3 # Copyright (C) 2015 Ipsilon project Contributors, for license see COPYING
5 from helpers.common import IpsilonTestBase # pylint: disable=relative-import
6 from helpers.http import HttpSessions # pylint: disable=relative-import
10 from string import Template
12 # Test Attribute Mapping and Allowed Attributes and their per-SP
16 idp_g = {'TEMPLATES': '${TESTDIR}/templates/install',
17 'CONFDIR': '${TESTDIR}/etc',
18 'DATADIR': '${TESTDIR}/lib',
19 'HTTPDCONFD': '${TESTDIR}/${NAME}/conf.d',
20 'STATICDIR': '${ROOTDIR}',
21 'BINDIR': '${ROOTDIR}/ipsilon',
22 'WSGI_SOCKET_PREFIX': '${TESTDIR}/${NAME}/logs/wsgi'}
25 idp_a = {'hostname': '${ADDRESS}:${PORT}',
26 'admin_user': '${TEST_USER}',
27 'system_user': '${TEST_USER}',
28 'instance': '${NAME}',
34 'server_debugging': 'True'}
37 sp_g = {'HTTPDCONFD': '${TESTDIR}/${NAME}/conf.d',
38 'SAML2_TEMPLATE': '${TESTDIR}/templates/install/saml2/sp.conf',
39 'SAML2_CONFFILE': '${TESTDIR}/${NAME}/conf.d/ipsilon-saml.conf',
40 'SAML2_HTTPDIR': '${TESTDIR}/${NAME}/saml2'}
43 sp_a = {'hostname': '${ADDRESS}:${PORT}',
44 'saml_idp_metadata': 'http://127.0.0.10:45080/idp1/saml2/metadata',
45 'saml_secure_setup': 'False',
47 'saml_nameid': '${NAMEID}',
48 'httpd_user': '${TEST_USER}'}
51 {'name': 'sp1', 'addr': '127.0.0.11', 'port': '45081'},
55 def convert_to_dict(envlist):
57 for pair in envlist.split('\n'):
58 if pair.find('=') > 0:
59 (key, value) = pair.split('=', 1)
60 if key.startswith('MELLON_') and not key.endswith('_0'):
65 def check_info_plugin(s, idp_name, urlbase, expected):
67 Logout, login, fetch SP page to get the info variables and
68 compare the MELLON_ ones to what we expect. IDP and NAMEID are
73 page = s.fetch_page(idp_name, '%s/%s?%s' % (
74 urlbase, 'saml2/logout',
75 'ReturnTo=%s/open/logged_out.html' % urlbase))
76 page.expected_value('text()', 'Logged out')
78 # Fetch the page (with implicit login)
79 page = s.fetch_page(idp_name, '%s/sp/' % spurl)
81 # Confirm that the expected values are in the output and that there
82 # are no unexpected MELLON_ vars, and drop the _0 version.
83 data = convert_to_dict(page.text)
85 data.pop('MELLON_IDP')
86 data.pop('MELLON_NAME_ID')
88 for key in expected.keys():
89 item = data.pop('MELLON_' + key)
90 if item != expected[key]:
91 raise ValueError('Expected %s, got %s' % (expected[key], item))
94 raise ValueError('Unexpected values %s' % data)
97 def fixup_sp_httpd(httpdir):
100 AddOutputFilter INCLUDES .html
102 Alias /sp ${HTTPDIR}/sp
104 <Directory ${HTTPDIR}/sp>
109 Alias /open ${HTTPDIR}/open
111 <Directory ${HTTPDIR}/open>
118 logged_out = """Logged out"""
120 t = Template(location)
121 text = t.substitute({'HTTPDIR': httpdir})
122 with open(httpdir + '/conf.d/ipsilon-saml.conf', 'a') as f:
125 os.mkdir(httpdir + '/sp')
126 with open(httpdir + '/sp/index.html', 'w') as f:
128 os.mkdir(httpdir + '/open')
129 with open(httpdir + '/open/logged_out.html', 'w') as f:
133 class IpsilonTest(IpsilonTestBase):
136 super(IpsilonTest, self).__init__('testmapping', __file__)
138 def setup_servers(self, env=None):
139 print "Installing IDP server"
143 idp = self.generate_profile(idp_g, idp_a, name, addr, port)
144 conf = self.setup_idp_server(idp, name, addr, port, env)
146 print "Starting IDP's httpd server"
147 self.start_http_server(conf, env)
149 for spdata in sp_list:
150 addr = spdata['addr']
151 port = spdata['port']
152 name = spdata['name']
154 print "Installing SP server %s" % name
155 sp_prof = self.generate_profile(sp_g, sp_a, name, addr, str(port))
156 conf = self.setup_sp_server(sp_prof, name, addr, str(port), env)
157 fixup_sp_httpd(os.path.dirname(conf))
159 print "Starting SP's httpd server"
160 self.start_http_server(conf, env)
163 if __name__ == '__main__':
166 user = pwd.getpwuid(os.getuid())[0]
168 spurl = 'http://%s:%s' % (sp['addr'], sp['port'])
170 # Set global mapping and allowed attributes, then test fetch from
172 sess = HttpSessions()
173 sess.add_server(idpname, 'http://127.0.0.10:45080', user, 'ipsilon')
174 sess.add_server(sp['name'], spurl)
176 print "testmapping: Authenticate to IDP ...",
178 sess.auth_to_idp(idpname)
