mirror of
https://github.com/NVIDIA/OpenShell.git
synced 2026-10-02 07:34:45 +08:00
* feat(service): add bearer authorization passthrough Signed-off-by: Derek Carr <decarr@redhat.com> * docs(sdk): add service authorization migration guide Signed-off-by: Derek Carr <decarr@redhat.com> * fix(server): remove stale version import Signed-off-by: Derek Carr <decarr@redhat.com> * docs(upgrade): remove service authorization SDK guide Signed-off-by: Derek Carr <decarr@redhat.com> * fix(e2e): relabel provider readiness TLS mount Signed-off-by: Derek Carr <decarr@redhat.com> * test(e2e): stabilize exposed service routing Signed-off-by: Derek Carr <decarr@redhat.com> * test(e2e): support HTTPS service routing Signed-off-by: Derek Carr <decarr@redhat.com> --------- Signed-off-by: Derek Carr <decarr@redhat.com>
138 lines
4.1 KiB
Go
138 lines
4.1 KiB
Go
// SPDX-FileCopyrightText: Copyright (c) 2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
|
|
// SPDX-License-Identifier: Apache-2.0
|
|
|
|
package converter
|
|
|
|
import (
|
|
"testing"
|
|
|
|
v1 "github.com/NVIDIA/OpenShell/sdk/go/openshell/v1/types"
|
|
dm "github.com/NVIDIA/OpenShell/sdk/go/proto/datamodelv1"
|
|
pb "github.com/NVIDIA/OpenShell/sdk/go/proto/openshellv1"
|
|
"github.com/stretchr/testify/assert"
|
|
"github.com/stretchr/testify/require"
|
|
)
|
|
|
|
func TestServiceEndpointFromProto(t *testing.T) {
|
|
resp := &pb.ServiceEndpointResponse{
|
|
Endpoint: &pb.ServiceEndpoint{
|
|
Metadata: &dm.ObjectMeta{
|
|
Id: "svc-1",
|
|
},
|
|
SandboxId: "sb-1",
|
|
Sandbox: "my-sandbox",
|
|
Name: "http-server",
|
|
TargetPort: 8080,
|
|
Domain: true,
|
|
AuthorizationMode: pb.ServiceAuthorizationMode_SERVICE_AUTHORIZATION_MODE_BEARER_PASSTHROUGH,
|
|
},
|
|
Url: "https://svc-1.example.com",
|
|
}
|
|
|
|
se := ServiceEndpointFromProto(resp)
|
|
|
|
require.NotNil(t, se)
|
|
assert.Equal(t, "svc-1", se.ID)
|
|
assert.Equal(t, "sb-1", se.SandboxID)
|
|
assert.Equal(t, "my-sandbox", se.Sandbox)
|
|
assert.Equal(t, "http-server", se.Name)
|
|
assert.Equal(t, uint32(8080), se.TargetPort)
|
|
assert.True(t, se.Domain)
|
|
assert.Equal(t, v1.ServiceAuthorizationModeBearerPassthrough, se.AuthorizationMode)
|
|
assert.Equal(t, "https://svc-1.example.com", se.URL)
|
|
}
|
|
|
|
func TestServiceEndpointFromProto_NilEndpoint(t *testing.T) {
|
|
resp := &pb.ServiceEndpointResponse{
|
|
Url: "https://orphan.example.com",
|
|
}
|
|
|
|
se := ServiceEndpointFromProto(resp)
|
|
|
|
require.NotNil(t, se)
|
|
assert.Empty(t, se.ID)
|
|
assert.Empty(t, se.SandboxID)
|
|
assert.Equal(t, "https://orphan.example.com", se.URL)
|
|
}
|
|
|
|
func TestServiceEndpointFromProto_NilMetadata(t *testing.T) {
|
|
resp := &pb.ServiceEndpointResponse{
|
|
Endpoint: &pb.ServiceEndpoint{
|
|
SandboxId: "sb-2",
|
|
Name: "api",
|
|
TargetPort: 3000,
|
|
},
|
|
}
|
|
|
|
se := ServiceEndpointFromProto(resp)
|
|
|
|
require.NotNil(t, se)
|
|
assert.Empty(t, se.ID)
|
|
assert.Equal(t, "sb-2", se.SandboxID)
|
|
assert.Equal(t, "api", se.Name)
|
|
assert.Equal(t, uint32(3000), se.TargetPort)
|
|
}
|
|
|
|
func TestServiceEndpointFromProto_Nil(t *testing.T) {
|
|
se := ServiceEndpointFromProto(nil)
|
|
assert.Nil(t, se)
|
|
}
|
|
|
|
func TestServiceEndpointToProto(t *testing.T) {
|
|
se := &v1.ServiceEndpoint{
|
|
ID: "svc-1",
|
|
SandboxID: "sb-1",
|
|
Sandbox: "my-sandbox",
|
|
Name: "http-server",
|
|
TargetPort: 8080,
|
|
Domain: true,
|
|
AuthorizationMode: v1.ServiceAuthorizationModeBearerPassthrough,
|
|
URL: "https://svc-1.example.com",
|
|
}
|
|
|
|
resp := ServiceEndpointToProto(se)
|
|
|
|
require.NotNil(t, resp)
|
|
require.NotNil(t, resp.Endpoint)
|
|
require.NotNil(t, resp.Endpoint.Metadata)
|
|
assert.Equal(t, "svc-1", resp.Endpoint.Metadata.Id)
|
|
assert.Equal(t, "sb-1", resp.Endpoint.SandboxId)
|
|
assert.Equal(t, "my-sandbox", resp.Endpoint.Sandbox)
|
|
assert.Equal(t, "http-server", resp.Endpoint.Name)
|
|
assert.Equal(t, uint32(8080), resp.Endpoint.TargetPort)
|
|
assert.True(t, resp.Endpoint.Domain)
|
|
assert.Equal(t, pb.ServiceAuthorizationMode_SERVICE_AUTHORIZATION_MODE_BEARER_PASSTHROUGH, resp.Endpoint.AuthorizationMode)
|
|
assert.Equal(t, "https://svc-1.example.com", resp.Url)
|
|
}
|
|
|
|
func TestServiceEndpointToProto_Nil(t *testing.T) {
|
|
resp := ServiceEndpointToProto(nil)
|
|
assert.Nil(t, resp)
|
|
}
|
|
|
|
func TestServiceEndpointRoundTrip(t *testing.T) {
|
|
original := &v1.ServiceEndpoint{
|
|
ID: "svc-rt",
|
|
SandboxID: "sb-rt",
|
|
Sandbox: "round-trip",
|
|
Name: "web",
|
|
TargetPort: 9090,
|
|
Domain: false,
|
|
AuthorizationMode: v1.ServiceAuthorizationModeBearerPassthrough,
|
|
URL: "http://localhost:9090",
|
|
}
|
|
|
|
proto := ServiceEndpointToProto(original)
|
|
back := ServiceEndpointFromProto(proto)
|
|
|
|
require.NotNil(t, back)
|
|
assert.Equal(t, original.ID, back.ID)
|
|
assert.Equal(t, original.SandboxID, back.SandboxID)
|
|
assert.Equal(t, original.Sandbox, back.Sandbox)
|
|
assert.Equal(t, original.Name, back.Name)
|
|
assert.Equal(t, original.TargetPort, back.TargetPort)
|
|
assert.Equal(t, original.Domain, back.Domain)
|
|
assert.Equal(t, original.AuthorizationMode, back.AuthorizationMode)
|
|
assert.Equal(t, original.URL, back.URL)
|
|
}
|