2019-06-11 22:24:35 +00:00
|
|
|
require "helper"
|
|
|
|
require "stringio"
|
2019-01-08 01:07:59 +00:00
|
|
|
|
2019-06-11 22:24:35 +00:00
|
|
|
require "inspec/config"
|
2019-06-07 23:33:56 +00:00
|
|
|
require "plugins/inspec-compliance/lib/inspec-compliance/api"
|
2019-01-08 01:07:59 +00:00
|
|
|
|
2019-06-11 22:24:35 +00:00
|
|
|
describe "Inspec::Config" do
|
2019-01-08 01:07:59 +00:00
|
|
|
|
|
|
|
# ========================================================================== #
|
|
|
|
# Constructor
|
|
|
|
# ========================================================================== #
|
2019-06-11 22:24:35 +00:00
|
|
|
describe "the constructor" do
|
|
|
|
describe "when no args are provided" do
|
|
|
|
it "should initialize properly" do
|
2019-01-08 01:07:59 +00:00
|
|
|
cfg = Inspec::Config.new
|
|
|
|
cfg.must_respond_to :final_options
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2019-06-11 22:24:35 +00:00
|
|
|
describe "when CLI args are provided" do
|
|
|
|
it "should initialize properly" do
|
|
|
|
cfg = Inspec::Config.new({ color: true, log_level: "warn" })
|
2019-01-08 01:07:59 +00:00
|
|
|
cfg.must_respond_to :final_options
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
# TODO: add test for reading from default config path
|
|
|
|
|
|
|
|
end
|
|
|
|
|
2019-03-06 19:59:06 +00:00
|
|
|
# ========================================================================== #
|
|
|
|
# Global Caching
|
|
|
|
# ========================================================================== #
|
|
|
|
|
2019-06-11 22:24:35 +00:00
|
|
|
describe "caching" do
|
2019-03-06 19:59:06 +00:00
|
|
|
# Note that since unit tests are randomized, we have no idea what is in
|
|
|
|
# the cache. We just want to validate that we get the same thing.
|
2019-06-11 22:24:35 +00:00
|
|
|
it "should cache the config object" do
|
2019-05-31 21:59:06 +00:00
|
|
|
Inspec::Config.new # in the unlikely event we are the first unit test
|
2019-03-06 19:59:06 +00:00
|
|
|
|
|
|
|
# Type check
|
|
|
|
cfg_cached = Inspec::Config.cached
|
|
|
|
cfg_cached.must_be_kind_of Inspec::Config
|
|
|
|
|
|
|
|
# Multiple calls to cached should return the same thing
|
|
|
|
cfg_2 = Inspec::Config.cached
|
|
|
|
cfg_2.must_equal cfg_cached
|
|
|
|
|
|
|
|
# Cached value unaffected by later instance creation
|
2019-05-31 21:59:06 +00:00
|
|
|
Inspec::Config.new(shoe_size: 9)
|
2019-03-06 19:59:06 +00:00
|
|
|
cfg_4 = Inspec::Config.cached
|
|
|
|
cfg_4.must_equal cfg_cached
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2019-01-08 01:07:59 +00:00
|
|
|
# ========================================================================== #
|
|
|
|
# File Validation
|
|
|
|
# ========================================================================== #
|
2019-06-11 22:24:35 +00:00
|
|
|
describe "when validating a file" do
|
2019-01-08 01:07:59 +00:00
|
|
|
let(:cfg) { Inspec::Config.new({}, cfg_io) }
|
|
|
|
let(:cfg_io) { StringIO.new(ConfigTestHelper.fixture(fixture_name)) }
|
|
|
|
let(:seen_fields) { cfg.final_options.keys.sort }
|
|
|
|
|
2019-06-11 22:24:35 +00:00
|
|
|
describe "when the file is a legacy file" do
|
|
|
|
let(:fixture_name) { "legacy" }
|
|
|
|
it "should read the file successfully" do
|
|
|
|
expected = %w{color reporter target_id type}.sort
|
2019-01-08 01:07:59 +00:00
|
|
|
seen_fields.must_equal expected
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2019-06-11 22:24:35 +00:00
|
|
|
describe "when the file is a valid v1.1 file" do
|
|
|
|
let(:fixture_name) { "basic" }
|
|
|
|
it "should read the file successfully" do
|
|
|
|
expected = %w{create_lockfile reporter type}.sort
|
2019-01-08 01:07:59 +00:00
|
|
|
seen_fields.must_equal expected
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2019-06-11 22:24:35 +00:00
|
|
|
describe "when the file is minimal" do
|
|
|
|
let(:fixture_name) { "minimal" }
|
|
|
|
it "should read the file successfully" do
