blob: c30961baa9af45a049959e6c375d777b49111d6f [file] [log] [blame]
DavidPurcellb25f93d2017-01-27 12:46:27 -05001# Copyright 2017 AT&T Corporation.
DavidPurcell029d8c32017-01-06 15:27:41 -05002# All Rights Reserved.
3#
4# Licensed under the Apache License, Version 2.0 (the "License"); you may
5# not use this file except in compliance with the License. You may obtain
6# a copy of the License at
7#
8# http://www.apache.org/licenses/LICENSE-2.0
9#
10# Unless required by applicable law or agreed to in writing, software
11# distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
12# WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
13# License for the specific language governing permissions and limitations
14# under the License.
15
16from tempest.lib import exceptions
17
18
Mykola Yakovliev11376ab2018-08-06 15:34:22 -050019class BasePatroleException(exceptions.TempestException):
20 message = "An unknown RBAC exception occurred"
21
22
Felipe Monteiro74f8e7d2018-09-30 12:33:49 -040023class BasePatroleResponseBodyException(BasePatroleException):
24 message = "Response body incomplete due to RBAC authorization failure"
Samantha Blanco36bea052017-07-19 12:01:59 -040025
Felipe Monteiro74f8e7d2018-09-30 12:33:49 -040026
27class RbacMissingAttributeResponseBody(BasePatroleResponseBodyException):
28 """Raised when a list or show action is missing an attribute following
29 RBAC authorization failure.
30 """
31 message = ("The response body is missing the expected %(attribute)s due "
32 "to policy enforcement failure")
33
34
35class RbacPartialResponseBody(BasePatroleResponseBodyException):
36 """Raised when a list action only returns a subset of the available
37 resources.
38
39 For example, admin can return more resources than member for a list action.
40 """
41 message = ("The response body only lists a subset of the available "
42 "resources due to partial policy enforcement failure. Response "
43 "body: %(body)s")
44
45
46class RbacEmptyResponseBody(BasePatroleResponseBodyException):
47 """Raised when a list or show action is empty following RBAC authorization
48 failure.
49 """
Sergey Vilgelmbab9e942018-10-11 14:04:48 -050050 message = "The response body is empty due to policy enforcement failure."
DavidPurcell029d8c32017-01-06 15:27:41 -050051
52
Mykola Yakovliev11376ab2018-08-06 15:34:22 -050053class RbacResourceSetupFailed(BasePatroleException):
Felipe Monteiro44d77842018-03-21 02:42:59 +000054 message = "RBAC resource setup failed"
DavidPurcell029d8c32017-01-06 15:27:41 -050055
56
Mykola Yakovliev11376ab2018-08-06 15:34:22 -050057class RbacOverPermissionException(BasePatroleException):
Felipe Monteirof16b6b32018-06-28 19:32:59 -040058 """Raised when the expected result is failure but the actual result is
59 pass.
60 """
61 message = "Unauthorized action was allowed to be performed"
62
63
Mykola Yakovliev11376ab2018-08-06 15:34:22 -050064class RbacUnderPermissionException(BasePatroleException):
Felipe Monteirof16b6b32018-06-28 19:32:59 -040065 """Raised when the expected result is pass but the actual result is
66 failure.
67 """
68 message = "Authorized action was not allowed to be performed"
69
70
Mykola Yakovliev11376ab2018-08-06 15:34:22 -050071class RbacExpectedWrongException(BasePatroleException):
Felipe Monteirof16b6b32018-06-28 19:32:59 -040072 """Raised when the expected exception does not match the actual exception
73 raised, when both are instances of Forbidden or NotFound, indicating
74 the test provides a wrong argument to `expected_error_codes`.
75 """
76 message = ("Expected %(expected)s to be raised but %(actual)s was raised "
77 "instead. Actual exception: %(exception)s")
Rick Bartra503c5572017-03-09 13:49:58 -050078
79
Mykola Yakovliev11376ab2018-08-06 15:34:22 -050080class RbacInvalidServiceException(BasePatroleException):
Felipe Monteiro51299a12018-06-28 20:03:27 -040081 """Raised when an invalid service is passed to ``rbac_rule_validation``
82 decorator.
83 """
Rick Bartra503c5572017-03-09 13:49:58 -050084 message = "Attempted to test an invalid service"
Felipe Monteiro48c913d2017-03-15 12:07:48 -040085
86
Mykola Yakovliev11376ab2018-08-06 15:34:22 -050087class RbacParsingException(BasePatroleException):
Felipe Monteiro48c913d2017-03-15 12:07:48 -040088 message = "Attempted to test an invalid policy file or action"
Rick Bartra12998942017-03-17 17:35:45 -040089
90
Mykola Yakovliev11376ab2018-08-06 15:34:22 -050091class RbacInvalidErrorCode(BasePatroleException):
Rick Bartra12998942017-03-17 17:35:45 -040092 message = "Unsupported error code passed in test"
Mykola Yakovliev11376ab2018-08-06 15:34:22 -050093
94
95class RbacOverrideRoleException(BasePatroleException):
96 """Raised when override_role is used incorrectly or fails somehow.
97
98 Used for safeguarding against false positives that might occur when the
99 expected exception isn't raised inside the ``override_role`` context.
100 Specifically, when:
101
102 * ``override_role`` isn't called
103 * an exception is raised before ``override_role`` context
104 * an exception is raised after ``override_role`` context
105 """
106 message = "Override role failure or incorrect usage"
Sergey Vilgelmbab9e942018-10-11 14:04:48 -0500107
108
109class RbacValidateListException(BasePatroleException):
110 """Raised when override_role_and_validate_list is used incorrectly.
111
112 Specifically, when:
113
114 * Neither ``resource_id`` nor ``resources`` is initialized
115 * Both ``resource_id`` and ``resources`` are initialized
116 * The ``ctx.resources`` variable wasn't set in
117 override_role_and_validate_list context.
118 """
119 message = "Incorrect usage of override_role_and_validate_list: %(reason)s"