|
8 | 8 | import org.apache.logging.log4j.core.LogEvent; |
9 | 9 | import org.apache.logging.log4j.core.impl.Log4jLogEvent; |
10 | 10 | import org.apache.logging.log4j.core.impl.Log4jLogEvent.Builder; |
| 11 | +import org.apache.logging.log4j.junit.InitialLoggerContext; |
11 | 12 | import org.apache.logging.log4j.message.Message; |
12 | 13 | import org.apache.logging.log4j.message.ParameterizedMessage; |
13 | 14 | import org.apache.logging.log4j.message.SimpleMessage; |
| 15 | +import org.apache.logging.log4j.test.appender.ListAppender; |
| 16 | +import org.junit.After; |
| 17 | +import static org.junit.Assert.assertEquals; |
| 18 | +import static org.junit.Assert.assertNotSame; |
| 19 | +import static org.junit.Assert.assertTrue; |
| 20 | +import org.junit.Before; |
| 21 | +import org.junit.ClassRule; |
| 22 | +import org.junit.FixMethodOrder; |
| 23 | +import org.junit.Test; |
| 24 | +import org.junit.runners.MethodSorters; |
14 | 25 | import org.owasp.security.logging.SecurityMarkers; |
| 26 | +import org.slf4j.LoggerFactory; |
15 | 27 |
|
16 | 28 | /** |
17 | 29 | * The class <code>MaskingRewritePolicyTest</code> contains tests for the class |
|
25 | 37 | * |
26 | 38 | * @version $Revision$ |
27 | 39 | */ |
28 | | -public class MaskingRewritePolicyTest extends TestCase { |
| 40 | +public class MaskingRewritePolicyTest { |
29 | 41 |
|
30 | | - /** |
31 | | - * Construct new test instance |
32 | | - * |
33 | | - * @param name |
34 | | - * the test name |
35 | | - */ |
36 | | - public MaskingRewritePolicyTest(String name) { |
37 | | - super(name); |
38 | | - } |
| 42 | + private static final String CONFIG = "log4j2.xml"; |
39 | 43 |
|
40 | | - public void testRewriteConfidentialNoParams() { |
41 | | - MaskingRewritePolicy fixture = new MaskingRewritePolicy(); |
42 | | - Marker marker = new MarkerManager.Log4jMarker( |
43 | | - SecurityMarkers.CONFIDENTIAL.getName()); |
44 | | - Log4jLogEvent event = createEvent(marker, new SimpleMessage()); |
45 | | - LogEvent result = fixture.rewrite(event); |
46 | | - assertEquals(event, result); |
47 | | - } |
| 44 | + private static final org.slf4j.Logger LOGGER = LoggerFactory |
| 45 | + .getLogger(MaskingRewritePolicyTest.class); |
48 | 46 |
|
49 | | - public void testRewriteConfidentialWithParams() { |
50 | | - MaskingRewritePolicy fixture = new MaskingRewritePolicy(); |
51 | | - Marker marker = new MarkerManager.Log4jMarker( |
52 | | - SecurityMarkers.CONFIDENTIAL.getName()); |
53 | | - Message message = new ParameterizedMessage("ddd", "gladiator"); |
54 | | - LogEvent event = createEvent(marker, message); |
55 | | - LogEvent result = fixture.rewrite(event); |
56 | | - assertNotSame(event, result); |
57 | | - } |
| 47 | + private static final String SSN = "123-45-6789"; |
58 | 48 |
|
59 | | - public void testRewriteNotConfidential() { |
60 | | - MaskingRewritePolicy fixture = new MaskingRewritePolicy(); |
61 | | - Marker marker = new MarkerManager.Log4jMarker( |
62 | | - SecurityMarkers.EVENT_FAILURE_MARKER_NAME); |
63 | | - Message message = new ParameterizedMessage("ddd", "gladiator"); |
64 | | - LogEvent event = createEvent(marker, message); |
