driftctl/pkg/middlewares/aws_bucket_policy_expander_...

194 lines
5.9 KiB
Go
Raw Normal View History

2021-01-27 22:47:39 +00:00
package middlewares
import (
"strings"
"testing"
awssdk "github.com/aws/aws-sdk-go/aws"
"github.com/aws/aws-sdk-go/aws/awsutil"
"github.com/r3labs/diff/v2"
"github.com/snyk/driftctl/enumeration/resource"
2022-07-21 08:37:03 +00:00
dctlresource "github.com/snyk/driftctl/pkg/resource"
"github.com/snyk/driftctl/pkg/resource/aws"
2021-01-27 22:47:39 +00:00
)
func TestAwsBucketPolicyExpander_Execute(t *testing.T) {
tests := []struct {
name string
2021-08-09 14:03:04 +00:00
resourcesFromState []*resource.Resource
2022-07-21 08:37:03 +00:00
mocks func(*dctlresource.MockResourceFactory)
2021-08-09 14:03:04 +00:00
expected []*resource.Resource
2021-01-27 22:47:39 +00:00
}{
{
2021-05-04 07:51:03 +00:00
name: "Inline policy, no aws_s3_bucket_policy attached",
2022-07-21 08:37:03 +00:00
mocks: func(factory *dctlresource.MockResourceFactory) {
2021-05-04 07:51:03 +00:00
factory.On(
"CreateAbstractResource",
aws.AwsS3BucketPolicyResourceType,
"foo",
map[string]interface{}{
"id": "foo",
"bucket": "foo",
"policy": "{\"Id\":\"MYINLINEBUCKETPOLICY\",\"Statement\":[{\"Action\":\"s3:*\",\"Condition\":{\"IpAddress\":{\"aws:SourceIp\":\"8.8.8.8/32\"}},\"Effect\":\"Deny\",\"Principal\":\"*\",\"Resource\":\"arn:aws:s3:::bucket-test-policy-like-sqs/*\",\"Sid\":\"IPAllow\"}],\"Version\":\"2012-10-17\"}",
},
2021-08-09 14:03:04 +00:00
).Once().Return(&resource.Resource{
2021-05-04 07:51:03 +00:00
Id: "foo",
Type: aws.AwsS3BucketPolicyResourceType,
})
},
2021-08-09 14:03:04 +00:00
resourcesFromState: []*resource.Resource{
{
2021-04-29 14:36:05 +00:00
Id: "foo",
Type: aws.AwsS3BucketResourceType,
Attrs: &resource.Attributes{
"bucket": "foo",
"policy": "{\"Id\":\"MYINLINEBUCKETPOLICY\",\"Statement\":[{\"Action\":\"s3:*\",\"Condition\":{\"IpAddress\":{\"aws:SourceIp\":\"8.8.8.8/32\"}},\"Effect\":\"Deny\",\"Principal\":\"*\",\"Resource\":\"arn:aws:s3:::bucket-test-policy-like-sqs/*\",\"Sid\":\"IPAllow\"}],\"Version\":\"2012-10-17\"}",
},
2021-01-27 22:47:39 +00:00
},
},
2021-08-09 14:03:04 +00:00
expected: []*resource.Resource{
{
2021-04-29 14:36:05 +00:00
Id: "foo",
Type: aws.AwsS3BucketResourceType,
Attrs: &resource.Attributes{
"bucket": "foo",
},
2021-01-27 22:47:39 +00:00
},
2021-08-09 14:03:04 +00:00
{
2021-05-04 07:51:03 +00:00
Id: "foo",
Type: aws.AwsS3BucketPolicyResourceType,
2021-01-27 22:47:39 +00:00
},
},
},
{
2021-05-04 07:51:03 +00:00
name: "No inline policy, aws_s3_bucket_policy attached",
2022-07-21 08:37:03 +00:00
mocks: func(factory *dctlresource.MockResourceFactory) {
2021-05-04 07:51:03 +00:00
factory.On(
"CreateAbstractResource",
aws.AwsS3BucketPolicyResourceType,
"foo",
map[string]interface{}{
"id": "foo",
"bucket": "foo",
"policy": "{\"Id\":\"MYBUCKETPOLICY\",\"Statement\":[{\"Action\":\"s3:*\",\"Condition\":{\"IpAddress\":{\"aws:SourceIp\":\"8.8.8.8/32\"}},\"Effect\":\"Deny\",\"Principal\":\"*\",\"Resource\":\"arn:aws:s3:::bucket-test-policy-like-sqs/*\",\"Sid\":\"IPAllow\"}],\"Version\":\"2012-10-17\"}",
},
2021-08-09 14:03:04 +00:00
).Once().Return(&resource.Resource{
2021-05-04 07:51:03 +00:00
Id: "foo",
Type: aws.AwsS3BucketPolicyResourceType,
})
},
2021-08-09 14:03:04 +00:00
resourcesFromState: []*resource.Resource{
{
2021-04-29 14:36:05 +00:00
Id: "foo",
Type: aws.AwsS3BucketResourceType,
Attrs: &resource.Attributes{
"bucket": "foo",
},
2021-01-27 22:47:39 +00:00
},
2021-08-09 14:03:04 +00:00
{
2021-05-04 07:51:03 +00:00
