Skip to content
Projects
Groups
Snippets
Help
This project
Loading...
Sign in / Register
Toggle navigation
D
django-cas
Overview
Overview
Details
Activity
Cycle Analytics
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Charts
Issues
0
Issues
0
List
Board
Labels
Milestones
Merge Requests
0
Merge Requests
0
CI / CD
CI / CD
Pipelines
Jobs
Schedules
Charts
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Charts
Create a new issue
Jobs
Commits
Issue Boards
Open sidebar
OpenEdx
django-cas
Commits
c59bbaf1
Commit
c59bbaf1
authored
Dec 03, 2010
by
Ed Crewe
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
add url cleanup for valid url for query string
parent
d649b8b2
Hide whitespace changes
Inline
Side-by-side
Showing
1 changed file
with
40 additions
and
18 deletions
+40
-18
django_cas/tests/cas_tests.py
+40
-18
No files found.
django_cas/tests/cas_tests.py
View file @
c59bbaf1
...
@@ -22,10 +22,10 @@ try:
...
@@ -22,10 +22,10 @@ try:
from
test_config
import
*
from
test_config
import
*
except
:
except
:
# Please edit these urls to match your cas server, proxy and app server urls
# Please edit these urls to match your cas server, proxy and app server urls
CAS_SERVER_URL
=
'https://my.sso.server'
CAS_SERVER_URL
=
'https://my.sso.server
/
'
APP_URL
=
'http://my.client.application'
APP_URL
=
'http://my.client.application
/
'
APP_RESTRICTED
=
'restricted'
APP_RESTRICTED
=
'restricted'
PROXY_URL
=
'https://my.proxy.application'
PROXY_URL
=
'https://my.proxy.application
/
'
# Depending on your cas login form you may need to adjust these field name keys
# Depending on your cas login form you may need to adjust these field name keys
TOKEN
=
'token'
# CSRF token field name
TOKEN
=
'token'
# CSRF token field name
CAS_SUCCESS
=
'Login successful'
# CAS server successful login flag (find string in html page)
CAS_SUCCESS
=
'Login successful'
# CAS server successful login flag (find string in html page)
...
@@ -40,6 +40,7 @@ class TestCAS(unittest.TestCase):
...
@@ -40,6 +40,7 @@ class TestCAS(unittest.TestCase):
opener
=
None
opener
=
None
auth
=
{}
auth
=
{}
urls
=
{}
def
setUp
(
self
):
def
setUp
(
self
):
cj
=
cookielib
.
CookieJar
()
cj
=
cookielib
.
CookieJar
()
...
@@ -47,12 +48,29 @@ class TestCAS(unittest.TestCase):
...
@@ -47,12 +48,29 @@ class TestCAS(unittest.TestCase):
urllib2
.
install_opener
(
opener
)
urllib2
.
install_opener
(
opener
)
self
.
opener
=
opener
self
.
opener
=
opener
self
.
get_auth
()
self
.
get_auth
()
self
.
set_url
(
'cas'
,
CAS_SERVER_URL
)
self
.
set_url
(
'app'
,
APP_URL
)
self
.
set_url
(
'proxy'
,
PROXY_URL
)
def
set_url
(
self
,
name
,
url
):
""" Make sure valid url with query string appended """
for
end
in
[
'/'
,
'.html'
,
'.htm'
]:
if
url
.
endswith
(
end
):
self
.
urls
[
name
]
=
url
return
self
.
urls
[
name
]
=
'
%
s/'
%
url
def
test_cas
(
self
):
def
test_cas
(
self
):
""" Test ordinary and proxy CAS login
""" Test ordinary and proxy CAS login
NB cant put these into separate tests since tickets
NB cant put these into separate tests since tickets
are required to be passed between tests
are required to be passed between tests
"""
"""
print
'Testing with following URLs'
print
'---------------------------'
print
'CAS server =
%
s'
%
self
.
urls
[
'cas'
]
print
'Application server =
%
s'
%
self
.
urls
[
'app'
]
print
'Proxy CAS server =
%
s'
%
self
.
urls
[
'proxy'
]
print
''
print
'Test ordinary CAS login'
print
'Test ordinary CAS login'
print
'-----------------------'
print
'-----------------------'
self
.
ticket
=
self
.
login
()
self
.
ticket
=
self
.
login
()
...
@@ -64,7 +82,7 @@ class TestCAS(unittest.TestCase):
...
