1
0
mirror of https://github.com/kakwa/ldapcherry synced 2024-11-11 12:08:51 +01:00
ldapcherry/tests/test_BackendLdap.py

250 lines
8.7 KiB
Python
Raw Normal View History

2015-05-21 08:33:56 +02:00
#!/usr/bin/env python
# -*- coding: utf-8 -*-
from __future__ import with_statement
from __future__ import unicode_literals
import pytest
import sys
from ldapcherry.backend.backendLdap import Backend, CaFileDontExist
2015-07-05 22:48:24 +02:00
from ldapcherry.exceptions import *
from disable import travis_disabled
2015-05-21 08:33:56 +02:00
import cherrypy
import logging
import ldap
2019-02-07 20:55:50 +01:00
if sys.version < '3':
from sets import Set as set
2015-05-21 08:33:56 +02:00
cfg = {
2015-05-25 18:52:14 +02:00
'module' : 'ldapcherry.backend.ldap',
2015-05-27 21:56:55 +02:00
'groupdn' : 'ou=groups,dc=example,dc=org',
2015-05-25 18:52:14 +02:00
'userdn' : 'ou=People,dc=example,dc=org',
'binddn' : 'cn=dnscherry,dc=example,dc=org',
'password' : 'password',
2015-06-17 20:51:21 +02:00
'uri' : 'ldap://ldap.dnscherry.org:390',
'ca' : './tests/test_env/etc/ldapcherry/TEST-cacert.pem',
2015-05-25 18:52:14 +02:00
'starttls' : 'off',
'checkcert' : 'off',
'user_filter_tmpl' : '(uid=%(username)s)',
'group_filter_tmpl' : '(member=%(userdn)s)',
'search_filter_tmpl' : '(|(uid=%(searchstring)s*)(sn=%(searchstring)s*))',
'objectclasses' : 'top, person, organizationalPerson, simpleSecurityObject, posixAccount',
'dn_user_attr' : 'uid',
2015-06-17 00:39:03 +02:00
'group_attr.member' : "%(dn)s",
2015-06-17 20:30:26 +02:00
'timeout' : 10,
'display_name' : 'My Test Ldap',
2015-05-21 08:33:56 +02:00
}
def syslog_error(msg='', context='',
severity=logging.INFO, traceback=False):
pass
cherrypy.log.error = syslog_error
attr = ['shéll', 'shell', 'cn', 'uid', 'uidNumber', 'gidNumber', 'home', 'userPassword', 'givenName', 'email', 'sn']
2015-05-21 08:33:56 +02:00
class TestError(object):
def testNominal(self):
2015-05-31 18:40:35 +02:00
inv = Backend(cfg, cherrypy.log, 'ldap', attr, 'uid')
2015-05-21 08:33:56 +02:00
return True
2015-06-17 22:20:21 +02:00
def testConnectSSLNoCheck(self):
cfg2 = cfg.copy()
cfg2['uri'] = 'ldaps://ldap.ldapcherry.org:637'
cfg2['checkcert'] = 'off'
inv = Backend(cfg2, cherrypy.log, 'ldap', attr, 'uid')
ldap = inv._connect()
ldap.simple_bind_s(inv.binddn, inv.bindpassword)
2015-06-17 00:06:30 +02:00
2015-05-21 08:33:56 +02:00
def testConnect(self):
2015-05-31 18:40:35 +02:00
inv = Backend(cfg, cherrypy.log, 'ldap', attr, 'uid')
ldap = inv._connect()
ldap.simple_bind_s(inv.binddn, inv.bindpassword)
2015-05-21 08:33:56 +02:00
return True
def testConnectSSL(self):
cfg2 = cfg.copy()
cfg2['uri'] = 'ldaps://ldap.dnscherry.org:637'
cfg2['checkcert'] = 'on'
2015-05-31 18:40:35 +02:00
inv = Backend(cfg2, cherrypy.log, 'ldap', attr, 'uid')
ldap = inv._connect()
ldap.simple_bind_s(inv.binddn, inv.bindpassword)
2015-05-21 08:33:56 +02:00
def testLdapUnavaible(self):
cfg2 = cfg.copy()
cfg2['uri'] = 'ldaps://notaldap:637'
cfg2['checkcert'] = 'on'