179 except Exception, e: # pylint: disable=broad-except
180 print >> sys.stderr, " ERROR: %s" % repr(e)
184 print "testmapping: Add SP Metadata to IDP ...",
186 sess.add_sp_metadata(idpname, sp['name'])
187 except Exception, e: # pylint: disable=broad-except
188 print >> sys.stderr, " ERROR: %s" % repr(e)
193 print "testmapping: Test default mapping and attrs ...",
195 'fullname': 'Test User %s' % user,
197 'givenname': 'Test User',
198 'email': '%s@example.com' % user,
201 check_info_plugin(sess, idpname, spurl, expect)
202 except Exception, e: # pylint: disable=broad-except
203 print >> sys.stderr, " ERROR: %s" % repr(e)
207 print "testmapping: Set default global mapping ...",
209 sess.set_attributes_and_mapping(idpname,
211 ['fullname', 'namefull']])
212 except Exception, e: # pylint: disable=broad-except
213 print >> sys.stderr, " ERROR: %s" % repr(e)
219 print "testmapping: Test global mapping ...",
221 'fullname': 'Test User %s' % user,
222 'namefull': 'Test User %s' % user,
224 'givenname': 'Test User',
225 'email': '%s@example.com' % user,
228 check_info_plugin(sess, idpname, spurl, expect)
229 except Exception, e: # pylint: disable=broad-except
230 print >> sys.stderr, " ERROR: %s" % repr(e)
235 print "testmapping: Set default allowed attributes ...",
237 sess.set_attributes_and_mapping(idpname, [],
238 ['namefull', 'givenname', 'surname'])
239 except Exception, e: # pylint: disable=broad-except
240 print >> sys.stderr, " ERROR: %s" % repr(e)
246 print "testmapping: Test global allowed attributes ...",
248 'namefull': 'Test User %s' % user,
250 'givenname': 'Test User',
252 check_info_plugin(sess, idpname, spurl, expect)
253 except Exception, e: # pylint: disable=broad-except
254 print >> sys.stderr, " ERROR: %s" % repr(e)
259 print "testmapping: Set SP allowed attributes ...",
261 sess.set_attributes_and_mapping(idpname, [['*', '*']],
262 ['wholename', 'givenname', 'surname',
263 'email', 'fullname'], sp['name'])
264 except Exception, e: # pylint: disable=broad-except
265 print >> sys.stderr, " ERROR: %s" % repr(e)
271 print "testmapping: Test SP allowed atributes ...",
273 'fullname': 'Test User %s' % user,
275 'givenname': 'Test User',
276 'email': '%s@example.com' % user,
278 check_info_plugin(sess, idpname, spurl, expect)
279 except Exception, e: # pylint: disable=broad-except
280 print >> sys.stderr, " ERROR: %s" % repr(e)
285 print "testmapping: Set SP attribute mapping ...",
287 sess.set_attributes_and_mapping(idpname,
289 ['fullname', 'wholename']],
290 ['wholename', 'givenname',
292 'email', 'fullname'],
294 except Exception, e: # pylint: disable=broad-except
295 print >> sys.stderr, " ERROR: %s" % repr(e)
301 print "testmapping: Test SP attribute mapping ...",
303 'wholename': 'Test User %s' % user,
304 'fullname': 'Test User %s' % user,
306 'givenname': 'Test User',
307 'email': '%s@example.com' % user,
309 check_info_plugin(sess, idpname, spurl, expect)
310 except Exception, e: # pylint: disable=broad-except
311 print >> sys.stderr, " ERROR: %s" % repr(e)
316 print "testmapping: Drop SP attribute mapping ...",
318 sess.set_attributes_and_mapping(idpname, [],
319 ['givenname', 'surname', 'email',
320 'fullname'], sp['name'])
321 except Exception, e: # pylint: disable=broad-except
322 print >> sys.stderr, " ERROR: %s" % repr(e)
328 print "testmapping: Test SP attr mapping with default allowed...",
330 'fullname': 'Test User %s' % user,
332 'givenname': 'Test User',
333 'email': '%s@example.com' % user,
335 check_info_plugin(sess, idpname, spurl, expect)
336 except Exception, e: # pylint: disable=broad-except
337 print >> sys.stderr, " ERROR: %s" % repr(e)
342 print "testmapping: Drop SP allowed attributes ...",
344 sess.set_attributes_and_mapping(idpname, [], [], sp['name'])
345 except Exception, e: # pylint: disable=broad-except
346 print >> sys.stderr, " ERROR: %s" % repr(e)
352 print "testmapping: Test mapping, should be back to global...",
354 'namefull': 'Test User %s' % user,
356 'givenname': 'Test User',
358 check_info_plugin(sess, idpname, spurl, expect)
359 except Exception, e: # pylint: disable=broad-except
360 print >> sys.stderr, " ERROR: %s" % repr(e)