2022-01-20 13:21:59 +01:00
package query
import (
2023-07-14 13:16:16 +02:00
"context"
2022-01-20 13:21:59 +01:00
"database/sql"
"database/sql/driver"
"errors"
"fmt"
"regexp"
"testing"
2023-07-14 13:16:16 +02:00
sq "github.com/Masterminds/squirrel"
2024-08-23 08:44:18 +02:00
"github.com/stretchr/testify/require"
2023-07-14 13:16:16 +02:00
2024-08-23 08:44:18 +02:00
"github.com/zitadel/zitadel/internal/api/authz"
2022-04-27 01:01:45 +02:00
"github.com/zitadel/zitadel/internal/domain"
2024-05-28 10:59:49 +02:00
"github.com/zitadel/zitadel/internal/zerrors"
2022-01-20 13:21:59 +01:00
)
2024-08-23 08:44:18 +02:00
func TestUser_authMethodsCheckPermission ( t * testing . T ) {
type want struct {
methods [ ] * AuthMethod
}
type args struct {
user string
methods * AuthMethods
}
tests := [ ] struct {
name string
args args
want want
permissions [ ] string
} {
{
"permissions for all users" ,
args {
"none" ,
& AuthMethods {
AuthMethods : [ ] * AuthMethod {
{ UserID : "first" } , { UserID : "second" } , { UserID : "third" } ,
} ,
} ,
} ,
want {
methods : [ ] * AuthMethod {
{ UserID : "first" } , { UserID : "second" } , { UserID : "third" } ,
} ,
} ,
[ ] string { "first" , "second" , "third" } ,
} ,
{
"permissions for one user, first" ,
args {
"none" ,
& AuthMethods {
AuthMethods : [ ] * AuthMethod {
{ UserID : "first" } , { UserID : "second" } , { UserID : "third" } ,
} ,
} ,
} ,
want {
methods : [ ] * AuthMethod {
{ UserID : "first" } ,
} ,
} ,
[ ] string { "first" } ,
} ,
{
"permissions for one user, second" ,
args {
"none" ,
& AuthMethods {
AuthMethods : [ ] * AuthMethod {
{ UserID : "first" } , { UserID : "second" } , { UserID : "third" } ,
} ,
} ,
} ,
want {
methods : [ ] * AuthMethod {
{ UserID : "second" } ,
} ,
} ,
[ ] string { "second" } ,
} ,
{
"permissions for one user, third" ,
args {
"none" ,
& AuthMethods {
AuthMethods : [ ] * AuthMethod {
{ UserID : "first" } , { UserID : "second" } , { UserID : "third" } ,
} ,
} ,
} ,
want {
methods : [ ] * AuthMethod {
{ UserID : "third" } ,
} ,
} ,
[ ] string { "third" } ,
} ,
{
"permissions for two users, first" ,
args {
"none" ,
& AuthMethods {
AuthMethods : [ ] * AuthMethod {
{ UserID : "first" } , { UserID : "second" } , { UserID : "third" } ,
} ,
} ,
} ,
want {
methods : [ ] * AuthMethod {
{ UserID : "first" } , { UserID : "third" } ,
} ,
} ,
[ ] string { "first" , "third" } ,
} ,
{
"permissions for two users, second" ,
args {
"none" ,
& AuthMethods {
AuthMethods : [ ] * AuthMethod {
{ UserID : "first" } , { UserID : "second" } , { UserID : "third" } ,
} ,
} ,
} ,
want {
methods : [ ] * AuthMethod {
{ UserID : "second" } , { UserID : "third" } ,
} ,
} ,
[ ] string { "second" , "third" } ,
} ,
{
"no permissions" ,
args {
"none" ,
& AuthMethods {
AuthMethods : [ ] * AuthMethod {
{ UserID : "first" } , { UserID : "second" } , { UserID : "third" } ,
} ,
} ,
} ,
want {
methods : [ ] * AuthMethod { } ,
} ,
[ ] string { } ,
} ,
{
"no permissions, self" ,
args {
"second" ,
& AuthMethods {
AuthMethods : [ ] * AuthMethod {
{ UserID : "first" } , { UserID : "second" } , { UserID : "third" } ,