2015-05-31 18:40:35 +02:00
inv = Backend(cfg2, cherrypy.log, 'ldap', attr, 'uid')
try:
ldapc = inv._connect()
ldapc.simple_bind_s(inv.binddn, inv.bindpassword)
except ldap.SERVER_DOWN as e:
2015-07-05 22:48:24 +02:00
return
else:
raise AssertionError("expected an exception")
def testMissingCA(self):
cfg2 = cfg.copy()
cfg2['uri'] = 'ldaps://ldap.dnscherry.org:637'
cfg2['checkcert'] = 'on'
cfg2['ca'] = './test/cfg/not_a_ca.crt'
try:
inv = Backend(cfg2, cherrypy.log, 'ldap', attr, 'uid')
ldapc = inv._connect()
except CaFileDontExist as e:
return
else:
raise AssertionError("expected an exception")
def testConnectSSLWrongCA(self):
cfg2 = cfg.copy()
cfg2['uri'] = 'ldaps://ldap.ldapcherry.org:637'
cfg2['checkcert'] = 'on'
2015-05-31 18:40:35 +02:00
inv = Backend(cfg2, cherrypy.log, 'ldap', attr, 'uid')
ldapc = inv._connect()
try:
ldapc.simple_bind_s(inv.binddn, inv.bindpassword)
except ldap.SERVER_DOWN as e:
assert e.args[0]['info'] == 'TLS: hostname does not match CN in peer certificate' or \
e.args[0]['info'] == '(unknown error code)'
else:
raise AssertionError("expected an exception")
2015-06-17 22:51:33 +02:00
def testConnectStartTLS(self):
cfg2 = cfg.copy()
cfg2['uri'] = 'ldap://ldap.ldapcherry.org:390'
cfg2['checkcert'] = 'off'
cfg2['starttls'] = 'on'
cfg2['ca'] = './test/cfg/ca.crt'
inv = Backend(cfg2, cherrypy.log, 'ldap', attr, 'uid')
ldapc = inv._connect()
ldapc.simple_bind_s(inv.binddn, inv.bindpassword)
2015-06-17 22:51:33 +02:00
2015-05-21 08:33:56 +02:00
def testAuthSuccess(self):
2015-05-31 18:40:35 +02:00
inv = Backend(cfg, cherrypy.log, 'ldap', attr, 'uid')
ret = inv.auth(u'jwatsoné', u'passwordwatsoné')
2015-05-22 01:33:15 +02:00
assert ret == True
2015-05-21 08:33:56 +02:00
def testAuthFailure(self):
2015-05-31 18:40:35 +02:00
inv = Backend(cfg, cherrypy.log, 'ldap', attr, 'uid')
res = inv.auth('notauser', 'password') or inv.auth(u'jwatsoné', 'notapasswordé')
2015-05-22 01:33:15 +02:00
assert res == False
2015-05-21 08:33:56 +02:00
def testGetUser(self):
2015-05-31 18:40:35 +02:00
inv = Backend(cfg, cherrypy.log, 'ldap', attr, 'uid')
ret = inv.get_user(u'jwatsoné')
expected = {'uid': u'jwatsoné', 'cn': 'John Watson', 'sn': 'watson'}
assert ret == expected
2015-06-17 00:39:03 +02:00
def testGetGroups(self):
2015-05-31 18:40:35 +02:00
inv = Backend(cfg, cherrypy.log, 'ldap', attr, 'uid')
ret = inv.get_groups(u'jwatsoné')
2015-05-27 21:56:55 +02:00
expected = ['cn=itpeople,ou=Groups,dc=example,dc=org']
assert ret == expected
2015-06-17 00:39:03 +02:00
def testAddDeleteGroups(self):
inv = Backend(cfg, cherrypy.log, 'ldap', attr, 'uid')
groups = [
'cn=hrpeople,ou=Groups,dc=example,dc=org',
'cn=itpeople,ou=Groups,dc=example,dc=org',
]
inv.add_to_groups(u'jwatsoné', groups)
ret = inv.get_groups(u'jwatsoné')
inv.del_from_groups(u'jwatsoné', ['cn=hrpeople,ou=Groups,dc=example,dc=org'])
inv.del_from_groups(u'jwatsoné', ['cn=hrpeople,ou=Groups,dc=example,dc=org'])
2015-06-17 00:39:03 +02:00
assert ret == ['cn=itpeople,ou=Groups,dc=example,dc=org', 'cn=hrpeople,ou=Groups,dc=example,dc=org']
