gitea/tests/integration
techknowlogick 5bb8d1924d
Support SAML authentication (#25165)
Closes https://github.com/go-gitea/gitea/issues/5512

This PR adds basic SAML support
- Adds SAML 2.0 as an auth source
- Adds SAML configuration documentation
- Adds integration test:
- Use bare-bones SAML IdP to test protocol flow and test account is
linked successfully (only runs on Postgres by default)
- Adds documentation for configuring and running SAML integration test
locally

Future PRs:
- Support group mapping
- Support auto-registration (account linking)

Co-Authored-By: @jackHay22

---------

Co-authored-by: jackHay22 <jack@allspice.io>
Co-authored-by: Lunny Xiao <xiaolunwen@gmail.com>
Co-authored-by: KN4CK3R <admin@oldschoolhack.me>
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
Co-authored-by: Jason Song <i@wolfogre.com>
Co-authored-by: morphelinho <morphelinho@users.noreply.github.com>
Co-authored-by: Zettat123 <zettat123@gmail.com>
Co-authored-by: Yarden Shoham <git@yardenshoham.com>
Co-authored-by: 6543 <6543@obermui.de>
Co-authored-by: silverwind <me@silverwind.io>
2024-02-23 00:08:17 +00:00
..
migration-test Preserve BOM in web editor (#28935) 2024-01-27 18:02:51 +00:00
schemas
actions_trigger_test.go Fix schedule tasks bugs (#28691) 2024-01-12 21:50:38 +00:00
admin_config_test.go
admin_user_test.go
api_actions_artifact_test.go Fix uploaded artifacts should be overwritten (#28726) 2024-01-17 11:21:16 +08:00
api_activitypub_person_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_admin_org_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_admin_test.go Unify user update methods (#28733) 2024-02-04 13:29:09 +00:00
api_branch_test.go Recommend/convert to use case-sensitive collation for MySQL/MSSQL (#28662) 2024-01-10 11:03:23 +00:00
api_comment_attachment_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_comment_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_feed_user_test.go
api_fork_test.go
api_gitignore_templates_test.go
api_gpg_keys_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_helper_for_declarative_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_httpsig_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_issue_attachment_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_issue_config_test.go
api_issue_label_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_issue_milestone_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_issue_pin_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_issue_reaction_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_issue_stopwatch_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_issue_subscription_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_issue_templates_test.go Refactor issue template parsing and fix API endpoint (#29069) 2024-02-12 05:04:10 +00:00
api_issue_test.go Disable query token param in integration tests (#28592) 2023-12-23 11:29:51 +08:00
api_issue_tracked_time_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_keys_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_label_templates_test.go
api_license_templates_test.go
api_nodeinfo_test.go Unify user update methods (#28733) 2024-02-04 13:29:09 +00:00
api_notification_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_oauth2_apps_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_org_avatar_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_org_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_packages_alpine_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_packages_cargo_test.go Simplify how git repositories are opened (#28937) 2024-01-27 21:09:51 +01:00
api_packages_chef_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_packages_composer_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_packages_conan_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_packages_conda_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_packages_container_test.go Prevent anonymous container access if RequireSignInView is enabled (#28877) 2024-01-21 16:31:29 +00:00
api_packages_cran_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_packages_debian_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_packages_generic_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_packages_goproxy_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_packages_helm_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_packages_maven_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_packages_npm_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_packages_nuget_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_packages_pub_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_packages_pypi_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_packages_rpm_test.go Fix some RPM registry flaws (#28782) 2024-01-19 11:37:10 +00:00
