|
34 | 34 | import static org.junit.Assert.assertArrayEquals; |
35 | 35 | import static org.junit.Assert.assertEquals; |
36 | 36 | import static org.junit.Assert.assertFalse; |
| 37 | +import static org.junit.Assert.assertNotEquals; |
37 | 38 | import static org.junit.Assert.assertNotNull; |
38 | 39 | import static org.junit.Assert.assertNull; |
39 | 40 | import static org.junit.Assert.assertSame; |
|
45 | 46 | import com.google.api.client.json.webtoken.JsonWebSignature; |
46 | 47 | import com.google.api.client.util.Clock; |
47 | 48 | import com.google.auth.Credentials; |
| 49 | +import com.google.auth.TestClock; |
48 | 50 | import com.google.auth.http.AuthHttpConstants; |
49 | 51 | import com.google.auth.oauth2.GoogleCredentialsTest.MockHttpTransportFactory; |
50 | 52 |
|
|
62 | 64 | import java.security.SignatureException; |
63 | 65 | import java.util.List; |
64 | 66 | import java.util.Map; |
| 67 | +import java.util.concurrent.TimeUnit; |
65 | 68 |
|
66 | 69 | /** |
67 | 70 | * Test case for {@link ServiceAccountCredentials}. |
@@ -224,6 +227,54 @@ public void getRequestMetadata_blocking_noURI_throws() throws IOException { |
224 | 227 | } |
225 | 228 | } |
226 | 229 |
|
| 230 | + @Test |
| 231 | + public void getRequestMetadata_blocking_cached() throws IOException { |
| 232 | + TestClock testClock = new TestClock(); |
| 233 | + |
| 234 | + PrivateKey privateKey = ServiceAccountCredentials.privateKeyFromPkcs8(SA_PRIVATE_KEY_PKCS8); |
| 235 | + ServiceAccountJwtAccessCredentials credentials = ServiceAccountJwtAccessCredentials.newBuilder() |
| 236 | + .setClientId(SA_CLIENT_ID) |
| 237 | + .setClientEmail(SA_CLIENT_EMAIL) |
| 238 | + .setPrivateKey(privateKey) |
| 239 | + .setPrivateKeyId(SA_PRIVATE_KEY_ID) |
| 240 | + .build(); |
| 241 | + credentials.clock = testClock; |
| 242 | + |
| 243 | + Map<String, List<String>> metadata1 = credentials.getRequestMetadata(CALL_URI); |
| 244 | + |
| 245 | + // Fast forward time a little |
| 246 | + long lifeSpanMs = TimeUnit.SECONDS.toMillis(10); |
| 247 | + testClock.setCurrentTime(lifeSpanMs); |
| 248 | + |
| 249 | + Map<String, List<String>> metadata2 = credentials.getRequestMetadata(CALL_URI); |
| 250 | + |
| 251 | + assertEquals(metadata1, metadata2); |
| 252 | + } |
| 253 | + |
| 254 | + @Test |
| 255 | + public void getRequestMetadata_blocking_cache_expired() throws IOException { |
| 256 | + TestClock testClock = new TestClock(); |
| 257 | + |
| 258 | + PrivateKey privateKey = ServiceAccountCredentials.privateKeyFromPkcs8(SA_PRIVATE_KEY_PKCS8); |
| 259 | + ServiceAccountJwtAccessCredentials credentials = ServiceAccountJwtAccessCredentials.newBuilder() |
| 260 | + .setClientId(SA_CLIENT_ID) |
| 261 | + .setClientEmail(SA_CLIENT_EMAIL) |
| 262 | + .setPrivateKey(privateKey) |
| 263 | + .setPrivateKeyId(SA_PRIVATE_KEY_ID) |
| 264 | + .build(); |
| 265 | + credentials.clock = testClock; |
| 266 | + |
| 267 | + Map<String, List<String>> metadata1 = credentials.getRequestMetadata(CALL_URI); |
| 268 | + |
| 269 | + // Fast forward time past the expiration |
| 270 | + long lifeSpanMs = TimeUnit.SECONDS.toMillis(ServiceAccountJwtAccessCredentials.LIFE_SPAN_SECS); |
| 271 | + testClock.setCurrentTime(lifeSpanMs); |
| 272 | + |
| 273 | + Map<String, List<String>> metadata2 = credentials.getRequestMetadata(CALL_URI); |
| 274 | + |
| 275 | + assertNotEquals(metadata1, metadata2); |
| 276 | + } |
| 277 | + |
227 | 278 | @Test |
228 | 279 | public void getRequestMetadata_async_hasJwtAccess() throws IOException { |
229 | 280 | PrivateKey privateKey = ServiceAccountCredentials.privateKeyFromPkcs8(SA_PRIVATE_KEY_PKCS8); |
@@ -278,6 +329,60 @@ public void getRequestMetadata_async_noURI_exception() throws IOException { |
278 | 329 | assertNotNull(callback.exception); |
279 | 330 | } |
280 | 331 |
|
| 332 | + @Test |
| 333 | + public void getRequestMetadata_async_cache_expired() throws IOException { |
| 334 | + TestClock testClock = new TestClock(); |
| 335 | + |
| 336 | + PrivateKey privateKey = ServiceAccountCredentials.privateKeyFromPkcs8(SA_PRIVATE_KEY_PKCS8); |
| 337 | + ServiceAccountJwtAccessCredentials credentials = ServiceAccountJwtAccessCredentials.newBuilder() |
| 338 | + .setClientId(SA_CLIENT_ID) |
| 339 | + .setClientEmail(SA_CLIENT_EMAIL) |
| 340 | + .setPrivateKey(privateKey) |
| 341 | + .setPrivateKeyId(SA_PRIVATE_KEY_ID) |
| 342 | + .build(); |
| 343 | + credentials.clock = testClock; |
| 344 | + MockExecutor executor = new MockExecutor(); |
| 345 | + |
| 346 | + MockRequestMetadataCallback callback1 = new MockRequestMetadataCallback(); |
| 347 | + credentials.getRequestMetadata(CALL_URI, executor, callback1); |
| 348 | + |
| 349 | + // Fast forward time past the expiration |
| 350 | + long lifeSpanMs = TimeUnit.SECONDS.toMillis(ServiceAccountJwtAccessCredentials.LIFE_SPAN_SECS); |
| 351 | + testClock.setCurrentTime(lifeSpanMs); |
| 352 | + |
| 353 | + MockRequestMetadataCallback callback2 = new MockRequestMetadataCallback(); |
| 354 | + credentials.getRequestMetadata(CALL_URI, executor, callback2); |
| 355 | + |
| 356 | + assertNotEquals(callback1.metadata, callback2.metadata); |
| 357 | + } |
| 358 | + |
| 359 | + @Test |
| 360 | + public void getRequestMetadata_async_cached() throws IOException { |
| 361 | + TestClock testClock = new TestClock(); |
| 362 | + |
| 363 | + PrivateKey privateKey = ServiceAccountCredentials.privateKeyFromPkcs8(SA_PRIVATE_KEY_PKCS8); |
| 364 | + ServiceAccountJwtAccessCredentials credentials = ServiceAccountJwtAccessCredentials.newBuilder() |
| 365 | + .setClientId(SA_CLIENT_ID) |
| 366 | + .setClientEmail(SA_CLIENT_EMAIL) |
| 367 | + .setPrivateKey(privateKey) |
| 368 | + .setPrivateKeyId(SA_PRIVATE_KEY_ID) |
| 369 | + .build(); |
| 370 | + credentials.clock = testClock; |
| 371 | + MockExecutor executor = new MockExecutor(); |
| 372 | + |
| 373 | + MockRequestMetadataCallback callback1 = new MockRequestMetadataCallback(); |
| 374 | + credentials.getRequestMetadata(CALL_URI, executor, callback1); |
| 375 | + |
| 376 | + // Fast forward time a little |
| 377 | + long lifeSpanMs = TimeUnit.SECONDS.toMillis(10); |
| 378 | + testClock.setCurrentTime(lifeSpanMs); |
| 379 | + |
| 380 | + MockRequestMetadataCallback callback2 = new MockRequestMetadataCallback(); |
| 381 | + credentials.getRequestMetadata(CALL_URI, executor, callback2); |
| 382 | + |
| 383 | + assertEquals(callback1.metadata, callback2.metadata); |
| 384 | + } |
| 385 | + |
281 | 386 | @Test |
282 | 387 | public void getAccount_sameAs() throws IOException { |
283 | 388 | PrivateKey privateKey = ServiceAccountCredentials.privateKeyFromPkcs8(SA_PRIVATE_KEY_PKCS8); |
@@ -466,6 +571,7 @@ public void serialize() throws IOException, ClassNotFoundException { |
466 | 571 | .build(); |
467 | 572 | ServiceAccountJwtAccessCredentials deserializedCredentials = |
468 | 573 | serializeAndDeserialize(credentials); |
| 574 | + verifyJwtAccess(deserializedCredentials.getRequestMetadata(), SA_CLIENT_EMAIL, CALL_URI, SA_PRIVATE_KEY_ID); |
469 | 575 | assertEquals(credentials, deserializedCredentials); |
470 | 576 | assertEquals(credentials.hashCode(), deserializedCredentials.hashCode()); |
471 | 577 | assertEquals(credentials.toString(), deserializedCredentials.toString()); |
|
0 commit comments