|
|
|
|
expected = %w{reporter type}.sort
|
2019-01-08 01:07:59 +00:00
|
|
|
seen_fields.must_equal expected
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2019-06-11 22:24:35 +00:00
|
|
|
describe "when the file has malformed json" do
|
|
|
|
let(:fixture_name) { "malformed_json" }
|
|
|
|
it "should throw an exception" do
|
2019-01-08 01:07:59 +00:00
|
|
|
ex = proc { cfg }.must_raise(Inspec::ConfigError::MalformedJson)
|
2019-01-17 16:07:13 +00:00
|
|
|
# Failed to load JSON configuration: 765: unexpected token at '{ "hot_garbage": "a", "version": "1.1",
|
|
|
|
# '
|
|
|
|
# Config was: "{ \"hot_garbage\": \"a\", \"version\": \"1.1\", \n"
|
2019-06-11 22:24:35 +00:00
|
|
|
ex.message.must_include "Failed to load JSON config" # The message
|
|
|
|
ex.message.must_include "unexpected token" # The specific parser error
|
|
|
|
ex.message.must_include "hot_garbage" # A sample of the unacceptable contents
|
2019-01-08 01:07:59 +00:00
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2019-06-11 22:24:35 +00:00
|
|
|
describe "when the file has a bad file version" do
|
|
|
|
let(:fixture_name) { "bad_version" }
|
|
|
|
it "should throw an exception" do
|
2019-01-08 01:07:59 +00:00
|
|
|
ex = proc { cfg }.must_raise(Inspec::ConfigError::Invalid)
|
2019-06-11 22:24:35 +00:00
|
|
|
ex.message.must_include "Unsupported config file version"
|
|
|
|
ex.message.must_include "99.99"
|
|
|
|
ex.message.must_include "1.1"
|
2019-01-08 01:07:59 +00:00
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2019-06-11 22:24:35 +00:00
|
|
|
describe "when a 1.1 file has an invalid top-level entry" do
|
|
|
|
let(:fixture_name) { "bad_top_level" }
|
|
|
|
it "should throw an exception" do
|
2019-01-08 01:07:59 +00:00
|
|
|
ex = proc { cfg }.must_raise(Inspec::ConfigError::Invalid)
|
2019-06-11 22:24:35 +00:00
|
|
|
ex.message.must_include "Unrecognized top-level"
|
|
|
|
ex.message.must_include "unsupported_field"
|
|
|
|
ex.message.must_include "compliance"
|
2019-01-08 01:07:59 +00:00
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
# ========================================================================== #
|
|
|
|
# Defaults
|
|
|
|
# ========================================================================== #
|
2019-06-11 22:24:35 +00:00
|
|
|
describe "reading defaults" do
|
2019-01-08 01:07:59 +00:00
|
|
|
let(:cfg) { Inspec::Config.new({}, nil, command) }
|
|
|
|
let(:final_options) { cfg.final_options }
|
|
|
|
let(:seen_fields) { cfg.final_options.keys.sort }
|
|
|
|
|
2019-06-11 22:24:35 +00:00
|
|
|
describe "when the exec command is used" do
|
2019-01-08 01:07:59 +00:00
|
|
|
let(:command) { :exec }
|
2019-06-11 22:24:35 +00:00
|
|
|
it "should have the correct defaults" do
|
|
|
|
expected = %w{color create_lockfile backend_cache reporter show_progress type}.sort
|
2019-01-08 01:07:59 +00:00
|
|
|
seen_fields.must_equal expected
|
2019-06-11 22:24:35 +00:00
|
|
|
final_options["reporter"].must_be_kind_of Hash
|
|
|
|
final_options["reporter"].count.must_equal 1
|
|
|
|
final_options["reporter"].keys.must_include "cli"
|
|
|
|
final_options["show_progress"].must_equal false
|
|
|
|
final_options["color"].must_equal true
|
|
|
|
final_options["create_lockfile"].must_equal true
|
|
|
|
final_options["backend_cache"].must_equal true
|
2019-01-08 01:07:59 +00:00
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2019-06-11 22:24:35 +00:00
|
|
|
describe "when the shell command is used" do
|
2019-01-08 01:07:59 +00:00
|
|
|
let(:command) { :shell }
|
2019-06-11 22:24:35 +00:00
|
|
|
it "should have the correct defaults" do
|
|
|
|
expected = %w{reporter type}.sort
|
2019-01-08 01:07:59 +00:00
|
|
|
seen_fields.must_equal expected
|
2019-06-11 22:24:35 +00:00
|
|
|
final_options["reporter"].must_be_kind_of Hash
|
|
|
|
final_options["reporter"].count.must_equal 1
|
|
|
|
final_options["reporter"].keys.must_include "cli"
