From fc710a3d4ff6c13435023e3c1bf3f398a9629574 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Halil=20=C4=B0brahim=20Kalkan?= Date: Sun, 18 Feb 2018 15:31:58 +0300 Subject: [PATCH] Added tests for authorization. --- .../Volo/Abp/AspNetCore/Mvc/AbpController.cs | 6 ++ .../AbpAspNetCoreIntegratedTestBase.cs | 8 +- .../Volo.Abp.AspNetCore.Mvc.Tests.csproj | 1 + .../Mvc/AbpAspNetCoreMvcTestModule.cs | 10 +++ .../Mvc/Authorization/AuthTestController.cs | 37 +++++++++ .../Authorization/AuthTestController_Tests.cs | 77 +++++++++++++++++++ .../FakeAuthenticationMiddleware.cs | 33 ++++++++ .../Mvc/Authorization/FakeUserClaims.cs | 11 +++ 8 files changed, 182 insertions(+), 1 deletion(-) create mode 100644 test/Volo.Abp.AspNetCore.Mvc.Tests/Volo/Abp/AspNetCore/Mvc/Authorization/AuthTestController.cs create mode 100644 test/Volo.Abp.AspNetCore.Mvc.Tests/Volo/Abp/AspNetCore/Mvc/Authorization/AuthTestController_Tests.cs create mode 100644 test/Volo.Abp.AspNetCore.Mvc.Tests/Volo/Abp/AspNetCore/Mvc/Authorization/FakeAuthenticationMiddleware.cs create mode 100644 test/Volo.Abp.AspNetCore.Mvc.Tests/Volo/Abp/AspNetCore/Mvc/Authorization/FakeUserClaims.cs diff --git a/src/Volo.Abp.AspNetCore.Mvc/Volo/Abp/AspNetCore/Mvc/AbpController.cs b/src/Volo.Abp.AspNetCore.Mvc/Volo/Abp/AspNetCore/Mvc/AbpController.cs index 3c0ffe9d2f..2f78ec1c2d 100644 --- a/src/Volo.Abp.AspNetCore.Mvc/Volo/Abp/AspNetCore/Mvc/AbpController.cs +++ b/src/Volo.Abp.AspNetCore.Mvc/Volo/Abp/AspNetCore/Mvc/AbpController.cs @@ -3,7 +3,9 @@ using Microsoft.AspNetCore.Mvc; using Microsoft.Extensions.Logging; using Microsoft.Extensions.Logging.Abstractions; using Volo.Abp.Guids; +using Volo.Abp.MultiTenancy; using Volo.Abp.ObjectMapping; +using Volo.Abp.Session; using Volo.Abp.Uow; namespace Volo.Abp.AspNetCore.Mvc @@ -18,6 +20,10 @@ namespace Volo.Abp.AspNetCore.Mvc public ILoggerFactory LoggerFactory { get; set; } + public ICurrentUser CurrentUser { get; set; } + + public ICurrentTenant CurrentTenant { get; set; } + protected IUnitOfWork CurrentUnitOfWork => UnitOfWorkManager?.Current; protected ILogger Logger => _lazyLogger.Value; diff --git a/src/Volo.Abp.AspNetCore.TestBase/Volo/Abp/AspNetCore/TestBase/AbpAspNetCoreIntegratedTestBase.cs b/src/Volo.Abp.AspNetCore.TestBase/Volo/Abp/AspNetCore/TestBase/AbpAspNetCoreIntegratedTestBase.cs index efdcf0eeb9..04995503b7 100644 --- a/src/Volo.Abp.AspNetCore.TestBase/Volo/Abp/AspNetCore/TestBase/AbpAspNetCoreIntegratedTestBase.cs +++ b/src/Volo.Abp.AspNetCore.TestBase/Volo/Abp/AspNetCore/TestBase/AbpAspNetCoreIntegratedTestBase.cs @@ -32,7 +32,13 @@ namespace Volo.Abp.AspNetCore.TestBase protected virtual IWebHostBuilder CreateWebHostBuilder() { return new WebHostBuilder() - .UseStartup(); + .UseStartup() + .ConfigureServices(ConfigureServices); + } + + protected virtual void ConfigureServices(WebHostBuilderContext context, IServiceCollection services) + { + } protected virtual TestServer CreateTestServer(IWebHostBuilder builder) diff --git a/test/Volo.Abp.AspNetCore.Mvc.Tests/Volo.Abp.AspNetCore.Mvc.Tests.csproj b/test/Volo.Abp.AspNetCore.Mvc.Tests/Volo.Abp.AspNetCore.Mvc.Tests.csproj index 64f8bc934b..d0d292dd49 100644 --- a/test/Volo.Abp.AspNetCore.Mvc.Tests/Volo.Abp.AspNetCore.Mvc.Tests.csproj +++ b/test/Volo.Abp.AspNetCore.Mvc.Tests/Volo.Abp.AspNetCore.Mvc.Tests.csproj @@ -18,6 +18,7 @@ + diff --git