2016-04-05 08:52:55 -07:00
|
|
|
import ./make-test.nix {
|
|
|
|
name = "taskserver";
|
|
|
|
|
2016-04-11 03:03:16 -07:00
|
|
|
nodes = rec {
|
2016-04-05 08:52:55 -07:00
|
|
|
server = {
|
|
|
|
networking.firewall.enable = false;
|
|
|
|
services.taskserver.enable = true;
|
2016-04-11 03:26:34 -07:00
|
|
|
services.taskserver.listenHost = "::";
|
2016-04-11 03:42:20 -07:00
|
|
|
services.taskserver.fqdn = "server";
|
2016-04-05 08:52:55 -07:00
|
|
|
services.taskserver.organisations = {
|
|
|
|
testOrganisation.users = [ "alice" "foo" ];
|
|
|
|
anotherOrganisation.users = [ "bob" ];
|
|
|
|
};
|
|
|
|
};
|
|
|
|
|
|
|
|
client1 = { pkgs, ... }: {
|
|
|
|
networking.firewall.enable = false;
|
2016-04-11 16:08:34 -07:00
|
|
|
environment.systemPackages = [ pkgs.taskwarrior pkgs.gnutls ];
|
2016-04-05 08:52:55 -07:00
|
|
|
users.users.alice.isNormalUser = true;
|
|
|
|
users.users.bob.isNormalUser = true;
|
|
|
|
users.users.foo.isNormalUser = true;
|
2016-04-11 03:03:16 -07:00
|
|
|
users.users.bar.isNormalUser = true;
|
2016-04-05 08:52:55 -07:00
|
|
|
};
|
|
|
|
|
2016-04-11 03:03:16 -07:00
|
|
|
client2 = client1;
|
2016-04-05 08:52:55 -07:00
|
|
|
};
|
|
|
|
|
|
|
|
testScript = { nodes, ... }: let
|
|
|
|
cfg = nodes.server.config.services.taskserver;
|
2016-04-11 03:26:34 -07:00
|
|
|
portStr = toString cfg.listenPort;
|
2016-04-05 08:52:55 -07:00
|
|
|
in ''
|
|
|
|
sub su ($$) {
|
|
|
|
my ($user, $cmd) = @_;
|
|
|
|
my $esc = $cmd =~ s/'/'\\${"'"}'/gr;
|
|
|
|
return "su - $user -c '$esc'";
|
|
|
|
}
|
|
|
|
|
|
|
|
sub setupClientsFor ($$) {
|
|
|
|
my ($org, $user) = @_;
|
|
|
|
|
|
|
|
for my $client ($client1, $client2) {
|
|
|
|
$client->nest("initialize client for user $user", sub {
|
|
|
|
$client->succeed(
|
|
|
|
su $user, "task rc.confirmation=no config confirmation no"
|
|
|
|
);
|
|
|
|
|
|
|
|
my $exportinfo = $server->succeed(
|
2016-04-05 09:40:15 -07:00
|
|
|
"nixos-taskserver export-user $org $user"
|
2016-04-05 08:52:55 -07:00
|
|
|
);
|
|
|
|
|
|
|
|
$exportinfo =~ s/'/'\\'''/g;
|
|
|
|
|
|
|
|
$client->succeed(su $user, "eval '$exportinfo' >&2");
|
|
|
|
$client->succeed(su $user,
|
|
|
|
"task config taskd.server server:${portStr} >&2"
|
|
|
|
);
|
|
|
|
|
|
|
|
$client->succeed(su $user, "task sync init >&2");
|
|
|
|
});
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2016-04-11 16:08:34 -07:00
|
|
|
sub restartServer {
|
|
|
|
$server->succeed("systemctl restart taskserver.service");
|
|
|
|
$server->waitForOpenPort(${portStr});
|
|
|
|
}
|
|
|
|
|
|
|
|
sub readdImperativeUser {
|
|
|
|
$server->nest("(re-)add imperative user bar", sub {
|
|
|
|
$server->execute("nixos-taskserver del-org imperativeOrg");
|
|
|
|
$server->succeed(
|
|
|
|
"nixos-taskserver add-org imperativeOrg",
|
|
|
|
"nixos-taskserver add-user imperativeOrg bar"
|
|
|
|
);
|
|
|
|
setupClientsFor "imperativeOrg", "bar";
|
|
|
|
});
|
|
|
|
}
|
|
|
|
|
2016-04-11 03:03:16 -07:00
|
|
|
sub testSync ($) {
|
|
|
|
my $user = $_[0];
|
|
|
|
subtest "sync for user $user", sub {
|
|
|
|
$client1->succeed(su $user, "task add foo >&2");
|
|
|
|
$client1->succeed(su $user, "task sync >&2");
|
|
|
|
$client2->fail(su $user, "task list >&2");
|
|
|
|
$client2->succeed(su $user, "task sync >&2");
|
|
|
|
$client2->succeed(su $user, "task list >&2");
|
|
|
|
};
|
|
|
|
}
|
|
|
|
|
2016-04-11 16:08:34 -07:00
|
|
|
sub checkClientCert ($) {
|
|
|
|
my $user = $_[0];
|
|
|
|
my $cmd = "gnutls-cli".
