2022-06-30 01:46:41 +02:00
|
|
|
|
using System.Security.Claims;
|
2021-11-15 10:46:13 +01:00
|
|
|
|
using AutoFixture.Xunit2;
|
|
|
|
|
using Bit.Api.Controllers;
|
2023-04-14 19:25:56 +02:00
|
|
|
|
using Bit.Core.Auth.Entities;
|
2023-05-10 21:52:08 +02:00
|
|
|
|
using Bit.Core.Auth.Enums;
|
2023-04-14 19:25:56 +02:00
|
|
|
|
using Bit.Core.Auth.Models.Data;
|
|
|
|
|
using Bit.Core.Auth.Repositories;
|
|
|
|
|
using Bit.Core.Auth.Services;
|
2021-11-15 10:46:13 +01:00
|
|
|
|
using Bit.Core.Context;
|
2022-01-11 10:40:51 +01:00
|
|
|
|
using Bit.Core.Entities;
|
2021-11-15 10:46:13 +01:00
|
|
|
|
using Bit.Core.Exceptions;
|
2022-05-10 23:12:09 +02:00
|
|
|
|
using Bit.Core.OrganizationFeatures.OrganizationApiKeys.Interfaces;
|
2023-01-30 22:42:10 +01:00
|
|
|
|
using Bit.Core.OrganizationFeatures.OrganizationLicenses.Interfaces;
|
2023-07-25 00:05:05 +02:00
|
|
|
|
using Bit.Core.OrganizationFeatures.OrganizationSubscriptions.Interface;
|
2021-11-15 10:46:13 +01:00
|
|
|
|
using Bit.Core.Repositories;
|
|
|
|
|
using Bit.Core.Services;
|
|
|
|
|
using Bit.Core.Settings;
|
|
|
|
|
using NSubstitute;
|
|
|
|
|
using Xunit;
|
|
|
|
|
|
|
|
|
|
namespace Bit.Api.Test.Controllers;
|
2022-08-29 22:06:55 +02:00
|
|
|
|
|
2021-11-15 10:46:13 +01:00
|
|
|
|
public class OrganizationsControllerTests : IDisposable
|
|
|
|
|
{
|
|
|
|
|
private readonly GlobalSettings _globalSettings;
|
|
|
|
|
private readonly ICurrentContext _currentContext;
|
|
|
|
|
private readonly IOrganizationRepository _organizationRepository;
|
|
|
|
|
private readonly IOrganizationService _organizationService;
|
|
|
|
|
private readonly IOrganizationUserRepository _organizationUserRepository;
|
|
|
|
|
private readonly IPaymentService _paymentService;
|
|
|
|
|
private readonly IPolicyRepository _policyRepository;
|
2023-04-14 12:13:16 +02:00
|
|
|
|
private readonly IProviderRepository _providerRepository;
|
2021-11-15 10:46:13 +01:00
|
|
|
|
private readonly ISsoConfigRepository _ssoConfigRepository;
|
|
|
|
|
private readonly ISsoConfigService _ssoConfigService;
|
|
|
|
|
private readonly IUserService _userService;
|
2022-11-29 01:39:09 +01:00
|
|
|
|
private readonly IGetOrganizationApiKeyQuery _getOrganizationApiKeyQuery;
|
2022-05-10 23:12:09 +02:00
|
|
|
|
private readonly IRotateOrganizationApiKeyCommand _rotateOrganizationApiKeyCommand;
|
|
|
|
|
private readonly IOrganizationApiKeyRepository _organizationApiKeyRepository;
|
2023-01-30 22:42:10 +01:00
|
|
|
|
private readonly ICloudGetOrganizationLicenseQuery _cloudGetOrganizationLicenseQuery;
|
2022-11-29 01:39:09 +01:00
|
|
|
|
private readonly ICreateOrganizationApiKeyCommand _createOrganizationApiKeyCommand;
|
2023-02-23 22:54:19 +01:00
|
|
|
|
private readonly IUpdateOrganizationLicenseCommand _updateOrganizationLicenseCommand;
|
2023-05-10 21:52:08 +02:00
|
|
|
|
private readonly IFeatureService _featureService;
|
2023-05-15 16:38:41 +02:00
|
|
|
|
private readonly ILicensingService _licensingService;
|
2023-07-25 00:05:05 +02:00
|
|
|
|
private readonly IUpdateSecretsManagerSubscriptionCommand _updateSecretsManagerSubscriptionCommand;
|
|
|
|
|
private readonly IUpgradeOrganizationPlanCommand _upgradeOrganizationPlanCommand;
|
2023-08-04 23:51:12 +02:00
|
|
|
|
private readonly IAddSecretsManagerSubscriptionCommand _addSecretsManagerSubscriptionCommand;
|