|
2019-01-08 01:07:59 +00:00
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
# ========================================================================== #
|
|
|
|
# Reading CLI Options
|
|
|
|
# ========================================================================== #
|
|
|
|
# The config facility supports passing in CLI options in the constructor, so
|
|
|
|
# that it can handle merging internally. That is tested here.
|
|
|
|
#
|
|
|
|
# This is different than storing options
|
|
|
|
# in the config file with the same name as the CLI options, which is
|
|
|
|
# tested under 'CLI Options Stored in File'
|
2019-06-11 22:24:35 +00:00
|
|
|
describe "reading CLI options" do
|
2019-01-08 01:07:59 +00:00
|
|
|
let(:cfg) { Inspec::Config.new(cli_opts) }
|
|
|
|
let(:final_options) { cfg.final_options }
|
|
|
|
let(:seen_fields) { cfg.final_options.keys.sort }
|
|
|
|
|
2019-06-11 22:24:35 +00:00
|
|
|
describe "when the CLI opts are present" do
|
2019-01-08 01:07:59 +00:00
|
|
|
let(:cli_opts) do
|
|
|
|
{
|
|
|
|
color: true,
|
2019-06-11 22:24:35 +00:00
|
|
|
"string_key" => "string_value",
|
|
|
|
array_value: [1, 2, 3],
|
2019-01-08 01:07:59 +00:00
|
|
|
}
|
|
|
|
end
|
|
|
|
|
2019-06-11 22:24:35 +00:00
|
|
|
it "should transparently round-trip the options" do
|
|
|
|
expected = %w{color array_value reporter string_key type}.sort
|
2019-01-08 01:07:59 +00:00
|
|
|
seen_fields.must_equal expected
|
|
|
|
final_options[:color].must_equal true
|
2019-06-11 22:24:35 +00:00
|
|
|
final_options["color"].must_equal true
|
|
|
|
final_options["string_key"].must_equal "string_value"
|
|
|
|
final_options[:string_key].must_equal "string_value"
|
|
|
|
final_options["array_value"].must_equal [1, 2, 3]
|
|
|
|
final_options[:array_value].must_equal [1, 2, 3]
|
2019-01-08 01:07:59 +00:00
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
# ========================================================================== #
|
|
|
|
# CLI Options Stored in File
|
|
|
|
# ========================================================================== #
|
2019-06-11 22:24:35 +00:00
|
|
|
describe "reading CLI options stored in the config file" do
|
2019-01-08 01:07:59 +00:00
|
|
|
let(:cfg) { Inspec::Config.new({}, cfg_io) }
|
|
|
|
let(:final_options) { cfg.final_options }
|
|
|
|
let(:cfg_io) { StringIO.new(ConfigTestHelper.fixture(fixture_name)) }
|
|
|
|
let(:seen_fields) { cfg.final_options.keys.sort }
|
|
|
|
|
|
|
|
# These two test cases have the same options but in different file versions.
|
2019-06-11 22:24:35 +00:00
|
|
|
describe "when the CLI opts are present in a 1.1 file" do
|
2019-01-08 01:07:59 +00:00
|
|
|
let(:fixture_name) { :like_legacy }
|
2019-06-11 22:24:35 +00:00
|
|
|
it "should read the options" do
|
|
|
|
expected = %w{color reporter target_id type}.sort
|
2019-01-08 01:07:59 +00:00
|
|
|
seen_fields.must_equal expected
|
2019-06-11 22:24:35 +00:00
|
|
|
final_options["color"].must_equal "true" # Dubious - should this be String or TrueClass?
|
|
|
|
final_options["target_id"].must_equal "mynode"
|
2019-01-08 01:07:59 +00:00
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2019-06-11 22:24:35 +00:00
|
|
|
describe "when the CLI opts are present in a legacy file" do
|
2019-01-08 01:07:59 +00:00
|
|
|
let(:fixture_name) { :legacy }
|
2019-06-11 22:24:35 +00:00
|
|
|
it "should read the options" do
|
|
|
|
expected = %w{color reporter target_id type}.sort
|
2019-01-08 01:07:59 +00:00
|
|
|
seen_fields.must_equal expected
|
2019-06-11 22:24:35 +00:00
|
|
|
final_options["color"].must_equal "true" # Dubious - should this be String or TrueClass?
