forked from quarkusio/quarkus
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Merge pull request quarkusio#40857 from michalvavrik/feature/websocke…
…ts-close-onauth-expired WebSocket NEXT: automatically close connection when OIDC extension provides SecurityIdentity and token expires
- Loading branch information
Showing
5 changed files
with
175 additions
and
7 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
129 changes: 129 additions & 0 deletions
129
...ent/src/test/java/io/quarkus/websockets/next/test/security/AuthenticationExpiredTest.java
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,129 @@ | ||
package io.quarkus.websockets.next.test.security; | ||
|
||
import static io.quarkus.websockets.next.test.security.SecurityTestBase.basicAuth; | ||
import static org.junit.jupiter.api.Assertions.assertEquals; | ||
import static org.junit.jupiter.api.Assertions.assertTrue; | ||
|
||
import java.net.URI; | ||
import java.time.Duration; | ||
import java.util.concurrent.atomic.AtomicReference; | ||
|
||
import jakarta.inject.Inject; | ||
import jakarta.inject.Singleton; | ||
|
||
import org.awaitility.Awaitility; | ||
import org.junit.jupiter.api.Assertions; | ||
import org.junit.jupiter.api.BeforeAll; | ||
import org.junit.jupiter.api.Test; | ||
import org.junit.jupiter.api.extension.RegisterExtension; | ||
|
||
import io.quarkus.security.Authenticated; | ||
import io.quarkus.security.identity.AuthenticationRequestContext; | ||
import io.quarkus.security.identity.SecurityIdentity; | ||
import io.quarkus.security.identity.SecurityIdentityAugmentor; | ||
import io.quarkus.security.runtime.QuarkusSecurityIdentity; | ||
import io.quarkus.security.test.utils.TestIdentityController; | ||
import io.quarkus.security.test.utils.TestIdentityProvider; | ||
import io.quarkus.test.QuarkusUnitTest; | ||
import io.quarkus.test.common.http.TestHTTPResource; | ||
import io.quarkus.websockets.next.CloseReason; | ||
import io.quarkus.websockets.next.OnClose; | ||
import io.quarkus.websockets.next.OnTextMessage; | ||
import io.quarkus.websockets.next.WebSocket; | ||
import io.quarkus.websockets.next.WebSocketConnection; | ||
import io.quarkus.websockets.next.test.utils.WSClient; | ||
import io.smallrye.mutiny.Uni; | ||
import io.vertx.core.Vertx; | ||
import io.vertx.core.buffer.Buffer; | ||
|
||
public class AuthenticationExpiredTest { | ||
|
||
@Inject | ||
Vertx vertx; | ||
|
||
@TestHTTPResource("end") | ||
URI endUri; | ||
|
||
@BeforeAll | ||
public static void setupUsers() { | ||
TestIdentityController.resetRoles() | ||
.add("admin", "admin", "admin") | ||
.add("user", "user", "user"); | ||
} | ||
|
||
@RegisterExtension | ||
static final QuarkusUnitTest config = new QuarkusUnitTest() | ||
.withApplicationRoot(root -> root.addClasses(Endpoint.class, TestIdentityProvider.class, | ||
TestIdentityController.class, WSClient.class, ExpiredIdentityAugmentor.class, SecurityTestBase.class)); | ||
|
||
@Test | ||
public void testConnectionClosedWhenAuthExpires() { | ||
try (WSClient client = new WSClient(vertx)) { | ||
client.connect(basicAuth("admin", "admin"), endUri); | ||
|
||
long threeSecondsFromNow = Duration.ofMillis(System.currentTimeMillis()).plusSeconds(3).toMillis(); | ||
for (int i = 1; true; i++) { | ||
if (client.isClosed()) { | ||
break; | ||
} else if (System.currentTimeMillis() > threeSecondsFromNow) { | ||
Assertions.fail("Authentication expired, therefore connection should had been closed"); | ||
} | ||
client.sendAndAwaitReply("Hello #" + i + " from "); | ||
} | ||
|
||
var receivedMessages = client.getMessages().stream().map(Buffer::toString).toList(); | ||
assertTrue(receivedMessages.size() > 2, receivedMessages.toString()); | ||
assertTrue(receivedMessages.contains("Hello #1 from admin"), receivedMessages.toString()); | ||
assertTrue(receivedMessages.contains("Hello #2 from admin"), receivedMessages.toString()); | ||
assertEquals(1008, client.closeStatusCode(), "Expected close status 1008, but got " + client.closeStatusCode()); | ||
|
||
Awaitility | ||
.await() | ||
.atMost(Duration.ofSeconds(1)) | ||
.untilAsserted(() -> assertTrue(Endpoint.CLOSED_MESSAGE.get() | ||
.startsWith("Connection closed with reason 'Authentication expired'"))); | ||
} | ||
} | ||
|
||
@Singleton | ||
public static class ExpiredIdentityAugmentor implements SecurityIdentityAugmentor { | ||
|
||
@Override | ||
public Uni<SecurityIdentity> augment(SecurityIdentity securityIdentity, | ||
AuthenticationRequestContext authenticationRequestContext) { | ||
return Uni | ||
.createFrom() | ||
.item(QuarkusSecurityIdentity | ||
.builder(securityIdentity) | ||
.addAttribute("quarkus.identity.expire-time", expireIn2Seconds()) | ||
.build()); | ||
} | ||
|
||
private static long expireIn2Seconds() { | ||
return Duration.ofMillis(System.currentTimeMillis()) | ||
.plusSeconds(2) | ||
.toSeconds(); | ||
} | ||
} | ||
|
||
@WebSocket(path = "/end") | ||
public static class Endpoint { | ||
|
||
static final AtomicReference<String> CLOSED_MESSAGE = new AtomicReference<>(); | ||
|
||
@Inject | ||
SecurityIdentity currentIdentity; | ||
|
||
@Authenticated | ||
@OnTextMessage | ||
String echo(String message) { | ||
return message + currentIdentity.getPrincipal().getName(); | ||
} | ||
|
||
@OnClose | ||
void close(CloseReason reason, WebSocketConnection connection) { | ||
CLOSED_MESSAGE.set("Connection closed with reason '%s': %s".formatted(reason.getMessage(), connection)); | ||
} | ||
} | ||
|
||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters