux := `option task = {
|
2019-03-08 21:18:11 +00:00
|
|
|
name: "my_task",
|
|
|
|
every: 1s,
|
|
|
|
}
|
|
|
|
from(bucket:"holder") |> range(start:-5m) |> to(bucket:"holder", org:"thing")`
|
2019-02-21 18:31:45 +00:00
|
|
|
_, err := svc.UpdateTask(ctx, taskID, influxdb.TaskUpdate{
|
|
|
|
Flux: &flux,
|
|
|
|
})
|
|
|
|
return err
|
|
|
|
},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
name: "UpdateTask with task auth",
|
|
|
|
auth: &influxdb.Authorization{Status: "active", Permissions: orgWriteTaskBucketPermissions},
|
2019-01-11 20:09:31 +00:00
|
|
|
check: func(ctx context.Context, svc influxdb.TaskService) error {
|
|
|
|
flux := `option task = {
|
|
|
|
name: "my_task",
|
|
|
|
every: 1s,
|
|
|
|
}
|
|
|
|
from(bucket:"holder") |> range(start:-5m) |> to(bucket:"holder", org:"thing")`
|
2019-02-21 18:31:45 +00:00
|
|
|
_, err := svc.UpdateTask(ctx, taskID, influxdb.TaskUpdate{
|
2019-01-11 20:09:31 +00:00
|
|
|
Flux: &flux,
|
|
|
|
})
|
|
|
|
return err
|
|
|
|
},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
name: "UpdateTask with bad bucket",
|
2019-02-21 18:31:45 +00:00
|
|
|
auth: &influxdb.Authorization{Status: "active", Permissions: orgWriteAllTaskPermissions},
|
2019-01-11 20:09:31 +00:00
|
|
|
check: func(ctx context.Context, svc influxdb.TaskService) error {
|
|
|
|
flux := `option task = {
|
|
|
|
name: "my_task",
|
|
|
|
every: 1s,
|
|
|
|
}
|
|
|
|
from(bucket:"cows") |> range(start:-5m) |> to(bucket:"cows", org:"thing")`
|
2019-02-21 18:31:45 +00:00
|
|
|
_, err := svc.UpdateTask(ctx, taskID, influxdb.TaskUpdate{
|
2019-01-11 20:09:31 +00:00
|
|
|
Flux: &flux,
|
|
|
|
})
|
|
|
|
if err == nil {
|
|
|
|
return errors.New("returned no error with unauthorized bucket")
|
|
|
|
}
|
|
|
|
return nil
|
|
|
|
},
|
|
|
|
},
|
2019-07-26 15:37:45 +00:00
|
|
|
{
|
|
|
|
name: "UpdateTask with bad org",
|
|
|
|
auth: &influxdb.Authorization{Status: "active", Permissions: orgWriteAllTaskBucketPermissions},
|
|
|
|
check: func(ctx context.Context, svc influxdb.TaskService) error {
|
|
|
|
var (
|
|
|
|
flux = `option task = {
|
|
|
|
name: "my_task",
|
|
|
|
every: 1s,
|
|
|
|
}
|
|
|
|
from(bucket:"cows") |> range(start:-5m) |> to(bucket:"other_bucket", org:"other_org")`
|
|
|
|
_, err = svc.UpdateTask(ctx, taskID, influxdb.TaskUpdate{
|
|
|
|
Flux: &flux,
|
|
|
|
})
|
|
|
|
)
|
|
|
|
|
|
|
|
perr, ok := err.(*influxdb.Error)
|
|
|
|
if !ok {
|
2019-08-22 02:08:51 +00:00
|
|
|
return fmt.Errorf("expected influxdb.error, got %q of type %T", err, err)
|
2019-07-26 15:37:45 +00:00
|
|
|
}
|
|
|
|
|
2019-07-31 09:46:28 +00:00
|
|
|
if perr.Code != influxdb.EUnauthorized {
|
|
|
|
return fmt.Errorf(`expected "unauthorized", got %q`, perr.Code)
|
2019-07-26 15:37:45 +00:00
|
|
|
}
|
|
|
|
|
2019-07-31 09:46:28 +00:00
|
|
|
if perr.Msg != "Failed to create task." {
|
2019-07-26 15:37:45 +00:00
|
|
|
return fmt.Errorf(`expected "Failed to authorize.", got %q`, perr.Msg)
|
|
|
|
}
|
|
|
|
|
2019-08-22 02:08:51 +00:00
|
|
|
cerr, ok := errors.Cause(perr.Err).(*influxdb.Error)
|
2019-07-26 15:37:45 +00:00
|
|
|
if !ok {
|
2019-08-22 02:08:51 +00:00
|
|
|
return fmt.Errorf("expected influxdb.error, got %q of type %T", perr.Err, perr.Err)
|
2019-07-26 15:37:45 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
if cerr.Code != influxdb.ENotFound {
|
|
|
|
