ldap_helpers_test.go 5.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205
  1. package ldap
  2. import (
  3. "testing"
  4. . "github.com/smartystreets/goconvey/convey"
  5. "gopkg.in/ldap.v3"
  6. "github.com/grafana/grafana/pkg/infra/log"
  7. )
  8. func TestLDAPHelpers(t *testing.T) {
  9. Convey("serializeUsers()", t, func() {
  10. Convey("simple case", func() {
  11. server := &Server{
  12. config: &ServerConfig{
  13. Attr: AttributeMap{
  14. Username: "username",
  15. Name: "name",
  16. MemberOf: "memberof",
  17. Email: "email",
  18. },
  19. SearchBaseDNs: []string{"BaseDNHere"},
  20. },
  21. connection: &mockConnection{},
  22. log: log.New("test-logger"),
  23. }
  24. entry := ldap.Entry{
  25. DN: "dn", Attributes: []*ldap.EntryAttribute{
  26. {Name: "username", Values: []string{"roelgerrits"}},
  27. {Name: "surname", Values: []string{"Gerrits"}},
  28. {Name: "email", Values: []string{"roel@test.com"}},
  29. {Name: "name", Values: []string{"Roel"}},
  30. {Name: "memberof", Values: []string{"admins"}},
  31. }}
  32. users := &ldap.SearchResult{Entries: []*ldap.Entry{&entry}}
  33. result, err := server.serializeUsers(users)
  34. So(err, ShouldBeNil)
  35. So(result[0].Login, ShouldEqual, "roelgerrits")
  36. So(result[0].Email, ShouldEqual, "roel@test.com")
  37. So(result[0].Groups, ShouldContain, "admins")
  38. })
  39. Convey("without lastname", func() {
  40. server := &Server{
  41. config: &ServerConfig{
  42. Attr: AttributeMap{
  43. Username: "username",
  44. Name: "name",
  45. MemberOf: "memberof",
  46. Email: "email",
  47. },
  48. SearchBaseDNs: []string{"BaseDNHere"},
  49. },
  50. connection: &mockConnection{},
  51. log: log.New("test-logger"),
  52. }
  53. entry := ldap.Entry{
  54. DN: "dn", Attributes: []*ldap.EntryAttribute{
  55. {Name: "username", Values: []string{"roelgerrits"}},
  56. {Name: "email", Values: []string{"roel@test.com"}},
  57. {Name: "name", Values: []string{"Roel"}},
  58. {Name: "memberof", Values: []string{"admins"}},
  59. }}
  60. users := &ldap.SearchResult{Entries: []*ldap.Entry{&entry}}
  61. result, err := server.serializeUsers(users)
  62. So(err, ShouldBeNil)
  63. So(result[0].Name, ShouldEqual, "Roel")
  64. })
  65. })
  66. Convey("initialBind", t, func() {
  67. Convey("Given bind dn and password configured", func() {
  68. connection := &mockConnection{}
  69. var actualUsername, actualPassword string
  70. connection.bindProvider = func(username, password string) error {
  71. actualUsername = username
  72. actualPassword = password
  73. return nil
  74. }
  75. server := &Server{
  76. connection: connection,
  77. config: &ServerConfig{
  78. BindDN: "cn=%s,o=users,dc=grafana,dc=org",
  79. BindPassword: "bindpwd",
  80. },
  81. }
  82. err := server.initialBind("user", "pwd")
  83. So(err, ShouldBeNil)
  84. So(server.requireSecondBind, ShouldBeTrue)
  85. So(actualUsername, ShouldEqual, "cn=user,o=users,dc=grafana,dc=org")
  86. So(actualPassword, ShouldEqual, "bindpwd")
  87. })
  88. Convey("Given bind dn configured", func() {
  89. connection := &mockConnection{}
  90. var actualUsername, actualPassword string
  91. connection.bindProvider = func(username, password string) error {
  92. actualUsername = username
  93. actualPassword = password
  94. return nil
  95. }
  96. server := &Server{
  97. connection: connection,
  98. config: &ServerConfig{
  99. BindDN: "cn=%s,o=users,dc=grafana,dc=org",
  100. },
  101. }
  102. err := server.initialBind("user", "pwd")
  103. So(err, ShouldBeNil)
  104. So(server.requireSecondBind, ShouldBeFalse)
  105. So(actualUsername, ShouldEqual, "cn=user,o=users,dc=grafana,dc=org")
  106. So(actualPassword, ShouldEqual, "pwd")
  107. })
  108. Convey("Given empty bind dn and password", func() {
  109. connection := &mockConnection{}
  110. unauthenticatedBindWasCalled := false
  111. var actualUsername string
  112. connection.unauthenticatedBindProvider = func(username string) error {
  113. unauthenticatedBindWasCalled = true
  114. actualUsername = username
  115. return nil
  116. }
  117. server := &Server{
  118. connection: connection,
  119. config: &ServerConfig{},
  120. }
  121. err := server.initialBind("user", "pwd")
  122. So(err, ShouldBeNil)
  123. So(server.requireSecondBind, ShouldBeTrue)
  124. So(unauthenticatedBindWasCalled, ShouldBeTrue)
  125. So(actualUsername, ShouldBeEmpty)
  126. })
  127. })
  128. Convey("serverBind()", t, func() {
  129. Convey("Given bind dn and password configured", func() {
  130. connection := &mockConnection{}
  131. var actualUsername, actualPassword string
  132. connection.bindProvider = func(username, password string) error {
  133. actualUsername = username
  134. actualPassword = password
  135. return nil
  136. }
  137. server := &Server{
  138. connection: connection,
  139. config: &ServerConfig{
  140. BindDN: "o=users,dc=grafana,dc=org",
  141. BindPassword: "bindpwd",
  142. },
  143. }
  144. err := server.serverBind()
  145. So(err, ShouldBeNil)
  146. So(actualUsername, ShouldEqual, "o=users,dc=grafana,dc=org")
  147. So(actualPassword, ShouldEqual, "bindpwd")
  148. })
  149. Convey("Given bind dn configured", func() {
  150. connection := &mockConnection{}
  151. unauthenticatedBindWasCalled := false
  152. var actualUsername string
  153. connection.unauthenticatedBindProvider = func(username string) error {
  154. unauthenticatedBindWasCalled = true
  155. actualUsername = username
  156. return nil
  157. }
  158. server := &Server{
  159. connection: connection,
  160. config: &ServerConfig{
  161. BindDN: "o=users,dc=grafana,dc=org",
  162. },
  163. }
  164. err := server.serverBind()
  165. So(err, ShouldBeNil)
  166. So(unauthenticatedBindWasCalled, ShouldBeTrue)
  167. So(actualUsername, ShouldEqual, "o=users,dc=grafana,dc=org")
  168. })
  169. Convey("Given empty bind dn and password", func() {
  170. connection := &mockConnection{}
  171. unauthenticatedBindWasCalled := false
  172. var actualUsername string
  173. connection.unauthenticatedBindProvider = func(username string) error {
  174. unauthenticatedBindWasCalled = true
  175. actualUsername = username
  176. return nil
  177. }
  178. server := &Server{
  179. connection: connection,
  180. config: &ServerConfig{},
  181. }
  182. err := server.serverBind()
  183. So(err, ShouldBeNil)
  184. So(unauthenticatedBindWasCalled, ShouldBeTrue)
  185. So(actualUsername, ShouldBeEmpty)
  186. })
  187. })
  188. }