|
46 | 46 | import static org.apache.paimon.rest.RESTCatalogOptions.DLF_ACCESS_KEY_SECRET; |
47 | 47 | import static org.apache.paimon.rest.RESTCatalogOptions.DLF_REGION; |
48 | 48 | import static org.apache.paimon.rest.RESTCatalogOptions.DLF_SECURITY_TOKEN; |
| 49 | +import static org.apache.paimon.rest.RESTCatalogOptions.DLF_TOKEN_ECS_METADATA_URL; |
| 50 | +import static org.apache.paimon.rest.RESTCatalogOptions.DLF_TOKEN_ECS_ROLE_NAME; |
49 | 51 | import static org.apache.paimon.rest.RESTCatalogOptions.DLF_TOKEN_LOADER; |
50 | 52 | import static org.apache.paimon.rest.RESTCatalogOptions.DLF_TOKEN_PATH; |
51 | 53 | import static org.apache.paimon.rest.RESTCatalogOptions.TOKEN; |
@@ -291,6 +293,124 @@ public void testCreateDlfAuthProviderByCustomDLFTokenLoader() |
291 | 293 | Assert.assertEquals(fetchToken.getSecurityToken(), customToken.getSecurityToken()); |
292 | 294 | } |
293 | 295 |
|
| 296 | + @Test |
| 297 | + public void testCreateDlfAuthProviderByECSTokenProvider() |
| 298 | + throws IOException, InterruptedException { |
| 299 | + MockECSMetadataService mockECSMetadataService = new MockECSMetadataService("EcsTestRole"); |
| 300 | + mockECSMetadataService.start(); |
| 301 | + try { |
| 302 | + DLFToken theFirstMockToken = generateToken(); |
| 303 | + mockECSMetadataService.setMockToken(theFirstMockToken); |
| 304 | + String theFirstMockTokenStr = |
| 305 | + OBJECT_MAPPER_INSTANCE.writeValueAsString(theFirstMockToken); |
| 306 | + long tokenRefreshInMills = 1000; |
| 307 | + // create options with token loader |
| 308 | + Options options = new Options(); |
| 309 | + options.set(DLF_TOKEN_LOADER.key(), "ecs"); |
| 310 | + options.set( |
| 311 | + DLF_TOKEN_ECS_METADATA_URL.key(), |
| 312 | + mockECSMetadataService.getUrl() + "latest/meta-data/Ram/security-credentials/"); |
| 313 | + options.set(RESTCatalogOptions.URI.key(), "serverUrl"); |
| 314 | + options.set(DLF_REGION.key(), "cn-hangzhou"); |
| 315 | + options.set(TOKEN_REFRESH_TIME.key(), tokenRefreshInMills + "ms"); |
| 316 | + AuthProvider authProvider = |
| 317 | + AuthProviderFactory.createAuthProvider( |
| 318 | + AuthProviderEnum.DLF.identifier(), options); |
| 319 | + ScheduledExecutorService executor = |
| 320 | + ThreadPoolUtils.createScheduledThreadPool(1, "refresh-token"); |
| 321 | + AuthSession session = AuthSession.fromRefreshAuthProvider(executor, authProvider); |
| 322 | + DLFAuthProvider dlfAuthProvider = (DLFAuthProvider) session.getAuthProvider(); |
| 323 | + String theFirstFetchTokenStr = |
| 324 | + OBJECT_MAPPER_INSTANCE.writeValueAsString(dlfAuthProvider.token); |
| 325 | + assertEquals(theFirstFetchTokenStr, theFirstMockTokenStr); |
| 326 | + |
| 327 | + DLFToken theSecondMockToken = generateToken(); |
| 328 | + String theSecondMockTokenStr = |
| 329 | + OBJECT_MAPPER_INSTANCE.writeValueAsString(theSecondMockToken); |
| 330 | + mockECSMetadataService.setMockToken(theSecondMockToken); |
| 331 | + Thread.sleep(tokenRefreshInMills * 2); |
| 332 | + String theSecondFetchTokenStr = |
| 333 | + OBJECT_MAPPER_INSTANCE.writeValueAsString(dlfAuthProvider.token); |
| 334 | + assertEquals(theSecondFetchTokenStr, theSecondMockTokenStr); |
| 335 | + } finally { |
| 336 | + mockECSMetadataService.shutdown(); |
| 337 | + } |
| 338 | + } |
| 339 | + |
| 340 | + @Test |
| 341 | + public void testCreateDlfAuthProviderByECSTokenProviderWithDefineRole() |
| 342 | + throws IOException, InterruptedException { |
| 343 | + MockECSMetadataService mockECSMetadataService = new MockECSMetadataService("CustomRole"); |
| 344 | + mockECSMetadataService.start(); |
| 345 | + try { |
