File: ldap_group.t

package info (click to toggle)
rt-authen-externalauth 0.10-4
  • links: PTS
  • area: main
  • in suites: wheezy
  • size: 440 kB
  • sloc: perl: 3,299; sh: 21; makefile: 17
file content (116 lines) | stat: -rw-r--r-- 3,494 bytes parent folder | download
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
use strict;
use warnings;

# This lets us change config during runtime without restarting
BEGIN {
    $ENV{RT_TEST_WEB_HANDLER} = 'inline';
}

use RT::Test tests => undef, testing => 'RT::Authen::ExternalAuth';
use Net::LDAP;
use RT::Authen::ExternalAuth;

eval { require Net::LDAP::Server::Test; 1; } or do {
    plan skip_all => 'Unable to test without Net::Server::LDAP::Test';
};


my $ldap_port = 1024 + int rand(10000) + $$ % 1024;
ok( my $server = Net::LDAP::Server::Test->new( $ldap_port, auto_schema => 1 ),
    "spawned test LDAP server on port $ldap_port" );

my $ldap = Net::LDAP->new("localhost:$ldap_port");
$ldap->bind();

my $users_dn = "ou=users,dc=bestpractical,dc=com";
my $group_dn = "cn=test group,ou=groups,dc=bestpractical,dc=com";

for (1 .. 2) {
    my $uid = "testuser$_";
    my $entry    = {
        cn           => "Test User $_",
        mail         => "$uid\@example.com",
        uid          => $uid,
        objectClass  => 'User',
        userPassword => 'password',
    };
    $ldap->add( "uid=$uid,$users_dn", attr => [%$entry] );
}

$ldap->add(
    $group_dn,
    attr => [
        cn          => "test group",
        memberDN    => [ "uid=testuser1,$users_dn" ],
        memberUid   => [ "testuser2" ],
        objectClass => 'Group',
    ],
);

#RT->Config->Set( Plugins                     => 'RT::Authen::ExternalAuth' );
RT->Config->Set( ExternalAuthPriority        => ['My_LDAP'] );
RT->Config->Set( ExternalInfoPriority        => ['My_LDAP'] );
RT->Config->Set( ExternalServiceUsesSSLorTLS => 0 );
RT->Config->Set( AutoCreateNonExternalUsers  => 0 );
RT->Config->Set( AutoCreate  => undef );
RT->Config->Set(
    ExternalSettings => {
        'My_LDAP' => {
            'type'            => 'ldap',
            'server'          => "127.0.0.1:$ldap_port",
            'base'            => $users_dn,
            'filter'          => '(objectClass=*)',
            'd_filter'        => '()',
            'group'           => $group_dn,
            'group_attr'      => 'memberDN',
            'tls'             => 0,
            'net_ldap_args'   => [ version => 3 ],
            'attr_match_list' => [ 'Name', 'EmailAddress' ],
            'attr_map'        => {
                'Name'         => 'uid',
                'EmailAddress' => 'mail',
            }
        },
    }
);

my ( $baseurl, $m ) = RT::Test->started_ok();

diag "Using DN to match group membership";
diag "test uri login";
{
    ok( !$m->login( 'fakeuser', 'password' ), 'not logged in with fake user' );
    $m->warning_like(qr/FAILED LOGIN for fakeuser/);
    
    ok( !$m->login( 'testuser2', 'password' ), 'not logged in with real user not in group' );
    $m->warning_like(qr/FAILED LOGIN for testuser2/);
    
    ok( $m->login( 'testuser1', 'password' ), 'logged in' );
}

diag "test user creation";
{
    my $testuser = RT::User->new($RT::SystemUser);
    my ($ok,$msg) = $testuser->Load( 'testuser1' );
    ok($ok,$msg);
    is($testuser->EmailAddress,'testuser1@example.com');
}

$m->logout;

diag "Using uid to match group membership";

RT->Config->Get('ExternalSettings')->{My_LDAP}{group_attr} = 'memberUid';
RT->Config->Get('ExternalSettings')->{My_LDAP}{group_attr_value} = 'uid';
diag "test uri login";
{
    ok( !$m->login( 'testuser1', 'password' ), 'not logged in with real user not in group' );
    $m->warning_like(qr/FAILED LOGIN for testuser1/);

    ok( $m->login( 'testuser2', 'password' ), 'logged in' );
}

$ldap->unbind();

undef $m;
done_testing;