Этот коммит содержится в:
Mario Vitale
2023-03-27 16:28:42 +02:00
родитель da7a6825ce
Коммит ba6b97fb62
1142 изменённых файлов: 44 добавлений и 44 удалений

Просмотреть файл

@@ -0,0 +1,89 @@
// Copyright (c) 2015-present Mattermost, Inc. All Rights Reserved.
// See LICENSE.txt for license information.
// ***************************************************************
// - [#] indicates a test step (e.g. # Go to a page)
// - [*] indicates an assertion (e.g. * Check the title)
// - Use element ID when selecting an element. Create one if none.
// ***************************************************************
// - Requires openldap and keycloak running
// - Requires keycloak certificate at fixtures folder
// -> copy ./mattermost-server/build/docker/keycloak/keycloak.crt to ./mattermost-webapp/e2e/cypress/tests/fixtures/keycloak.crt
// - Requires Cypress' chromeWebSecurity to be false
// Group: @channels @enterprise @ldap @saml @keycloak
import {getAdminAccount} from '../../../support/env';
import {getRandomId} from '../../../utils';
import {getKeycloakServerSettings} from '../../../utils/config';
describe('AD / LDAP', () => {
let samlLdapUser;
let testTeamId;
before(() => {
cy.shouldNotRunOnCloudEdition();
cy.apiRequireLicenseForFeature('LDAP', 'SAML');
// # Create new LDAP user
cy.createLDAPUser().then((user) => {
samlLdapUser = user;
});
// # Create new team
cy.apiCreateTeam('saml-team', 'SAML Team').then(({team}) => {
testTeamId = team.id;
});
const samlConfig = getKeycloakServerSettings();
cy.apiUpdateConfig(samlConfig).then(() => {
// # Require keycloak with realm setup
cy.apiRequireKeycloak();
// # Upload certificate, overwrite existing
cy.apiUploadSAMLIDPCert('keycloak.crt');
// # Create Keycloak user and login for the first time
cy.keycloakCreateUsers([samlLdapUser]);
cy.doKeycloakLogin(samlLdapUser);
// # Wait for the UI to be ready which indicates SAML registration is complete
cy.findByText('Logout').click();
});
});
beforeEach(() => {
cy.apiAdminLogin();
cy.apiGetUserByEmail(samlLdapUser.email).then(({user}) => {
cy.apiAddUserToTeam(testTeamId, user.id);
cy.apiRevokeUserSessions(user.id);
});
});
it('MM-T3666 - SAML / LDAP sync with ID Attribute', () => {
// # Login via Keycloak
cy.doKeycloakLogin(samlLdapUser);
// * Check the user settings
cy.verifyAccountNameSettings(samlLdapUser.firstname, samlLdapUser.lastname);
// # Update LDAP user then sync
const randomId = getRandomId();
const newFirstName = `Firstname${randomId}`;
const newLastName = `Lastname${randomId}`;
cy.updateLDAPUser({
...samlLdapUser,
firstname: newFirstName,
lastname: newLastName,
});
const admin = getAdminAccount();
cy.runLdapSync(admin);
// # Reload the page
cy.reload();
// * Check the user settings is in sync with the new attributes
cy.verifyAccountNameSettings(newFirstName, newLastName);
});
});

Просмотреть файл

@@ -0,0 +1,128 @@
// Copyright (c) 2015-present Mattermost, Inc. All Rights Reserved.
// See LICENSE.txt for license information.
// ***************************************************************
// - [#] indicates a test step (e.g. # Go to a page)
// - [*] indicates an assertion (e.g. * Check the title)
// - Use element ID when selecting an element. Create one if none.
// ***************************************************************
// - Requires openldap and keycloak running
// - Requires keycloak certificate at fixtures folder
// -> copy ./mattermost-server/build/docker/keycloak/keycloak.crt to ./mattermost-webapp/e2e/cypress/tests/fixtures/keycloak.crt
// - Requires Cypress' chromeWebSecurity to be false
// Group: @channels @enterprise @ldap @saml @keycloak
import {getAdminAccount} from '../../../support/env';
import {generateLDAPUser} from '../../../support/ldap_server_commands';
import {getKeycloakServerSettings} from '../../../utils/config';
describe('AD / LDAP', () => {
const nonLDAPUser = generateLDAPUser();
let samlLdapUser;
let testTeamId;
before(() => {
cy.createLDAPUser().then((user) => {
samlLdapUser = user;
});
cy.shouldNotRunOnCloudEdition();
cy.apiRequireLicenseForFeature('LDAP', 'SAML');
// # Create new LDAP user
cy.createLDAPUser().then((user) => {
samlLdapUser = user;
});
// # Create new team
cy.apiCreateTeam('saml-team', 'SAML Team').then(({team}) => {
testTeamId = team.id;
});
const samlConfig = getKeycloakServerSettings();
cy.apiUpdateConfig(samlConfig).then(() => {
// # Require keycloak with realm setup
cy.apiRequireKeycloak();
// # Upload certificate, overwrite existing
cy.apiUploadSAMLIDPCert('keycloak.crt');
// # Create Keycloak user and login for the first time
cy.keycloakCreateUsers([samlLdapUser, nonLDAPUser]);
cy.doKeycloakLogin(samlLdapUser);
// # Wait for the UI to be ready which indicates SAML registration is complete
cy.findByText('Logout').click();
});
});
it('MM-T3664 - SAML User, Not in LDAP', () => {
// # Login to Keycloak
cy.doKeycloakLogin(nonLDAPUser);
// * Should render an error since user is not registered in LDAP
cy.findByText('User not registered on AD/LDAP server.');
// # Run LDAP Sync
const admin = getAdminAccount();
cy.runLdapSync(admin);
// # REgister as LDAP user
cy.createLDAPUser({user: nonLDAPUser});
// # Add user to team
cy.apiAdminLogin();
cy.apiGetUserByEmail(nonLDAPUser.email).then(({user}) => {
cy.apiAddUserToTeam(testTeamId, user.id);
});
// # Login to Keycloak
cy.doKeycloakLogin(nonLDAPUser);
// * Should successfully login and view the default channel
cy.postMessage('hello');
// * Check user setting is in sync with LDAP
cy.verifyAccountNameSettings(nonLDAPUser.firstname, nonLDAPUser.lastname);
});
it('MM-T3665 - Deactivate user in SAML', () => {
// # Add user to team
cy.apiAdminLogin();
cy.apiGetUserByEmail(samlLdapUser.email).then(({user}) => {
cy.apiAddUserToTeam(testTeamId, user.id);
});
// # Login to Keycloak
cy.doKeycloakLogin(samlLdapUser);
// * Should successfully login and view the default channel
cy.postMessage('hello');
// # Suspend Keycloak user
cy.keycloakSuspendUser(samlLdapUser.email);
// # Login to Keycloak
cy.doKeycloakLogin(samlLdapUser);
// * Verify login failed
cy.verifyKeycloakLoginFailed();
// # Activate user in keycloak
cy.keycloakUnsuspendUser(samlLdapUser.email);
// # Login again
cy.findByText('Password').type(samlLdapUser.password);
cy.findAllByText('Log In').last().click();
// * Should successfully login and view the default channel
cy.postMessage('hello');
// * Check the user settings
cy.verifyAccountNameSettings(samlLdapUser.firstname, samlLdapUser.lastname);
});
});