api_packages_rubygems_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_packages_swift_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_packages_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_packages_vagrant_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_private_serv_test.go Final round of db.DefaultContext refactor (#27587) 2023-10-14 08:37:24 +00:00
api_pull_commits_test.go
api_pull_review_test.go Workaround to clean up old reviews on creating a new one (#28554) 2024-02-19 14:42:18 +01:00
api_pull_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_releases_test.go Simplify how git repositories are opened (#28937) 2024-01-27 21:09:51 +01:00
api_repo_archive_test.go Disable query token param in integration tests (#28592) 2023-12-23 11:29:51 +08:00
api_repo_avatar_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_repo_branch_test.go Disable query token param in integration tests (#28592) 2023-12-23 11:29:51 +08:00
api_repo_collaborator_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_repo_edit_test.go Add merge style fast-forward-only (#28954) 2024-02-12 23:37:23 +01:00
api_repo_file_create_test.go Simplify how git repositories are opened (#28937) 2024-01-27 21:09:51 +01:00
api_repo_file_delete_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_repo_file_get_test.go
api_repo_file_helpers.go
api_repo_file_update_test.go Simplify how git repositories are opened (#28937) 2024-01-27 21:09:51 +01:00
api_repo_files_change_test.go Simplify how git repositories are opened (#28937) 2024-01-27 21:09:51 +01:00
api_repo_get_contents_list_test.go Simplify how git repositories are opened (#28937) 2024-01-27 21:09:51 +01:00
api_repo_get_contents_test.go Simplify how git repositories are opened (#28937) 2024-01-27 21:09:51 +01:00
api_repo_git_blobs_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_repo_git_commits_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_repo_git_hook_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_repo_git_notes_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_repo_git_ref_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_repo_git_tags_test.go Simplify how git repositories are opened (#28937) 2024-01-27 21:09:51 +01:00
api_repo_git_trees_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_repo_hook_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_repo_languages_test.go
api_repo_lfs_locks_test.go
api_repo_lfs_migrate_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_repo_lfs_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_repo_raw_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_repo_secrets_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_repo_tags_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_repo_teams_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_repo_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_repo_topic_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_settings_test.go
api_team_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_team_user_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_token_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_twofa_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_user_avatar_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_user_email_test.go Unify user update methods (#28733) 2024-02-04 13:29:09 +00:00
api_user_follow_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_user_heatmap_test.go Refactor timeutil package (#28623) 2023-12-28 10:09:57 +00:00
api_user_info_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_user_org_perm_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_user_orgs_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_user_search_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_user_secrets_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_user_star_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
api_user_watch_test.go Add tests for #28765 (#28773) 2024-01-12 17:15:42 +00:00
api_wiki_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
attachment_test.go
auth_ldap_test.go Fix labels referencing the wrong ID in the user profile settings (#29199) 2024-02-17 15:01:25 +00:00
