blob: 6bdd7dfd1a0116af93e4a5a678ac16f24b5b3bae [file] [log] [blame]
DavidPurcellb25f93d2017-01-27 12:46:27 -05001# Copyright 2017 AT&T Corporation.
DavidPurcell029d8c32017-01-06 15:27:41 -05002# All Rights Reserved.
3#
4# Licensed under the Apache License, Version 2.0 (the "License"); you may
5# not use this file except in compliance with the License. You may obtain
6# a copy of the License at
7#
8# http://www.apache.org/licenses/LICENSE-2.0
9#
10# Unless required by applicable law or agreed to in writing, software
11# distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
12# WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
13# License for the specific language governing permissions and limitations
14# under the License.
15
16from tempest.lib import exceptions
17
18
Mykola Yakovliev11376ab2018-08-06 15:34:22 -050019class BasePatroleException(exceptions.TempestException):
20 message = "An unknown RBAC exception occurred"
21
22
Mykola Yakovliev11376ab2018-08-06 15:34:22 -050023class RbacMalformedResponse(BasePatroleException):
Samantha Blanco36bea052017-07-19 12:01:59 -040024 message = ("The response body is missing the expected %(attribute)s due "
25 "to policy enforcement failure.")
26
Felipe Monteirodcd153a2018-09-23 21:15:54 -040027 def __init__(self, empty=False, **kwargs):
Samantha Blanco36bea052017-07-19 12:01:59 -040028 if empty:
29 self.message = ("The response body is empty due to policy "
30 "enforcement failure.")
31 kwargs = {}
Samantha Blanco36bea052017-07-19 12:01:59 -040032 super(RbacMalformedResponse, self).__init__(**kwargs)
DavidPurcell029d8c32017-01-06 15:27:41 -050033
34
Mykola Yakovliev11376ab2018-08-06 15:34:22 -050035class RbacResourceSetupFailed(BasePatroleException):
Felipe Monteiro44d77842018-03-21 02:42:59 +000036 message = "RBAC resource setup failed"
DavidPurcell029d8c32017-01-06 15:27:41 -050037
38
Mykola Yakovliev11376ab2018-08-06 15:34:22 -050039class RbacOverPermissionException(BasePatroleException):
Felipe Monteirof16b6b32018-06-28 19:32:59 -040040 """Raised when the expected result is failure but the actual result is
41 pass.
42 """
43 message = "Unauthorized action was allowed to be performed"
44
45
Mykola Yakovliev11376ab2018-08-06 15:34:22 -050046class RbacUnderPermissionException(BasePatroleException):
Felipe Monteirof16b6b32018-06-28 19:32:59 -040047 """Raised when the expected result is pass but the actual result is
48 failure.
49 """
50 message = "Authorized action was not allowed to be performed"
51
52
Mykola Yakovliev11376ab2018-08-06 15:34:22 -050053class RbacExpectedWrongException(BasePatroleException):
Felipe Monteirof16b6b32018-06-28 19:32:59 -040054 """Raised when the expected exception does not match the actual exception
55 raised, when both are instances of Forbidden or NotFound, indicating
56 the test provides a wrong argument to `expected_error_codes`.
57 """
58 message = ("Expected %(expected)s to be raised but %(actual)s was raised "
59 "instead. Actual exception: %(exception)s")
Rick Bartra503c5572017-03-09 13:49:58 -050060
61
Mykola Yakovliev11376ab2018-08-06 15:34:22 -050062class RbacInvalidServiceException(BasePatroleException):
Felipe Monteiro51299a12018-06-28 20:03:27 -040063 """Raised when an invalid service is passed to ``rbac_rule_validation``
64 decorator.
65 """
Rick Bartra503c5572017-03-09 13:49:58 -050066 message = "Attempted to test an invalid service"
Felipe Monteiro48c913d2017-03-15 12:07:48 -040067
68
Mykola Yakovliev11376ab2018-08-06 15:34:22 -050069class RbacParsingException(BasePatroleException):
Felipe Monteiro48c913d2017-03-15 12:07:48 -040070 message = "Attempted to test an invalid policy file or action"
Rick Bartra12998942017-03-17 17:35:45 -040071
72
Mykola Yakovliev11376ab2018-08-06 15:34:22 -050073class RbacInvalidErrorCode(BasePatroleException):
Rick Bartra12998942017-03-17 17:35:45 -040074 message = "Unsupported error code passed in test"
Mykola Yakovliev11376ab2018-08-06 15:34:22 -050075
76
77class RbacOverrideRoleException(BasePatroleException):
78 """Raised when override_role is used incorrectly or fails somehow.
79
80 Used for safeguarding against false positives that might occur when the
81 expected exception isn't raised inside the ``override_role`` context.
82 Specifically, when:
83
84 * ``override_role`` isn't called
85 * an exception is raised before ``override_role`` context
86 * an exception is raised after ``override_role`` context
87 """
88 message = "Override role failure or incorrect usage"