} ,
} ,
} ,
want {
methods : [ ] * AuthMethod { { UserID : "second" } } ,
} ,
[ ] string { } ,
} ,
}
for _ , tt := range tests {
t . Run ( tt . name , func ( t * testing . T ) {
checkPermission := func ( ctx context . Context , permission , orgID , resourceID string ) ( err error ) {
for _ , perm := range tt . permissions {
if resourceID == perm {
return nil
}
}
return errors . New ( "failed" )
}
authMethodsCheckPermission ( authz . SetCtxData ( context . Background ( ) , authz . CtxData { UserID : tt . args . user } ) , tt . args . methods , checkPermission )
require . Equal ( t , tt . want . methods , tt . args . methods . AuthMethods )
} )
}
}
2023-02-27 22:36:43 +01:00
var (
prepareUserAuthMethodsStmt = ` SELECT projections.user_auth_methods4.token_id, ` +
` projections.user_auth_methods4.creation_date, ` +
` projections.user_auth_methods4.change_date, ` +
` projections.user_auth_methods4.resource_owner, ` +
` projections.user_auth_methods4.user_id, ` +
` projections.user_auth_methods4.sequence, ` +
` projections.user_auth_methods4.name, ` +
` projections.user_auth_methods4.state, ` +
` projections.user_auth_methods4.method_type, ` +
` COUNT(*) OVER () ` +
` FROM projections.user_auth_methods4 ` +
` AS OF SYSTEM TIME '-1 ms' `
prepareUserAuthMethodsCols = [ ] string {
"token_id" ,
"creation_date" ,
"change_date" ,
"resource_owner" ,
"user_id" ,
"sequence" ,
"name" ,
"state" ,
"method_type" ,
"count" ,
}
2024-06-18 13:27:44 +02:00
prepareActiveAuthMethodTypesStmt = ` SELECT projections.users13_notifications.password_set, ` +
2023-06-20 18:23:28 +02:00
` auth_method_types.method_type, ` +
` user_idps_count.count ` +
2024-06-18 13:27:44 +02:00
` FROM projections.users13 ` +
` LEFT JOIN projections.users13_notifications ON projections.users13.id = projections.users13_notifications.user_id AND projections.users13.instance_id = projections.users13_notifications.instance_id ` +
2023-06-20 18:23:28 +02:00
` LEFT JOIN (SELECT DISTINCT(auth_method_types.method_type), auth_method_types.user_id, auth_method_types.instance_id FROM projections.user_auth_methods4 AS auth_method_types ` +
` WHERE auth_method_types.state = $1) AS auth_method_types ` +
2024-06-18 13:27:44 +02:00
` ON auth_method_types.user_id = projections.users13.id AND auth_method_types.instance_id = projections.users13.instance_id ` +
2023-06-20 18:23:28 +02:00
` LEFT JOIN (SELECT user_idps_count.user_id, user_idps_count.instance_id, COUNT(user_idps_count.user_id) AS count FROM projections.idp_user_links3 AS user_idps_count ` +
` GROUP BY user_idps_count.user_id, user_idps_count.instance_id) AS user_idps_count ` +
2024-06-18 13:27:44 +02:00
` ON user_idps_count.user_id = projections.users13.id AND user_idps_count.instance_id = projections.users13.instance_id ` +
2023-06-20 18:23:28 +02:00
` AS OF SYSTEM TIME '-1 ms `
prepareActiveAuthMethodTypesCols = [ ] string {
"password_set" ,
"method_type" ,
"idps_count" ,
}
2024-06-18 13:27:44 +02:00
prepareAuthMethodTypesRequiredStmt = ` SELECT projections.users13.type, ` +
2023-07-20 06:06:16 +02:00
` auth_methods_force_mfa.force_mfa, ` +
` auth_methods_force_mfa.force_mfa_local_only ` +
2024-06-18 13:27:44 +02:00
` FROM projections.users13 ` +
2024-05-28 10:59:49 +02:00
` LEFT JOIN (SELECT auth_methods_force_mfa.force_mfa, auth_methods_force_mfa.force_mfa_local_only, auth_methods_force_mfa.instance_id, auth_methods_force_mfa.aggregate_id, auth_methods_force_mfa.is_default FROM projections.login_policies5 AS auth_methods_force_mfa) AS auth_methods_force_mfa ` +
2024-06-18 13:27:44 +02:00
` ON (auth_methods_force_mfa.aggregate_id = projections.users13.instance_id OR auth_methods_force_mfa.aggregate_id = projections.users13.resource_owner) AND auth_methods_force_mfa.instance_id = projections.users13.instance_id ` +
2024-05-28 10:59:49 +02:00
` ORDER BY auth_methods_force_mfa . is_default LIMIT 1
2023-07-14 13:16:16 +02:00
`
prepareAuthMethodTypesRequiredCols = [ ] string {
2024-05-23 07:35:10 +02:00
"type" ,
2023-07-14 13:16:16 +02:00
"force_mfa" ,
2023-07-20 06:06:16 +02:00
"force_mfa_local_only" ,
2023-07-14 13:16:16 +02:00
}
2023-02-27 22:36:43 +01:00
)
2022-01-20 13:21:59 +01:00
func Test_UserAuthMethodPrepares ( t * testing . T ) {
type want struct {
sqlExpectations sqlExpectation
err checkErr
}
tests := [ ] struct {
name string
prepare interface { }
want want
object interface { }
} {
{
name : "prepareUserAuthMethodsQuery no result" ,
prepare : prepareUserAuthMethodsQuery ,
want : want {
sqlExpectations : mockQueries (
2023-02-27 22:36:43 +01:00
regexp . QuoteMeta ( prepareUserAuthMethodsStmt ) ,
2022-01-20 13:21:59 +01:00
nil ,
nil ,
) ,
} ,
object : & AuthMethods { AuthMethods : [ ] * AuthMethod { } } ,
} ,
{
name : "prepareUserAuthMethodsQuery one result" ,
prepare : prepareUserAuthMethodsQuery ,
want : want {
sqlExpectations : mockQueries (
2023-02-27 22:36:43 +01:00
regexp . QuoteMeta ( prepareUserAuthMethodsStmt ) ,
prepareUserAuthMethodsCols ,
2022-01-20 13:21:59 +01:00
[ ] [ ] driver . Value {
{
"token_id" ,
testNow ,
testNow ,
"ro" ,
"user_id" ,
uint64 ( 20211108 ) ,
"name" ,
domain . MFAStateReady ,
domain . UserAuthMethodTypeU2F ,
} ,
} ,
) ,
} ,
object : & AuthMethods {
SearchResponse : SearchResponse {
Count : 1 ,
} ,
AuthMethods : [ ] * AuthMethod {
{
TokenID : "token_id" ,
CreationDate : testNow ,
ChangeDate : testNow ,
ResourceOwner : "ro" ,
UserID : "user_id" ,
Sequence : 20211108 ,
Name : "name" ,
State : domain . MFAStateReady ,
Type : domain . UserAuthMethodTypeU2F ,
} ,
} ,
} ,
} ,
{
name : "prepareUserAuthMethodsQuery multiple result" ,
prepare : prepareUserAuthMethodsQuery ,
want : want {
sqlExpectations : mockQueries (
2023-02-27 22:36:43 +01:00
regexp . QuoteMeta ( prepareUserAuthMethodsStmt ) ,
prepareUserAuthMethodsCols ,
2022-01-20 13:21:59 +01:00
[ ] [ ] driver . Value {
{
"token_id" ,
testNow ,
testNow ,
"ro" ,
"user_id" ,
uint64 ( 20211108 ) ,
"name" ,
domain . MFAStateReady ,
domain . UserAuthMethodTypeU2F ,
} ,
{
"token_id-2" ,
testNow ,
testNow ,
"ro" ,
"user_id" ,
uint64 ( 20211108 ) ,
"name-2" ,
domain . MFAStateReady ,
domain . UserAuthMethodTypePasswordless ,
} ,
} ,
) ,
} ,
object : & AuthMethods {
SearchResponse : SearchResponse {
Count : 2 ,
} ,
AuthMethods : [ ] * AuthMethod {
{
TokenID : "token_id" ,
CreationDate : testNow ,
ChangeDate : testNow ,
ResourceOwner : "ro" ,
UserID : "user_id" ,
Sequence : 20211108 ,
Name : "name" ,
State : domain . MFAStateReady ,
Type : domain . UserAuthMethodTypeU2F ,
} ,
{
TokenID : "token_id-2" ,
CreationDate : testNow ,
ChangeDate : testNow ,
ResourceOwner : "ro" ,
UserID : "user_id" ,
Sequence : 20211108 ,
Name : "name-2" ,
State : domain . MFAStateReady ,
Type : domain . UserAuthMethodTypePasswordless ,
} ,
} ,
} ,
} ,
{
name : "prepareUserAuthMethodsQuery sql err" ,
prepare : prepareUserAuthMethodsQuery ,
want : want {
sqlExpectations : mockQueryErr (
2023-02-27 22:36:43 +01:00
regexp . QuoteMeta ( prepareUserAuthMethodsStmt ) ,
2022-01-20 13:21:59 +01:00
sql . ErrConnDone ,
) ,
err : func ( err error ) ( error , bool ) {
if ! errors . Is ( err , sql . ErrConnDone ) {
return fmt . Errorf ( "err should be sql.ErrConnDone got: %w" , err ) , false
}
return nil , true
} ,
} ,
2023-08-22 12:49:22 +02:00
object : ( * AuthMethodTypes ) ( nil ) ,
2022-01-20 13:21:59 +01:00
} ,
2023-06-20 18:23:28 +02:00
{
2024-07-22 14:46:27 +02:00
name : "prepareUserAuthMethodTypesQuery no result" ,
prepare : func ( ctx context . Context , db prepareDatabase ) ( sq . SelectBuilder , func ( * sql . Rows ) ( * AuthMethodTypes , error ) ) {
builder , scan := prepareUserAuthMethodTypesQuery ( ctx , db , true )
return builder , func ( rows * sql . Rows ) ( * AuthMethodTypes , error ) {
return scan ( rows )
}
} ,
2023-06-20 18:23:28 +02:00
want : want {
sqlExpectations : mockQueries (
regexp . QuoteMeta ( prepareActiveAuthMethodTypesStmt ) ,
nil ,
nil ,
) ,
} ,
object : & AuthMethodTypes { AuthMethodTypes : [ ] domain . UserAuthMethodType { } } ,
} ,
{
2024-07-22 14:46:27 +02:00
name : "prepareUserAuthMethodTypesQuery one second factor" ,
prepare : func ( ctx context . Context , db prepareDatabase ) ( sq . SelectBuilder , func ( * sql . Rows ) ( * AuthMethodTypes , error ) ) {
builder , scan := prepareUserAuthMethodTypesQuery ( ctx , db , true )
return builder , func ( rows * sql . Rows ) ( * AuthMethodTypes , error ) {
return scan ( rows )
}
} ,
2023-06-20 18:23:28 +02:00
want : want {
sqlExpectations : mockQueries (
regexp . QuoteMeta ( prepareActiveAuthMethodTypesStmt ) ,
prepareActiveAuthMethodTypesCols ,
[ ] [ ] driver . Value {
{
true ,
domain . UserAuthMethodTypePasswordless ,
1 ,
} ,
} ,
) ,
} ,
object : & AuthMethodTypes {
SearchResponse : SearchResponse {
Count : 3 ,
} ,
AuthMethodTypes : [ ] domain . UserAuthMethodType {
domain . UserAuthMethodTypePasswordless ,
domain . UserAuthMethodTypePassword ,
domain . UserAuthMethodTypeIDP ,
} ,
} ,
} ,
{
2024-07-22 14:46:27 +02:00
name : "prepareUserAuthMethodTypesQuery multiple second factors" ,
prepare : func ( ctx context . Context , db prepareDatabase ) ( sq . SelectBuilder , func ( * sql . Rows ) ( * AuthMethodTypes , error ) ) {
