-
Notifications
You must be signed in to change notification settings - Fork 297
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Enable security for bwc tests #3269
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -7,13 +7,32 @@ | |
*/ | ||
package org.opensearch.security.bwc; | ||
|
||
import java.io.IOException; | ||
import java.util.List; | ||
import java.util.Map; | ||
import java.util.Optional; | ||
import java.util.Set; | ||
import java.util.stream.Collectors; | ||
|
||
import org.apache.hc.client5.http.auth.AuthScope; | ||
import org.apache.hc.client5.http.auth.UsernamePasswordCredentials; | ||
import org.apache.hc.client5.http.impl.auth.BasicCredentialsProvider; | ||
import org.apache.hc.client5.http.impl.nio.PoolingAsyncClientConnectionManagerBuilder; | ||
import org.apache.hc.client5.http.nio.AsyncClientConnectionManager; | ||
import org.apache.hc.client5.http.ssl.ClientTlsStrategyBuilder; | ||
import org.apache.hc.client5.http.ssl.NoopHostnameVerifier; | ||
import org.apache.hc.core5.function.Factory; | ||
import org.apache.hc.core5.http.Header; | ||
import org.apache.hc.core5.http.HttpHost; | ||
import org.apache.hc.core5.http.message.BasicHeader; | ||
import org.apache.hc.core5.http.nio.ssl.TlsStrategy; | ||
import org.apache.hc.core5.reactor.ssl.TlsDetails; | ||
import org.apache.hc.core5.ssl.SSLContextBuilder; | ||
import org.junit.Assume; | ||
import org.junit.Before; | ||
import org.opensearch.common.settings.Settings; | ||
import org.opensearch.common.util.concurrent.ThreadContext; | ||
import org.opensearch.test.rest.OpenSearchRestTestCase; | ||
|
||
import org.opensearch.Version; | ||
import org.opensearch.common.settings.Settings; | ||
|
@@ -22,6 +41,14 @@ | |
import static org.hamcrest.MatcherAssert.assertThat; | ||
import static org.hamcrest.Matchers.hasItem; | ||
|
||
import org.opensearch.client.RestClient; | ||
import org.opensearch.client.RestClientBuilder; | ||
|
||
import org.junit.Assert; | ||
|
||
import javax.net.ssl.SSLContext; | ||
import javax.net.ssl.SSLEngine; | ||
|
||
public class SecurityBackwardsCompatibilityIT extends OpenSearchRestTestCase { | ||
|
||
private ClusterType CLUSTER_TYPE; | ||
|
@@ -35,6 +62,11 @@ private void testSetup() { | |
CLUSTER_NAME = System.getProperty("tests.clustername"); | ||
} | ||
|
||
@Override | ||
protected final boolean preserveClusterUponCompletion() { | ||
return true; | ||
} | ||
|
||
@Override | ||
protected final boolean preserveIndicesUponCompletion() { | ||
return true; | ||
|
@@ -50,6 +82,11 @@ protected boolean preserveTemplatesUponCompletion() { | |
return true; | ||
} | ||
|
||
@Override | ||
protected String getProtocol() { | ||
return "https"; | ||
} | ||
|
||
@Override | ||
protected final Settings restClientSettings() { | ||
return Settings.builder() | ||
|
@@ -61,6 +98,56 @@ protected final Settings restClientSettings() { | |
.build(); | ||
} | ||
|
||
@Override | ||
protected RestClient buildClient(Settings settings, HttpHost[] hosts) throws IOException { | ||
RestClientBuilder builder = RestClient.builder(hosts); | ||
configureHttpsClient(builder, settings); | ||
boolean strictDeprecationMode = settings.getAsBoolean("strictDeprecationMode", true); | ||
builder.setStrictDeprecationMode(strictDeprecationMode); | ||
return builder.build(); | ||
} | ||
|
||
protected static void configureHttpsClient(RestClientBuilder builder, Settings settings) throws IOException { | ||
Map<String, String> headers = ThreadContext.buildDefaultHeaders(settings); | ||
Header[] defaultHeaders = new Header[headers.size()]; | ||