return fmt.Errorf(`expected "not found", got %q`, perr.Code)
|
|
|
|
}
|
|
|
|
|
|
|
|
return nil
|
|
|
|
},
|
|
|
|
},
|
2019-01-11 20:09:31 +00:00
|
|
|
{
|
|
|
|
name: "DeleteTask missing auth",
|
|
|
|
auth: &influxdb.Authorization{Permissions: []influxdb.Permission{}},
|
|
|
|
check: func(ctx context.Context, svc influxdb.TaskService) error {
|
|
|
|
err := svc.DeleteTask(ctx, taskID)
|
|
|
|
if err == nil {
|
|
|
|
return errors.New("returned without error without permission")
|
|
|
|
}
|
|
|
|
return nil
|
|
|
|
},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
name: "DeleteTask readonly auth",
|
2019-02-21 18:31:45 +00:00
|
|
|
auth: &influxdb.Authorization{Permissions: orgReadAllTaskPermissions},
|
2019-01-11 20:09:31 +00:00
|
|
|
check: func(ctx context.Context, svc influxdb.TaskService) error {
|
|
|
|
err := svc.DeleteTask(ctx, taskID)
|
|
|
|
if err == nil {
|
|
|
|
return errors.New("returned without error without permission")
|
|
|
|
}
|
|
|
|
return nil
|
|
|
|
},
|
|
|
|
},
|
|
|
|
{
|
2019-02-21 18:31:45 +00:00
|
|
|
name: "DeleteTask with org auth",
|
|
|
|
auth: &influxdb.Authorization{Status: "active", Permissions: orgWriteAllTaskPermissions},
|
|
|
|
check: func(ctx context.Context, svc influxdb.TaskService) error {
|
|
|
|
err := svc.DeleteTask(ctx, taskID)
|
|
|
|
return err
|
|
|
|
},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
name: "DeleteTask with task auth",
|
|
|
|
auth: &influxdb.Authorization{Status: "active", Permissions: orgWriteTaskPermissions},
|
2019-01-11 20:09:31 +00:00
|
|
|
check: func(ctx context.Context, svc influxdb.TaskService) error {
|
|
|
|
err := svc.DeleteTask(ctx, taskID)
|
|
|
|
return err
|
|
|
|
},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
name: "FindLogs with bad auth",
|
2019-02-21 18:31:45 +00:00
|
|
|
auth: &influxdb.Authorization{Status: "active", Permissions: wrongOrgReadAllTaskPermissions},
|
2019-01-11 20:09:31 +00:00
|
|
|
check: func(ctx context.Context, svc influxdb.TaskService) error {
|
|
|
|
_, _, err := svc.FindLogs(ctx, influxdb.LogFilter{
|
2019-02-16 00:04:54 +00:00
|
|
|
Task: taskID,
|
2019-01-11 20:09:31 +00:00
|
|
|
})
|
|
|
|
if err == nil {
|
|
|
|
return errors.New("returned no error with a invalid auth")
|
|
|
|
}
|
|
|
|
return nil
|
|
|
|
},
|
|
|
|
},
|
|
|
|
{
|
2019-02-21 18:31:45 +00:00
|
|
|
name: "FindLogs with org auth",
|
|
|
|
auth: &influxdb.Authorization{Status: "active", Permissions: orgReadAllTaskPermissions},
|
|
|
|
check: func(ctx context.Context, svc influxdb.TaskService) error {
|
|
|
|
_, _, err := svc.FindLogs(ctx, influxdb.LogFilter{
|
|
|
|
Task: taskID,
|
|
|
|
})
|
|
|
|
return err
|
|
|
|
},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
name: "FindLogs with task auth",
|
|
|
|
auth: &influxdb.Authorization{Status: "active", Permissions: orgReadTaskPermissions},
|
2019-01-11 20:09:31 +00:00
|
|
|
check: func(ctx context.Context, svc influxdb.TaskService) error {
|
|
|
|
_, _, err := svc.FindLogs(ctx, influxdb.LogFilter{
|
2019-02-16 00:04:54 +00:00
|
|
|
Task: taskID,
|
2019-01-11 20:09:31 +00:00
|
|
|
})
|
|
|
|
return err
|
|
|
|
},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
name: "FindRuns with bad auth",
|
2019-02-21 18:31:45 +00:00
|
|
|
auth: &influxdb.Authorization{Status: "active", Permissions: wrongOrgReadAllTaskPermissions},
|
2019-01-11 20:09:31 +00:00
|
|
|
check: func(ctx context.Context, svc influxdb.TaskService) error {
|
|
|
|
_, _, err := svc.FindRuns(ctx, influxdb.RunFilter{
|
2019-02-16 00:04:54 +00:00
|
|
|
Task: taskID,
|
2019-01-11 20:09:31 +00:00
|
|
|
})
|
|
|
|
if err == nil {
|
|
|
|
return errors.New("returned no error with a invalid auth")
|
|
|
|
}
|
|
|
|
return nil
|
|
|
|
},
|
|
|
|
},
|
|
|
|
{
|
2019-02-21 18:31:45 +00:00
|
|
|
name: "FindRuns with org auth",
|
|
|
|
auth: &influxdb.Authorization{Status: "active", Permissions: orgReadAllTaskPermissions},
|
|
|
|
check: func(ctx context.Context, svc influxdb.TaskService) error {
|
|
|
|
_, _, err := svc.FindRuns(ctx, influxdb.RunFilter{
|
|
|
|
Task: taskID,
|
|
|
|
})
|
|
|
|
return err
|
|
|
|
},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
name: "FindRuns with task auth",
|
|
|
|
auth: &influxdb.Authorization{Status: "active", Permissions: orgReadTaskPermissions},
|
2019-01-11 20:09:31 +00:00
|
|
|
check: func(ctx context.Context, svc influxdb.TaskService) error {
|
|
|
|
_, _, err := svc.FindRuns(ctx, influxdb.RunFilter{
|
2019-02-16 00:04:54 +00:00
|
|
|
Task: taskID,
|
2019-01-11 20:09:31 +00:00
|
|
|
})
|
|
|
|
return err
|
|
|
|
},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
name: "FindRunByID missing auth",
|
|
|
|
auth: &influxdb.Authorization{Permissions: []influxdb.Permission{}},
|
|
|
|
check: func(ctx context.Context, svc influxdb.TaskService) error {
|
|
|
|
_, err := svc.FindRunByID(ctx, taskID, 10)
|
|
|
|
if err == nil {
|
|
|
|
return errors.New("returned without error without permission")
|
|
|
|
}
|
|
|
|
return nil
|
|
|
|
},
|
|
|
|
},
|
|
|
|
{
|
2019-02-21 18:31:45 +00:00
|
|
|
name: "FindRunByID with org auth",
|
|
|
|
auth: &influxdb.Authorization{Status: "active", Permissions: orgReadAllTaskPermissions},
|
|
|
|
check: func(ctx context.Context, svc influxdb.TaskService) error {
|
|
|
|
_, err := svc.FindRunByID(ctx, taskID, 10)
|
|
|
|
return err
|
|
|
|
},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
name: "FindRunByID with task auth",
|
|
|
|
auth: &influxdb.Authorization{Status: "active", Permissions: orgReadTaskPermissions},
|
2019-01-11 20:09:31 +00:00
|
|
|
check: func(ctx context.Context, svc influxdb.TaskService) error {
|
|
|
|
_, err := svc.FindRunByID(ctx, taskID, 10)
|
|
|
|
return err
|
|
|
|
},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
name: "CancelRun with bad auth",
|
2019-02-21 18:31:45 +00:00
|
|
|
auth: &influxdb.Authorization{Status: "active", Permissions: wrongOrgReadAllTaskPermissions},
|
2019-01-11 20:09:31 +00:00
|
|
|
check: func(ctx context.Context, svc influxdb.TaskService) error {
|
2019-02-21 18:31:45 +00:00
|
|
|
err := svc.CancelRun(ctx, taskID, 10)
|
2019-01-11 20:09:31 +00:00
|
|
|
if err == nil {
|
|
|
|
return errors.New("returned no error with a invalid auth")
|
|
|
|
}
|
|
|
|
return nil
|
|
|
|
},
|
|
|
|
},
|
|
|
|
{
|
2019-02-21 18:31:45 +00:00
|
|
|
name: "CancelRun with org auth",
|
|
|
|
auth: &influxdb.Authorization{Status: "active", Permissions: orgWriteAllTaskPermissions},
|
|
|
|
check: func(ctx context.Context, svc influxdb.TaskService) error {
|
|
|
|
err := svc.CancelRun(ctx, taskID, 10)
|
|
|
|
return err
|
|
|
|
},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
name: "CancelRun with task auth",
|
|
|
|