def testSearchUser(self):
2015-05-31 18:40:35 +02:00
inv = Backend(cfg, cherrypy.log, 'ldap', attr, 'uid')
ret = inv.search('smith')
2015-07-05 22:48:24 +02:00
expected = {'ssmith': {'sn': 'smith', 'uid': 'ssmith', 'cn': 'Sheri Smith', 'userPassword': 'passwordsmith'}, 'jsmith': {'sn': 'Smith', 'uid': 'jsmith', 'cn': 'John Smith', 'userPassword': 'passwordsmith'}}
assert ret == expected
def testAddUser(self):
try:
inv.del_user(u'test☭,cn=')
except:
pass
2015-05-31 18:40:35 +02:00
inv = Backend(cfg, cherrypy.log, 'ldap', attr, 'uid')
user = {
'uid': u'test☭,cn=',
2016-07-28 19:53:32 +02:00
'sn': u'test☭',
'cn': u'test☭',
'userPassword': u'test☭',
'uidNumber': '42',
'gidNumber': '42',
'homeDirectory': '/home/test/'
}
inv.add_user(user)
inv.del_user(u'test☭,cn=')
2015-06-16 21:32:14 +02:00
def testModifyUser(self):
inv = Backend(cfg, cherrypy.log, 'ldap', attr, 'uid')
user = {
'uid': u'test☭',
2016-07-28 19:53:32 +02:00
'sn': u'test☭',
'cn': u'test☭',
'userPassword': u'test☭',
2015-06-16 21:32:14 +02:00
'uidNumber': '42',
'gidNumber': '42',
'homeDirectory': '/home/test/'
}
inv.add_user(user)
inv.set_attrs(u'test☭', {'gecos': 'test2', 'homeDirectory': '/home/test/'})
inv.del_user(u'test☭')
2015-06-16 21:32:14 +02:00
def testAddUserDuplicate(self):
2015-05-31 18:40:35 +02:00
inv = Backend(cfg, cherrypy.log, 'ldap', attr, 'uid')
user = {
2016-07-28 19:53:32 +02:00
'uid': u'test☭',
'sn': u'test☭',
'cn': u'test☭',
'uidNumber': '42',
2016-07-28 19:53:32 +02:00
'userPassword': u'test☭',
'gidNumber': '42',
'homeDirectory': '/home/test/'
}
try:
inv.add_user(user)
inv.add_user(user)
except UserAlreadyExists:
2016-07-28 19:53:32 +02:00
inv.del_user(u'test☭')
return
else:
2016-07-28 19:53:32 +02:00
inv.del_user(u'test☭')
raise AssertionError("expected an exception")
def testDelUserDontExists(self):
2015-05-31 18:40:35 +02:00
inv = Backend(cfg, cherrypy.log, 'ldap', attr, 'uid')
try:
2016-07-28 19:53:32 +02:00
inv.del_user(u'test☭')
inv.del_user(u'test☭')
except UserDoesntExist:
return
else:
raise AssertionError("expected an exception")
2015-05-28 09:56:25 +02:00
def testGetUser(self):
2015-05-31 18:40:35 +02:00
inv = Backend(cfg, cherrypy.log, 'ldap', attr, 'uid')
ret = inv.get_user(u'jwatsoné')
expected = {'uid': u'jwatsoné', 'objectClass': 'inetOrgPerson', 'carLicense': 'HERCAR 125', 'sn': 'watson', 'mail': 'j.watson@example.com', 'homePhone': '555-111-2225', 'cn': 'John Watson', 'userPassword': u'passwordwatsoné'}
2015-05-28 09:56:25 +02:00
assert ret == expected
2015-05-31 18:40:35 +02:00
def testAddUserMissingMustattribute(self):
inv = Backend(cfg, cherrypy.log, 'ldap', attr, 'uid')
user = {
2016-07-28 19:53:32 +02:00
'uid': u'test☭',
'sn': u'test☭',
'cn': u'test☭',
'userPassword': u'test☭',
'gidNumber': '42',
'homeDirectory': '/home/test/'
}
try:
inv.add_user(user)
except ldap.OBJECT_CLASS_VIOLATION:
return
else:
2016-07-28 19:53:32 +02:00
inv.del_user(u'test☭')
raise AssertionError("expected an exception")