|
|
|
|
" --x509cafile=/home/$user/.task/keys/ca.cert".
|
|
|
|
" --x509keyfile=/home/$user/.task/keys/private.key".
|
|
|
|
" --x509certfile=/home/$user/.task/keys/public.cert".
|
|
|
|
" --port=${portStr} server < /dev/null";
|
|
|
|
return su $user, $cmd;
|
|
|
|
}
|
|
|
|
|
2016-04-05 08:52:55 -07:00
|
|
|
startAll;
|
|
|
|
|
|
|
|
$server->waitForUnit("taskserver.service");
|
|
|
|
|
|
|
|
$server->succeed(
|
2016-04-05 09:40:15 -07:00
|
|
|
"nixos-taskserver list-users testOrganisation | grep -qxF alice",
|
|
|
|
"nixos-taskserver list-users testOrganisation | grep -qxF foo",
|
|
|
|
"nixos-taskserver list-users anotherOrganisation | grep -qxF bob"
|
2016-04-05 08:52:55 -07:00
|
|
|
);
|
|
|
|
|
|
|
|
$server->waitForOpenPort(${portStr});
|
|
|
|
|
|
|
|
$client1->waitForUnit("multi-user.target");
|
|
|
|
$client2->waitForUnit("multi-user.target");
|
|
|
|
|
|
|
|
setupClientsFor "testOrganisation", "alice";
|
|
|
|
setupClientsFor "testOrganisation", "foo";
|
|
|
|
setupClientsFor "anotherOrganisation", "bob";
|
|
|
|
|
2016-04-11 03:03:16 -07:00
|
|
|
testSync $_ for ("alice", "bob", "foo");
|
|
|
|
|
|
|
|
$server->fail("nixos-taskserver add-user imperativeOrg bar");
|
2016-04-11 16:08:34 -07:00
|
|
|
readdImperativeUser;
|
2016-04-11 03:03:16 -07:00
|
|
|
|
|
|
|
testSync "bar";
|
2016-04-11 16:08:34 -07:00
|
|
|
|
|
|
|
subtest "checking certificate revocation of user bar", sub {
|
|
|
|
$client1->succeed(checkClientCert "bar");
|
|
|
|
|
|
|
|
$server->succeed("nixos-taskserver del-user imperativeOrg bar");
|
|
|
|
restartServer;
|
|
|
|
|
|
|
|
$client1->fail(checkClientCert "bar");
|
|
|
|
|
|
|
|
$client1->succeed(su "bar", "task add destroy everything >&2");
|
|
|
|
$client1->fail(su "bar", "task sync >&2");
|
|
|
|
};
|
|
|
|
|
|
|
|
readdImperativeUser;
|
|
|
|
|
|
|
|
subtest "checking certificate revocation of org imperativeOrg", sub {
|
|
|
|
$client1->succeed(checkClientCert "bar");
|
|
|
|
|
|
|
|
$server->succeed("nixos-taskserver del-org imperativeOrg");
|
|
|
|
restartServer;
|
|
|
|
|
|
|
|
$client1->fail(checkClientCert "bar");
|
|
|
|
|
|
|
|
$client1->succeed(su "bar", "task add destroy even more >&2");
|
|
|
|
$client1->fail(su "bar", "task sync >&2");
|
|
|
|
};
|
2016-04-05 08:52:55 -07:00
|
|
|
'';
|
|
|
|
}
|