blob: ea107169bbbeaf60d1223f4344a2df46ea0b3e08 [file] [log] [blame]
rajalakshmi-ganesan7312bb52013-01-29 20:03:42 +05301# Copyright 2013 OpenStack Foundation
2# All Rights Reserved.
3#
4# Licensed under the Apache License, Version 2.0 (the "License"); you may
5# not use this file except in compliance with the License. You may obtain
6# a copy of the License at
7#
8# http://www.apache.org/licenses/LICENSE-2.0
9#
10# Unless required by applicable law or agreed to in writing, software
11# distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
12# WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
13# License for the specific language governing permissions and limitations
14# under the License.
15
Andrea Frittoli8bbdb162014-01-06 11:06:13 +000016import json
nayna-patel153e9dd2014-05-16 09:00:05 +000017import urllib
rajalakshmi-ganesan7312bb52013-01-29 20:03:42 +053018
19from lxml import etree
20
vponomaryov960eeb42014-02-22 18:25:25 +020021from tempest.common import rest_client
Matthew Treinish28f164c2014-03-04 18:55:06 +000022from tempest.common import xml_utils as common
Matthew Treinish684d8992014-01-30 16:27:40 +000023from tempest import config
Andrea Frittoli8bbdb162014-01-06 11:06:13 +000024from tempest import exceptions
rajalakshmi-ganesan7312bb52013-01-29 20:03:42 +053025
Matthew Treinish684d8992014-01-30 16:27:40 +000026CONF = config.CONF
27
rajalakshmi-ganesan7312bb52013-01-29 20:03:42 +053028XMLNS = "http://docs.openstack.org/identity/api/v3"
29
30
vponomaryov960eeb42014-02-22 18:25:25 +020031class IdentityV3ClientXML(rest_client.RestClient):
32 TYPE = "xml"
rajalakshmi-ganesan7312bb52013-01-29 20:03:42 +053033
Andrea Frittoli8bbdb162014-01-06 11:06:13 +000034 def __init__(self, auth_provider):
35 super(IdentityV3ClientXML, self).__init__(auth_provider)
Matthew Treinish684d8992014-01-30 16:27:40 +000036 self.service = CONF.identity.catalog_type
rajalakshmi-ganesan7312bb52013-01-29 20:03:42 +053037 self.endpoint_url = 'adminURL'
Andrea Frittoli8bbdb162014-01-06 11:06:13 +000038 self.api_version = "v3"
rajalakshmi-ganesan7312bb52013-01-29 20:03:42 +053039
40 def _parse_projects(self, node):
41 array = []
42 for child in node.getchildren():
43 tag_list = child.tag.split('}', 1)
44 if tag_list[1] == "project":
Haiwei Xuaad85db2014-03-05 05:17:39 +090045 array.append(common.xml_to_json(child))
rajalakshmi-ganesan7312bb52013-01-29 20:03:42 +053046 return array
47
nayna-patel4df72dc2013-05-29 10:27:24 +000048 def _parse_domains(self, node):
49 array = []
50 for child in node.getchildren():
51 tag_list = child.tag.split('}', 1)
52 if tag_list[1] == "domain":
Haiwei Xuaad85db2014-03-05 05:17:39 +090053 array.append(common.xml_to_json(child))
nayna-patel4df72dc2013-05-29 10:27:24 +000054 return array
55
wanglianmin29b0f4c2014-03-06 19:09:16 +080056 def _parse_groups(self, node):
57 array = []
58 for child in node.getchildren():
59 tag_list = child.tag.split('}', 1)
60 if tag_list[1] == "group":
61 array.append(common.xml_to_json(child))
62 return array
63
Zhi Kun Liue8136f02014-01-07 18:56:28 +080064 def _parse_group_users(self, node):
65 array = []
66 for child in node.getchildren():
67 tag_list = child.tag.split('}', 1)
68 if tag_list[1] == "user":
Haiwei Xuaad85db2014-03-05 05:17:39 +090069 array.append(common.xml_to_json(child))
Zhi Kun Liue8136f02014-01-07 18:56:28 +080070 return array
71
nayna-patel755d8142013-07-16 06:45:34 +000072 def _parse_roles(self, node):
73 array = []
74 for child in node.getchildren():
75 tag_list = child.tag.split('}', 1)
76 if tag_list[1] == "role":
Haiwei Xuaad85db2014-03-05 05:17:39 +090077 array.append(common.xml_to_json(child))
nayna-patel755d8142013-07-16 06:45:34 +000078 return array
79
rajalakshmi-ganesan7312bb52013-01-29 20:03:42 +053080 def _parse_array(self, node):
81 array = []
82 for child in node.getchildren():
Haiwei Xuaad85db2014-03-05 05:17:39 +090083 array.append(common.xml_to_json(child))
rajalakshmi-ganesan7312bb52013-01-29 20:03:42 +053084 return array
85
86 def _parse_body(self, body):
Haiwei Xuaad85db2014-03-05 05:17:39 +090087 _json = common.xml_to_json(body)
Andrea Frittoli8bbdb162014-01-06 11:06:13 +000088 return _json
rajalakshmi-ganesan7312bb52013-01-29 20:03:42 +053089
90 def create_user(self, user_name, **kwargs):
91 """Creates a user."""
92 password = kwargs.get('password', None)
93 email = kwargs.get('email', None)
94 en = kwargs.get('enabled', 'true')
95 project_id = kwargs.get('project_id', None)
96 description = kwargs.get('description', None)
97 domain_id = kwargs.get('domain_id', 'default')
Haiwei Xuaad85db2014-03-05 05:17:39 +090098 post_body = common.Element("user",
99 xmlns=XMLNS,
100 name=user_name,
101 password=password,
102 description=description,
103 email=email,
104 enabled=str(en).lower(),
105 project_id=project_id,
106 domain_id=domain_id)
107 resp, body = self.post('users', str(common.Document(post_body)))
David Kranze9d2f422014-07-02 13:57:41 -0400108 self.expected_success(201, resp.status)
rajalakshmi-ganesan7312bb52013-01-29 20:03:42 +0530109 body = self._parse_body(etree.fromstring(body))
110 return resp, body
111
112 def update_user(self, user_id, name, **kwargs):
113 """Updates a user."""
David Kranze9d2f422014-07-02 13:57:41 -0400114 _, body = self.get_user(user_id)
nayna-patel755d8142013-07-16 06:45:34 +0000115 email = kwargs.get('email', body['email'])
116 en = kwargs.get('enabled', body['enabled'])
117 project_id = kwargs.get('project_id', body['project_id'])
118 description = kwargs.get('description', body['description'])
119 domain_id = kwargs.get('domain_id', body['domain_id'])
Haiwei Xuaad85db2014-03-05 05:17:39 +0900120 update_user = common.Element("user",
121 xmlns=XMLNS,
122 name=name,
123 email=email,
124 project_id=project_id,
125 domain_id=domain_id,
126 description=description,
127 enabled=str(en).lower())
rajalakshmi-ganesan7312bb52013-01-29 20:03:42 +0530128 resp, body = self.patch('users/%s' % user_id,
Haiwei Xuaad85db2014-03-05 05:17:39 +0900129 str(common.Document(update_user)))
David Kranze9d2f422014-07-02 13:57:41 -0400130 self.expected_success(200, resp.status)
rajalakshmi-ganesan7312bb52013-01-29 20:03:42 +0530131 body = self._parse_body(etree.fromstring(body))
132 return resp, body
133
134 def list_user_projects(self, user_id):
135 """Lists the projects on which a user has roles assigned."""
Valeriy Ponomaryov88686d82014-02-16 12:24:51 +0200136 resp, body = self.get('users/%s/projects' % user_id)
David Kranze9d2f422014-07-02 13:57:41 -0400137 self.expected_success(200, resp.status)
rajalakshmi-ganesan7312bb52013-01-29 20:03:42 +0530138 body = self._parse_projects(etree.fromstring(body))
139 return resp, body
140
141 def get_users(self):
142 """Get the list of users."""
Valeriy Ponomaryov88686d82014-02-16 12:24:51 +0200143 resp, body = self.get("users")
David Kranze9d2f422014-07-02 13:57:41 -0400144 self.expected_success(200, resp.status)
rajalakshmi-ganesan7312bb52013-01-29 20:03:42 +0530145 body = self._parse_array(etree.fromstring(body))
146 return resp, body
147
148 def get_user(self, user_id):
149 """GET a user."""
Valeriy Ponomaryov88686d82014-02-16 12:24:51 +0200150 resp, body = self.get("users/%s" % user_id)
David Kranze9d2f422014-07-02 13:57:41 -0400151 self.expected_success(200, resp.status)
rajalakshmi-ganesan7312bb52013-01-29 20:03:42 +0530152 body = self._parse_body(etree.fromstring(body))
153 return resp, body
154
155 def delete_user(self, user_id):
156 """Deletes a User."""
Valeriy Ponomaryov88686d82014-02-16 12:24:51 +0200157 resp, body = self.delete("users/%s" % user_id)
David Kranze9d2f422014-07-02 13:57:41 -0400158 self.expected_success(204, resp.status)
rajalakshmi-ganesan7312bb52013-01-29 20:03:42 +0530159 return resp, body
160
161 def create_project(self, name, **kwargs):
162 """Creates a project."""
163 description = kwargs.get('description', None)
164 en = kwargs.get('enabled', 'true')
165 domain_id = kwargs.get('domain_id', 'default')
Haiwei Xuaad85db2014-03-05 05:17:39 +0900166 post_body = common.Element("project",
167 xmlns=XMLNS,
168 description=description,
169 domain_id=domain_id,
170 enabled=str(en).lower(),
171 name=name)
rajalakshmi-ganesan7312bb52013-01-29 20:03:42 +0530172 resp, body = self.post('projects',
Haiwei Xuaad85db2014-03-05 05:17:39 +0900173 str(common.Document(post_body)))
David Kranze9d2f422014-07-02 13:57:41 -0400174 self.expected_success(201, resp.status)
rajalakshmi-ganesan7312bb52013-01-29 20:03:42 +0530175 body = self._parse_body(etree.fromstring(body))
176 return resp, body
177
nayna-patel153e9dd2014-05-16 09:00:05 +0000178 def list_projects(self, params=None):
Nayna Patele6331362013-08-12 06:59:48 +0000179 """Get the list of projects."""
nayna-patel153e9dd2014-05-16 09:00:05 +0000180 url = 'projects'
181 if params:
182 url += '?%s' % urllib.urlencode(params)
183 resp, body = self.get(url)
David Kranze9d2f422014-07-02 13:57:41 -0400184 self.expected_success(200, resp.status)
Nayna Patele6331362013-08-12 06:59:48 +0000185 body = self._parse_projects(etree.fromstring(body))
186 return resp, body
187
188 def update_project(self, project_id, **kwargs):
189 """Updates a Project."""
190 resp, body = self.get_project(project_id)
191 name = kwargs.get('name', body['name'])
192 desc = kwargs.get('description', body['description'])
193 en = kwargs.get('enabled', body['enabled'])
194 domain_id = kwargs.get('domain_id', body['domain_id'])
Haiwei Xuaad85db2014-03-05 05:17:39 +0900195 post_body = common.Element("project",
196 xmlns=XMLNS,
197 name=name,
198 description=desc,
199 enabled=str(en).lower(),
200 domain_id=domain_id)
Nayna Patele6331362013-08-12 06:59:48 +0000201 resp, body = self.patch('projects/%s' % project_id,
Haiwei Xuaad85db2014-03-05 05:17:39 +0900202 str(common.Document(post_body)))
David Kranze9d2f422014-07-02 13:57:41 -0400203 self.expected_success(200, resp.status)
Nayna Patele6331362013-08-12 06:59:48 +0000204 body = self._parse_body(etree.fromstring(body))
205 return resp, body
206
rajalakshmi-ganesan7312bb52013-01-29 20:03:42 +0530207 def get_project(self, project_id):
208 """GET a Project."""
