-
Notifications
You must be signed in to change notification settings - Fork 25.2k
Add realm information for Authenticate API #35648
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from 14 commits
Commits
Show all changes
15 commits
Select commit
Hold shift + click to select a range
1490fb9
Add the authenticating and lookup realm in the response of the authen…
jkakavas 8933bfa
Address feedback 1/2
jkakavas f8e0ff5
Version-guard response
jkakavas 5caaf04
will implement AbstractHlrcStreamableXContentTestCase in a follow-up PR
jkakavas 639234e
Address feedback
jkakavas ff17838
Update documentation for HLRC
jkakavas acf6755
fix rest-api doc tests
jkakavas f9f4cfa
Handle null Authentication gracefully
jkakavas 2f9c00a
Fix failing tests
jkakavas 5e7c81b
Merge remote-tracking branch 'origin/master' into realm-in-authentica…
jkakavas 81c9316
fix version guarding
jkakavas 0ba865a
Merge remote-tracking branch 'origin/master' into realm-in-authentica…
jkakavas 269197f
Encapsulate realm name,type in RealmInfo
jkakavas 928ecd1
adjust api-docs-tests
jkakavas 24a0fe1
fix AD realm type name
jkakavas File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -70,7 +70,14 @@ protected AuthenticateResponse createTestInstance() { | |
final String fullName = randomFrom(random(), null, randomAlphaOfLengthBetween(0, 4)); | ||
final String email = randomFrom(random(), null, randomAlphaOfLengthBetween(0, 4)); | ||
final boolean enabled = randomBoolean(); | ||
return new AuthenticateResponse(new User(username, roles, metadata, fullName, email), enabled); | ||
final String authenticationRealmName = randomAlphaOfLength(5); | ||
final String authenticationRealmType = randomFrom("file", "native", "ldap", "ad", "saml", "kerberos"); | ||
final String lookupRealmName = randomAlphaOfLength(5); | ||
final String lookupRealmType = randomFrom("file", "native", "ldap", "ad", "saml", "kerberos"); | ||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. It's totally insignificant, but the actual AD realm type is |
||
return new AuthenticateResponse( | ||
new User(username, roles, metadata, fullName, email), enabled, | ||
new AuthenticateResponse.RealmInfo(authenticationRealmName, authenticationRealmType), | ||
new AuthenticateResponse.RealmInfo(lookupRealmName, lookupRealmType)); | ||
} | ||
|
||
private void toXContent(AuthenticateResponse response, XContentBuilder builder) throws IOException { | ||
|
@@ -87,41 +94,64 @@ private void toXContent(AuthenticateResponse response, XContentBuilder builder) | |
builder.field(AuthenticateResponse.EMAIL.getPreferredName(), user.getEmail()); | ||
} | ||
builder.field(AuthenticateResponse.ENABLED.getPreferredName(), enabled); | ||
builder.startObject(AuthenticateResponse.AUTHENTICATION_REALM.getPreferredName()); | ||
builder.field(AuthenticateResponse.REALM_NAME.getPreferredName(), response.getAuthenticationRealm().getName()); | ||
builder.field(AuthenticateResponse.REALM_TYPE.getPreferredName(), response.getAuthenticationRealm().getType()); | ||
builder.endObject(); | ||
builder.startObject(AuthenticateResponse.LOOKUP_REALM.getPreferredName()); | ||
builder.field(AuthenticateResponse.REALM_NAME.getPreferredName(), response.getLookupRealm().getName()); | ||
builder.field(AuthenticateResponse.REALM_TYPE.getPreferredName(), response.getLookupRealm().getType()); | ||
builder.endObject(); | ||
builder.endObject(); | ||
} | ||
|
||
private AuthenticateResponse copy(AuthenticateResponse response) { | ||
final User originalUser = response.getUser(); | ||
final User copyUser = new User(originalUser.getUsername(), originalUser.getRoles(), originalUser.getMetadata(), | ||
originalUser.getFullName(), originalUser.getEmail()); | ||
return new AuthenticateResponse(copyUser, response.enabled()); | ||