65 | | - LogEvent result = fixture.rewrite(event); |
66 | | - assertEquals(event, result); |
67 | | - } |
| 49 | + @ClassRule |
| 50 | + public static InitialLoggerContext context = new InitialLoggerContext(CONFIG); |
68 | 51 |
|
69 | | - public void testRewriteConfidentialWithZeroParams() { |
70 | | - MaskingRewritePolicy fixture = new MaskingRewritePolicy(); |
71 | | - Marker marker = new MarkerManager.Log4jMarker( |
72 | | - SecurityMarkers.CONFIDENTIAL.getName()); |
73 | | - Message message = new ParameterizedMessage("ddd", null); |
74 | | - LogEvent event = createEvent(marker, message); |
75 | | - LogEvent result = fixture.rewrite(event); |
76 | | - assertEquals(event, result); |
77 | | - } |
| 52 | + ListAppender appender; |
78 | 53 |
|
79 | | - public void testRewriteConfidentialNoMessage() { |
80 | | - MaskingRewritePolicy fixture = new MaskingRewritePolicy(); |
81 | | - Marker marker = new MarkerManager.Log4jMarker( |
82 | | - SecurityMarkers.CONFIDENTIAL.getName()); |
83 | | - Log4jLogEvent event = createEvent(marker, null); |
84 | | - LogEvent result = fixture.rewrite(event); |
85 | | - assertEquals(event, result); |
| 54 | + @Before |
| 55 | + public void setUp() { |
| 56 | + System.out.println("CONTEXT: " + context); |
| 57 | + appender = context.getListAppender("List"); |
86 | 58 | } |
87 | 59 |
|
88 | | - public void testRewriteNoMarker() { |
89 | | - MaskingRewritePolicy fixture = new MaskingRewritePolicy(); |
90 | | - Message message = new ParameterizedMessage("ddd", "gladiator"); |
91 | | - Log4jLogEvent event = createEvent(null, message); |
92 | | - LogEvent result = fixture.rewrite(event); |
93 | | - assertEquals(event, result); |
94 | | - } |
| 60 | + @After |
| 61 | + public void tearDown() { |
| 62 | + appender.clear(); |
| 63 | + } |
| 64 | + |
| 65 | + @Test |
| 66 | + public void testRewriteMultiMarker() { |
| 67 | + System.out.println("running testRewriteMultiMarker()"); |
| 68 | + org.slf4j.Marker multiMarker = SecurityMarkers.getMarker(SecurityMarkers.CONFIDENTIAL, SecurityMarkers.SECURITY_FAILURE); |
| 69 | + |
| 70 | + // test a logging event with the multi-marker |
| 71 | + LOGGER.info(multiMarker, "ssn={}", SSN); |
| 72 | + LogEvent failEvent = appender.getEvents().get(0); |
| 73 | + Message message = failEvent.getMessage(); |
| 74 | + |
| 75 | + System.out.println("Formatted message: " + message.getFormattedMessage()); |
| 76 | + assertTrue(message.getFormattedMessage().contains("ssn=" + MaskingRewritePolicy.MASKED_PASSWORD)); |
| 77 | + } |
| 78 | + |
| 79 | + /** |
| 80 | + * This test case has the CONFIDENTIAL marker so the results should be masked |
| 81 | + */ |
| 82 | + @Test |
| 83 | + public void testRewriteConfidentialWithParams() { |
| 84 | + System.out.println("running testRewriteConfidentialWithParams()"); |
| 85 | + |
| 86 | + // test a logging event with the CONFIDENTIAL marker |
| 87 | + LOGGER.info(SecurityMarkers.CONFIDENTIAL, "ssn={}", SSN); |
| 88 | + LogEvent failEvent = appender.getEvents().get(0); |
| 89 | + Message message = failEvent.getMessage(); |
| 90 | + |
| 91 | + System.out.println("Formatted message: " + message.getFormattedMessage()); |
