feat: validate profile with apple (#21862)
> Related issue: #17558 # Checklist for submitter If some of the following don't apply, delete the relevant line. <!-- Note that API documentation changes are now addressed by the product design team. --> - [x] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/Committing-Changes.md#changes-files) for more information. - [x] Input data is properly validated, `SELECT *` is avoided, SQL injection is prevented (using placeholders for values in statements) - [x] Added/updated tests - [x] Manual QA for all new/changed functionality
This commit is contained in:
@@ -23,9 +23,11 @@ import (
|
||||
"github.com/fleetdm/fleet/v4/server/config"
|
||||
"github.com/fleetdm/fleet/v4/server/fleet"
|
||||
apple_mdm "github.com/fleetdm/fleet/v4/server/mdm/apple"
|
||||
nanodep_client "github.com/fleetdm/fleet/v4/server/mdm/nanodep/client"
|
||||
"github.com/fleetdm/fleet/v4/server/mdm/nanodep/tokenpki"
|
||||
"github.com/fleetdm/fleet/v4/server/mock"
|
||||
mdmmock "github.com/fleetdm/fleet/v4/server/mock/mdm"
|
||||
nanodep_mock "github.com/fleetdm/fleet/v4/server/mock/nanodep"
|
||||
"github.com/fleetdm/fleet/v4/server/ptr"
|
||||
"github.com/fleetdm/fleet/v4/server/service"
|
||||
"github.com/google/uuid"
|
||||
@@ -1171,6 +1173,9 @@ func TestApplyAsGitOps(t *testing.T) {
|
||||
testCertPEM := tokenpki.PEMCertificate(testCert.Raw)
|
||||
testKeyPEM := tokenpki.PEMRSAPrivateKey(testKey)
|
||||
fleetCfg := config.TestConfig()
|
||||
// Mock Apple DEP API
|
||||
depStorage := SetupMockDEPStorageAndMockDEPServer(t)
|
||||
|
||||
config.SetTestMDMConfig(t, &fleetCfg, testCertPEM, testKeyPEM, "../../server/service/testdata")
|
||||
|
||||
_, ds := runServerWithMockedDS(t, &service.TestServerOpts{
|
||||
@@ -1178,6 +1183,7 @@ func TestApplyAsGitOps(t *testing.T) {
|
||||
MDMStorage: enqueuer,
|
||||
MDMPusher: mockPusher{},
|
||||
FleetConfig: &fleetCfg,
|
||||
DEPStorage: depStorage,
|
||||
})
|
||||
|
||||
gitOps := &fleet.User{
|
||||
@@ -1296,6 +1302,20 @@ func TestApplyAsGitOps(t *testing.T) {
|
||||
return nil
|
||||
}
|
||||
|
||||
ds.GetMDMAppleEnrollmentProfileByTypeFunc = func(ctx context.Context, typ fleet.MDMAppleEnrollmentType) (*fleet.MDMAppleEnrollmentProfile, error) {
|
||||
return &fleet.MDMAppleEnrollmentProfile{Token: "foobar"}, nil
|
||||
}
|
||||
ds.CountABMTokensWithTermsExpiredFunc = func(ctx context.Context) (int, error) {
|
||||
return 0, nil
|
||||
}
|
||||
|
||||
ds.GetABMTokenOrgNamesAssociatedWithTeamFunc = func(ctx context.Context, teamID *uint) ([]string, error) {
|
||||
return []string{"foobar"}, nil
|
||||
}
|
||||
ds.ListABMTokensFunc = func(ctx context.Context) ([]*fleet.ABMToken, error) {
|
||||
return []*fleet.ABMToken{{ID: 1}}, nil
|
||||
}
|
||||
|
||||
// Apply global config.
|
||||
name := writeTmpYml(t, `---
|
||||
apiVersion: v1
|
||||
@@ -1632,6 +1652,34 @@ spec:
|
||||
assert.Equal(t, "select * from app_schemes;", appliedQueries[0].Query)
|
||||
}
|
||||
|
||||
func SetupMockDEPStorageAndMockDEPServer(t *testing.T) *nanodep_mock.Storage {
|
||||
ts := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||
switch {
|
||||
case strings.Contains(r.URL.Path, "/server/devices"):
|
||||
_, err := w.Write([]byte("{}"))
|
||||
require.NoError(t, err)
|
||||
case strings.Contains(r.URL.Path, "/session"):
|
||||
_, err := w.Write([]byte(`{"auth_session_token": "yoo"}`))
|
||||
require.NoError(t, err)
|
||||
case strings.Contains(r.URL.Path, "/profile"):
|
||||
_, err := w.Write([]byte(`{"profile_uuid": "profile123"}`))
|
||||
require.NoError(t, err)
|
||||
}
|
||||
}))
|
||||
depStorage := &nanodep_mock.Storage{}
|
||||
depStorage.RetrieveConfigFunc = func(context.Context, string) (*nanodep_client.Config, error) {
|
||||
return &nanodep_client.Config{
|
||||
BaseURL: ts.URL,
|
||||
}, nil
|
||||
}
|
||||
depStorage.RetrieveAuthTokensFunc = func(ctx context.Context, name string) (*nanodep_client.OAuth1Tokens, error) {
|
||||
return &nanodep_client.OAuth1Tokens{}, nil
|
||||
}
|
||||
t.Cleanup(func() { ts.Close() })
|
||||
|
||||
return depStorage
|
||||
}
|
||||
|
||||
func TestApplyEnrollSecrets(t *testing.T) {
|
||||
_, ds := runServerWithMockedDS(t)
|
||||
|
||||
@@ -1885,7 +1933,8 @@ func TestApplyMacosSetup(t *testing.T) {
|
||||
tier = fleet.TierPremium
|
||||
}
|
||||
license := &fleet.LicenseInfo{Tier: tier, Expiration: time.Now().Add(24 * time.Hour)}
|
||||
_, ds := runServerWithMockedDS(t, &service.TestServerOpts{License: license})
|
||||
depStorage := SetupMockDEPStorageAndMockDEPServer(t)
|
||||
_, ds := runServerWithMockedDS(t, &service.TestServerOpts{License: license, DEPStorage: depStorage})
|
||||
|
||||
tm1 := &fleet.Team{ID: 1, Name: "tm1"}
|
||||
teamsByName := map[string]*fleet.Team{
|
||||
@@ -2027,6 +2076,21 @@ func TestApplyMacosSetup(t *testing.T) {
|
||||
ds.GetMDMAppleBootstrapPackageMetaFunc = func(ctx context.Context, teamID uint) (*fleet.MDMAppleBootstrapPackage, error) {
|
||||
return nil, nil
|
||||
}
|
||||
|
||||
ds.GetMDMAppleEnrollmentProfileByTypeFunc = func(ctx context.Context, typ fleet.MDMAppleEnrollmentType) (*fleet.MDMAppleEnrollmentProfile, error) {
|
||||
return &fleet.MDMAppleEnrollmentProfile{Token: "foobar"}, nil
|
||||
}
|
||||
ds.CountABMTokensWithTermsExpiredFunc = func(ctx context.Context) (int, error) {
|
||||
return 0, nil
|
||||
}
|
||||
|
||||
ds.GetABMTokenOrgNamesAssociatedWithTeamFunc = func(ctx context.Context, teamID *uint) ([]string, error) {
|
||||
return []string{"foobar"}, nil
|
||||
}
|
||||
ds.ListABMTokensFunc = func(ctx context.Context) ([]*fleet.ABMToken, error) {
|
||||
return []*fleet.ABMToken{{ID: 1}}, nil
|
||||
}
|
||||
|
||||
return ds
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user