2022-08-29 22:06:55 +02:00
|
|
|
|
|
2021-11-15 10:46:13 +01:00
|
|
|
|
private readonly OrganizationsController _sut;
|
2022-08-29 22:06:55 +02:00
|
|
|
|
|
2021-11-15 10:46:13 +01:00
|
|
|
|
public OrganizationsControllerTests()
|
|
|
|
|
{
|
|
|
|
|
_currentContext = Substitute.For<ICurrentContext>();
|
|
|
|
|
_globalSettings = Substitute.For<GlobalSettings>();
|
|
|
|
|
_organizationRepository = Substitute.For<IOrganizationRepository>();
|
|
|
|
|
_organizationService = Substitute.For<IOrganizationService>();
|
|
|
|
|
_organizationUserRepository = Substitute.For<IOrganizationUserRepository>();
|
|
|
|
|
_paymentService = Substitute.For<IPaymentService>();
|
|
|
|
|
_policyRepository = Substitute.For<IPolicyRepository>();
|
2023-04-14 12:13:16 +02:00
|
|
|
|
_providerRepository = Substitute.For<IProviderRepository>();
|
2021-11-15 10:46:13 +01:00
|
|
|
|
_ssoConfigRepository = Substitute.For<ISsoConfigRepository>();
|
|
|
|
|
_ssoConfigService = Substitute.For<ISsoConfigService>();
|
2022-11-29 01:39:09 +01:00
|
|
|
|
_getOrganizationApiKeyQuery = Substitute.For<IGetOrganizationApiKeyQuery>();
|
2022-05-10 23:12:09 +02:00
|
|
|
|
_rotateOrganizationApiKeyCommand = Substitute.For<IRotateOrganizationApiKeyCommand>();
|
|
|
|
|
_organizationApiKeyRepository = Substitute.For<IOrganizationApiKeyRepository>();
|
2021-11-15 10:46:13 +01:00
|
|
|
|
_userService = Substitute.For<IUserService>();
|
2023-01-30 22:42:10 +01:00
|
|
|
|
_cloudGetOrganizationLicenseQuery = Substitute.For<ICloudGetOrganizationLicenseQuery>();
|
2022-11-29 01:39:09 +01:00
|
|
|
|
_createOrganizationApiKeyCommand = Substitute.For<ICreateOrganizationApiKeyCommand>();
|
2023-02-23 22:54:19 +01:00
|
|
|
|
_updateOrganizationLicenseCommand = Substitute.For<IUpdateOrganizationLicenseCommand>();
|
2023-05-10 21:52:08 +02:00
|
|
|
|
_featureService = Substitute.For<IFeatureService>();
|
2023-05-15 16:38:41 +02:00
|
|
|
|
_licensingService = Substitute.For<ILicensingService>();
|
2023-07-25 00:05:05 +02:00
|
|
|
|
_updateSecretsManagerSubscriptionCommand = Substitute.For<IUpdateSecretsManagerSubscriptionCommand>();
|
|
|
|
|
_upgradeOrganizationPlanCommand = Substitute.For<IUpgradeOrganizationPlanCommand>();
|
2023-08-04 23:51:12 +02:00
|
|
|
|
_addSecretsManagerSubscriptionCommand = Substitute.For<IAddSecretsManagerSubscriptionCommand>();
|
2022-08-29 20:53:16 +02:00
|
|
|
|
|
2021-11-15 10:46:13 +01:00
|
|
|
|
_sut = new OrganizationsController(_organizationRepository, _organizationUserRepository,
|
2023-04-14 12:13:16 +02:00
|
|
|
|
_policyRepository, _providerRepository, _organizationService, _userService, _paymentService, _currentContext,
|
2022-11-29 01:39:09 +01:00
|
|
|
|
_ssoConfigRepository, _ssoConfigService, _getOrganizationApiKeyQuery, _rotateOrganizationApiKeyCommand,
|
2023-02-23 22:54:19 +01:00
|
|
|
|
_createOrganizationApiKeyCommand, _organizationApiKeyRepository, _updateOrganizationLicenseCommand,
|
2023-07-25 00:05:05 +02:00
|
|
|
|
_cloudGetOrganizationLicenseQuery, _featureService, _globalSettings, _licensingService,
|
2023-08-04 23:51:12 +02:00
|
|
|
|
_updateSecretsManagerSubscriptionCommand, _upgradeOrganizationPlanCommand, _addSecretsManagerSubscriptionCommand);
|
2022-08-29 22:06:55 +02:00
|
|
|
|
}
|
|
|
|
|
|
2021-11-15 10:46:13 +01:00
|
|
|
|
public void Dispose()
|
2022-08-29 22:06:55 +02:00
|
|
|
|
{
|
2021-11-15 10:46:13 +01:00