@@ -64,7 +82,7 @@ class TestCAS(unittest.TestCase):
iou
=
self
.
proxy1_iou
()
iou
=
self
.
proxy1_iou
()
if
iou
.
startswith
(
'PGT'
):
if
iou
.
startswith
(
'PGT'
):
print
'PASS: Got IOU -
%
s for
%
s'
%
(
iou
,
PROXY_URL
)
print
'PASS: Got IOU -
%
s for
%
s'
%
(
iou
,
self
.
urls
[
'proxy'
]
)
else
:
else
:
print
iou
print
iou
...
@@ -83,9 +101,9 @@ class TestCAS(unittest.TestCase):
...
@@ -83,9 +101,9 @@ class TestCAS(unittest.TestCase):
proxy
=
self
.
proxy4_login
(
pt
)
proxy
=
self
.
proxy4_login
(
pt
)
if
proxy
:
if
proxy
:
print
'PASS: Logged in successfully to
%
s via
%
s'
%
(
APP_URL
,
proxy
)
print
'PASS: Logged in successfully to
%
s via
%
s'
%
(
self
.
urls
[
'app'
]
,
proxy
)
else
:
else
:
print
'FAIL: The proxy login to
%
s via
%
s has failed'
%
(
APP_URL
,
PROXY_URL
)
print
'FAIL: The proxy login to
%
s via
%
s has failed'
%
(
self
.
urls
[
'app'
],
self
.
urls
[
'proxy'
]
)
def
get_auth
(
self
):
def
get_auth
(
self
):
...
@@ -99,12 +117,16 @@ class TestCAS(unittest.TestCase):
...
@@ -99,12 +117,16 @@ class TestCAS(unittest.TestCase):
def
get_token
(
self
,
url
,
token
=
TOKEN
):
def
get_token
(
self
,
url
,
token
=
TOKEN
):
""" Get CSRF token """
""" Get CSRF token """
r
=
self
.
opener
.
open
(
url
)
try
:
r
=
self
.
opener
.
open
(
url
)
except
:
return
'FAIL: URL not found
%
s'
%
url
page
=
r
.
read
()
page
=
r
.
read
()
starts
=
[
'<input type="hidden" name="
%
s"'
%
token
,
starts
=
[
'<input type="hidden" name="
%
s"'
%
token
,
'value="'
]
'value="'
]
return
self
.
find_in_page
(
page
,
starts
,
'"'
)
return
self
.
find_in_page
(
page
,
starts
,
'"'
)
def
get_ticket
(
self
,
page
,
app_url
):
def
get_ticket
(
self
,
page
,
app_url
):
""" Get CSRF token """
""" Get CSRF token """
starts
=
[
app_url
,
'?ticket='
]
starts
=
[
app_url
,
'?ticket='
]
...
@@ -146,7 +168,7 @@ class TestCAS(unittest.TestCase):
...
@@ -146,7 +168,7 @@ class TestCAS(unittest.TestCase):
def
login
(
self
):
def
login
(
self
):
""" Login to CAS server """
""" Login to CAS server """
url
=
'
%
s
/login?service=
%
s'
%
(
CAS_SERVER_URL
,
APP_URL
)
url
=
'
%
s
login?service=
%
s'
%
(
self
.
urls
[
'cas'
],
self
.
urls
[
'app'
]
)
ticket
=
''
ticket
=
''
token
=
self
.
get_token
(
url
)
token
=
self
.
get_token
(
url
)
if
token
:
if
token
:
...
@@ -158,14 +180,14 @@ class TestCAS(unittest.TestCase):
...
@@ -158,14 +180,14 @@ class TestCAS(unittest.TestCase):
else
:
else
:
print
'FAIL: CSRF Token could not be found on page'
print
'FAIL: CSRF Token could not be found on page'
return
ticket
return
ticket
self
.
auth
[
'service'
]
=
APP_URL
self
.
auth
[
'service'
]
=
self
.
urls
[
'app'
]
data
=
urllib
.
urlencode
(
self
.
auth
)
data
=
urllib
.
urlencode
(
self
.
auth
)
sso_resp
=
self
.
opener
.
open
(
url
,
data
)
sso_resp
=
self
.
opener
.
open
(
url
,
data
)
sso_page
=
sso_resp
.
read
()
sso_page
=
sso_resp
.
read
()
found
=
sso_page
.
find
(
CAS_SUCCESS
)
>
-
1
found
=
sso_page
.
find
(
CAS_SUCCESS
)
>
-
1
sso_resp
.
close
()
sso_resp
.
close
()
if
found
:
if
found
:
ticket
=
self
.
get_ticket
(
sso_page
,
APP_URL
)
ticket
=
self
.
get_ticket
(
sso_page
,
self
.
urls
[
'app'
]
)
print
'PASS: CAS logged in to
%
s'
%
url
print
'PASS: CAS logged in to
%
s'
%
url
else
:
else
:
print
'FAIL: Couldnt login to
%
s'
%
url
print
'FAIL: Couldnt login to
%
s'
%
url
...