auth: &influxdb.Authorization{Status: "active", Permissions: orgWriteTaskPermissions},
|
2019-01-11 20:09:31 +00:00
|
|
|
check: func(ctx context.Context, svc influxdb.TaskService) error {
|
2019-02-21 18:31:45 +00:00
|
|
|
err := svc.CancelRun(ctx, taskID, 10)
|
2019-01-11 20:09:31 +00:00
|
|
|
return err
|
|
|
|
},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
name: "RetryRun with bad auth",
|
2019-02-21 18:31:45 +00:00
|
|
|
auth: &influxdb.Authorization{Status: "active", Permissions: wrongOrgReadAllTaskPermissions},
|
2019-01-11 20:09:31 +00:00
|
|
|
check: func(ctx context.Context, svc influxdb.TaskService) error {
|
2019-02-21 18:31:45 +00:00
|
|
|
_, err := svc.RetryRun(ctx, taskID, 10)
|
2019-01-11 20:09:31 +00:00
|
|
|
if err == nil {
|
|
|
|
return errors.New("returned no error with a invalid auth")
|
|
|
|
}
|
|
|
|
return nil
|
|
|
|
},
|
|
|
|
},
|
|
|
|
{
|
2019-02-21 18:31:45 +00:00
|
|
|
name: "RetryRun with org auth",
|
|
|
|
auth: &influxdb.Authorization{Status: "active", Permissions: orgWriteAllTaskPermissions},
|
2019-01-11 20:09:31 +00:00
|
|
|
check: func(ctx context.Context, svc influxdb.TaskService) error {
|
2019-02-21 18:31:45 +00:00
|
|
|
_, err := svc.RetryRun(ctx, taskID, 10)
|
|
|
|
return err
|
|
|
|
},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
name: "RetryRun with task auth",
|
|
|
|
auth: &influxdb.Authorization{Status: "active", Permissions: orgWriteTaskPermissions},
|
|
|
|
check: func(ctx context.Context, svc influxdb.TaskService) error {
|
|
|
|
_, err := svc.RetryRun(ctx, taskID, 10)
|
2019-01-11 20:09:31 +00:00
|
|
|
return err
|
|
|
|
},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
name: "ForceRun with bad auth",
|
2019-02-21 18:31:45 +00:00
|
|
|
auth: &influxdb.Authorization{Status: "active", Permissions: wrongOrgReadAllTaskPermissions},
|
2019-01-11 20:09:31 +00:00
|
|
|
check: func(ctx context.Context, svc influxdb.TaskService) error {
|
2019-02-21 18:31:45 +00:00
|
|
|
_, err := svc.ForceRun(ctx, taskID, 10000)
|
2019-01-11 20:09:31 +00:00
|
|
|
if err == nil {
|
|
|
|
return errors.New("returned no error with a invalid auth")
|
|
|
|
}
|
|
|
|
return nil
|
|
|
|
},
|
|
|
|
},
|
|
|
|
{
|
2019-02-21 18:31:45 +00:00
|
|
|
name: "ForceRun with org auth",
|
|
|
|
auth: &influxdb.Authorization{Status: "active", Permissions: orgWriteAllTaskPermissions},
|
|
|
|
check: func(ctx context.Context, svc influxdb.TaskService) error {
|
|
|
|
_, err := svc.ForceRun(ctx, taskID, 10000)
|
|
|
|
return err
|
|
|
|
},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
name: "ForceRun with task auth",
|
|
|
|
auth: &influxdb.Authorization{Status: "active", Permissions: orgWriteTaskPermissions},
|
2019-01-11 20:09:31 +00:00
|
|
|
check: func(ctx context.Context, svc influxdb.TaskService) error {
|
2019-02-21 18:31:45 +00:00
|
|
|
_, err := svc.ForceRun(ctx, taskID, 10000)
|
2019-01-11 20:09:31 +00:00
|
|
|
return err
|
|
|
|
},
|
|
|
|
},
|
|
|
|
}
|
|
|
|
|
|
|
|
for _, test := range tests {
|
|
|
|
t.Run(test.name, func(t *testing.T) {
|
|
|
|
ctx := pctx.SetAuthorizer(context.Background(), test.auth)
|
|
|
|
if err := test.check(ctx, validTaskService); err != nil {
|
|
|
|
if aerr, ok := err.(http.AuthzError); ok {
|
|
|
|
t.Error(aerr.AuthzError())
|
|
|
|
}
|
|
|
|
t.Error(err)
|
|
|
|
}
|
|
|
|
})
|
|
|
|
}
|
|
|
|
}
|