* feat(plugins): add security client plugin Signed-off-by: florian <[email protected]> * test(plugins): skip security plugin tests when disabled Signed-off-by: florian <[email protected]> * fix(security): remove non-ASCII character Signed-off-by: florian <[email protected]> * chore(CHANGELOG): added entry for security api support in changelog Signed-off-by: florian <[email protected]> * test(plugins): add asynchronous tests version Signed-off-by: florian <[email protected]> * test: remove some warnings Signed-off-by: florian <[email protected]> * chore(USER_GUIDE): add a security plugin part Signed-off-by: florian <[email protected]> * test(security): Split out security plugin tests in its own file Signed-off-by: florian <[email protected]> * chore: apply reviews Signed-off-by: florian <[email protected]> --------- Signed-off-by: florian <[email protected]>
88 lines
2.9 KiB
Python
88 lines
2.9 KiB
Python
# -*- coding: utf-8 -*-
|
|
# SPDX-License-Identifier: Apache-2.0
|
|
#
|
|
# The OpenSearch Contributors require contributions made to
|
|
# this file be licensed under the Apache-2.0 license or a
|
|
# compatible open source license.
|
|
#
|
|
# Modifications Copyright OpenSearch Contributors. See
|
|
# GitHub history for details.
|
|
|
|
import sys
|
|
import uuid
|
|
|
|
import pytest
|
|
from mock import Mock
|
|
|
|
pytestmark = pytest.mark.asyncio
|
|
|
|
|
|
class TestAsyncSigner:
|
|
def mock_session(self):
|
|
access_key = uuid.uuid4().hex
|
|
secret_key = uuid.uuid4().hex
|
|
token = uuid.uuid4().hex
|
|
dummy_session = Mock()
|
|
dummy_session.access_key = access_key
|
|
dummy_session.secret_key = secret_key
|
|
dummy_session.token = token
|
|
return dummy_session
|
|
|
|
@pytest.mark.skipif(
|
|
sys.version_info < (3, 6), reason="AWSV4SignerAsyncAuth requires python3.6+"
|
|
)
|
|
async def test_aws_signer_async_as_http_auth(self):
|
|
region = "us-west-2"
|
|
|
|
from opensearchpy.helpers.asyncsigner import AWSV4SignerAsyncAuth
|
|
|
|
auth = AWSV4SignerAsyncAuth(self.mock_session(), region)
|
|
headers = auth("GET", "http://localhost", {}, {})
|
|
assert "Authorization" in headers
|
|
assert "X-Amz-Date" in headers
|
|
assert "X-Amz-Security-Token" in headers
|
|
|
|
@pytest.mark.skipif(
|
|
sys.version_info < (3, 6), reason="AWSV4SignerAuth requires python3.6+"
|
|
)
|
|
async def test_aws_signer_async_when_region_is_null(self):
|
|
session = self.mock_session()
|
|
|
|
from opensearchpy.helpers.asyncsigner import AWSV4SignerAsyncAuth
|
|
|
|
with pytest.raises(ValueError) as e:
|
|
AWSV4SignerAsyncAuth(session, None)
|
|
assert str(e.value) == "Region cannot be empty"
|
|
|
|
with pytest.raises(ValueError) as e:
|
|
AWSV4SignerAsyncAuth(session, "")
|
|
assert str(e.value) == "Region cannot be empty"
|
|
|
|
@pytest.mark.skipif(
|
|
sys.version_info < (3, 6), reason="AWSV4SignerAuth requires python3.6+"
|
|
)
|
|
async def test_aws_signer_async_when_credentials_is_null(self):
|
|
region = "us-west-1"
|
|
|
|
from opensearchpy.helpers.asyncsigner import AWSV4SignerAsyncAuth
|
|
|
|
with pytest.raises(ValueError) as e:
|
|
AWSV4SignerAsyncAuth(None, region)
|
|
assert str(e.value) == "Credentials cannot be empty"
|
|
|
|
@pytest.mark.skipif(
|
|
sys.version_info < (3, 6), reason="AWSV4SignerAsyncAuth requires python3.6+"
|
|
)
|
|
async def test_aws_signer_async_when_service_is_specified(self):
|
|
region = "us-west-2"
|
|
service = "aoss"
|
|
|
|
from opensearchpy.helpers.asyncsigner import AWSV4SignerAsyncAuth
|
|
|
|
auth = AWSV4SignerAsyncAuth(self.mock_session(), region, service)
|
|
headers = auth("GET", "http://localhost", {}, {})
|
|
assert "Authorization" in headers
|
|
assert "X-Amz-Date" in headers
|
|
assert "X-Amz-Security-Token" in headers
|
|
assert "X-Amz-Content-SHA256" in headers
|