|
18 | 18 | */
|
19 | 19 | package org.apache.shiro.web.filter.authz;
|
20 | 20 |
|
| 21 | +import java.util.HashMap; |
| 22 | +import java.util.Map; |
21 | 23 | import javax.servlet.http.HttpServletRequest;
|
22 | 24 | import javax.servlet.http.HttpServletResponse;
|
23 | 25 | import org.junit.Test;
|
24 | 26 |
|
25 | 27 | import static org.apache.shiro.web.filter.authz.SslFilter.HSTS.*;
|
| 28 | +import org.easymock.Capture; |
| 29 | +import org.easymock.CaptureType; |
26 | 30 | import static org.easymock.EasyMock.*;
|
| 31 | +import org.easymock.IAnswer; |
27 | 32 | import static org.junit.Assert.*;
|
| 33 | +import org.junit.Before; |
28 | 34 |
|
29 | 35 | public class SslFilterTest {
|
| 36 | + |
| 37 | + private HttpServletRequest request; |
| 38 | + private HttpServletResponse response; |
| 39 | + private SslFilter sslFilter; |
| 40 | + |
| 41 | + @Before |
| 42 | + public void before() { |
| 43 | + request = createNiceMock(HttpServletRequest.class); |
| 44 | + response = createNiceMock(HttpServletResponse.class); |
| 45 | + sslFilter = new SslFilter(); |
| 46 | + |
| 47 | + final Map<String,String> headers = new HashMap<String,String>(); |
| 48 | + |
| 49 | + final Capture<String> capturedName = newCapture(); |
| 50 | + final Capture<String> capturedValue = newCapture(); |
| 51 | + |
| 52 | + // mock HttpServletResponse.getHeader |
| 53 | + expect(response.getHeader(capture(capturedName))).andAnswer(new IAnswer<String>() { |
| 54 | + @Override |
| 55 | + public String answer() throws Throwable { |
| 56 | + String name = capturedName.getValue(); |
| 57 | + return headers.get(name); |
| 58 | + } |
| 59 | + |
| 60 | + }); |
| 61 | + |
| 62 | + // mock HttpServletResponse.addHeader |
| 63 | + response.addHeader(capture(capturedName), capture(capturedValue)); |
| 64 | + expectLastCall().andAnswer(new IAnswer<Void>() { |
| 65 | + @Override |
| 66 | + public Void answer() throws Throwable { |
| 67 | + String name = capturedName.getValue(); |
| 68 | + String value = capturedValue.getValue(); |
| 69 | + headers.put(name, value); |
| 70 | + return (null); |
| 71 | + } |
| 72 | + }); |
| 73 | + |
| 74 | + replay(response); |
| 75 | + } |
30 | 76 |
|
31 | 77 | @Test
|
32 | 78 | public void testDisabledByDefault() {
|
33 |
| - HttpServletRequest request = createNiceMock(HttpServletRequest.class); |
34 |
| - HttpServletResponse response = createNiceMock(HttpServletResponse.class); |
35 |
| - |
36 |
| - SslFilter sslFilter = new SslFilter(); |
37 |
| - |
38 | 79 | sslFilter.postHandle(request, response);
|
39 | 80 | assertNull(response.getHeader(HTTP_HEADER));
|
40 | 81 | }
|
41 | 82 |
|
42 | 83 | @Test
|
43 | 84 | public void testDefaultValues() {
|
44 |
| - HttpServletRequest request = createNiceMock(HttpServletRequest.class); |
45 |
| - HttpServletResponse response = createNiceMock(HttpServletResponse.class); |
46 |
| - |
47 |
| -// String expected = new StringBuilder() |
48 |
| -// .append(HTTP_HEADER) |
49 |
| -// .append(": ") |
50 |
| -// .append("max-age=") |
51 |
| -// .append(DEFAULT_MAX_AGE) |
52 |
| -// .toString(); |
53 |
| -// expect(response.addHeader(expected, expected)) |
54 |
| -// .andReturn(expected) |
55 |
| -// .anyTimes(); |
56 |
| - replay(response); |
57 |
| -// |
58 |
| - SslFilter sslFilter = new SslFilter(); |
59 | 85 | sslFilter.getHsts().setEnabled(true);
|
60 |
| - |
61 | 86 | sslFilter.postHandle(request, response);
|
62 |
| - |
63 |
| - //assertEquals(expected, response.getHeader(HTTP_HEADER)); |
| 87 | + assertEquals("max-age=" + DEFAULT_MAX_AGE, response.getHeader(HTTP_HEADER)); |
64 | 88 | }
|
| 89 | + |
| 90 | + @Test |
| 91 | + public void testSetProperties() { |
| 92 | + sslFilter.getHsts().setEnabled(true); |
| 93 | + sslFilter.getHsts().setMaxAge(7776000); |
| 94 | + sslFilter.getHsts().setIncludeSubDomains(true); |
| 95 | + sslFilter.postHandle(request, response); |
| 96 | + |
| 97 | + String expected = "max-age=" + 7776000 + "; includeSubDomains"; |
65 | 98 |
|
| 99 | + assertEquals(expected, response.getHeader(HTTP_HEADER)); |
| 100 | + } |
| 101 | + |
66 | 102 | }
|
0 commit comments