builder , scan := prepareUserAuthMethodTypesQuery ( ctx , db , true )
return builder , func ( rows * sql . Rows ) ( * AuthMethodTypes , error ) {
return scan ( rows )
}
} ,
2023-06-20 18:23:28 +02:00
want : want {
sqlExpectations : mockQueries (
regexp . QuoteMeta ( prepareActiveAuthMethodTypesStmt ) ,
prepareActiveAuthMethodTypesCols ,
[ ] [ ] driver . Value {
{
true ,
domain . UserAuthMethodTypePasswordless ,
1 ,
} ,
{
true ,
2023-08-02 18:57:53 +02:00
domain . UserAuthMethodTypeTOTP ,
2023-06-20 18:23:28 +02:00
1 ,
} ,
} ,
) ,
} ,
object : & AuthMethodTypes {
SearchResponse : SearchResponse {
Count : 4 ,
} ,
AuthMethodTypes : [ ] domain . UserAuthMethodType {
domain . UserAuthMethodTypePasswordless ,
2023-08-02 18:57:53 +02:00
domain . UserAuthMethodTypeTOTP ,
2023-06-20 18:23:28 +02:00
domain . UserAuthMethodTypePassword ,
domain . UserAuthMethodTypeIDP ,
} ,
} ,
} ,
{
2024-07-22 14:46:27 +02:00
name : "prepareUserAuthMethodTypesQuery sql err" ,
prepare : func ( ctx context . Context , db prepareDatabase ) ( sq . SelectBuilder , func ( * sql . Rows ) ( * AuthMethodTypes , error ) ) {
builder , scan := prepareUserAuthMethodTypesQuery ( ctx , db , true )
return builder , func ( rows * sql . Rows ) ( * AuthMethodTypes , error ) {
return scan ( rows )
}
} ,
2023-06-20 18:23:28 +02:00
want : want {
sqlExpectations : mockQueryErr (
regexp . QuoteMeta ( prepareActiveAuthMethodTypesStmt ) ,
sql . ErrConnDone ,
) ,
err : func ( err error ) ( error , bool ) {
if ! errors . Is ( err , sql . ErrConnDone ) {
return fmt . Errorf ( "err should be sql.ErrConnDone got: %w" , err ) , false
}
return nil , true
} ,
} ,
2023-08-22 12:49:22 +02:00
object : ( * AuthMethodTypes ) ( nil ) ,
2023-06-20 18:23:28 +02:00
} ,
2023-07-14 13:16:16 +02:00
{
name : "prepareUserAuthMethodTypesRequiredQuery no result" ,
2024-05-28 10:59:49 +02:00
prepare : func ( ctx context . Context , db prepareDatabase ) ( sq . SelectBuilder , func ( * sql . Row ) ( * UserAuthMethodRequirements , error ) ) {
2023-07-14 13:16:16 +02:00
builder , scan := prepareUserAuthMethodTypesRequiredQuery ( ctx , db )
2024-05-28 10:59:49 +02:00
return builder , func ( row * sql . Row ) ( * UserAuthMethodRequirements , error ) {
return scan ( row )
2023-07-14 13:16:16 +02:00
}
} ,
want : want {
2024-05-28 10:59:49 +02:00
sqlExpectations : mockQueriesScanErr (
2023-07-14 13:16:16 +02:00
regexp . QuoteMeta ( prepareAuthMethodTypesRequiredStmt ) ,
nil ,
nil ,
) ,
2024-05-28 10:59:49 +02:00
err : func ( err error ) ( error , bool ) {
if ! zerrors . IsNotFound ( err ) {
return fmt . Errorf ( "err should be zitadel.NotFoundError got: %w" , err ) , false
}
return nil , true
} ,
2023-07-14 13:16:16 +02:00
} ,
2024-05-28 10:59:49 +02:00
object : ( * UserAuthMethodRequirements ) ( nil ) ,
2023-07-14 13:16:16 +02:00
} ,
{
name : "prepareUserAuthMethodTypesRequiredQuery one second factor" ,
2024-05-28 10:59:49 +02:00
prepare : func ( ctx context . Context , db prepareDatabase ) ( sq . SelectBuilder , func ( * sql . Row ) ( * UserAuthMethodRequirements , error ) ) {