|
|
|
|
final_options["target_id"].must_equal "mynode"
|
2019-01-08 01:07:59 +00:00
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
# ========================================================================== #
|
|
|
|
# Parsing and Validating Reporters
|
|
|
|
# ========================================================================== #
|
|
|
|
|
|
|
|
# TODO: this should be moved into plugins for the reporters
|
2019-06-11 22:24:35 +00:00
|
|
|
describe "when parsing reporters" do
|
2019-01-08 01:07:59 +00:00
|
|
|
let(:cfg) { Inspec::Config.new(cli_opts) }
|
2019-06-11 22:24:35 +00:00
|
|
|
let(:seen_reporters) { cfg["reporter"] }
|
2019-01-08 01:07:59 +00:00
|
|
|
|
2019-06-11 22:24:35 +00:00
|
|
|
describe "when paring CLI reporter" do
|
|
|
|
let(:cli_opts) { { "reporter" => ["cli"] } }
|
|
|
|
it "parse cli reporters" do
|
|
|
|
expected_value = { "cli" => { "stdout" => true } }
|
2019-01-08 01:07:59 +00:00
|
|
|
seen_reporters.must_equal expected_value
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2019-06-11 22:24:35 +00:00
|
|
|
describe "when paring CLI reporter" do
|
|
|
|
let(:cli_opts) { { "reporter" => ["cli"], "target_id" => "1d3e399f-4d71-4863-ac54-84d437fbc444" } }
|
|
|
|
it "parses cli report and attaches target_id" do
|
|
|
|
expected_value = { "cli" => { "stdout" => true, "target_id" => "1d3e399f-4d71-4863-ac54-84d437fbc444" } }
|
2019-01-08 01:07:59 +00:00
|
|
|
seen_reporters.must_equal expected_value
|
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2019-06-11 22:24:35 +00:00
|
|
|
describe "when validating reporters" do
|
2019-01-08 01:07:59 +00:00
|
|
|
# validate_reporters is private, so we use .send
|
|
|
|
let(:cfg) { Inspec::Config.new }
|
2019-06-11 22:24:35 +00:00
|
|
|
it "valid reporter" do
|
|
|
|
reporters = { "json" => { "stdout" => true } }
|
2019-01-17 16:36:46 +00:00
|
|
|
cfg.send(:validate_reporters!, reporters)
|
2019-01-08 01:07:59 +00:00
|
|
|
end
|
|
|
|
|
2019-06-11 22:24:35 +00:00
|
|
|
it "invalid reporter type" do
|
|
|
|
reporters = %w{json magenta}
|
2019-01-17 16:36:46 +00:00
|
|
|
proc { cfg.send(:validate_reporters!, reporters) }.must_raise NotImplementedError
|
2019-01-08 01:07:59 +00:00
|
|
|
end
|
|
|
|
|
2019-06-11 22:24:35 +00:00
|
|
|
it "two reporters outputting to stdout" do
|
|
|
|
stdout = { "stdout" => true }
|
|
|
|
reporters = { "json" => stdout, "cli" => stdout }
|
2019-01-17 16:36:46 +00:00
|
|
|
proc { cfg.send(:validate_reporters!, reporters) }.must_raise ArgumentError
|
2019-01-08 01:07:59 +00:00
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
# ========================================================================== #
|
|
|
|
# Miscellaneous Option Finalization
|
|
|
|
# ========================================================================== #
|
|
|
|
|
2019-06-11 22:24:35 +00:00
|
|
|
describe "option finalization" do
|
|
|
|
it "raises if `--password/--sudo-password` are used without value" do
|
2019-01-08 01:07:59 +00:00
|
|
|
# When you invoke `inspec shell --password` (with no value for password,
|
|
|
|
# though it is setup to expect a string) Thor will set the key with value -1
|
2019-06-11 22:24:35 +00:00
|
|
|
ex = proc { Inspec::Config.new({ "sudo_password" => -1 }) }.must_raise(ArgumentError)
|
2019-01-08 01:07:59 +00:00
|
|
|
ex.message.must_match(/Please provide a value for --sudo-password/)
|
|
|
|
end
|
|
|
|
|
2019-06-11 22:24:35 +00:00
|
|
|
it "assumes `--sudo` if `--sudo-password` is used without it" do
|
2019-02-22 07:20:00 +00:00
|
|
|
@mock_logger = Minitest::Mock.new
|
|
|
|
@mock_logger.expect(:warn, nil, [/Adding `--sudo`./])
|
2019-05-31 21:59:06 +00:00
|
|
|
Inspec::Log.stub :warn, (proc { |message| @mock_logger.warn(message) }) do
|
2019-06-11 22:24:35 +00:00