@@ -173,7 +195,7 @@ class TestCAS(unittest.TestCase):
...
@@ -173,7 +195,7 @@ class TestCAS(unittest.TestCase):
def
get_restricted
(
self
):
def
get_restricted
(
self
):
""" Access a restricted URL and see if its accessible """
""" Access a restricted URL and see if its accessible """
url
=
APP_URL
+
APP_RESTRICTED
url
=
self
.
urls
[
'app'
]
+
APP_RESTRICTED
app_resp
=
self
.
opener
.
open
(
url
)
app_resp
=
self
.
opener
.
open
(
url
)
ok
=
app_resp
.
code
==
200
ok
=
app_resp
.
code
==
200
app_resp
.
close
()
app_resp
.
close
()
...
@@ -185,10 +207,10 @@ class TestCAS(unittest.TestCase):
...
@@ -185,10 +207,10 @@ class TestCAS(unittest.TestCase):
def
proxy1_iou
(
self
):
def
proxy1_iou
(
self
):
""" Use login ticket to get proxy iou
""" Use login ticket to get proxy iou
NB: SSO server installation may require
PROXY_URL
/?pgtIou be called at the root
NB: SSO server installation may require
self.urls['proxy']
/?pgtIou be called at the root
"""
"""
url_args
=
(
CAS_SERVER_URL
,
self
.
ticket
,
APP_URL
,
PROXY_URL
)
url_args
=
(
self
.
urls
[
'cas'
],
self
.
ticket
,
self
.
urls
[
'app'
],
self
.
urls
[
'proxy'
]
)
url
=
'
%
s
/
serviceValidate?ticket=
%
s&service=
%
s&pgtUrl=
%
s'
%
url_args
url
=
'
%
sserviceValidate?ticket=
%
s&service=
%
s&pgtUrl=
%
s'
%
url_args
try
:
try
:
iou
=
self
.
opener
.
open
(
url
)
iou
=
self
.
opener
.
open
(
url
)
except
:
except
:
...
@@ -223,8 +245,8 @@ class TestCAS(unittest.TestCase):
...
@@ -223,8 +245,8 @@ class TestCAS(unittest.TestCase):
def
proxy3_pt
(
self
,
pgt
):
def
proxy3_pt
(
self
,
pgt
):
""" Use granting ticket to get proxy """
""" Use granting ticket to get proxy """
url_args
=
(
CAS_SERVER_URL
,
APP_URL
,
pgt
)
url_args
=
(
self
.
urls
[
'cas'
],
self
.
urls
[
'app'
]
,
pgt
)
url
=
'
%
s
/
proxy?targetService=
%
s&pgt=
%
s'
%
url_args
url
=
'
%
sproxy?targetService=
%
s&pgt=
%
s'
%
url_args
try
:
try
:
pt
=
self
.
opener
.
open
(
url
)
pt
=
self
.
opener
.
open
(
url
)
except
:
except
:
...
@@ -239,8 +261,8 @@ class TestCAS(unittest.TestCase):
...
@@ -239,8 +261,8 @@ class TestCAS(unittest.TestCase):
def
proxy4_login
(
self
,
pt
):
def
proxy4_login
(
self
,
pt
):
""" Use proxy ticket to login """
""" Use proxy ticket to login """
url_args
=
(
CAS_SERVER_URL
,
APP_URL
,
pt
)
url_args
=
(
self
.
urls
[
'cas'
],
self
.
urls
[
'app'
]
,
pt
)
url
=
'
%
s
/
proxyValidate?service=
%
s&ticket=
%
s'
%
url_args
url
=
'
%
sproxyValidate?service=
%
s&ticket=
%
s'
%
url_args
try
:
try
:
login
=
self
.
opener
.
open
(
url
)
login
=
self
.
opener
.
open
(
url
)
except
:
except
:
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment