Jiri Simsa | d7616c9 | 2015-03-24 23:44:30 -0700 | [diff] [blame] | 1 | // Copyright 2015 The Vanadium Authors. All rights reserved. |
| 2 | // Use of this source code is governed by a BSD-style |
| 3 | // license that can be found in the LICENSE file. |
| 4 | |
Todd Wang | 8c4e5cc | 2015-04-09 11:30:52 -0700 | [diff] [blame] | 5 | // Package identitylib implements a test identityd service under the |
| 6 | // v.io/x/ref/test/modules framework. |
Todd Wang | 0826599 | 2015-04-06 16:45:20 -0700 | [diff] [blame] | 7 | package identitylib |
Nicolas LaCasse | c7cdf42 | 2015-01-08 14:11:29 -0800 | [diff] [blame] | 8 | |
| 9 | import ( |
| 10 | "flag" |
| 11 | "fmt" |
Nicolas LaCasse | c7cdf42 | 2015-01-08 14:11:29 -0800 | [diff] [blame] | 12 | "net" |
| 13 | "strconv" |
| 14 | "time" |
| 15 | |
Jiri Simsa | 6ac9522 | 2015-02-23 16:11:49 -0800 | [diff] [blame] | 16 | "v.io/v23" |
Nicolas LaCasse | c7cdf42 | 2015-01-08 14:11:29 -0800 | [diff] [blame] | 17 | |
Suharsh Sivakumar | c004811 | 2015-03-19 11:48:28 -0700 | [diff] [blame] | 18 | "v.io/x/ref/services/identity/internal/auditor" |
| 19 | "v.io/x/ref/services/identity/internal/blesser" |
| 20 | "v.io/x/ref/services/identity/internal/caveats" |
| 21 | "v.io/x/ref/services/identity/internal/oauth" |
| 22 | "v.io/x/ref/services/identity/internal/revocation" |
| 23 | "v.io/x/ref/services/identity/internal/server" |
| 24 | "v.io/x/ref/services/identity/internal/util" |
Cosmos Nicolaou | 1381f8a | 2015-03-13 09:40:34 -0700 | [diff] [blame] | 25 | "v.io/x/ref/test/modules" |
Nicolas LaCasse | c7cdf42 | 2015-01-08 14:11:29 -0800 | [diff] [blame] | 26 | ) |
| 27 | |
| 28 | var ( |
Suharsh Sivakumar | 510d43f | 2015-04-01 18:13:26 -0700 | [diff] [blame] | 29 | externalHttpAddr = flag.String("external-http-addr", "", "External address on which the HTTP server listens on. If none is provided the server will only listen on -http-addr.") |
| 30 | httpAddr = flag.CommandLine.String("http-addr", "localhost:0", "Address on which the HTTP server listens on.") |
| 31 | tlsConfig = flag.CommandLine.String("tls-config", "", "Comma-separated list of TLS certificate and private key files. This must be provided.") |
Nicolas LaCasse | c7cdf42 | 2015-01-08 14:11:29 -0800 | [diff] [blame] | 32 | ) |
| 33 | |
Todd Wang | 9587390 | 2015-05-22 14:21:30 -0700 | [diff] [blame] | 34 | var TestIdentityd = modules.Register(func(env *modules.Env, args ...string) error { |
Nicolas LaCasse | c7cdf42 | 2015-01-08 14:11:29 -0800 | [diff] [blame] | 35 | // Duration to use for tls cert and blessing duration. |
| 36 | duration := 365 * 24 * time.Hour |
| 37 | |
Jiri Simsa | 6ac9522 | 2015-02-23 16:11:49 -0800 | [diff] [blame] | 38 | ctx, shutdown := v23.Init() |
Suharsh Sivakumar | 9d17e4a | 2015-02-02 22:42:16 -0800 | [diff] [blame] | 39 | defer shutdown() |
