3 # Copyright (C) 2015 Ipsilon project Contributors, for license see COPYING
5 from helpers.common import IpsilonTestBase # pylint: disable=relative-import
6 from helpers.http import HttpSessions # pylint: disable=relative-import
10 from string import Template
12 # Test Attribute Mapping and Allowed Attributes and their per-SP
16 idp_g = {'TEMPLATES': '${TESTDIR}/templates/install',
17 'CONFDIR': '${TESTDIR}/etc',
18 'DATADIR': '${TESTDIR}/lib',
19 'CACHEDIR': '${TESTDIR}/cache',
20 'HTTPDCONFD': '${TESTDIR}/${NAME}/conf.d',
21 'STATICDIR': '${ROOTDIR}',
22 'BINDIR': '${ROOTDIR}/ipsilon',
23 'WSGI_SOCKET_PREFIX': '${TESTDIR}/${NAME}/logs/wsgi'}
26 idp_a = {'hostname': '${ADDRESS}:${PORT}',
27 'admin_user': '${TEST_USER}',
28 'system_user': '${TEST_USER}',
29 'instance': '${NAME}',
35 'server_debugging': 'True'}
38 sp_g = {'HTTPDCONFD': '${TESTDIR}/${NAME}/conf.d',
39 'SAML2_TEMPLATE': '${TESTDIR}/templates/install/saml2/sp.conf',
40 'SAML2_CONFFILE': '${TESTDIR}/${NAME}/conf.d/ipsilon-saml.conf',
41 'SAML2_HTTPDIR': '${TESTDIR}/${NAME}/saml2'}
44 sp_a = {'hostname': '${ADDRESS}:${PORT}',
45 'saml_idp_metadata': 'http://127.0.0.10:45080/idp1/saml2/metadata',
46 'saml_secure_setup': 'False',
48 'saml_nameid': '${NAMEID}',
49 'httpd_user': '${TEST_USER}'}
52 {'name': 'sp1', 'addr': '127.0.0.11', 'port': '45081'},
56 def convert_to_dict(envlist):
58 for pair in envlist.split('\n'):
59 if pair.find('=') > 0:
60 (key, value) = pair.split('=', 1)
61 if key.startswith('MELLON_') and not key.endswith('_0'):
66 def check_info_plugin(s, idp_name, urlbase, expected):
68 Logout, login, fetch SP page to get the info variables and
69 compare the MELLON_ ones to what we expect. IDP and NAMEID are
74 page = s.fetch_page(idp_name, '%s/%s?%s' % (
75 urlbase, 'saml2/logout',
76 'ReturnTo=%s/open/logged_out.html' % urlbase))
77 page.expected_value('text()', 'Logged out')
79 # Fetch the page (with implicit login)
80 page = s.fetch_page(idp_name, '%s/sp/' % spurl)
82 # Confirm that the expected values are in the output and that there
83 # are no unexpected MELLON_ vars, and drop the _0 version.
84 data = convert_to_dict(page.text)
86 data.pop('MELLON_IDP')
87 data.pop('MELLON_NAME_ID')
90 item = data.pop('MELLON_' + key)
91 if item != expected[key]:
92 raise ValueError('Expected %s, got %s' % (expected[key], item))
95 raise ValueError('Unexpected values %s' % data)
98 def fixup_sp_httpd(httpdir):
101 AddOutputFilter INCLUDES .html
103 Alias /sp ${HTTPDIR}/sp
105 <Directory ${HTTPDIR}/sp>
110 Alias /open ${HTTPDIR}/open
112 <Directory ${HTTPDIR}/open>
119 logged_out = """Logged out"""
121 t = Template(location)
122 text = t.substitute({'HTTPDIR': httpdir})
123 with open(httpdir + '/conf.d/ipsilon-saml.conf', 'a') as f:
126 os.mkdir(httpdir + '/sp')
127 with open(httpdir + '/sp/index.html', 'w') as f:
129 os.mkdir(httpdir + '/open')
130 with open(httpdir + '/open/logged_out.html', 'w') as f:
134 class IpsilonTest(IpsilonTestBase):
137 super(IpsilonTest, self).__init__('testmapping', __file__)
139 def setup_servers(self, env=None):
140 print "Installing IDP server"
144 idp = self.generate_profile(idp_g, idp_a, name, addr, port)
145 conf = self.setup_idp_server(idp, name, addr, port, env)
147 print "Starting IDP's httpd server"
148 self.start_http_server(conf, env)
150 for spdata in sp_list:
151 addr = spdata['addr']
152 port = spdata['port']
153 name = spdata['name']
155 print "Installing SP server %s" % name
156 sp_prof = self.generate_profile(sp_g, sp_a, name, addr, str(port))
157 conf = self.setup_sp_server(sp_prof, name, addr, str(port), env)
158 fixup_sp_httpd(os.path.dirname(conf))
160 print "Starting SP's httpd server"
161 self.start_http_server(conf, env)
164 if __name__ == '__main__':
167 user = pwd.getpwuid(os.getuid())[0]
169 spurl = 'http://%s:%s' % (sp['addr'], sp['port'])
171 # Set global mapping and allowed attributes, then test fetch from
173 sess = HttpSessions()
174 sess.add_server(idpname, 'http://127.0.0.10:45080', user, 'ipsilon')
175 sess.add_server(sp['name'], spurl)
177 print "testmapping: Authenticate to IDP ...",
179 sess.auth_to_idp(idpname)
