2026-05-16 01:54:44 +02:00
|
|
|
package main
|
|
|
|
|
|
2026-05-17 05:59:48 +02:00
|
|
|
import (
|
|
|
|
|
"bytes"
|
|
|
|
|
"encoding/json"
|
|
|
|
|
"path/filepath"
|
|
|
|
|
"strings"
|
|
|
|
|
"testing"
|
2026-05-16 01:54:44 +02:00
|
|
|
|
2026-05-17 05:59:48 +02:00
|
|
|
"github.com/netkingdom/flex-auth/pkg/api"
|
|
|
|
|
)
|
|
|
|
|
|
|
|
|
|
func TestRunVersion(t *testing.T) {
|
|
|
|
|
var stdout, stderr bytes.Buffer
|
|
|
|
|
code := run([]string{"version"}, &stdout, &stderr)
|
|
|
|
|
if code != 0 {
|
|
|
|
|
t.Fatalf("code = %d, stderr = %s", code, stderr.String())
|
|
|
|
|
}
|
|
|
|
|
if strings.TrimSpace(stdout.String()) == "" {
|
|
|
|
|
t.Fatal("version output is empty")
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
func TestRunTestPolicy(t *testing.T) {
|
|
|
|
|
var stdout, stderr bytes.Buffer
|
|
|
|
|
code := run([]string{"test-policy", "--file", examplePath("policy_package.md")}, &stdout, &stderr)
|
|
|
|
|
if code != 0 {
|
|
|
|
|
t.Fatalf("code = %d, stderr = %s", code, stderr.String())
|
|
|
|
|
}
|
|
|
|
|
if !strings.Contains(stdout.String(), `"valid": true`) {
|
|
|
|
|
t.Fatalf("stdout = %s; want valid policy result", stdout.String())
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
func TestRunCheck(t *testing.T) {
|
|
|
|
|
var stdout, stderr bytes.Buffer
|
|
|
|
|
code := run([]string{
|
|
|
|
|
"check",
|
|
|
|
|
"--registry", examplePath("registry_snapshot.json"),
|
|
|
|
|
"--policy", examplePath("policy_package.md"),
|
|
|
|
|
"--request", examplePath("check_request.yaml"),
|
|
|
|
|
}, &stdout, &stderr)
|
|
|
|
|
if code != 0 {
|
|
|
|
|
t.Fatalf("code = %d, stderr = %s", code, stderr.String())
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
var decision api.DecisionEnvelope
|
|
|
|
|
if err := json.Unmarshal(stdout.Bytes(), &decision); err != nil {
|
|
|
|
|
t.Fatalf("unmarshal decision: %v\n%s", err, stdout.String())
|
|
|
|
|
}
|
|
|
|
|
if decision.Effect != api.DecisionEffectAllow {
|
|
|
|
|
t.Fatalf("decision.Effect = %q; want allow", decision.Effect)
|
2026-05-16 01:54:44 +02:00
|
|
|
}
|
|
|
|
|
}
|
2026-05-17 05:59:48 +02:00
|
|
|
|
|
|
|
|
func TestRunBatchCheck(t *testing.T) {
|
|
|
|
|
var stdout, stderr bytes.Buffer
|
|
|
|
|
code := run([]string{
|
|
|
|
|
"batch-check",
|
|
|
|
|
"--registry", examplePath("registry_snapshot.json"),
|
|
|
|
|
"--policy", examplePath("policy_package.md"),
|
|
|
|
|
"--request", examplePath("batch_check_request.yaml"),
|
|
|
|
|
}, &stdout, &stderr)
|
|
|
|
|
if code != 0 {
|
|
|
|
|
t.Fatalf("code = %d, stderr = %s", code, stderr.String())
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
var decisions []api.DecisionEnvelope
|
|
|
|
|
if err := json.Unmarshal(stdout.Bytes(), &decisions); err != nil {
|
|
|
|
|
t.Fatalf("unmarshal decisions: %v\n%s", err, stdout.String())
|
|
|
|
|
}
|
|
|
|
|
if len(decisions) != 2 || decisions[0].Effect != api.DecisionEffectAllow || decisions[1].Effect != api.DecisionEffectDeny {
|
|
|
|
|
t.Fatalf("decisions = %+v; want allow then deny", decisions)
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
func TestRunValidateAccessDescriptor(t *testing.T) {
|
|
|
|
|
var stdout, stderr bytes.Buffer
|
|
|
|
|
code := run([]string{"validate", "--kind", "access-descriptor", "--file", examplePath("access_descriptor.yaml")}, &stdout, &stderr)
|
|
|
|
|
if code != 0 {
|
|
|
|
|
t.Fatalf("code = %d, stderr = %s", code, stderr.String())
|
|
|
|
|
}
|
|
|
|
|
if !strings.Contains(stdout.String(), `"status": "valid"`) {
|
|
|
|
|
t.Fatalf("stdout = %s; want valid status", stdout.String())
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
func examplePath(name string) string {
|
|
|
|
|
return filepath.Join("..", "..", "examples", "caring", name)
|
|
|
|
|
}
|