2023-07-14 13:16:16 +02:00
builder , scan := prepareUserAuthMethodTypesRequiredQuery ( ctx , db )
2024-05-28 10:59:49 +02:00
return builder , func ( row * sql . Row ) ( * UserAuthMethodRequirements , error ) {
return scan ( row )
2023-07-14 13:16:16 +02:00
}
} ,
want : want {
sqlExpectations : mockQueries (
regexp . QuoteMeta ( prepareAuthMethodTypesRequiredStmt ) ,
prepareAuthMethodTypesRequiredCols ,
[ ] [ ] driver . Value {
{
2024-05-23 07:35:10 +02:00
domain . UserTypeHuman ,
2023-07-14 13:16:16 +02:00
true ,
2023-07-20 06:06:16 +02:00
true ,
2023-07-14 13:16:16 +02:00
} ,
} ,
) ,
} ,
2024-05-23 07:35:10 +02:00
object : & UserAuthMethodRequirements {
2024-06-12 14:24:17 +02:00
UserType : domain . UserTypeHuman ,
2024-05-23 07:35:10 +02:00
ForceMFA : true ,
ForceMFALocalOnly : true ,
2023-07-14 13:16:16 +02:00
} ,
} ,
{
name : "prepareUserAuthMethodTypesRequiredQuery multiple second factors" ,
2024-05-28 10:59:49 +02:00
prepare : func ( ctx context . Context , db prepareDatabase ) ( sq . SelectBuilder , func ( * sql . Row ) ( * UserAuthMethodRequirements , error ) ) {
2023-07-14 13:16:16 +02:00
builder , scan := prepareUserAuthMethodTypesRequiredQuery ( ctx , db )
2024-05-28 10:59:49 +02:00
return builder , func ( row * sql . Row ) ( * UserAuthMethodRequirements , error ) {
return scan ( row )
2023-07-14 13:16:16 +02:00
}
} ,
want : want {
sqlExpectations : mockQueries (
regexp . QuoteMeta ( prepareAuthMethodTypesRequiredStmt ) ,
prepareAuthMethodTypesRequiredCols ,
[ ] [ ] driver . Value {
{
2024-05-23 07:35:10 +02:00
domain . UserTypeHuman ,
2023-07-14 13:16:16 +02:00
true ,
2023-07-20 06:06:16 +02:00
true ,
2023-07-14 13:16:16 +02:00
} ,
} ,
) ,
} ,
2024-05-23 07:35:10 +02:00
object : & UserAuthMethodRequirements {
2024-06-12 14:24:17 +02:00
UserType : domain . UserTypeHuman ,
2024-05-23 07:35:10 +02:00
ForceMFA : true ,
ForceMFALocalOnly : true ,
2023-07-14 13:16:16 +02:00
} ,
} ,
{
name : "prepareUserAuthMethodTypesRequiredQuery sql err" ,
2024-05-28 10:59:49 +02:00
prepare : func ( ctx context . Context , db prepareDatabase ) ( sq . SelectBuilder , func ( * sql . Row ) ( * UserAuthMethodRequirements , error ) ) {
2023-07-14 13:16:16 +02:00
builder , scan := prepareUserAuthMethodTypesRequiredQuery ( ctx , db )
2024-05-28 10:59:49 +02:00
return builder , func ( row * sql . Row ) ( * UserAuthMethodRequirements , error ) {
return scan ( row )
2023-07-14 13:16:16 +02:00
}
} ,
want : want {
sqlExpectations : mockQueryErr (
regexp . QuoteMeta ( prepareAuthMethodTypesRequiredStmt ) ,
sql . ErrConnDone ,
) ,
err : func ( err error ) ( error , bool ) {
if ! errors . Is ( err , sql . ErrConnDone ) {
return fmt . Errorf ( "err should be sql.ErrConnDone got: %w" , err ) , false
}
return nil , true
} ,
} ,
object : nil ,
} ,
2022-01-20 13:21:59 +01:00
}
for _ , tt := range tests {
t . Run ( tt . name , func ( t * testing . T ) {
2023-02-27 22:36:43 +01:00
assertPrepare ( t , tt . prepare , tt . object , tt . want . sqlExpectations , tt . want . err , defaultPrepareArgs ... )
2022-01-20 13:21:59 +01:00
} )
}
}