|
|
|
cfg = Inspec::Config.new("sudo_password" => "somepass")
|
|
|
|
cfg.key?("sudo").must_equal true
|
2019-02-22 07:20:00 +00:00
|
|
|
end
|
|
|
|
@mock_logger.verify
|
2019-01-08 01:07:59 +00:00
|
|
|
end
|
|
|
|
|
2019-06-11 22:24:35 +00:00
|
|
|
it "calls `Compliance::API.login` if `opts[:compliance] is passed`" do
|
2019-01-08 01:07:59 +00:00
|
|
|
InspecPlugins::Compliance::API.expects(:login)
|
2019-06-11 22:24:35 +00:00
|
|
|
cfg_io = StringIO.new(ConfigTestHelper.fixture("with_compliance"))
|
|
|
|
Inspec::Config.new({ backend: "mock" }, cfg_io)
|
2019-01-08 01:07:59 +00:00
|
|
|
end
|
|
|
|
end
|
2019-01-08 22:59:35 +00:00
|
|
|
# ========================================================================== #
|
|
|
|
# Fetching Credentials
|
|
|
|
# ========================================================================== #
|
2019-06-11 22:24:35 +00:00
|
|
|
describe "when fetching creds" do
|
2019-01-08 22:59:35 +00:00
|
|
|
let(:cfg) { Inspec::Config.new(cli_opts, cfg_io) }
|
|
|
|
let(:cfg_io) { StringIO.new(ConfigTestHelper.fixture(file_fixture_name)) }
|
|
|
|
let(:seen_fields) { creds.keys.sort }
|
|
|
|
let(:creds) { cfg.unpack_train_credentials }
|
|
|
|
|
2019-06-11 22:24:35 +00:00
|
|
|
describe "when generic creds are present on the cli" do
|
2019-01-08 22:59:35 +00:00
|
|
|
let(:cfg_io) { nil }
|
2019-06-11 22:24:35 +00:00
|
|
|
let(:cli_opts) { { sudo: true, 'shell_command': "ksh" } }
|
|
|
|
it "should pass the credentials as-is" do
|
2019-07-09 00:20:30 +00:00
|
|
|
expected = %i{backend sudo shell_command}.sort
|
2019-01-08 22:59:35 +00:00
|
|
|
seen_fields.must_equal expected
|
|
|
|
creds[:sudo].must_equal true
|
2019-06-11 22:24:35 +00:00
|
|
|
creds[:shell_command].must_equal "ksh"
|
|
|
|
creds[:backend].must_equal "local" # Checking for default
|
2019-01-08 22:59:35 +00:00
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2019-06-11 22:24:35 +00:00
|
|
|
describe "when creds are specified on the CLI with a backend and transport prefixes" do
|
2019-01-08 22:59:35 +00:00
|
|
|
let(:cfg_io) { nil }
|
2019-06-11 22:24:35 +00:00
|
|
|
let(:cli_opts) { { backend: "ssh", ssh_host: "example.com", ssh_key_files: "mykey" } }
|
|
|
|
it "should read the backend and strip prefixes" do
|
2019-07-09 00:20:30 +00:00
|
|
|
expected = %i{backend host key_files}.sort
|
2019-01-08 22:59:35 +00:00
|
|
|
seen_fields.must_equal expected
|
2019-06-11 22:24:35 +00:00
|
|
|
creds[:backend].must_equal "ssh"
|
|
|
|
creds[:host].must_equal "example.com"
|
|
|
|
creds[:key_files].must_equal "mykey"
|
2019-01-08 22:59:35 +00:00
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2019-06-11 22:24:35 +00:00
|
|
|
describe "when creds are specified with a credset target_uri in a 1.1 file without transport prefixes" do
|
2019-01-09 06:58:28 +00:00
|
|
|
let(:file_fixture_name) { :basic }
|
2019-06-11 22:24:35 +00:00
|
|
|
let(:cli_opts) { { target: "ssh://set1" } }
|
|
|
|
it "should use the credset to lookup the creds in the file" do
|
2019-07-09 00:20:30 +00:00
|
|
|
expected = %i{backend host user}.sort
|
2019-01-09 06:58:28 +00:00
|
|
|
seen_fields.must_equal expected
|
2019-06-11 22:24:35 +00:00
|
|
|
creds[:backend].must_equal "ssh"
|
|
|
|
creds[:host].must_equal "some.host"
|
|
|
|
creds[:user].must_equal "some_user"
|
2019-01-09 06:58:28 +00:00
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2019-06-11 22:24:35 +00:00
|
|
|
describe "when creds are specified with a credset that contains odd characters" do
|
2019-02-22 12:05:16 +00:00
|
|
|
let(:file_fixture_name) { :match_checks_in_credset_names }
|
|
|
|
[
|
2019-06-11 22:24:35 +00:00
|
|
|
"ssh://TitleCase",
|
|
|
|
"ssh://snake_case",
|
|
|
|
"ssh://conta1nsnumeral5",
|
2019-02-22 12:05:16 +00:00
|
|
|