a/test/Volo.Abp.AspNetCore.Mvc.Tests/Volo/Abp/AspNetCore/Mvc/AbpAspNetCoreMvcTestModule.cs b/test/Volo.Abp.AspNetCore.Mvc.Tests/Volo/Abp/AspNetCore/Mvc/AbpAspNetCoreMvcTestModule.cs index 5a58e47fb2..98b9310302 100644 --- a/test/Volo.Abp.AspNetCore.Mvc.Tests/Volo/Abp/AspNetCore/Mvc/AbpAspNetCoreMvcTestModule.cs +++ b/test/Volo.Abp.AspNetCore.Mvc.Tests/Volo/Abp/AspNetCore/Mvc/AbpAspNetCoreMvcTestModule.cs @@ -2,6 +2,7 @@ using Microsoft.AspNetCore.Builder; using Microsoft.Extensions.DependencyInjection; using Volo.Abp.AspNetCore.Modularity; +using Volo.Abp.AspNetCore.Mvc.Authorization; using Volo.Abp.AspNetCore.TestBase; using Volo.Abp.Autofac; using Volo.Abp.MemoryDb; @@ -30,6 +31,14 @@ namespace Volo.Abp.AspNetCore.Mvc { services.AddLocalization(); //TODO: Move to the framework..? + services.AddAuthorization(options => + { + options.AddPolicy("MyClaimTestPolicy", policy => + { + policy.RequireClaim("MyCustomClaimType", "42"); + }); + }); + services.Configure(options => { options.ConventionalControllers.Create(typeof(TestAppModule).Assembly, opts => @@ -48,6 +57,7 @@ namespace Volo.Abp.AspNetCore.Mvc { var app = context.GetApplicationBuilder(); + app.UseMiddleware(); app.UseUnitOfWork(); app.UseMvcWithDefaultRoute(); } diff --git a/test/Volo.Abp.AspNetCore.Mvc.Tests/Volo/Abp/AspNetCore/Mvc/Authorization/AuthTestController.cs b/test/Volo.Abp.AspNetCore.Mvc.Tests/Volo/Abp/AspNetCore/Mvc/Authorization/AuthTestController.cs new file mode 100644 index 0000000000..7fada1efd8 --- /dev/null +++ b/test/Volo.Abp.AspNetCore.Mvc.Tests/Volo/Abp/AspNetCore/Mvc/Authorization/AuthTestController.cs @@ -0,0 +1,37 @@ +using System; +using Microsoft.AspNetCore.Authorization; +using Microsoft.AspNetCore.Mvc; +using Shouldly; + +namespace Volo.Abp.AspNetCore.Mvc.Authorization +{ + [Authorize] + public class AuthTestController : AbpController + { + public static Guid FakeUserId { get; } = new Guid(); + + [AllowAnonymous] + public ActionResult AnonymousTest() + { + return Content("OK"); + } + + public ActionResult SimpleAuthorizationTest() + { + CurrentUser.Id.ShouldBe(FakeUserId); + return Content("OK"); + } + + [Authorize("MyClaimTestPolicy")] + public ActionResult CustomPolicyTest() + { + return Content("OK"); + } + + //[Authorize("TestPermission")] + //public ActionResult PermissionTest() + //{ + // return Content("OK"); + //} + } +} diff --git a/test/Volo.Abp.AspNetCore.Mvc.Tests/Volo/Abp/AspNetCore/Mvc/Authorization/AuthTestController_Tests.cs b/test/Volo.Abp.AspNetCore.Mvc.Tests/Volo/Abp/AspNetCore/Mvc/Authorization/AuthTestController_Tests.cs new file mode 100644 index 0000000000..b33b8e8149 --- /dev/null +++ b/test/Volo.Abp.AspNetCore.Mvc.Tests/Volo/Abp/AspNetCore/Mvc/Authorization/AuthTestController_Tests.cs @@ -0,0 +1,77 @@ +using System; +using System.Security.Claims; +using System.Threading.Tasks; +using Shouldly; +using Volo.Abp.AspNetCore.TestBase; +using Volo.Abp.Autofac; +using Volo.Abp.MemoryDb; +using Volo.Abp.Modularity; +using Volo.Abp.Security.Claims; +using Volo.Abp.Session; +using Xunit; + +namespace Volo.Abp.AspNetCore.Mvc.Authorization +{ + [DependsOn( + typeof(AbpAspNetCoreTestBaseModule), + typeof(AbpMemoryDbTestModule), + typeof(AbpAspNetCoreMvcModule), + typeof(AbpAutofacModule) + )] + public class AuthTestController_Tests : AspNetCoreMvcTestBase + { + private readonly FakeUserClaims _fakeRequiredService; + + public