2020-06-16 13:12:40 -07:00
|
|
|
using System;
|
2019-12-22 15:54:46 -07:00
|
|
|
using System.Collections.Generic;
|
2020-06-16 13:12:40 -07:00
|
|
|
using System.Globalization;
|
|
|
|
using System.Net;
|
2019-12-22 15:54:46 -07:00
|
|
|
using System.Security.Claims;
|
|
|
|
using System.Threading.Tasks;
|
2020-06-16 13:12:40 -07:00
|
|
|
using AutoFixture;
|
|
|
|
using AutoFixture.AutoMoq;
|
2019-12-22 15:54:46 -07:00
|
|
|
using Jellyfin.Api.Auth.RequiresElevationPolicy;
|
|
|
|
using Jellyfin.Api.Constants;
|
2020-06-16 13:12:40 -07:00
|
|
|
using Jellyfin.Data.Entities;
|
|
|
|
using Jellyfin.Data.Enums;
|
|
|
|
using Jellyfin.Server.Implementations.Users;
|
|
|
|
using MediaBrowser.Common.Configuration;
|
|
|
|
using MediaBrowser.Controller.Library;
|
|
|
|
using MediaBrowser.Model.Configuration;
|
2019-12-22 15:54:46 -07:00
|
|
|
using Microsoft.AspNetCore.Authorization;
|
2020-06-16 13:12:40 -07:00
|
|
|
using Microsoft.AspNetCore.Http;
|
|
|
|
using Moq;
|
2019-12-22 15:54:46 -07:00
|
|
|
using Xunit;
|
|
|
|
|
|
|
|
namespace Jellyfin.Api.Tests.Auth.RequiresElevationPolicy
|
|
|
|
{
|
|
|
|
public class RequiresElevationHandlerTests
|
|
|
|
{
|
2020-06-16 13:12:40 -07:00
|
|
|
/// <summary>
|
|
|
|
/// 127.0.0.1.
|
|
|
|
/// </summary>
|
|
|
|
private const long InternalIp = 16777343;
|
|
|
|
|
|
|
|
private readonly Mock<IConfigurationManager> _configurationManagerMock;
|
|
|
|
private readonly List<IAuthorizationRequirement> _requirements;
|
2019-12-22 15:54:46 -07:00
|
|
|
private readonly RequiresElevationHandler _sut;
|
2020-06-16 13:12:40 -07:00
|
|
|
private readonly Mock<IUserManager> _userManagerMock;
|
|
|
|
private readonly Mock<IHttpContextAccessor> _httpContextAccessor;
|
2019-12-22 15:54:46 -07:00
|
|
|
|
|
|
|
public RequiresElevationHandlerTests()
|
|
|
|
{
|
2020-06-16 13:12:40 -07:00
|
|
|
var fixture = new Fixture().Customize(new AutoMoqCustomization());
|
|
|
|
_configurationManagerMock = fixture.Freeze<Mock<IConfigurationManager>>();
|
|
|
|
_requirements = new List<IAuthorizationRequirement> { new RequiresElevationRequirement() };
|
|
|
|
_userManagerMock = fixture.Freeze<Mock<IUserManager>>();
|
|
|
|
_httpContextAccessor = fixture.Freeze<Mock<IHttpContextAccessor>>();
|
|
|
|
|
|
|
|
_sut = fixture.Create<RequiresElevationHandler>();
|
2019-12-22 15:54:46 -07:00
|
|
|
}
|
|
|
|
|
|
|
|
[Theory]
|
|
|
|
[InlineData(UserRoles.Administrator, true)]
|
|
|
|
[InlineData(UserRoles.User, false)]
|
|
|
|
[InlineData(UserRoles.Guest, false)]
|
|
|
|
public async Task ShouldHandleRolesCorrectly(string role, bool shouldSucceed)
|
|
|
|
{
|
2020-06-16 13:12:40 -07:00
|
|
|
SetupConfigurationManager(true);
|
|
|
|
var (user, claims) = SetupUser(role);
|
2019-12-22 15:54:46 -07:00
|
|
|
|
2020-06-16 13:12:40 -07:00
|
|
|
_userManagerMock.Setup(u => u.GetUserById(It.IsAny<Guid>()))
|
|
|
|
.Returns(user);
|
|
|
|
|
|
|
|
_httpContextAccessor.Setup(h => h.HttpContext.Connection.RemoteIpAddress)
|
|
|
|
.Returns(new IPAddress(InternalIp));
|
2019-12-22 15:54:46 -07:00
|
|
|
|
2020-06-16 13:12:40 -07:00
|
|
|
var context = new AuthorizationHandlerContext(_requirements, claims, null);
|
2019-12-22 15:54:46 -07:00
|
|
|
|
|
|
|
await _sut.HandleAsync(context);
|
|
|
|
Assert.Equal(shouldSucceed, context.HasSucceeded);
|
|
|
|
}
|
2020-06-16 13:12:40 -07:00
|
|
|
|
|
|
|
private static (User, ClaimsPrincipal) SetupUser(string role)
|
|
|
|
{
|
|
|
|
var user = new User(
|
|
|
|
"jellyfin",
|
|
|
|
typeof(DefaultAuthenticationProvider).FullName,
|
|
|
|
typeof(DefaultPasswordResetProvider).FullName);
|
|
|
|
|
|
|
|
user.SetPermission(PermissionKind.IsAdministrator, role.Equals(UserRoles.Administrator, StringComparison.OrdinalIgnoreCase));
|
|
|
|
var claims = new[]
|
|
|
|
{
|
|
|
|
new Claim(ClaimTypes.Role, role),
|
|
|
|
new Claim(ClaimTypes.Name, "jellyfin"),
|
|
|
|
new Claim(InternalClaimTypes.UserId, Guid.Empty.ToString("N", CultureInfo.InvariantCulture)),
|
|
|
|
new Claim(InternalClaimTypes.DeviceId, Guid.Empty.ToString("N", CultureInfo.InvariantCulture)),
|
|
|
|
new Claim(InternalClaimTypes.Device, "test"),
|
|
|
|
new Claim(InternalClaimTypes.Client, "test"),
|
|
|
|
new Claim(InternalClaimTypes.Version, "test"),
|
|
|
|
new Claim(InternalClaimTypes.Token, "test"),
|
|
|
|
};
|
|
|
|
|
|
|
|
var identity = new ClaimsIdentity(claims);
|
|
|
|
return (user, new ClaimsPrincipal(identity));
|
|
|
|
}
|
|
|
|
|
|
|
|
private void SetupConfigurationManager(bool startupWizardCompleted)
|
|
|
|
{
|
|
|
|
var commonConfiguration = new BaseApplicationConfiguration
|
|
|
|
{
|
|
|
|
IsStartupWizardCompleted = startupWizardCompleted
|
|
|
|
};
|
|
|
|
|
|
|
|
_configurationManagerMock.Setup(c => c.CommonConfiguration)
|
|
|
|
.Returns(commonConfiguration);
|
|
|
|
}
|
2019-12-22 15:54:46 -07:00
|
|
|
}
|
|
|
|
}
|