].each do |target_uri|
|
|
|
|
it "should be able to unpack #{target_uri}" do
|
|
|
|
# let() caching breaks things here
|
|
|
|
cfg_io = StringIO.new(ConfigTestHelper.fixture(file_fixture_name))
|
|
|
|
cfg = Inspec::Config.new({ target: target_uri }, cfg_io)
|
|
|
|
creds = cfg.unpack_train_credentials
|
|
|
|
creds.count.must_equal 2
|
2019-06-11 22:24:35 +00:00
|
|
|
creds[:backend].must_equal "ssh"
|
|
|
|
creds[:found].must_equal "yes"
|
2019-02-22 12:05:16 +00:00
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
[
|
2019-06-11 22:24:35 +00:00
|
|
|
"ssh://contains.dots",
|
2019-02-22 12:05:16 +00:00
|
|
|
].each do |target_uri|
|
|
|
|
it "should handoff unpacking #{target_uri} to train" do
|
|
|
|
# let() caching breaks things here
|
|
|
|
cfg_io = StringIO.new(ConfigTestHelper.fixture(file_fixture_name))
|
|
|
|
cfg = Inspec::Config.new({ target: target_uri }, cfg_io)
|
|
|
|
creds = cfg.unpack_train_credentials
|
|
|
|
|
|
|
|
creds.count.must_equal 2
|
2019-06-11 22:24:35 +00:00
|
|
|
creds[:backend].must_equal "ssh"
|
|
|
|
creds[:host].must_equal "contains.dots"
|
2019-02-22 12:05:16 +00:00
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
[
|
2019-06-11 22:24:35 +00:00
|
|
|
"ssh://contains spaces",
|
2019-02-22 12:05:16 +00:00
|
|
|
].each do |target_uri|
|
|
|
|
it "should be not able to unpack #{target_uri}" do
|
|
|
|
# let() caching breaks things here
|
|
|
|
cfg_io = StringIO.new(ConfigTestHelper.fixture(file_fixture_name))
|
|
|
|
cfg = Inspec::Config.new({ target: target_uri }, cfg_io)
|
|
|
|
|
2019-05-31 21:59:06 +00:00
|
|
|
assert_raises(Train::UserError) { cfg.unpack_train_credentials }
|
2019-02-22 12:05:16 +00:00
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2019-06-11 22:24:35 +00:00
|
|
|
describe "when creds are specified with a credset target_uri in a 1.1 file and a prefixed override on the CLI" do
|
2019-01-09 06:58:28 +00:00
|
|
|
let(:file_fixture_name) { :basic }
|
2019-06-11 22:24:35 +00:00
|
|
|
let(:cli_opts) { { target: "ssh://set1", ssh_user: "bob" } }
|
|
|
|
it "should use the credset to lookup the creds in the file then override the single value" do
|
2019-07-09 00:20:30 +00:00
|
|
|
expected = %i{backend host user}.sort
|
2019-01-09 06:58:28 +00:00
|
|
|
seen_fields.must_equal expected
|
2019-06-11 22:24:35 +00:00
|
|
|
creds[:backend].must_equal "ssh"
|
|
|
|
creds[:host].must_equal "some.host"
|
|
|
|
creds[:user].must_equal "bob"
|
2019-01-09 06:58:28 +00:00
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2019-06-11 22:24:35 +00:00
|
|
|
describe "when creds are specified with a non-credset target_uri" do
|
2019-01-08 22:59:35 +00:00
|
|
|
let(:cfg_io) { nil }
|
2019-06-11 22:24:35 +00:00
|
|
|
let(:cli_opts) { { target: "ssh://bob@somehost" } }
|
|
|
|
it "should unpack the options using the URI parser" do
|
2019-07-09 00:20:30 +00:00
|
|
|
expected = %i{backend host user}.sort
|
2019-01-08 22:59:35 +00:00
|
|
|
seen_fields.must_equal expected
|
2019-06-11 22:24:35 +00:00
|
|
|
creds[:backend].must_equal "ssh"
|
|
|
|
creds[:host].must_equal "somehost"
|
|
|
|
creds[:user].must_equal "bob"
|
2019-01-08 22:59:35 +00:00
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2019-06-11 22:24:35 +00:00
|
|
|
describe "when backcompat creds are specified on the CLI without a transport prefix" do
|
2019-01-08 22:59:35 +00:00
|
|
|
let(:cfg_io) { nil }
|
2019-06-11 22:24:35 +00:00
|
|
|
let(:cli_opts) { { target: "ssh://some.host", user: "bob" } }
|
|
|
|
it "should assign the options correctly" do
|
2019-07-09 00:20:30 +00:00
|
|
|
expected = %i{backend host user}.sort
|
2019-01-08 22:59:35 +00:00
|
|
|
seen_fields.must_equal expected
|
2019-06-11 22:24:35 +00:00
|
|
|
creds[:backend].must_equal "ssh"
|
|
|
|
