@Test publicvoid testAllAuthenticatedUsersAsAppRoleNoUser() throws IOException {
List<String> userRoles = new ArrayList<>();
List<String> constraintRoles = new ArrayList<>();
List<String> applicationRoles = new ArrayList<>();
// Configure this test
userRoles.add(ROLE1);
constraintRoles.add(SecurityConstraint.ROLE_ALL_AUTHENTICATED_USERS);
applicationRoles.add(SecurityConstraint.ROLE_ALL_AUTHENTICATED_USERS);
@Test publicvoid testAllAuthenticatedUsersAsAppRoleWithUser() throws IOException {
List<String> userRoles = new ArrayList<>();
List<String> constraintRoles = new ArrayList<>();
List<String> applicationRoles = new ArrayList<>();
// Configure this test
userRoles.add(SecurityConstraint.ROLE_ALL_AUTHENTICATED_USERS);
constraintRoles.add(SecurityConstraint.ROLE_ALL_AUTHENTICATED_USERS);
applicationRoles.add(SecurityConstraint.ROLE_ALL_AUTHENTICATED_USERS);
@Test publicvoid testNoAuthConstraint() throws IOException { // No auth constraint == allow access for all
List<String> applicationRoles = new ArrayList<>();
@Test publicvoid testCombineConstraints01() throws IOException { // Allowed roles should be the union of the roles in the constraints // User role is in first constraint
List<String> userRoles = new ArrayList<>();
List<String> constraintOneRoles = new ArrayList<>();
List<String> constraintTwoRoles = new ArrayList<>();
List<String> applicationRoles = new ArrayList<>();
@Test publicvoid testCombineConstraints02() throws IOException { // Allowed roles should be the union of the roles in the constraints // User role is in last constraint
List<String> userRoles = new ArrayList<>();
List<String> constraintOneRoles = new ArrayList<>();
List<String> constraintTwoRoles = new ArrayList<>();
List<String> applicationRoles = new ArrayList<>();
@Test publicvoid testCombineConstraints03() throws IOException { // Allowed roles should be the union of the roles in the constraints // User role is not in any constraint
List<String> userRoles = new ArrayList<>();
List<String> constraintOneRoles = new ArrayList<>();
List<String> constraintTwoRoles = new ArrayList<>();
List<String> applicationRoles = new ArrayList<>();
@Test publicvoid testCombineConstraints04() throws IOException { // Allowed roles should be the union of the roles in the constraints // * is any app role // User role is not in any constraint
List<String> userRoles = new ArrayList<>();
List<String> constraintOneRoles = new ArrayList<>();
List<String> constraintTwoRoles = new ArrayList<>();
List<String> applicationRoles = new ArrayList<>();
@Test publicvoid testCombineConstraints05() throws IOException { // Allowed roles should be the union of the roles in the constraints // * is any app role // User role is a non-app constraint role
List<String> userRoles = new ArrayList<>();
List<String> constraintOneRoles = new ArrayList<>();
List<String> constraintTwoRoles = new ArrayList<>();
List<String> applicationRoles = new ArrayList<>();
@Test publicvoid testCombineConstraints06() throws IOException { // Allowed roles should be the union of the roles in the constraints // * is any app role // User role is an app role
List<String> userRoles = new ArrayList<>();
List<String> constraintOneRoles = new ArrayList<>();
List<String> constraintTwoRoles = new ArrayList<>();
List<String> applicationRoles = new ArrayList<>();
@Test publicvoid testCombineConstraints07() throws IOException { // Allowed roles should be the union of the roles in the constraints // * is any app role // User has no role
List<String> userRoles = new ArrayList<>();
List<String> constraintOneRoles = new ArrayList<>();
List<String> constraintTwoRoles = new ArrayList<>();
List<String> applicationRoles = new ArrayList<>();
@Test publicvoid testCombineConstraints08() throws IOException { // Allowed roles should be the union of the roles in the constraints // ** is any authenticated user // User has no role
List<String> userRoles = new ArrayList<>();
List<String> constraintOneRoles = new ArrayList<>();
List<String> constraintTwoRoles = new ArrayList<>();
List<String> applicationRoles = new ArrayList<>();
@Test publicvoid testCombineConstraints09() throws IOException { // Allowed roles should be the union of the roles in the constraints // ** is any authenticated user // User has constraint role
List<String> userRoles = new ArrayList<>();
List<String> constraintOneRoles = new ArrayList<>();
List<String> constraintTwoRoles = new ArrayList<>();
List<String> applicationRoles = new ArrayList<>();
@Test publicvoid testCombineConstraints10() throws IOException { // Allowed roles should be the union of the roles in the constraints // ** is any authenticated user // User has app role
List<String> userRoles = new ArrayList<>();
List<String> constraintOneRoles = new ArrayList<>();
List<String> constraintTwoRoles = new ArrayList<>();
List<String> applicationRoles = new ArrayList<>();
@Test publicvoid testCombineConstraints11() throws IOException { // Allowed roles should be the union of the roles in the constraints // ** is any authenticated user // User is not authenticated
List<String> constraintOneRoles = new ArrayList<>();
List<String> constraintTwoRoles = new ArrayList<>();
List<String> applicationRoles = new ArrayList<>();
@Test publicvoid testCombineConstraints12() throws IOException { // Allowed roles should be the union of the roles in the constraints // Constraint without role or implied role permits unauthenticated users // User is not authenticated
List<String> constraintTwoRoles = new ArrayList<>();
