Files
Jay Brown 2ff6e05ffc Merged in feature/permit-integration-1 (pull request #172)
Permit integration - part 1

* WIP permit integration

* slim down build

* Merge branch 'main' of bitbucket.org:aarete/query-orchestration into feature/permit-integration-1

* omit swagger from auth

* clean build

* comment

* part 1 completed

this is the initial permitio parts and tests without integration. Also testing.md since we have a new test target `task test:permitio`

* feature flag for no jwt validation

* permit integration

* fix ci unit tests

* ci fix

* build fix

* fix home handler

* fix redirect

* test fix

* update docs for auth
2025-07-11 19:27:14 +00:00

181 lines
4.9 KiB
Go

//go:build permitio
package cognitoauth
import (
"os"
"testing"
"github.com/joho/godotenv"
"github.com/stretchr/testify/assert"
"github.com/stretchr/testify/require"
)
func init() {
// Load .env file if it exists (for tests)
_ = godotenv.Load("../../.env")
_ = godotenv.Load(".env")
}
// TestValidatePermitIOConfiguration tests the startup validation function
func TestValidatePermitIOConfiguration(t *testing.T) {
if testing.Short() {
t.Skip("Skipping integration test in short mode")
}
// Save original environment variables
originalAPIKey := os.Getenv("PERMIT_IO_API_KEY")
originalPDPURL := os.Getenv("PERMIT_IO_PDP_URL")
originalDisableAuth := os.Getenv("DISABLE_AUTH")
// Clean up after test
defer func() {
os.Setenv("PERMIT_IO_API_KEY", originalAPIKey)
os.Setenv("PERMIT_IO_PDP_URL", originalPDPURL)
os.Setenv("DISABLE_AUTH", originalDisableAuth)
}()
t.Run("AuthDisabled", func(t *testing.T) {
// Test that validation is skipped when DISABLE_AUTH=true
os.Setenv("DISABLE_AUTH", "true")
os.Setenv("PERMIT_IO_API_KEY", "") // Missing API key
os.Setenv("PERMIT_IO_PDP_URL", "") // Missing PDP URL
// Should succeed even with missing credentials
err := ValidatePermitIOConfiguration()
assert.NoError(t, err, "Should skip validation when DISABLE_AUTH=true")
})
t.Run("ValidConfiguration", func(t *testing.T) {
// Ensure auth is enabled for this test
os.Setenv("DISABLE_AUTH", "false")
// Set up valid configuration
validAPIKey := originalAPIKey
if validAPIKey == "" {
validAPIKey = getTestAPIKey()
}
require.NotEmpty(t, validAPIKey, "Test API key must be available")
os.Setenv("PERMIT_IO_API_KEY", validAPIKey)
os.Setenv("PERMIT_IO_PDP_URL", testPDPURL)
// Should succeed with valid configuration
err := ValidatePermitIOConfiguration()
assert.NoError(t, err, "Valid configuration should pass validation")
})
t.Run("MissingAPIKey", func(t *testing.T) {
// Ensure auth is enabled for this test
os.Setenv("DISABLE_AUTH", "false")
// Test missing API key (PDP URL should use default)
os.Setenv("PERMIT_IO_API_KEY", "")
os.Setenv("PERMIT_IO_PDP_URL", testPDPURL)
err := ValidatePermitIOConfiguration()
assert.Error(t, err)
assert.Contains(t, err.Error(), "PERMIT_IO_API_KEY environment variable must be set")
})
t.Run("DefaultPDPURL", func(t *testing.T) {
// Ensure auth is enabled for this test
os.Setenv("DISABLE_AUTH", "false")
// Test that default PDP URL is used when not set
validAPIKey := originalAPIKey
if validAPIKey == "" {
validAPIKey = getTestAPIKey()
}
os.Setenv("PERMIT_IO_API_KEY", validAPIKey)
os.Setenv("PERMIT_IO_PDP_URL", "") // Use default
// This will likely fail because default localhost:7766 might not be running,
// but it should not fail due to missing environment variable
err := ValidatePermitIOConfiguration()
// Error should be about connectivity, not missing env var
if err != nil {
assert.NotContains(t, err.Error(), "environment variable must be set")
}
})
t.Run("InvalidPDPURL", func(t *testing.T) {
// Ensure auth is enabled for this test
os.Setenv("DISABLE_AUTH", "false")
validAPIKey := originalAPIKey
if validAPIKey == "" {
validAPIKey = getTestAPIKey()
}
os.Setenv("PERMIT_IO_API_KEY", validAPIKey)
os.Setenv("PERMIT_IO_PDP_URL", "http://invalid-host-12345:9999")
err := ValidatePermitIOConfiguration()
assert.Error(t, err)
assert.Contains(t, err.Error(), "PDP connectivity failed")
})
t.Run("InvalidAPIKey", func(t *testing.T) {
// Ensure auth is enabled for this test
os.Setenv("DISABLE_AUTH", "false")
// Create an invalid API key by modifying the valid one
validAPIKey := originalAPIKey
if validAPIKey == "" {
validAPIKey = getTestAPIKey()
}
require.NotEmpty(t, validAPIKey, "Test API key must be available")
// Change the last character to make it invalid
invalidAPIKey := validAPIKey[:len(validAPIKey)-1] + "X"
if validAPIKey[len(validAPIKey)-1] == 'X' {
invalidAPIKey = validAPIKey[:len(validAPIKey)-1] + "Y"
}
os.Setenv("PERMIT_IO_API_KEY", invalidAPIKey)
os.Setenv("PERMIT_IO_PDP_URL", testPDPURL)
err := ValidatePermitIOConfiguration()
assert.Error(t, err)
assert.Contains(t, err.Error(), "API key validation failed")
})
}
// TestMaskAPIKey tests the API key masking function
func TestMaskAPIKey(t *testing.T) {
tests := []struct {
name string
apiKey string
expected string
}{
{
name: "LongAPIKey",
apiKey: "permit_key_1234567890abcdef",
expected: "permit_k...",
},
{
name: "ShortAPIKey",
apiKey: "short",
expected: "***masked***",
},
{
name: "ExactlyEightChars",
apiKey: "12345678",
expected: "***masked***",
},
{
name: "NineChars",
apiKey: "123456789",
expected: "12345678...",
},
}
for _, tt := range tests {
t.Run(tt.name, func(t *testing.T) {
result := maskAPIKey(tt.apiKey)
assert.Equal(t, tt.expected, result)
})
}
}