creds[:host].must_equal "some.host"
|
|
|
|
creds[:user].must_equal "bob"
|
2019-01-08 22:59:35 +00:00
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|
2019-01-08 01:07:59 +00:00
|
|
|
|
|
|
|
# ========================================================================== #
|
|
|
|
# Merging Options
|
|
|
|
# ========================================================================== #
|
2019-06-11 22:24:35 +00:00
|
|
|
describe "when merging options" do
|
2019-01-08 01:07:59 +00:00
|
|
|
let(:cfg) { Inspec::Config.new(cli_opts, cfg_io, command) }
|
|
|
|
let(:cfg_io) { StringIO.new(ConfigTestHelper.fixture(file_fixture_name)) }
|
|
|
|
let(:seen_fields) { cfg.final_options.keys.sort }
|
|
|
|
let(:command) { nil }
|
|
|
|
|
2019-06-11 22:24:35 +00:00
|
|
|
describe "when there is both a default and a config file setting" do
|
2019-01-08 01:07:59 +00:00
|
|
|
let(:file_fixture_name) { :override_check }
|
|
|
|
let(:cli_opts) { {} }
|
2019-06-11 22:24:35 +00:00
|
|
|
it "the config file setting should prevail" do
|
|
|
|
Inspec::Config::Defaults.stubs(:default_for_command).returns("target_id" => "value_from_default")
|
|
|
|
expected = %w{reporter target_id type}.sort
|
2019-01-08 01:07:59 +00:00
|
|
|
seen_fields.must_equal expected
|
2019-06-11 22:24:35 +00:00
|
|
|
cfg.final_options["target_id"].must_equal "value_from_config_file"
|
|
|
|
cfg.final_options[:target_id].must_equal "value_from_config_file"
|
2019-01-08 01:07:59 +00:00
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2019-06-11 22:24:35 +00:00
|
|
|
describe "when there is both a default and a CLI option" do
|
|
|
|
let(:cli_opts) { { target_id: "value_from_cli_opts" } }
|
2019-01-08 01:07:59 +00:00
|
|
|
let(:cfg_io) { nil }
|
2019-06-11 22:24:35 +00:00
|
|
|
it "the CLI option should prevail" do
|
|
|
|
Inspec::Config::Defaults.stubs(:default_for_command).returns("target_id" => "value_from_default")
|
|
|
|
expected = %w{reporter target_id type}.sort
|
2019-01-08 01:07:59 +00:00
|
|
|
seen_fields.must_equal expected
|
2019-06-11 22:24:35 +00:00
|
|
|
cfg.final_options["target_id"].must_equal "value_from_cli_opts"
|
|
|
|
cfg.final_options[:target_id].must_equal "value_from_cli_opts"
|
2019-01-08 01:07:59 +00:00
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2019-06-11 22:24:35 +00:00
|
|
|
describe "when there is both a config file setting and a CLI option" do
|
2019-01-08 01:07:59 +00:00
|
|
|
let(:file_fixture_name) { :override_check }
|
2019-06-11 22:24:35 +00:00
|
|
|
let(:cli_opts) { { target_id: "value_from_cli_opts" } }
|
|
|
|
it "the CLI option should prevail" do
|
|
|
|
expected = %w{reporter target_id type}.sort
|
2019-01-08 01:07:59 +00:00
|
|
|
seen_fields.must_equal expected
|
2019-06-11 22:24:35 +00:00
|
|
|
cfg.final_options["target_id"].must_equal "value_from_cli_opts"
|
|
|
|
cfg.final_options[:target_id].must_equal "value_from_cli_opts"
|
2019-01-08 01:07:59 +00:00
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
describe 'specifically check default vs config file override for "reporter" setting' do
|
|
|
|
let(:cli_opts) { {} }
|
|
|
|
let(:command) { :shell } # shell default is [ :cli ]
|
|
|
|
let(:file_fixture_name) { :override_check } # This fixture sets the cfg file contents to request a json reporter
|
2019-06-11 22:24:35 +00:00
|
|
|
it "the config file setting should prevail" do
|
|
|
|
expected = %w{reporter target_id type}.sort
|
2019-01-08 01:07:59 +00:00
|
|
|
seen_fields.must_equal expected
|
2019-06-11 22:24:35 +00:00
|
|
|
cfg.final_options["reporter"].must_be_kind_of Hash
|
|
|
|
cfg.final_options["reporter"].keys.must_equal ["json"]
|
|
|
|
cfg.final_options["reporter"]["json"]["path"].must_equal "path/from/config/file"
|
2019-01-08 01:07:59 +00:00
|
|
|