int i = 0; | ||
for (Map.Entry<String, String> entry : headers.entrySet()) { | ||
defaultHeaders[i++] = new BasicHeader(entry.getKey(), entry.getValue()); | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. I can see that within the loop, a new BasicHeader object is created for each entry, using the key as the header name and the value as the header value. This BasicHeader object is then stored in the defaultHeaders array at the index specified by i, which is then incremented. And my question is more like "why we need these basic header for each entry?" There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Apache HttpClient has 2 concrete types of headers: BasicHeader and BufferedHeader. BasicHeader is a Basic implementation of Header which allows a header key and a header value. |
||
} | ||
builder.setDefaultHeaders(defaultHeaders); | ||
builder.setHttpClientConfigCallback(httpClientBuilder -> { | ||
String userName = Optional.ofNullable(System.getProperty("tests.opensearch.username")) | ||
.orElseThrow(() -> new RuntimeException("user name is missing")); | ||
String password = Optional.ofNullable(System.getProperty("tests.opensearch.password")) | ||
.orElseThrow(() -> new RuntimeException("password is missing")); | ||
BasicCredentialsProvider credentialsProvider = new BasicCredentialsProvider(); | ||
credentialsProvider.setCredentials(new AuthScope(null, -1), new UsernamePasswordCredentials(userName, password.toCharArray())); | ||
RyanL1997 marked this conversation as resolved.
Show resolved
Hide resolved
|
||
try { | ||
SSLContext sslContext = SSLContextBuilder.create().loadTrustMaterial(null, (chains, authType) -> true).build(); | ||
|
||
TlsStrategy tlsStrategy = ClientTlsStrategyBuilder.create() | ||
.setSslContext(sslContext) | ||
.setTlsVersions(new String[] { "TLSv1", "TLSv1.1", "TLSv1.2", "SSLv3" }) | ||
.setHostnameVerifier(NoopHostnameVerifier.INSTANCE) | ||
// See please https://issues.apache.org/jira/browse/HTTPCLIENT-2219 | ||
.setTlsDetailsFactory(new Factory<SSLEngine, TlsDetails>() { | ||
@Override | ||
public TlsDetails create(final SSLEngine sslEngine) { | ||
return new TlsDetails(sslEngine.getSession(), sslEngine.getApplicationProtocol()); | ||
} | ||
}) | ||
.build(); | ||
|
||
final AsyncClientConnectionManager cm = PoolingAsyncClientConnectionManagerBuilder.create() | ||
.setTlsStrategy(tlsStrategy) | ||
.build(); | ||
return httpClientBuilder.setDefaultCredentialsProvider(credentialsProvider).setConnectionManager(cm); | ||
} catch (Exception e) { | ||
throw new RuntimeException(e); | ||
} | ||
}); | ||
} | ||
|
||
public void testBasicBackwardsCompatibility() throws Exception { | ||
String round = System.getProperty("tests.rest.bwcsuite_round"); | ||
|
||
|
@@ -73,6 +160,12 @@ public void testBasicBackwardsCompatibility() throws Exception { | |
} | ||
} | ||
|
||
@SuppressWarnings("unchecked") | ||
public void testWhoAmI() throws Exception { | ||
Map<String, Object> responseMap = (Map<String, Object>) getAsMap("_plugins/_security/whoami"); | ||
Assert.assertTrue(responseMap.containsKey("dn")); | ||
} | ||
|
||
private enum ClusterType { | ||
OLD, | ||
MIXED, | ||
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Just for my knowledge what is this boolean for?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Its to bypass this method which throws a
WarningFailureException
when using snapshots. It fails because its trying to json parse a response along with a warning that's printed out around the dot syntax for system index deprecation.