| 40 | |
Suharsh Sivakumar | 510d43f | 2015-04-01 18:13:26 -0700 | [diff] [blame] | 41 | // If no tls-config has been provided, generate new cert and key and use them. |
| 42 | if flag.CommandLine.Lookup("tls-config").Value.String() == "" { |
Suharsh Sivakumar | 4a30f21 | 2015-03-25 17:03:42 -0700 | [diff] [blame] | 43 | addr := *externalHttpAddr |
| 44 | if *externalHttpAddr == "" { |
| 45 | addr = *httpAddr |
| 46 | } |
| 47 | host, _, err := net.SplitHostPort(addr) |
| 48 | if err != nil { |
Bogdan Caprita | 013b106 | 2015-05-06 17:15:15 -0700 | [diff] [blame] | 49 | return fmt.Errorf("Failed to parse %q: %v", addr, err) |
Suharsh Sivakumar | 4a30f21 | 2015-03-25 17:03:42 -0700 | [diff] [blame] | 50 | } |
| 51 | certFile, keyFile, err := util.WriteCertAndKey(host, duration) |
Nicolas LaCasse | c7cdf42 | 2015-01-08 14:11:29 -0800 | [diff] [blame] | 52 | if err != nil { |
| 53 | return fmt.Errorf("Could not write cert and key: %v", err) |
| 54 | } |
Suharsh Sivakumar | 510d43f | 2015-04-01 18:13:26 -0700 | [diff] [blame] | 55 | if err := flag.CommandLine.Set("tls-config", certFile+","+keyFile); err != nil { |
| 56 | return fmt.Errorf("Could not set tls-config: %v", err) |
Nicolas LaCasse | c7cdf42 | 2015-01-08 14:11:29 -0800 | [diff] [blame] | 57 | } |
| 58 | } |
| 59 | |
Suharsh Sivakumar | 510d43f | 2015-04-01 18:13:26 -0700 | [diff] [blame] | 60 | // Pick a free port if http-addr flag is not set. |
Suharsh Sivakumar | 9d17e4a | 2015-02-02 22:42:16 -0800 | [diff] [blame] | 61 | // We can't use :0 here, because the identity server calls |
| 62 | // http.ListenAndServeTLS, which blocks, leaving us with no way to tell |
Nicolas LaCasse | c7cdf42 | 2015-01-08 14:11:29 -0800 | [diff] [blame] | 63 | // what port the server is running on. Hence, we must pass in an |
| 64 | // actual port so we know where the server is running. |
Suharsh Sivakumar | 510d43f | 2015-04-01 18:13:26 -0700 | [diff] [blame] | 65 | if flag.CommandLine.Lookup("http-addr").Value.String() == flag.CommandLine.Lookup("http-addr").DefValue { |
| 66 | if err := flag.CommandLine.Set("http-addr", "localhost:"+freePort()); err != nil { |
| 67 | return fmt.Errorf("Could not set http-addr: %v", err) |
Nicolas LaCasse | c7cdf42 | 2015-01-08 14:11:29 -0800 | [diff] [blame] | 68 | } |
| 69 | } |
| 70 | |
Ankur | cb02c52 | 2015-08-18 19:27:43 -0700 | [diff] [blame] | 71 | mockClientID := "test-client-id" |
| 72 | mockClientName := "test-client" |
| 73 | |
Nicolas LaCasse | c7cdf42 | 2015-01-08 14:11:29 -0800 | [diff] [blame] | 74 | auditor, reader := auditor.NewMockBlessingAuditor() |
Cosmos Nicolaou | d922992 | 2015-06-24 14:12:24 -0700 | [diff] [blame] | 75 | revocationManager := revocation.NewMockRevocationManager(ctx) |