cfg.final_options[:reporter].must_be_kind_of Hash
|
2019-06-11 22:24:35 +00:00
|
|
|
cfg.final_options[:reporter].keys.must_equal ["json"]
|
|
|
|
cfg.final_options[:reporter]["json"]["path"].must_equal "path/from/config/file"
|
2019-01-08 01:07:59 +00:00
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
# ========================================================================== #
|
|
|
|
# Test Fixtures
|
|
|
|
# ========================================================================== #
|
|
|
|
|
|
|
|
module ConfigTestHelper
|
|
|
|
def fixture(fixture_name)
|
|
|
|
case fixture_name.to_sym
|
|
|
|
when :legacy
|
|
|
|
# TODO - this is dubious, but based on https://www.inspec.io/docs/reference/reporters/#automate-reporter
|
|
|
|
# Things that have 'compliance' as a toplevel have also been seen
|
|
|
|
<<~EOJ1
|
2019-06-11 22:24:35 +00:00
|
|
|
{
|
|
|
|
"color": "true",
|
|
|
|
"target_id": "mynode",
|
|
|
|
"reporter": {
|
|
|
|
"automate" : {
|
|
|
|
"url" : "https://YOUR_A2_URL/data-collector/v0/",
|
|
|
|
"token" : "YOUR_A2_ADMIN_TOKEN"
|
|
|
|
}
|
2019-01-08 01:07:59 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
EOJ1
|
|
|
|
when :basic
|
|
|
|
<<~EOJ2
|
2019-06-11 22:24:35 +00:00
|
|
|
{
|
|
|
|
"version": "1.1",
|
|
|
|
"cli_options": {
|
|
|
|
"create_lockfile": "false"
|
|
|
|
},
|
|
|
|
"reporter": {
|
|
|
|
"automate" : {
|
|
|
|
"url": "http://some.where",
|
|
|
|
"token" : "YOUR_A2_ADMIN_TOKEN"
|
|
|
|
}
|
|
|
|
},
|
|
|
|
"credentials": {
|
|
|
|
"ssh": {
|
|
|
|
"set1": {
|
|
|
|
"host": "some.host",
|
|
|
|
"user": "some_user"
|
|
|
|
}
|
2019-01-09 06:58:28 +00:00
|
|
|
}
|
|
|
|
}
|
2019-01-08 01:07:59 +00:00
|
|
|
}
|
|
|
|
EOJ2
|
|
|
|
when :like_legacy
|
|
|
|
<<~EOJ3
|
2019-06-11 22:24:35 +00:00
|
|
|
{
|
|
|
|
"version": "1.1",
|
|
|
|
"cli_options": {
|
|
|
|
"color": "true",
|
|
|
|
"target_id": "mynode"
|
|
|
|
},
|
|
|
|
"reporter": {
|
|
|
|
"automate" : {
|
|
|
|
"url" : "https://YOUR_A2_URL/data-collector/v0/",
|
|
|
|
"token" : "YOUR_A2_ADMIN_TOKEN"
|
|
|
|
}
|
2019-01-08 01:07:59 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
EOJ3
|
|
|
|
when :override_check
|
|
|
|
<<~EOJ4
|
2019-06-11 22:24:35 +00:00
|
|
|
{
|
|
|
|
"version": "1.1",
|
|
|
|
"cli_options": {
|
|
|
|
"target_id": "value_from_config_file"
|
|
|
|
},
|
|
|
|
"reporter": {
|
|
|
|
"json": {
|
|
|
|
"path": "path/from/config/file"
|
|
|
|
}
|
2019-01-08 01:07:59 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
EOJ4
|
|
|
|
when :minimal
|
|
|
|
'{ "version": "1.1" }'
|
|
|
|
when :bad_version
|
|
|
|
'{ "version": "99.99" }'
|
|
|
|
when :bad_top_level
|
|
|
|
'{ "version": "1.1", "unsupported_field": "some_value" }'
|
|
|
|
when :malformed_json
|
2019-01-17 16:07:13 +00:00
|
|
|
'{ "hot_garbage": "a", "version": "1.1", '
|
2019-01-08 01:07:59 +00:00
|
|
|
when :with_compliance
|
|
|
|
# TODO - this is dubious, need to verify
|
|
|
|
<<~EOJ5
|
2019-06-11 22:24:35 +00:00
|
|
|
{
|
|
|
|
"compliance": {
|
|
|
|
"server":"https://some.host",
|
|
|
|
"user":"someuser"
|
|
|
|
}
|
2019-01-08 01:07:59 +00:00
|
|
|
}
|
|
|
|
EOJ5
|
2019-02-22 12:05:16 +00:00
|
|
|
when :match_checks_in_credset_names
|
|
|
|
<<~EOJ6
|
2019-06-11 22:24:35 +00:00
|
|
|
{
|
|
|
|
"version": "1.1",
|
|
|
|
"credentials": {
|
|
|
|
"ssh": {
|
|
|
|
"TitleCase": {
|
|
|
|
"found": "yes"
|
|
|
|
},
|
|
|
|
"snake_case": {
|
|
|
|
"found": "yes"
|
|
|
|
},
|
|
|
|
"conta1nsnumeral5": {
|
|
|
|
"found": "yes"
|
|
|
|
},
|
|
|
|
"contains.dots": {
|
|
|
|
"found": "no"
|
|
|
|
},
|
|
|
|
"contains spaces": {
|
|
|
|
"found": "no"
|
|
|
|
}
|
2019-02-22 12:05:16 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
EOJ6
|
2019-01-08 01:07:59 +00:00
|
|
|
end
|
|
|
|
end
|
|
|
|
module_function :fixture
|
|
|
|
end
|