Просмотреть файл

@@ -0,0 +1,115 @@
// Copyright (c) 2015-present Mattermost, Inc. All Rights Reserved.
// See LICENSE.txt for license information.
// ***************************************************************
// - [#] indicates a test step (e.g. # Go to a page)
// - [*] indicates an assertion (e.g. * Check the title)
// - Use element ID when selecting an element. Create one if none.
// ***************************************************************
// - Requires openldap and keycloak running
// - Requires keycloak certificate at fixtures folder
// -> copy ./mattermost-server/build/docker/keycloak/keycloak.crt to ./mattermost-webapp/e2e/cypress/tests/fixtures/keycloak.crt
// - Requires Cypress' chromeWebSecurity to be false
// Group: @channels @enterprise @ldap @saml @keycloak
import {getAdminAccount} from '../../../support/env';
import {getRandomId} from '../../../utils';
import {getKeycloakServerSettings} from '../../../utils/config';
describe('AD / LDAP', () => {
const admin = getAdminAccount();
const samlConfig = getKeycloakServerSettings();
let samlLdapUser;
let testTeamId;
before(() => {
cy.shouldNotRunOnCloudEdition();
cy.apiRequireLicenseForFeature('LDAP', 'SAML');
// # Create new LDAP user
cy.createLDAPUser().then((user) => {
samlLdapUser = user;
});
// # Create new team
cy.apiCreateTeam('saml-team', 'SAML Team').then(({team}) => {
testTeamId = team.id;
});
cy.apiUpdateConfig(samlConfig).then(() => {
// # Require keycloak with realm setup
cy.apiRequireKeycloak();
// # Upload certificate, overwrite existing
cy.apiUploadSAMLIDPCert('keycloak.crt');
// # Create Keycloak user and login for the first time
cy.keycloakCreateUsers([samlLdapUser]);
cy.doKeycloakLogin(samlLdapUser);
// # Wait for the UI to be ready which indicates SAML registration is complete
cy.findByText('Logout').click();
// # Add user to team
cy.apiAdminLogin();
cy.apiGetUserByEmail(samlLdapUser.email).then(({user}) => {
cy.apiAddUserToTeam(testTeamId, user.id);
});
});
});
it('MM-T3013_1 - SAML LDAP Sync Off, user attributes pulled from SAML', () => {
// # Login to Keycloak
cy.doKeycloakLogin(samlLdapUser);
// * Check the user settings
cy.verifyAccountNameSettings(samlLdapUser.firstname, samlLdapUser.lastname);
// # Run LDAP Sync
cy.runLdapSync(admin);
// Refresh make sure user not logged out.
cy.reload();
// * Check the user settings
cy.verifyAccountNameSettings(samlLdapUser.firstname, samlLdapUser.lastname);
});
it('MM-T3013_2 - SAML LDAP Sync On, user attributes pulled from LDAP', () => {
const testConfig = {
...samlConfig,
SamlSettings: {
...samlConfig.SamlSettings,
EnableSyncWithLdap: true,
},
};
cy.apiAdminLogin();
cy.apiUpdateConfig(testConfig);
// # Login to Keycloak
cy.doKeycloakLogin(samlLdapUser);
// * Check the user settings
cy.verifyAccountNameSettings(samlLdapUser.firstname, samlLdapUser.lastname);
// # Update LDAP user then sync
const randomId = getRandomId();
const newFirstName = `Firstname${randomId}`;
const newLastName = `Lastname${randomId}`;
cy.updateLDAPUser({
...samlLdapUser,
firstname: newFirstName,
lastname: newLastName,
});
cy.runLdapSync(admin);
// # Refresh make sure user not logged out.
cy.reload();
// * Check the user settings
cy.verifyAccountNameSettings(newFirstName, newLastName);
});
});