【问题标题】:Shiro: How to write a test for an endpoint protected with @RequiresRoles?Shiro:如何为受@RequiresRoles 保护的端点编写测试?
【发布时间】:2018-03-18 04:11:52
【问题描述】:

假设我有这个资源:

import javax.ws.rs.GET;
import javax.ws.rs.Path;
import javax.ws.rs.PathParam;
import javax.ws.rs.Produces;
import javax.ws.rs.core.MediaType;
import javax.ws.rs.core.Response;

import org.apache.shiro.authz.annotation.RequiresAuthentication;
import org.apache.shiro.authz.annotation.RequiresRoles;

import io.swagger.annotations.Api;
import io.swagger.annotations.ApiOperation;

@Path("/authhello")
@Api(value = "hello", description = "Simple endpoints for testing api authentification",
    hidden = true)
@Produces(MediaType.APPLICATION_JSON)
@RequiresAuthentication
public class AuthenticatedHelloWorldResource {

  private static final String READ = "READ";
  private static final String WRITE = "WRITE";

  @GET
  @ApiOperation(value = "helloworld",
      notes = "Simple hello world.",
      response = String.class)
  @RequiresRoles(READ)
  public Response helloWorld() {
    String hello = "Hello world!";
    return Response.status(Response.Status.OK).entity(hello).build();
  }

  @GET
  @Path("/{param}")
  @ApiOperation(value = "helloReply",
      notes = "Returns Hello you! and {param}",
      response = String.class)
  @RequiresRoles(WRITE)
  public Response getMsg(@PathParam("param") String msg) {
    String output = "Hello you! " + msg;
    return Response.status(Response.Status.OK).entity(output).build();
  }
}

我是否应该编写测试来确认某些(测试)用户从端点获得响应,而某些用户却没有?如果是这样:我该如何编写这些测试?我尝试过这样的事情:

import javax.ws.rs.core.Application;

import org.glassfish.jersey.server.ResourceConfig;
import org.junit.Test;

import com.cognite.api.shiro.AbstractShiroTest;

import static org.junit.Assert.assertEquals;

public class AuthenticatedHelloWorldTest extends AbstractShiroTest {

  @Override
  protected Application configure() {
    return new ResourceConfig(AuthenticatedHelloWorldResource.class);
  }

  @Test
  public void testAuthenticatedReadHelloWorld() {
    final String hello = target("/authhello").request().get(String.class);
    assertEquals("Hello world!", hello);
  }

  @Test
  public void testAuthenticatedWriteHelloWorld() {
    final String hello = target("/authhello/test").request().get(String.class);
    assertEquals("Hello you! test", hello);
  }

}

但我不确定如何实际测试@RequiresRoles-annotation 的功能。我已经阅读了Shiro's page on testing,但我无法编写一个失败的测试(例如,一个没有WRITE 角色试图访问/authhello/test 的主题的测试)。任何提示将不胜感激。

【问题讨论】:

    标签: java jax-rs shiro


    【解决方案1】:

    我应该测试一下吗?

    是的。如果您想确保某些角色将有权或无权访问您的资源。这将是一个安全集成测试。

    如果我要测试它,我应该如何设置整个应用程序 + 在测试中使用 http 请求实际调用它?还是有更简单的方法?

    部分问题在于@RequiresAuthentication 和@RequiresRoles 本身只是类和方法元信息。注释本身不提供安全检查功能。

    从您的问题中不清楚您使用的是哪种类型的容器,但我可以猜测它是普通的 Jersey JAX-RS 服务(我说的对吗?)。为了让 Shiro 执行安全检查,您应该在端点周围添加一些 JAX-RS 过滤器(也许是其他方式?)。要测试安全性,您应该在测试中复制此设置。否则,没有引擎处理您的注释,因此没有安全检查。

    【讨论】:

    • 感谢您抽出宝贵时间回答。经过一番认真的挖掘和阅读后,我意识到,正如您所说,我缺少一些设置代码。我设法在我的测试中复制了在应用程序中完成的设置(尽管很遗憾我无法在这里分享一个示例)。
    猜你喜欢
    • 2022-11-18
    • 2013-09-17
    • 1970-01-01
    • 2011-03-04
    • 1970-01-01
    • 1970-01-01
    • 2012-05-22
    • 2020-05-09
    • 1970-01-01
    相关资源
    最近更新 更多