ldap_helpers_test.go 3.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140
  1. package ldap
  2. import (
  3. "testing"
  4. . "github.com/smartystreets/goconvey/convey"
  5. "gopkg.in/ldap.v3"
  6. "github.com/grafana/grafana/pkg/infra/log"
  7. )
  8. func TestLDAPHelpers(t *testing.T) {
  9. Convey("serializeUsers()", t, func() {
  10. Convey("simple case", func() {
  11. server := &Server{
  12. Config: &ServerConfig{
  13. Attr: AttributeMap{
  14. Username: "username",
  15. Name: "name",
  16. MemberOf: "memberof",
  17. Email: "email",
  18. },
  19. SearchBaseDNs: []string{"BaseDNHere"},
  20. },
  21. Connection: &MockConnection{},
  22. log: log.New("test-logger"),
  23. }
  24. entry := ldap.Entry{
  25. DN: "dn", Attributes: []*ldap.EntryAttribute{
  26. {Name: "username", Values: []string{"roelgerrits"}},
  27. {Name: "surname", Values: []string{"Gerrits"}},
  28. {Name: "email", Values: []string{"roel@test.com"}},
  29. {Name: "name", Values: []string{"Roel"}},
  30. {Name: "memberof", Values: []string{"admins"}},
  31. }}
  32. users := &ldap.SearchResult{Entries: []*ldap.Entry{&entry}}
  33. result, err := server.serializeUsers(users)
  34. So(err, ShouldBeNil)
  35. So(result[0].Login, ShouldEqual, "roelgerrits")
  36. So(result[0].Email, ShouldEqual, "roel@test.com")
  37. So(result[0].Groups, ShouldContain, "admins")
  38. })
  39. Convey("without lastname", func() {
  40. server := &Server{
  41. Config: &ServerConfig{
  42. Attr: AttributeMap{
  43. Username: "username",
  44. Name: "name",
  45. MemberOf: "memberof",
  46. Email: "email",
  47. },
  48. SearchBaseDNs: []string{"BaseDNHere"},
  49. },
  50. Connection: &MockConnection{},
  51. log: log.New("test-logger"),
  52. }
  53. entry := ldap.Entry{
  54. DN: "dn", Attributes: []*ldap.EntryAttribute{
  55. {Name: "username", Values: []string{"roelgerrits"}},
  56. {Name: "email", Values: []string{"roel@test.com"}},
  57. {Name: "name", Values: []string{"Roel"}},
  58. {Name: "memberof", Values: []string{"admins"}},
  59. }}
  60. users := &ldap.SearchResult{Entries: []*ldap.Entry{&entry}}
  61. result, err := server.serializeUsers(users)
  62. So(err, ShouldBeNil)
  63. So(result[0].Name, ShouldEqual, "Roel")
  64. })
  65. })
  66. Convey("serverBind()", t, func() {
  67. Convey("Given bind dn and password configured", func() {
  68. connection := &MockConnection{}
  69. var actualUsername, actualPassword string
  70. connection.bindProvider = func(username, password string) error {
  71. actualUsername = username
  72. actualPassword = password
  73. return nil
  74. }
  75. server := &Server{
  76. Connection: connection,
  77. Config: &ServerConfig{
  78. BindDN: "o=users,dc=grafana,dc=org",
  79. BindPassword: "bindpwd",
  80. },
  81. }
  82. err := server.serverBind()
  83. So(err, ShouldBeNil)
  84. So(actualUsername, ShouldEqual, "o=users,dc=grafana,dc=org")
  85. So(actualPassword, ShouldEqual, "bindpwd")
  86. })
  87. Convey("Given bind dn configured", func() {
  88. connection := &MockConnection{}
  89. unauthenticatedBindWasCalled := false
  90. var actualUsername string
  91. connection.unauthenticatedBindProvider = func(username string) error {
  92. unauthenticatedBindWasCalled = true
  93. actualUsername = username
  94. return nil
  95. }
  96. server := &Server{
  97. Connection: connection,
  98. Config: &ServerConfig{
  99. BindDN: "o=users,dc=grafana,dc=org",
  100. },
  101. }
  102. err := server.serverBind()
  103. So(err, ShouldBeNil)
  104. So(unauthenticatedBindWasCalled, ShouldBeTrue)
  105. So(actualUsername, ShouldEqual, "o=users,dc=grafana,dc=org")
  106. })
  107. Convey("Given empty bind dn and password", func() {
  108. connection := &MockConnection{}
  109. unauthenticatedBindWasCalled := false
  110. var actualUsername string
  111. connection.unauthenticatedBindProvider = func(username string) error {
  112. unauthenticatedBindWasCalled = true
  113. actualUsername = username
  114. return nil
  115. }
  116. server := &Server{
  117. Connection: connection,
  118. Config: &ServerConfig{},
  119. }
  120. err := server.serverBind()
  121. So(err, ShouldBeNil)
  122. So(unauthenticatedBindWasCalled, ShouldBeTrue)
  123. So(actualUsername, ShouldBeEmpty)
  124. })
  125. })
  126. }