Id: "foo",
Type: aws.AwsS3BucketPolicyResourceType,
2021-01-27 22:47:39 +00:00
},
},
2021-08-09 14:03:04 +00:00
expected: []*resource.Resource{
{
2021-04-29 14:36:05 +00:00
Id: "foo",
Type: aws.AwsS3BucketResourceType,
Attrs: &resource.Attributes{
"bucket": "foo",
},
2021-01-27 22:47:39 +00:00
},
2021-08-09 14:03:04 +00:00
{
2021-05-04 07:51:03 +00:00
Id: "foo",
Type: aws.AwsS3BucketPolicyResourceType,
2021-01-27 22:47:39 +00:00
},
},
},
{
2021-05-04 07:51:03 +00:00
name: "Inline policy and aws_s3_bucket_policy",
2021-08-09 14:03:04 +00:00
resourcesFromState: []*resource.Resource{
{
2021-04-29 14:36:05 +00:00
Id: "foo",
Type: aws.AwsS3BucketResourceType,
Attrs: &resource.Attributes{
"bucket": "foo",
"policy": awssdk.String("{\"Id\":\"MYINLINEBUCKETPOLICY\",\"Statement\":[{\"Action\":\"s3:*\",\"Condition\":{\"IpAddress\":{\"aws:SourceIp\":\"8.8.8.8/32\"}},\"Effect\":\"Deny\",\"Principal\":\"*\",\"Resource\":\"arn:aws:s3:::bucket-test-policy-like-sqs/*\",\"Sid\":\"IPAllow\"}],\"Version\":\"2012-10-17\"}"),
},
2021-01-27 22:47:39 +00:00
},
2021-08-09 14:03:04 +00:00
{
2021-05-04 07:51:03 +00:00
Id: "foo",
Type: aws.AwsS3BucketPolicyResourceType,
Attrs: &resource.Attributes{
"bucket": "foo",
"policy": "{\"Id\":\"MYBUCKETPOLICY\",\"Statement\":[{\"Action\":\"s3:*\",\"Condition\":{\"IpAddress\":{\"aws:SourceIp\":\"8.8.8.8/32\"}},\"Effect\":\"Deny\",\"Principal\":\"*\",\"Resource\":\"arn:aws:s3:::bucket-test-policy-like-sqs/*\",\"Sid\":\"IPAllow\"}],\"Version\":\"2012-10-17\"}",
},
2021-01-27 22:47:39 +00:00
},
},
2021-08-09 14:03:04 +00:00
expected: []*resource.Resource{
{
2021-04-29 14:36:05 +00:00
Id: "foo",
Type: aws.AwsS3BucketResourceType,
Attrs: &resource.Attributes{
"bucket": "foo",
},
2021-01-27 22:47:39 +00:00
},
2021-08-09 14:03:04 +00:00
{
2021-05-04 07:51:03 +00:00
Id: "foo",
Type: aws.AwsS3BucketPolicyResourceType,
Attrs: &resource.Attributes{
"bucket": "foo",
"policy": "{\"Id\":\"MYBUCKETPOLICY\",\"Statement\":[{\"Action\":\"s3:*\",\"Condition\":{\"IpAddress\":{\"aws:SourceIp\":\"8.8.8.8/32\"}},\"Effect\":\"Deny\",\"Principal\":\"*\",\"Resource\":\"arn:aws:s3:::bucket-test-policy-like-sqs/*\",\"Sid\":\"IPAllow\"}],\"Version\":\"2012-10-17\"}",
},
2021-01-27 22:47:39 +00:00
},
},
},
2021-04-29 14:36:05 +00:00
{
2021-05-04 07:51:03 +00:00
name: "empty policy ",
2021-08-09 14:03:04 +00:00
resourcesFromState: []*resource.Resource{
{
2021-04-29 14:36:05 +00:00
Id: "foo",
Type: aws.AwsS3BucketResourceType,
Attrs: &resource.Attributes{
"bucket": "foo",
"policy": "",
},
},
},
2021-08-09 14:03:04 +00:00
expected: []*resource.Resource{
{
2021-04-29 14:36:05 +00:00
Id: "foo",
Type: aws.AwsS3BucketResourceType,
Attrs: &resource.Attributes{
"bucket": "foo",
"policy": "",
},
},
},
},
2021-01-27 22:47:39 +00:00
}
for _, tt := range tests {
t.Run(tt.name, func(t *testing.T) {
2021-03-29 16:10:50 +00:00
2022-07-21 08:37:03 +00:00
factory := &dctlresource.MockResourceFactory{}
2021-05-04 07:51:03 +00:00
if tt.mocks != nil {
tt.mocks(factory)
}
2021-03-29 16:10:50 +00:00
m := NewAwsBucketPolicyExpander(factory)
2021-08-09 14:03:04 +00:00
err := m.Execute(&[]*resource.Resource{}, &tt.resourcesFromState)
2021-01-27 22:47:39 +00:00
if err != nil {
t.Fatal(err)
}
changelog, err := diff.Diff(tt.expected, tt.resourcesFromState)
if err != nil {
t.Fatal(err)
}
if len(changelog) > 0 {
for _, change := range changelog {
t.Errorf("%s got = %v, want %v", strings.Join(change.Path, "."), awsutil.Prettify(change.From), awsutil.Prettify(change.To))
}
}
})
}
}