return new AuthenticateResponse(copyUser, response.enabled(), response.getAuthenticationRealm(), | ||
response.getLookupRealm()); | ||
} | ||
|
||
private AuthenticateResponse mutate(AuthenticateResponse response) { | ||
final User originalUser = response.getUser(); | ||
switch (randomIntBetween(1, 6)) { | ||
switch (randomIntBetween(1, 8)) { | ||
case 1: | ||
return new AuthenticateResponse(new User(originalUser.getUsername() + "wrong", originalUser.getRoles(), | ||
originalUser.getMetadata(), originalUser.getFullName(), originalUser.getEmail()), response.enabled()); | ||
originalUser.getMetadata(), originalUser.getFullName(), originalUser.getEmail()), response.enabled(), | ||
response.getAuthenticationRealm(), response.getLookupRealm()); | ||
case 2: | ||
final Collection<String> wrongRoles = new ArrayList<>(originalUser.getRoles()); | ||
wrongRoles.add(randomAlphaOfLengthBetween(1, 4)); | ||
return new AuthenticateResponse(new User(originalUser.getUsername(), wrongRoles, originalUser.getMetadata(), | ||
originalUser.getFullName(), originalUser.getEmail()), response.enabled()); | ||
originalUser.getFullName(), originalUser.getEmail()), response.enabled(), response.getAuthenticationRealm(), | ||
response.getLookupRealm()); | ||
case 3: | ||
final Map<String, Object> wrongMetadata = new HashMap<>(originalUser.getMetadata()); | ||
wrongMetadata.put("wrong_string", randomAlphaOfLengthBetween(0, 4)); | ||
return new AuthenticateResponse(new User(originalUser.getUsername(), originalUser.getRoles(), wrongMetadata, | ||
originalUser.getFullName(), originalUser.getEmail()), response.enabled()); | ||
originalUser.getFullName(), originalUser.getEmail()), response.enabled(), response.getAuthenticationRealm(), | ||
response.getLookupRealm()); | ||
case 4: | ||
return new AuthenticateResponse(new User(originalUser.getUsername(), originalUser.getRoles(), originalUser.getMetadata(), | ||
originalUser.getFullName() + "wrong", originalUser.getEmail()), response.enabled()); | ||
originalUser.getFullName() + "wrong", originalUser.getEmail()), response.enabled(), | ||
response.getAuthenticationRealm(), response.getLookupRealm()); | ||
case 5: | ||
return new AuthenticateResponse(new User(originalUser.getUsername(), originalUser.getRoles(), originalUser.getMetadata(), | ||
originalUser.getFullName(), originalUser.getEmail() + "wrong"), response.enabled()); | ||
originalUser.getFullName(), originalUser.getEmail() + "wrong"), response.enabled(), | ||
response.getAuthenticationRealm(), response.getLookupRealm()); | ||
case 6: | ||
return new AuthenticateResponse(new User(originalUser.getUsername(), originalUser.getRoles(), originalUser.getMetadata(), | ||
originalUser.getFullName(), originalUser.getEmail()), !response.enabled()); | ||
originalUser.getFullName(), originalUser.getEmail()), !response.enabled(), response.getAuthenticationRealm(), | ||
response.getLookupRealm()); | ||
case 7: | ||
return new AuthenticateResponse(new User(originalUser.getUsername(), originalUser.getRoles(), originalUser.getMetadata(), | ||
originalUser.getFullName(), originalUser.getEmail()), response.enabled(), response.getAuthenticationRealm(), | ||
new AuthenticateResponse.RealmInfo(randomAlphaOfLength(5), randomAlphaOfLength(5))); | ||
case 8: | ||
return new AuthenticateResponse(new User(originalUser.getUsername(), originalUser.getRoles(), originalUser.getMetadata(), | ||
originalUser.getFullName(), originalUser.getEmail()), response.enabled(), | ||
new AuthenticateResponse.RealmInfo(randomAlphaOfLength(5), randomAlphaOfLength(5)), response.getLookupRealm()); | ||
} | ||
throw new IllegalStateException("Bad random number"); | ||
} | ||
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.