180 except Exception, e: # pylint: disable=broad-except
181 print >> sys.stderr, " ERROR: %s" % repr(e)
185 print "testmapping: Add SP Metadata to IDP ...",
187 sess.add_sp_metadata(idpname, sp['name'])
188 except Exception, e: # pylint: disable=broad-except
189 print >> sys.stderr, " ERROR: %s" % repr(e)
194 print "testmapping: Test default mapping and attrs ...",
196 'fullname': 'Test User %s' % user,
198 'givenname': 'Test User',
199 'email': '%s@example.com' % user,
202 check_info_plugin(sess, idpname, spurl, expect)
203 except Exception, e: # pylint: disable=broad-except
204 print >> sys.stderr, " ERROR: %s" % repr(e)
208 print "testmapping: Set default global mapping ...",
210 sess.set_attributes_and_mapping(idpname,
212 ['fullname', 'namefull']])
213 except Exception, e: # pylint: disable=broad-except
214 print >> sys.stderr, " ERROR: %s" % repr(e)
220 print "testmapping: Test global mapping ...",
222 'fullname': 'Test User %s' % user,
223 'namefull': 'Test User %s' % user,
225 'givenname': 'Test User',
226 'email': '%s@example.com' % user,
229 check_info_plugin(sess, idpname, spurl, expect)
230 except Exception, e: # pylint: disable=broad-except
231 print >> sys.stderr, " ERROR: %s" % repr(e)
236 print "testmapping: Set default allowed attributes ...",
238 sess.set_attributes_and_mapping(idpname, [],
239 ['namefull', 'givenname', 'surname'])
240 except Exception, e: # pylint: disable=broad-except
241 print >> sys.stderr, " ERROR: %s" % repr(e)
247 print "testmapping: Test global allowed attributes ...",
249 'namefull': 'Test User %s' % user,
251 'givenname': 'Test User',
253 check_info_plugin(sess, idpname, spurl, expect)
254 except Exception, e: # pylint: disable=broad-except
255 print >> sys.stderr, " ERROR: %s" % repr(e)
260 print "testmapping: Set SP allowed attributes ...",
262 sess.set_attributes_and_mapping(idpname, [['*', '*']],
263 ['wholename', 'givenname', 'surname',
264 'email', 'fullname'], sp['name'])
265 except Exception, e: # pylint: disable=broad-except
266 print >> sys.stderr, " ERROR: %s" % repr(e)
272 print "testmapping: Test SP allowed atributes ...",
274 'fullname': 'Test User %s' % user,
276 'givenname': 'Test User',
277 'email': '%s@example.com' % user,
279 check_info_plugin(sess, idpname, spurl, expect)
280 except Exception, e: # pylint: disable=broad-except
281 print >> sys.stderr, " ERROR: %s" % repr(e)
286 print "testmapping: Set SP attribute mapping ...",
288 sess.set_attributes_and_mapping(idpname,
290 ['fullname', 'wholename']],
291 ['wholename', 'givenname',
293 'email', 'fullname'],
295 except Exception, e: # pylint: disable=broad-except
296 print >> sys.stderr, " ERROR: %s" % repr(e)
302 print "testmapping: Test SP attribute mapping ...",
304 'wholename': 'Test User %s' % user,
305 'fullname': 'Test User %s' % user,
307 'givenname': 'Test User',
308 'email': '%s@example.com' % user,
310 check_info_plugin(sess, idpname, spurl, expect)
311 except Exception, e: # pylint: disable=broad-except
312 print >> sys.stderr, " ERROR: %s" % repr(e)
317 print "testmapping: Drop SP attribute mapping ...",
319 sess.set_attributes_and_mapping(idpname, [],
320 ['givenname', 'surname', 'email',
321 'fullname'], sp['name'])
322 except Exception, e: # pylint: disable=broad-except
323 print >> sys.stderr, " ERROR: %s" % repr(e)
329 print "testmapping: Test SP attr mapping with default allowed...",
331 'fullname': 'Test User %s' % user,
333 'givenname': 'Test User',
334 'email': '%s@example.com' % user,
336 check_info_plugin(sess, idpname, spurl, expect)
337 except Exception, e: # pylint: disable=broad-except
338 print >> sys.stderr, " ERROR: %s" % repr(e)
343 print "testmapping: Drop SP allowed attributes ...",
345 sess.set_attributes_and_mapping(idpname, [], [], sp['name'])
346 except Exception, e: # pylint: disable=broad-except
347 print >> sys.stderr, " ERROR: %s" % repr(e)
353 print "testmapping: Test mapping, should be back to global...",
355 'namefull': 'Test User %s' % user,
357 'givenname': 'Test User',
359 check_info_plugin(sess, idpname, spurl, expect)
360 except Exception, e: # pylint: disable=broad-except
361 print >> sys.stderr, " ERROR: %s" % repr(e)