| 346 | + DLFToken theFirstMockToken = generateToken(); |
| 347 | + mockECSMetadataService.setMockToken(theFirstMockToken); |
| 348 | + String theFirstMockTokenStr = |
| 349 | + OBJECT_MAPPER_INSTANCE.writeValueAsString(theFirstMockToken); |
| 350 | + long tokenRefreshInMills = 1000; |
| 351 | + // create options with token loader |
| 352 | + Options options = new Options(); |
| 353 | + options.set(DLF_TOKEN_LOADER.key(), "ecs"); |
| 354 | + options.set( |
| 355 | + DLF_TOKEN_ECS_METADATA_URL.key(), |
| 356 | + mockECSMetadataService.getUrl() + "latest/meta-data/Ram/security-credentials/"); |
| 357 | + options.set(DLF_TOKEN_ECS_ROLE_NAME.key(), "CustomRole"); |
| 358 | + options.set(RESTCatalogOptions.URI.key(), "serverUrl"); |
| 359 | + options.set(DLF_REGION.key(), "cn-hangzhou"); |
| 360 | + options.set(TOKEN_REFRESH_TIME.key(), tokenRefreshInMills + "ms"); |
| 361 | + AuthProvider authProvider = |
| 362 | + AuthProviderFactory.createAuthProvider( |
| 363 | + AuthProviderEnum.DLF.identifier(), options); |
| 364 | + ScheduledExecutorService executor = |
| 365 | + ThreadPoolUtils.createScheduledThreadPool(1, "refresh-token"); |
| 366 | + AuthSession session = AuthSession.fromRefreshAuthProvider(executor, authProvider); |
| 367 | + DLFAuthProvider dlfAuthProvider = (DLFAuthProvider) session.getAuthProvider(); |
| 368 | + String theFirstFetchTokenStr = |
| 369 | + OBJECT_MAPPER_INSTANCE.writeValueAsString(dlfAuthProvider.token); |
| 370 | + assertEquals(theFirstFetchTokenStr, theFirstMockTokenStr); |
| 371 | + |
| 372 | + DLFToken theSecondMockToken = generateToken(); |
| 373 | + String theSecondMockTokenStr = |
| 374 | + OBJECT_MAPPER_INSTANCE.writeValueAsString(theSecondMockToken); |
| 375 | + mockECSMetadataService.setMockToken(theSecondMockToken); |
| 376 | + Thread.sleep(tokenRefreshInMills * 2); |
| 377 | + String theSecondFetchTokenStr = |
| 378 | + OBJECT_MAPPER_INSTANCE.writeValueAsString(dlfAuthProvider.token); |
| 379 | + assertEquals(theSecondFetchTokenStr, theSecondMockTokenStr); |
| 380 | + } finally { |
| 381 | + mockECSMetadataService.shutdown(); |
| 382 | + } |
| 383 | + } |
| 384 | + |
| 385 | + @Test |
| 386 | + public void testCreateDlfAuthProviderByECSTokenProviderWithInvalidRole() |
| 387 | + throws IOException, InterruptedException { |
| 388 | + MockECSMetadataService mockECSMetadataService = new MockECSMetadataService("EcsTestRole"); |
| 389 | + mockECSMetadataService.start(); |
| 390 | + try { |
| 391 | + DLFToken theFirstMockToken = generateToken(); |
| 392 | + mockECSMetadataService.setMockToken(theFirstMockToken); |
| 393 | + // create options with token loader |
| 394 | + Options options = new Options(); |
| 395 | + options.set(DLF_TOKEN_LOADER.key(), "ecs"); |
| 396 | + options.set( |
| 397 | + DLF_TOKEN_ECS_METADATA_URL.key(), |
| 398 | + mockECSMetadataService.getUrl() + "latest/meta-data/Ram/security-credentials/"); |
| 399 | + options.set(DLF_TOKEN_ECS_ROLE_NAME.key(), "CustomRole"); |
| 400 | + options.set(RESTCatalogOptions.URI.key(), "serverUrl"); |
| 401 | + options.set(DLF_REGION.key(), "cn-hangzhou"); |
| 402 | + assertThrows( |
| 403 | + RuntimeException.class, |
| 404 | + () -> { |
| 405 | + AuthProvider authProvider = |
| 406 | + AuthProviderFactory.createAuthProvider( |
| 407 | + AuthProviderEnum.DLF.identifier(), options); |
| 408 | + }); |
| 409 | + } finally { |
| 410 | + mockECSMetadataService.shutdown(); |
| 411 | + } |
| 412 | + } |
| 413 | + |
294 | 414 | @Test |
295 | 415 | public void testDLFAuthProviderAuthHeaderWhenDataIsNotEmpty() throws Exception { |
296 | 416 | String fileName = UUID.randomUUID().toString(); |
|
0 commit comments