forked from Versent/saml2aws
-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathaws_account_test.go
78 lines (62 loc) · 1.96 KB
/
aws_account_test.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
package saml2aws
import (
"os"
"testing"
"github.com/stretchr/testify/assert"
)
func TestExtractAWSAccounts(t *testing.T) {
data, err := os.ReadFile("testdata/saml.html")
assert.Nil(t, err)
accounts, err := ExtractAWSAccounts(data)
assert.Nil(t, err)
assert.Len(t, accounts, 2)
account := accounts[0]
assert.Equal(t, account.Name, "Account: account-alias (000000000001)")
assert.Len(t, account.Roles, 2)
role := account.Roles[0]
assert.Equal(t, role.RoleARN, "arn:aws:iam::000000000001:role/Development")
assert.Equal(t, role.Name, "Development")
role = account.Roles[1]
assert.Equal(t, role.RoleARN, "arn:aws:iam::000000000001:role/Production")
assert.Equal(t, role.Name, "Production")
account = accounts[1]
assert.Equal(t, account.Name, "Account: 000000000002")
assert.Len(t, account.Roles, 1)
role = account.Roles[0]
assert.Equal(t, role.RoleARN, "arn:aws:iam::000000000002:role/Production")
assert.Equal(t, role.Name, "Production")
}
func TestAssignPrincipals(t *testing.T) {
awsRoles := []*AWSRole{
{
PrincipalARN: "arn:aws:iam::000000000001:saml-provider/test-idp",
RoleARN: "arn:aws:iam::000000000001:role/Development",
},
}
awsAccounts := []*AWSAccount{
{
Roles: []*AWSRole{
{
RoleARN: "arn:aws:iam::000000000001:role/Development",
},
},
},
}
AssignPrincipals(awsRoles, awsAccounts)
assert.Equal(t, "arn:aws:iam::000000000001:saml-provider/test-idp", awsAccounts[0].Roles[0].PrincipalARN)
}
func TestLocateRole(t *testing.T) {
awsRoles := []*AWSRole{
{
PrincipalARN: "arn:aws:iam::000000000001:saml-provider/test-idp",
RoleARN: "arn:aws:iam::000000000001:role/Development",
},
{
PrincipalARN: "arn:aws:iam::000000000002:saml-provider/test-idp",
RoleARN: "arn:aws:iam::000000000002:role/Development",
},
}
role, err := LocateRole(awsRoles, "arn:aws:iam::000000000001:role/Development")
assert.Empty(t, err)
assert.Equal(t, "arn:aws:iam::000000000001:role/Development", role.RoleARN)
}