Ankur | cb02c52 | 2015-08-18 19:27:43 -0700 | [diff] [blame] | 76 | oauthProvider := oauth.NewMockOAuth("testemail@example.com", mockClientID) |
Nicolas LaCasse | c7cdf42 | 2015-01-08 14:11:29 -0800 | [diff] [blame] | 77 | |
Ankur | 123a5c7 | 2015-01-12 16:03:43 -0800 | [diff] [blame] | 78 | params := blesser.OAuthBlesserParams{ |
| 79 | OAuthProvider: oauthProvider, |
Nicolas LaCasse | c7cdf42 | 2015-01-08 14:11:29 -0800 | [diff] [blame] | 80 | BlessingDuration: duration, |
Nicolas LaCasse | c7cdf42 | 2015-01-08 14:11:29 -0800 | [diff] [blame] | 81 | RevocationManager: revocationManager, |
Ankur | cb02c52 | 2015-08-18 19:27:43 -0700 | [diff] [blame] | 82 | AccessTokenClients: []oauth.AccessTokenClient{ |
| 83 | oauth.AccessTokenClient{ |
| 84 | Name: mockClientName, |
| 85 | ClientID: mockClientID, |
| 86 | }, |
| 87 | }, |
Nicolas LaCasse | c7cdf42 | 2015-01-08 14:11:29 -0800 | [diff] [blame] | 88 | } |
| 89 | |
| 90 | s := server.NewIdentityServer( |
Ankur | 123a5c7 | 2015-01-12 16:03:43 -0800 | [diff] [blame] | 91 | oauthProvider, |
Nicolas LaCasse | c7cdf42 | 2015-01-08 14:11:29 -0800 | [diff] [blame] | 92 | auditor, |
| 93 | reader, |
| 94 | revocationManager, |
Ankur | 123a5c7 | 2015-01-12 16:03:43 -0800 | [diff] [blame] | 95 | params, |
Asim Shankar | c195b6d | 2015-02-03 11:26:55 -0800 | [diff] [blame] | 96 | caveats.NewMockCaveatSelector(), |
Robin Thellend | 1b3c7d8 | 2015-03-26 13:52:37 -0700 | [diff] [blame] | 97 | "", |
| 98 | "identity") |
Nicolas LaCasse | c7cdf42 | 2015-01-08 14:11:29 -0800 | [diff] [blame] | 99 | |
Jiri Simsa | 6ac9522 | 2015-02-23 16:11:49 -0800 | [diff] [blame] | 100 | l := v23.GetListenSpec(ctx) |
Nicolas LaCasse | c7cdf42 | 2015-01-08 14:11:29 -0800 | [diff] [blame] | 101 | |
Suharsh Sivakumar | 510d43f | 2015-04-01 18:13:26 -0700 | [diff] [blame] | 102 | _, eps, externalHttpAddress := s.Listen(ctx, &l, *externalHttpAddr, *httpAddr, *tlsConfig) |
Nicolas LaCasse | c7cdf42 | 2015-01-08 14:11:29 -0800 | [diff] [blame] | 103 | |
Todd Wang | 9587390 | 2015-05-22 14:21:30 -0700 | [diff] [blame] | 104 | fmt.Fprintf(env.Stdout, "TEST_IDENTITYD_NAME=%s\n", eps[0]) |
| 105 | fmt.Fprintf(env.Stdout, "TEST_IDENTITYD_HTTP_ADDR=%s\n", externalHttpAddress) |
Nicolas LaCasse | c7cdf42 | 2015-01-08 14:11:29 -0800 | [diff] [blame] | 106 | |
Todd Wang | 9587390 | 2015-05-22 14:21:30 -0700 | [diff] [blame] | 107 | modules.WaitForEOF(env.Stdin) |
Nicolas LaCasse | c7cdf42 | 2015-01-08 14:11:29 -0800 | [diff] [blame] | 108 | return nil |
Todd Wang | 9587390 | 2015-05-22 14:21:30 -0700 | [diff] [blame] | 109 | }, "TestIdentityd") |
Nicolas LaCasse | c7cdf42 | 2015-01-08 14:11:29 -0800 | [diff] [blame] | 110 | |
| 111 | func freePort() string { |
| 112 | l, _ := net.Listen("tcp", ":0") |
| 113 | defer l.Close() |
| 114 | return strconv.Itoa(l.Addr().(*net.TCPAddr).Port) |
| 115 | } |