List<String> applicationRoles = new ArrayList<>();
@Test publicvoid testCombineConstraints13() throws IOException { // Allowed roles should be the union of the roles in the constraints // Constraint without role or implied role permits unauthenticated users // User is not authenticated
List<String> constraintTwoRoles = new ArrayList<>();
List<String> applicationRoles = new ArrayList<>();
@Test publicvoid testCombineConstraints14() throws IOException { // Allowed roles should be the union of the roles in the constraints // Constraint without role or implied role permits unauthenticated users // User is not authenticated
List<String> constraintTwoRoles = new ArrayList<>();
List<String> applicationRoles = new ArrayList<>();
@Test publicvoid testCombineConstraints15() throws IOException { // Allowed roles should be the union of the roles in the constraints // Constraint with empty auth section prevents all access // User has matching constraint role
List<String> userRoles = new ArrayList<>();
List<String> constraintOneRoles = new ArrayList<>();
List<String> constraintTwoRoles = new ArrayList<>();
List<String> applicationRoles = new ArrayList<>();
@Test publicvoid testCombineConstraints16() throws IOException { // Allowed roles should be the union of the roles in the constraints // Constraint with empty auth section prevents all access // User has matching role
List<String> userRoles = new ArrayList<>();
List<String> constraintOneRoles = new ArrayList<>();
List<String> constraintTwoRoles = new ArrayList<>();
List<String> applicationRoles = new ArrayList<>();
@Test publicvoid testCombineConstraints17() throws IOException { // Allowed roles should be the union of the roles in the constraints // Constraint with empty auth section prevents all access // User matches all authenticated users
List<String> userRoles = new ArrayList<>();
List<String> constraintOneRoles = new ArrayList<>();
List<String> constraintTwoRoles = new ArrayList<>();
List<String> applicationRoles = new ArrayList<>();
// Configure the security constraints for the resource
SecurityConstraint constraintOne = new SecurityConstraint(); if (constraintOneRoles != null) {
constraintOne.setAuthConstraint(true); for (String constraintRole : constraintOneRoles) {
constraintOne.addAuthRole(constraintRole); if (applicationRoles.contains(
SecurityConstraint.ROLE_ALL_AUTHENTICATED_USERS)) {
constraintOne.treatAllAuthenticatedUsersAsApplicationRole();
}
}
}
SecurityConstraint constraintTwo = new SecurityConstraint(); if (constraintTwoRoles != null) {
constraintTwo.setAuthConstraint(true); for (String constraintRole : constraintTwoRoles) {
constraintTwo.addAuthRole(constraintRole); if (applicationRoles.contains(
SecurityConstraint.ROLE_ALL_AUTHENTICATED_USERS)) {
constraintTwo.treatAllAuthenticatedUsersAsApplicationRole();
}
}
}
SecurityConstraint[] constraints = new SecurityConstraint[] { constraintOne, constraintTwo };
// Set up the mock request and response
Request request = new Request(null);
Response response = new TesterResponse();
Context context = new TesterContext(); for (String applicationRole : applicationRoles) {
context.addSecurityRole(applicationRole);
}
request.getMappingData().context = context;
// Set up an authenticated user // Configure the users in the Realm if (userRoles != null) {
GenericPrincipal gp = new GenericPrincipal(USER1, userRoles);
request.setUserPrincipal(gp);
}
// Check if user meets constraints boolean result = mapRealm.hasResourcePermission(
request, response, constraints, null);
/* *Thistestcasecoversthespecialcaseinsection13.4.1oftheServlet *3.1specificationfor{@linkjakarta.servlet.annotation.HttpConstraint}.
*/
@Test publicvoid testHttpConstraint() throws IOException { // Get the annotation from the test case Class<TesterServletSecurity01> clazz = TesterServletSecurity01.class;
ServletSecurity servletSecurity =
clazz.getAnnotation(ServletSecurity.class);
// Convert the annotation into constraints
ServletSecurityElement servletSecurityElement = new ServletSecurityElement(servletSecurity);
SecurityConstraint[] constraints =
SecurityConstraint.createConstraints(
servletSecurityElement, "/*");
// Create a separate constraint that covers DELETE
SecurityConstraint deleteConstraint = new SecurityConstraint();
deleteConstraint.addAuthRole(ROLE1);
SecurityCollection deleteCollection = new SecurityCollection();
deleteCollection.addMethod("DELETE");
deleteCollection.addPatternDecoded("/*");
deleteConstraint.addCollection(deleteCollection);
TesterMapRealm mapRealm = new TesterMapRealm();
// Set up the mock request and response
TesterRequest request = new TesterRequest();
Response response = new TesterResponse();
Context context = request.getContext();
context.addSecurityRole(ROLE1);
context.addSecurityRole(ROLE2);
request.getMappingData().context = context;
// Create the principals
List<String> userRoles1 = new ArrayList<>();
userRoles1.add(ROLE1);
GenericPrincipal gp1 = new GenericPrincipal(USER1, userRoles1);
List<String> userRoles2 = new ArrayList<>();
userRoles2.add(ROLE2);
GenericPrincipal gp2 = new GenericPrincipal(USER2, userRoles2);
List<String> userRoles99 = new ArrayList<>();
GenericPrincipal gp99 = new GenericPrincipal(USER99, userRoles99);
// Add the constraints to the context for (SecurityConstraint constraint : constraints) {
context.addConstraint(constraint);
}
context.addConstraint(deleteConstraint);
// All users should be able to perform a GET
request.setMethod("GET");
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.