| 92 | + assertTrue(message.getFormattedMessage().contains("ssn=" + MaskingRewritePolicy.MASKED_PASSWORD)); |
| 93 | + } |
| 94 | + |
| 95 | + /** |
| 96 | + * This test case has the CONFIDENTIAL marker, but it is not parameterized |
| 97 | + * so masking cannot take place. |
| 98 | + */ |
| 99 | + @Test |
| 100 | + public void testRewriteConfidentialNoParams() { |
| 101 | + System.out.println("running testRewriteConfidentialNoParams()"); |
| 102 | + |
| 103 | + // test a logging event with the CONFIDENTIAL marker |
| 104 | + LOGGER.info(SecurityMarkers.CONFIDENTIAL, "ssn=" + SSN); |
| 105 | + LogEvent failEvent = appender.getEvents().get(0); |
| 106 | + Message message = failEvent.getMessage(); |
| 107 | + |
| 108 | + System.out.println("Formatted message: " + message.getFormattedMessage()); |
| 109 | + assertTrue(message.getFormattedMessage().contains("ssn=" + SSN)); |
| 110 | + } |
| 111 | + |
| 112 | + /** |
| 113 | + * This test case is parameterized, but does not have the CONFIDENTIAL |
| 114 | + * marker, so it should not be masked |
| 115 | + */ |
| 116 | + @Test |
| 117 | + public void testRewriteNotConfidential() { |
| 118 | + System.out.println("running testRewriteSingleMarker()"); |
| 119 | + |
| 120 | + // test a logging event with the CONFIDENTIAL marker |
| 121 | + LOGGER.info(SecurityMarkers.SECURITY_SUCCESS, "ssn={}", SSN); |
| 122 | + LogEvent failEvent = appender.getEvents().get(0); |
| 123 | + Message message = failEvent.getMessage(); |
| 124 | + |
| 125 | + System.out.println("Formatted message: " + message.getFormattedMessage()); |
| 126 | + assertTrue(message.getFormattedMessage().contains("ssn=" + SSN)); |
| 127 | + } |
| 128 | + |
| 129 | + @Test |
| 130 | + public void testRewriteNoMarker() { |
| 131 | + System.out.println("running testRewriteNoMarker()"); |
| 132 | + |
| 133 | + // test a logging event with no marker |
| 134 | + LOGGER.info("ssn={}", SSN); |
| 135 | + LogEvent failEvent = appender.getEvents().get(0); |
| 136 | + Message message = failEvent.getMessage(); |
| 137 | + |
| 138 | + System.out.println("Formatted message: " + message.getFormattedMessage()); |
| 139 | + assertTrue(message.getFormattedMessage().contains("ssn=" + SSN)); |
| 140 | + } |
| 141 | + |
| 142 | + @Test |
| 143 | + public void testRewriteConfidentialNoMessage() { |
| 144 | + System.out.println("running testRewriteConfidentialNoMessage()"); |
95 | 145 |
|
96 | | - private Log4jLogEvent createEvent(Marker marker, Message message) { |
97 | | - Log4jLogEvent.Builder builder = new Builder(); |
98 | | - builder.setMarker(marker).setLevel(Level.DEBUG).setLoggerName("jjj") |
99 | | - .setLoggerFqcn("ggg").setMessage(message); |
100 | | - Log4jLogEvent event = builder.build(); |
101 | | - return event; |
| 146 | + // test a logging event with null marker |
| 147 | + LOGGER.info(null); |
| 148 | + LogEvent failEvent = appender.getEvents().get(0); |
| 149 | + Message message = failEvent.getMessage(); |
| 150 | + |
| 151 | + System.out.println("Formatted message: " + message.getFormattedMessage()); |
| 152 | + assertTrue(message.getFormattedMessage() == null); |
102 | 153 | } |
103 | 154 | } |
0 commit comments