KickJava   Java API By Example, From Geeks To Geeks.

Java > Open Source Codes > org > jboss > test > web > security > jacc > DataWebConstraintsUnitTestCase


1 /*
2 * JBoss, Home of Professional Open Source
3 * Copyright 2005, JBoss Inc., and individual contributors as indicated
4 * by the @authors tag. See the copyright.txt in the distribution for a
5 * full listing of individual contributors.
6 *
7 * This is free software; you can redistribute it and/or modify it
8 * under the terms of the GNU Lesser General Public License as
9 * published by the Free Software Foundation; either version 2.1 of
10 * the License, or (at your option) any later version.
11 *
12 * This software is distributed in the hope that it will be useful,
13 * but WITHOUT ANY WARRANTY; without even the implied warranty of
14 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
15 * Lesser General Public License for more details.
16 *
17 * You should have received a copy of the GNU Lesser General Public
18 * License along with this software; if not, write to the Free
19 * Software Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA
20 * 02110-1301 USA, or see the FSF site: http://www.fsf.org.
21 */

22 package org.jboss.test.web.security.jacc;
23
24 import java.security.Policy JavaDoc;
25 import java.security.ProtectionDomain JavaDoc;
26 import java.util.ArrayList JavaDoc;
27 import java.util.List JavaDoc;
28 import javax.security.jacc.PolicyConfiguration JavaDoc;
29 import javax.security.jacc.PolicyContext JavaDoc;
30 import javax.security.jacc.WebResourcePermission JavaDoc;
31
32 import junit.framework.TestCase;
33 import org.jboss.metadata.WebMetaData;
34 import org.jboss.metadata.WebSecurityMetaData;
35 import org.jboss.security.SimplePrincipal;
36 import org.jboss.security.jacc.DelegatingPolicy;
37 import org.jboss.security.jacc.JBossPolicyConfigurationFactory;
38 import org.jboss.web.WebPermissionMapping;
39
40 /**
41
42  * @author Scott.Stark@jboss.org
43  * @version $Revision: 37459 $
44  */

45 public class DataWebConstraintsUnitTestCase extends TestCase
46 {
47    public void testUncheckedExact() throws Exception JavaDoc
48    {
49       Policy JavaDoc p = Policy.getPolicy();
50       SimplePrincipal[] caller = null;
51       ProtectionDomain JavaDoc pd = new ProtectionDomain JavaDoc(null, null, null, caller);
52
53       WebResourcePermission JavaDoc wrp = new WebResourcePermission JavaDoc("/", "GET");
54       assertTrue("/ GET", p.implies(pd, wrp));
55       wrp = new WebResourcePermission JavaDoc("/", "POST");
56       assertTrue("/ POST", p.implies(pd, wrp));
57       wrp = new WebResourcePermission JavaDoc("/any", "POST");
58       assertTrue("/any POST", p.implies(pd, wrp));
59       wrp = new WebResourcePermission JavaDoc("/", "DELETE");
60       assertTrue("/any DELETE", p.implies(pd, wrp));
61
62    }
63
64    protected void setUp() throws Exception JavaDoc
65    {
66       PolicyConfiguration JavaDoc pc;
67       WebMetaData metaData = new WebMetaData();
68       ArrayList JavaDoc securityContraints = new ArrayList JavaDoc();
69       addSC(securityContraints);
70       metaData.setSecurityConstraints(securityContraints);
71
72       DelegatingPolicy policy = new DelegatingPolicy();
73       Policy.setPolicy(policy);
74       JBossPolicyConfigurationFactory pcf = new JBossPolicyConfigurationFactory();
75       pc = pcf.getPolicyConfiguration("UncheckedWebConstraintsUnitTestCase", true);
76       WebPermissionMapping.createPermissions(metaData, pc);
77       pc.commit();
78       System.out.println(policy.listContextPolicies());
79       PolicyContext.setContextID("UncheckedWebConstraintsUnitTestCase");
80    }
81
82    /*
83    <security-constraint>
84        <web-resource-collection>
85            <web-resource-name>SSL Only</web-resource-name>
86            <url-pattern>/*</url-pattern>
87        </web-resource-collection>
88        <user-data-constraint>
89             <transport-guarantee>CONFIDENTIAL</transport-guarantee>
90        </user-data-constraint>
91    </security-constraint>
92    */

93    private void addSC(List JavaDoc securityContraints)
94    {
95       WebSecurityMetaData wsmd = new WebSecurityMetaData();
96       securityContraints.add(wsmd);
97       // web-resource-collection/web-resource-name = exact, get method, roleA
98
WebSecurityMetaData.WebResourceCollection wrc = wsmd.addWebResource("SSL Only");
99       wrc.addPattern("/*");
100       wsmd.setUnchecked(true);
101       wsmd.setTransportGuarantee("CONFIDENTIAL");
102    }
103
104 }
105
Popular Tags