Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/maven.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@ name: Maven CI
on:
workflow_dispatch: {}
push:
branches: [ main ]
branches: [ main, 1.9.x ]
pull_request:
branches: [ ]

Expand Down
8 changes: 8 additions & 0 deletions pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -111,6 +111,7 @@

<!-- Test 3rd-party dependencies: -->
<easymock.version>4.1</easymock.version>
<mockito.version>3.12.4</mockito.version>
<gmaven.version>1.8.0</gmaven.version>
<groovy.version>2.5.14</groovy.version>
<junit.version>4.12</junit.version>
Expand Down Expand Up @@ -666,6 +667,12 @@
<version>${easymock.version}</version>
<scope>test</scope>
</dependency>
<dependency>
<groupId>org.mockito</groupId>
<artifactId>mockito-core</artifactId>
<version>${mockito.version}</version>
<scope>test</scope>
</dependency>
<!-- Writing tests in groovy is fast!: -->
<dependency>
<groupId>org.codehaus.groovy</groupId>
Expand Down Expand Up @@ -1229,6 +1236,7 @@
<link>https://docs.spring.io/spring/docs/2.5.x/javadoc-api/</link>
<link>https://junit.org/junit4/javadoc/4.12/</link>
<link>http://easymock.org/api/easymock/2.4</link>
<link>https://javadoc.io/doc/org.mockito/mockito-core/${mockito.version}/org/mockito/Mockito.html</link>
<link>https://www.quartz-scheduler.org/api/1.8.6/</link>
</links>
<!-- Don't include the sample apps - they're not part of Shiro's API: -->
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -29,7 +29,10 @@
import javax.servlet.http.HttpServletResponse;
import java.io.IOException;

import static org.easymock.EasyMock.*;
import static org.mockito.Mockito.atLeastOnce;
import static org.mockito.Mockito.mock;
import static org.mockito.Mockito.verify;
import static org.mockito.Mockito.when;

/**
* Test cases for the {@link AuthorizationFilter} class.
Expand All @@ -43,22 +46,20 @@ public void testUserOnAccessDeniedWithResponseError() throws IOException {

//log in the user using the account provided by the superclass for tests:
SecurityUtils.getSubject().login(new UsernamePasswordToken("test", "test"));

AuthorizationFilter filter = new AuthorizationFilter() {
@Override
protected boolean isAccessAllowed(ServletRequest request, ServletResponse response, Object mappedValue)
throws Exception {
protected boolean isAccessAllowed(ServletRequest request, ServletResponse response, Object mappedValue) {
return false; //for this test case
}
};

HttpServletRequest request = createNiceMock(HttpServletRequest.class);
HttpServletResponse response = createNiceMock(HttpServletResponse.class);
HttpServletRequest request = mock(HttpServletRequest.class);
HttpServletResponse response = mock(HttpServletResponse.class);

response.sendError(HttpServletResponse.SC_UNAUTHORIZED);
replay(response);
// response.sendError(HttpServletResponse.SC_UNAUTHORIZED);
filter.onAccessDenied(request, response);
verify(response);
verify(response).sendError(HttpServletResponse.SC_UNAUTHORIZED);
}

@Test
Expand All @@ -73,27 +74,22 @@ public void testUserOnAccessDeniedWithRedirect() throws IOException {

AuthorizationFilter filter = new AuthorizationFilter() {
@Override
protected boolean isAccessAllowed(ServletRequest request, ServletResponse response, Object mappedValue)
throws Exception {
protected boolean isAccessAllowed(ServletRequest request, ServletResponse response, Object mappedValue) {
return false; //for this test case
}
};
filter.setUnauthorizedUrl(unauthorizedUrl);

HttpServletRequest request = createNiceMock(HttpServletRequest.class);
HttpServletResponse response = createNiceMock(HttpServletResponse.class);

expect(request.getContextPath()).andReturn("/").anyTimes();
HttpServletRequest request = mock(HttpServletRequest.class);
HttpServletResponse response = mock(HttpServletResponse.class);

String encoded = "/" + unauthorizedUrl;
expect(response.encodeRedirectURL(unauthorizedUrl)).andReturn(encoded);
when(response.encodeRedirectURL(unauthorizedUrl)).thenReturn(encoded);
response.sendRedirect(encoded);
replay(request);
replay(response);

filter.onAccessDenied(request, response);

verify(request);
verify(response);
verify(response, atLeastOnce()).sendRedirect(encoded);
verify(response).encodeRedirectURL(unauthorizedUrl);
}
}
}