|
|
|
|
_sut?.Dispose();
|
2022-08-29 22:06:55 +02:00
|
|
|
|
}
|
|
|
|
|
|
2021-11-15 10:46:13 +01:00
|
|
|
|
[Theory, AutoData]
|
2021-11-18 12:15:22 +01:00
|
|
|
|
public async Task OrganizationsController_UserCannotLeaveOrganizationThatProvidesKeyConnector(
|
|
|
|
|
Guid orgId, User user)
|
2022-08-29 22:06:55 +02:00
|
|
|
|
{
|
2021-11-15 10:46:13 +01:00
|
|
|
|
var ssoConfig = new SsoConfig
|
|
|
|
|
{
|
|
|
|
|
Id = default,
|
|
|
|
|
Data = new SsoConfigurationData
|
|
|
|
|
{
|
2023-05-10 21:52:08 +02:00
|
|
|
|
MemberDecryptionType = MemberDecryptionType.KeyConnector
|
2021-11-17 11:46:35 +01:00
|
|
|
|
}.Serialize(),
|
2021-11-15 10:46:13 +01:00
|
|
|
|
Enabled = true,
|
|
|
|
|
OrganizationId = orgId,
|
|
|
|
|
};
|
2022-08-29 22:06:55 +02:00
|
|
|
|
|
2021-11-18 12:15:22 +01:00
|
|
|
|
user.UsesKeyConnector = true;
|
2022-08-29 22:06:55 +02:00
|
|
|
|
|
2021-11-15 10:46:13 +01:00
|
|
|
|
_currentContext.OrganizationUser(orgId).Returns(true);
|
|
|
|
|
_ssoConfigRepository.GetByOrganizationIdAsync(orgId).Returns(ssoConfig);
|
2021-11-22 10:55:25 +01:00
|
|
|
|
_userService.GetUserByPrincipalAsync(Arg.Any<ClaimsPrincipal>()).Returns(user);
|
2022-08-29 22:06:55 +02:00
|
|
|
|
|
2021-11-15 10:46:13 +01:00
|
|
|
|
var exception = await Assert.ThrowsAsync<BadRequestException>(
|
|
|
|
|
() => _sut.Leave(orgId.ToString()));
|
2022-08-29 22:06:55 +02:00
|
|
|
|
|
2021-11-21 23:22:28 +01:00
|
|
|
|
Assert.Contains("Your organization's Single Sign-On settings prevent you from leaving.",
|
2021-11-15 10:46:13 +01:00
|
|
|
|
exception.Message);
|
2022-08-29 22:06:55 +02:00
|
|
|
|
|
2021-11-15 10:46:13 +01:00
|
|
|
|
await _organizationService.DidNotReceiveWithAnyArgs().DeleteUserAsync(default, default);
|
|
|
|
|
}
|
2022-08-29 22:06:55 +02:00
|
|
|
|
|
2021-11-18 12:15:22 +01:00
|
|
|
|
[Theory]
|
|
|
|
|
[InlineAutoData(true, false)]
|
|
|
|
|
[InlineAutoData(false, true)]
|
|
|
|
|
[InlineAutoData(false, false)]
|
|
|
|
|
public async Task OrganizationsController_UserCanLeaveOrganizationThatDoesntProvideKeyConnector(
|
|
|
|
|
bool keyConnectorEnabled, bool userUsesKeyConnector, Guid orgId, User user)
|
2022-08-29 22:06:55 +02:00
|
|
|
|
{
|
2021-11-18 12:15:22 +01:00
|
|
|
|
var ssoConfig = new SsoConfig
|
|
|
|
|
{
|
|
|
|
|
Id = default,
|
|
|
|
|
Data = new SsoConfigurationData
|
|
|
|
|
{
|
2023-05-10 21:52:08 +02:00
|
|
|
|
MemberDecryptionType = keyConnectorEnabled
|
|
|
|
|
? MemberDecryptionType.KeyConnector
|
|
|
|
|
: MemberDecryptionType.MasterPassword
|
2021-11-18 12:15:22 +01:00
|
|
|
|
}.Serialize(),
|
|
|
|
|
Enabled = true,
|
|
|
|
|
OrganizationId = orgId,
|
|
|
|
|
};
|
2022-08-29 22:06:55 +02:00
|
|
|
|
|
2021-11-18 12:15:22 +01:00
|
|
|
|
user.UsesKeyConnector = userUsesKeyConnector;
|
2022-08-29 22:06:55 +02:00
|
|
|
|
|
2021-11-18 12:15:22 +01:00
|
|
|
|
_currentContext.OrganizationUser(orgId).Returns(true);
|
|
|
|
|
_ssoConfigRepository.GetByOrganizationIdAsync(orgId).Returns(ssoConfig);
|
2021-11-22 10:55:25 +01:00
|
|
|
|
_userService.GetUserByPrincipalAsync(Arg.Any<ClaimsPrincipal>()).Returns(user);
|
2022-08-29 22:06:55 +02:00
|
|
|
|
|
2021-11-18 12:15:22 +01:00
|
|
|
|
await _organizationService.DeleteUserAsync(orgId, user.Id);
|
|
|
|
|
await _organizationService.Received(1).DeleteUserAsync(orgId, user.Id);
|
2021-11-15 10:46:13 +01:00
|
|
|
|
}
|
|
|
|
|
}
|