avatar.png
benchmarks_test.go
branches_test.go Refactor locale&string&template related code (#29165) 2024-02-14 21:48:45 +00:00
change_default_branch_test.go
cmd_keys_test.go
compare_test.go
cors_test.go Refactor CORS handler (#28587) 2023-12-25 20:13:18 +08:00
create_no_session_test.go
csrf_test.go
db_collation_test.go Recommend/convert to use case-sensitive collation for MySQL/MSSQL (#28662) 2024-01-10 11:03:23 +00:00
delete_user_test.go
download_test.go
dump_restore_test.go
editor_test.go
empty_repo_test.go Unify user update methods (#28733) 2024-02-04 13:29:09 +00:00
eventsource_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
explore_repos_test.go
git_clone_wiki_test.go
git_helper_for_declarative_test.go Adjust object format interface (#28469) 2023-12-17 11:56:08 +00:00
git_smart_http_test.go
git_test.go Prevent double use of git cat-file session. (#29298) 2024-02-21 19:54:17 +01:00
goget_test.go
gpg_git_test.go Replace assert.Fail with assert.FailNow (#27578) 2023-10-11 11:02:24 +00:00
html_helper.go
incoming_email_test.go
integration_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
issue_test.go Fix incorrect URL for "Reference in New Issue" (#28716) 2024-01-07 10:50:03 +00:00
lfs_getobject_test.go Remove GetByBean method because sometimes it's danger when query condition parameter is zero and also introduce new generic methods (#28220) 2023-12-07 15:27:36 +08:00
lfs_local_endpoint_test.go
lfs_view_test.go
links_test.go
markup_external_test.go
migrate_test.go Upgrade xorm to new version which supported update join for all supported databases (#28590) 2023-12-31 05:00:35 +00:00
mirror_pull_test.go Simplify how git repositories are opened (#28937) 2024-01-27 21:09:51 +01:00
mirror_push_test.go Simplify how git repositories are opened (#28937) 2024-01-27 21:09:51 +01:00
nonascii_branches_test.go
oauth_test.go
org_count_test.go Use db.Find instead of writing methods for every object (#28084) 2023-11-24 03:49:41 +00:00
org_project_test.go
org_team_invite_test.go
org_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
private-testing.key
privateactivity_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
project_test.go Do some missing checks (#28423) 2023-12-12 05:01:17 +00:00
pull_compare_test.go
pull_create_test.go Retarget depending pulls when the parent branch is deleted (#28686) 2024-01-17 01:44:56 +01:00
pull_diff_test.go
pull_merge_test.go Refactor locale&string&template related code (#29165) 2024-02-14 21:48:45 +00:00
pull_review_test.go
pull_status_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
pull_update_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
README_ZH.md
README.md Support SAML authentication (#25165) 2024-02-23 00:08:17 +00:00
release_test.go Refactor locale&string&template related code (#29165) 2024-02-14 21:48:45 +00:00
rename_branch_test.go
repo_activity_test.go Retarget depending pulls when the parent branch is deleted (#28686) 2024-01-17 01:44:56 +01:00
repo_branch_test.go Refactor locale&string&template related code (#29165) 2024-02-14 21:48:45 +00:00
repo_commits_search_test.go Integration Test for Commit Search containing Square Brackets (#28751) 2024-01-11 11:04:45 +08:00
repo_commits_test.go
repo_fork_test.go
repo_generate_test.go
repo_mergecommit_revert_test.go Fix reverting a merge commit failing (#28794) 2024-01-16 15:06:51 +00:00
repo_migrate_test.go
repo_search_test.go Convert to url auth to header auth in tests (#28484) 2023-12-21 23:59:59 +00:00
repo_tag_test.go Move more functions to db.Find (#28419) 2024-01-15 02:19:25 +00:00
repo_test.go Avoid unnecessary 500 panic when a commit doesn't exist (#28719) 2024-01-07 18:20:22 +08:00
repo_topic_test.go
repo_watch_test.go
repofiles_change_test.go Simplify how git repositories are opened (#28937) 2024-01-27 21:09:51 +01:00
saml_test.go Support SAML authentication (#25165) 2024-02-23 00:08:17 +00:00
session_test.go Fix session key conflict with database keyword (#28613) 2023-12-27 15:24:23 +08:00
setting_test.go
signin_test.go Refactor locale&string&template related code (#29165) 2024-02-14 21:48:45 +00:00
signout_test.go
signup_test.go Refactor locale&string&template related code (#29165) 2024-02-14 21:48:45 +00:00
ssh_key_test.go
timetracking_test.go
user_avatar_test.go
user_test.go Refactor locale&string&template related code (#29165) 2024-02-14 21:48:45 +00:00
version_test.go
view_test.go
webfinger_test.go
xss_test.go

Integration tests

Integration tests can be run with make commands for the appropriate backends, namely:

make test-sqlite
make test-pgsql
make test-mysql
make test-mssql

Make sure to perform a clean build before running tests:

make clean build

Run tests via local act_runner

Run all jobs

act_runner exec -W ./.github/workflows/pull-db-tests.yml --event=pull_request --default-actions-url="https://github.com" -i catthehacker/ubuntu:runner-latest

Warning: This file defines many jobs, so it will be resource-intensive and therefor not recommended.

Run single job

act_runner exec -W ./.github/workflows/pull-db-tests.yml --event=pull_request --default-actions-url="https://github.com" -i catthehacker/ubuntu:runner-latest -j <job_name>

You can list all job names via:

act_runner exec -W ./.github/workflows/pull-db-tests.yml --event=pull_request --default-actions-url="https://github.com" -i catthehacker/ubuntu:runner-latest -l

Run sqlite integration tests

Start tests

make test-sqlite

Run MySQL integration tests

Setup a MySQL database inside docker

docker run -e "MYSQL_DATABASE=test" -e "MYSQL_ALLOW_EMPTY_PASSWORD=yes" -p 3306:3306 --rm --name mysql mysql:latest #(just ctrl-c to stop db and clean the container)
docker run -p 9200:9200 -p 9300:9300 -e "discovery.type=single-node" --rm --name elasticsearch elasticsearch:7.6.0 #(in a second terminal, just ctrl-c to stop db and clean the container)

Start tests based on the database container

TEST_MYSQL_HOST=localhost:3306 TEST_MYSQL_DBNAME=test TEST_MYSQL_USERNAME=root TEST_MYSQL_PASSWORD='' make test-mysql

Run pgsql integration tests

Setup a pgsql database inside docker

docker run -e "POSTGRES_DB=test" -p 5432:5432 --rm --name pgsql postgres:latest #(just ctrl-c to stop db and clean the container)

Start tests based on the database container

TEST_PGSQL_HOST=localhost:5432 TEST_PGSQL_DBNAME=test TEST_PGSQL_USERNAME=postgres TEST_PGSQL_PASSWORD=postgres make test-pgsql

Run mssql integration tests

Setup a mssql database inside docker

docker run -e "ACCEPT_EULA=Y" -e "MSSQL_PID=Standard" -e "SA_PASSWORD=MwantsaSecurePassword1" -p 1433:1433 --rm --name mssql microsoft/mssql-server-linux:latest #(just ctrl-c to stop db and clean the container)

Start tests based on the database container

TEST_MSSQL_HOST=localhost:1433 TEST_MSSQL_DBNAME=gitea_test TEST_MSSQL_USERNAME=sa TEST_MSSQL_PASSWORD=MwantsaSecurePassword1 make test-mssql

Running individual tests

Example command to run GPG test:

For SQLite:

make test-sqlite#GPG

For other databases(replace mssql to mysql, or pgsql):

TEST_MSSQL_HOST=localhost:1433 TEST_MSSQL_DBNAME=test TEST_MSSQL_USERNAME=sa TEST_MSSQL_PASSWORD=MwantsaSecurePassword1 make test-mssql#GPG

Setting timeouts for declaring long-tests and long-flushes

We appreciate that some testing machines may not be very powerful and the default timeouts for declaring a slow test or a slow clean-up flush may not be appropriate.

You can either:

  • Within the test ini file set the following section:
[integration-tests]
SLOW_TEST = 10s ; 10s is the default value
SLOW_FLUSH = 5S ; 5s is the default value
  • Set the following environment variables:
GITEA_SLOW_TEST_TIME="10s" GITEA_SLOW_FLUSH_TIME="5s" make test-sqlite

Running SimpleSAML for testing SAML locally

docker run \
-p 8080:8080 \
-p 8443:8443 \
-e SIMPLESAMLPHP_SP_ENTITY_ID=http://localhost:3003/user/saml/test-sp/metadata \
-e SIMPLESAMLPHP_SP_ASSERTION_CONSUMER_SERVICE=http://localhost:3003/user/saml/test-sp/acs \
-e SIMPLESAMLPHP_SP_SINGLE_LOGOUT_SERVICE=http://localhost:3003/user/saml/test-sp/acs \
--add-host=localhost:192.168.65.2 \
-d allspice/simple-saml
TEST_SIMPLESAML_URL=localhost:8080 make test-sqlite#TestSAMLRegistration