middleware_test.py 4.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158
  1. #!/usr/bin/env python
  2. # Licensed to Cloudera, Inc. under one
  3. # or more contributor license agreements. See the NOTICE file
  4. # distributed with this work for additional information
  5. # regarding copyright ownership. Cloudera, Inc. licenses this file
  6. # to you under the Apache License, Version 2.0 (the
  7. # "License"); you may not use this file except in compliance
  8. # with the License. You may obtain a copy of the License at
  9. #
  10. # http://www.apache.org/licenses/LICENSE-2.0
  11. #
  12. # Unless required by applicable law or agreed to in writing, software
  13. # distributed under the License is distributed on an "AS IS" BASIS,
  14. # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  15. # See the License for the specific language governing permissions and
  16. # limitations under the License.
  17. import json
  18. import os
  19. import tempfile
  20. from django.conf import settings
  21. from nose.tools import assert_equal, assert_false, assert_true
  22. from nose.plugins.skip import SkipTest
  23. import desktop.conf
  24. from desktop.conf import AUDIT_EVENT_LOG_DIR
  25. from desktop.lib.django_test_util import make_logged_in_client
  26. from desktop.lib.test_utils import add_permission
  27. def test_view_perms():
  28. # Super user
  29. c = make_logged_in_client()
  30. response = c.get("/useradmin/")
  31. assert_equal(200, response.status_code)
  32. response = c.get("/useradmin/users/edit/test")
  33. assert_equal(200, response.status_code)
  34. # Normal user
  35. c = make_logged_in_client('user', is_superuser=False)
  36. add_permission('user', 'test-view-group', 'access_view:useradmin:edit_user', 'useradmin')
  37. response = c.get("/useradmin/")
  38. assert_equal(401, response.status_code)
  39. response = c.get("/useradmin/users/edit/test")
  40. assert_equal(401, response.status_code)
  41. response = c.get("/useradmin/users/edit/user") # Can access his profile page
  42. assert_equal(200, response.status_code, response.content)
  43. def test_ensure_safe_method_middleware():
  44. try:
  45. # Super user
  46. c = make_logged_in_client()
  47. # GET works
  48. response = c.get("/useradmin/")
  49. assert_equal(200, response.status_code)
  50. # Disallow GET
  51. done = desktop.conf.HTTP_ALLOWED_METHODS.set_for_testing([])
  52. # GET should not work because allowed methods is empty.
  53. response = c.get("/useradmin/")
  54. assert_equal(405, response.status_code)
  55. finally:
  56. done()
  57. def test_audit_logging_middleware_enable():
  58. c = make_logged_in_client(username='test_audit_logging', is_superuser=False)
  59. # Make sure we enable it with a file path
  60. with tempfile.NamedTemporaryFile("w+t") as log_tmp:
  61. log_path = log_tmp.name
  62. reset = AUDIT_EVENT_LOG_DIR.set_for_testing(log_path)
  63. settings.MIDDLEWARE_CLASSES.append('desktop.middleware.AuditLoggingMiddleware') # Re-add middleware
  64. try:
  65. # Check if we audit correctly
  66. response = c.get("/useradmin/permissions/edit/beeswax/access")
  67. assert_true('audited' in response, response)
  68. audit = open(log_path).readlines()
  69. for line in audit:
  70. audit_json = json.loads(line)
  71. audit_record = list(audit_json.values())[0]
  72. assert_equal('test_audit_logging', audit_record['user'], audit_record)
  73. assert_equal('/useradmin/permissions/edit/beeswax/access', audit_record['url'], audit_record)
  74. finally:
  75. settings.MIDDLEWARE_CLASSES.pop()
  76. reset()
  77. def test_audit_logging_middleware_disable():
  78. c = make_logged_in_client(username='test_audit_logging', is_superuser=False)
  79. reset = AUDIT_EVENT_LOG_DIR.set_for_testing('')
  80. try:
  81. # No middleware yet
  82. response = c.get("/oozie/")
  83. assert_false('audited' in response, response)
  84. finally:
  85. reset()
  86. def test_ensure_safe_redirect_middleware():
  87. raise SkipTest
  88. done = []
  89. settings.MIDDLEWARE_CLASSES.append('desktop.middleware.EnsureSafeRedirectURLMiddleware')
  90. try:
  91. # Super user
  92. c = make_logged_in_client()
  93. # POST works
  94. response = c.post("/hue/accounts/login/", {
  95. 'username': 'test',
  96. 'password': 'test',
  97. })
  98. assert_equal(302, response.status_code)
  99. # Disallow most redirects
  100. done.append(desktop.conf.REDIRECT_WHITELIST.set_for_testing('^\d+$'))
  101. response = c.post("/hue/accounts/login/", {
  102. 'username': 'test',
  103. 'password': 'test',
  104. 'next': 'http://example.com',
  105. })
  106. assert_equal(403, response.status_code)
  107. # Allow all redirects
  108. done.append(desktop.conf.REDIRECT_WHITELIST.set_for_testing('.*'))
  109. response = c.post("/hue/accounts/login/", {
  110. 'username': 'test',
  111. 'password': 'test',
  112. 'next': 'http://example.com',
  113. })
  114. assert_equal(302, response.status_code)
  115. # Allow all redirects and disallow most at the same time.
  116. # should have a logic OR functionality.
  117. done.append(desktop.conf.REDIRECT_WHITELIST.set_for_testing('\d+,.*'))
  118. response = c.post("", {
  119. 'username': 'test',
  120. 'password': 'test',
  121. 'next': 'http://example.com',
  122. })
  123. assert_equal(302, response.status_code)
  124. finally:
  125. settings.MIDDLEWARE_CLASSES.pop()
  126. for finish in done:
  127. finish()