AuthTestController_Tests() + { + _fakeRequiredService = GetRequiredService(); + } + + [Fact] + public async Task Should_Call_Anonymous_Method_Without_Authentication() + { + var result = await GetResponseAsStringAsync("/AuthTest/AnonymousTest"); + result.ShouldBe("OK"); + } + + [Fact] + public async Task Should_Call_Simple_Authorized_Method_With_Authenticated_User() + { + _fakeRequiredService.Claims.AddRange(new[] + { + new Claim(AbpClaimTypes.UserId, AuthTestController.FakeUserId.ToString()) + }); + + var result = await GetResponseAsStringAsync("/AuthTest/SimpleAuthorizationTest"); + result.ShouldBe("OK"); + } + + [Fact] + public async Task Custom_Claim_Policy_Should_Work_With_Right_Claim_Provided() + { + _fakeRequiredService.Claims.AddRange(new[] + { + new Claim(AbpClaimTypes.UserId, AuthTestController.FakeUserId.ToString()), + new Claim("MyCustomClaimType", "42") + }); + + var result = await GetResponseAsStringAsync("/AuthTest/CustomPolicyTest"); + result.ShouldBe("OK"); + } + + [Fact] + public async Task Custom_Claim_Policy_Should_Not_Work_With_Wrong_Claim_Value() + { + _fakeRequiredService.Claims.AddRange(new[] + { + new Claim(AbpClaimTypes.UserId, AuthTestController.FakeUserId.ToString()), + new Claim("MyCustomClaimType", "43") + }); + + //TODO: We can get a real exception if we properly configure authentication schemas for this project + await Assert.ThrowsAsync(async () => + await GetResponseAsStringAsync("/AuthTest/CustomPolicyTest") + ); + } + } +} diff --git a/test/Volo.Abp.AspNetCore.Mvc.Tests/Volo/Abp/AspNetCore/Mvc/Authorization/FakeAuthenticationMiddleware.cs b/test/Volo.Abp.AspNetCore.Mvc.Tests/Volo/Abp/AspNetCore/Mvc/Authorization/FakeAuthenticationMiddleware.cs new file mode 100644 index 0000000000..6f9aef0520 --- /dev/null +++ b/test/Volo.Abp.AspNetCore.Mvc.Tests/Volo/Abp/AspNetCore/Mvc/Authorization/FakeAuthenticationMiddleware.cs @@ -0,0 +1,33 @@ +using System.Collections.Generic; +using System.Linq; +using System.Security.Claims; +using System.Threading.Tasks; +using Microsoft.AspNetCore.Http; + +namespace Volo.Abp.AspNetCore.Mvc.Authorization +{ + public class FakeAuthenticationMiddleware + { + private readonly RequestDelegate _next; + private readonly FakeUserClaims _fakeUserClaims; + + public FakeAuthenticationMiddleware(RequestDelegate next, FakeUserClaims fakeUserClaims) + { + _next = next; + _fakeUserClaims = fakeUserClaims; + } + + public async Task Invoke(HttpContext httpContext) + { + if (_fakeUserClaims.Claims.Any()) + { + httpContext.User = new ClaimsPrincipal(new List + { + new ClaimsIdentity(_fakeUserClaims.Claims, "FakeSchema") + }); + } + + await _next(httpContext); + } + } +} \ No newline at end of file diff --git a/test/Volo.Abp.AspNetCore.Mvc.Tests/Volo/Abp/AspNetCore/Mvc/Authorization/FakeUserClaims.cs b/test/Volo.Abp.AspNetCore.Mvc.Tests/Volo/Abp/AspNetCore/Mvc/Authorization/FakeUserClaims.cs new file mode 100644 index 0000000000..2c78ee6fb6 --- /dev/null +++ b/test/Volo.Abp.AspNetCore.Mvc.Tests/Volo/Abp/AspNetCore/Mvc/Authorization/FakeUserClaims.cs @@ -0,0 +1,11 @@ +using System.Collections.Generic; +using System.Security.Claims; +using Volo.Abp.DependencyInjection; + +namespace Volo.Abp.AspNetCore.Mvc.Authorization +{ + public class FakeUserClaims : ISingletonDependency + { + public List Claims { get; } = new List(); + } +} \ No newline at end of file