Valeriy Ponomaryov88686d82014-02-16 12:24:51 +0200209 resp, body = self.get("projects/%s" % project_id)
David Kranze9d2f422014-07-02 13:57:41 -0400210 self.expected_success(200, resp.status)
rajalakshmi-ganesan7312bb52013-01-29 20:03:42 +0530211 body = self._parse_body(etree.fromstring(body))
212 return resp, body
213
214 def delete_project(self, project_id):
215 """Delete a project."""
216 resp, body = self.delete('projects/%s' % str(project_id))
David Kranze9d2f422014-07-02 13:57:41 -0400217 self.expected_success(204, resp.status)
rajalakshmi-ganesan7312bb52013-01-29 20:03:42 +0530218 return resp, body
219
220 def create_role(self, name):
221 """Create a Role."""
Haiwei Xuaad85db2014-03-05 05:17:39 +0900222 post_body = common.Element("role",
223 xmlns=XMLNS,
224 name=name)
225 resp, body = self.post('roles', str(common.Document(post_body)))
David Kranze9d2f422014-07-02 13:57:41 -0400226 self.expected_success(201, resp.status)
rajalakshmi-ganesan7312bb52013-01-29 20:03:42 +0530227 body = self._parse_body(etree.fromstring(body))
228 return resp, body
229
230 def get_role(self, role_id):
231 """GET a Role."""
Valeriy Ponomaryov88686d82014-02-16 12:24:51 +0200232 resp, body = self.get('roles/%s' % str(role_id))
David Kranze9d2f422014-07-02 13:57:41 -0400233 self.expected_success(200, resp.status)
rajalakshmi-ganesan7312bb52013-01-29 20:03:42 +0530234 body = self._parse_body(etree.fromstring(body))
235 return resp, body
236
wanglianmina3e84ea2014-03-26 17:30:33 +0800237 def list_roles(self):
238 """Get the list of Roles."""
239 resp, body = self.get("roles")
David Kranze9d2f422014-07-02 13:57:41 -0400240 self.expected_success(200, resp.status)
wanglianmina3e84ea2014-03-26 17:30:33 +0800241 body = self._parse_roles(etree.fromstring(body))
242 return resp, body
243
nayna-patel755d8142013-07-16 06:45:34 +0000244 def update_role(self, name, role_id):
245 """Updates a Role."""
Haiwei Xuaad85db2014-03-05 05:17:39 +0900246 post_body = common.Element("role",
247 xmlns=XMLNS,
248 name=name)
nayna-patel755d8142013-07-16 06:45:34 +0000249 resp, body = self.patch('roles/%s' % str(role_id),
Haiwei Xuaad85db2014-03-05 05:17:39 +0900250 str(common.Document(post_body)))
David Kranze9d2f422014-07-02 13:57:41 -0400251 self.expected_success(200, resp.status)
nayna-patel755d8142013-07-16 06:45:34 +0000252 body = self._parse_body(etree.fromstring(body))
253 return resp, body
254
rajalakshmi-ganesan7312bb52013-01-29 20:03:42 +0530255 def delete_role(self, role_id):
256 """Delete a role."""
Valeriy Ponomaryov88686d82014-02-16 12:24:51 +0200257 resp, body = self.delete('roles/%s' % str(role_id))
David Kranze9d2f422014-07-02 13:57:41 -0400258 self.expected_success(204, resp.status)
rajalakshmi-ganesan7312bb52013-01-29 20:03:42 +0530259 return resp, body
260
261 def assign_user_role(self, project_id, user_id, role_id):
262 """Add roles to a user on a tenant."""
263 resp, body = self.put('projects/%s/users/%s/roles/%s' %
Valeriy Ponomaryov88686d82014-02-16 12:24:51 +0200264 (project_id, user_id, role_id), '')
David Kranze9d2f422014-07-02 13:57:41 -0400265 self.expected_success(204, resp.status)
rajalakshmi-ganesan7312bb52013-01-29 20:03:42 +0530266 return resp, body
nayna-patel4df72dc2013-05-29 10:27:24 +0000267
268 def create_domain(self, name, **kwargs):
269 """Creates a domain."""
270 description = kwargs.get('description', None)
271 en = kwargs.get('enabled', True)
Haiwei Xuaad85db2014-03-05 05:17:39 +0900272 post_body = common.Element("domain",
273 xmlns=XMLNS,
274 name=name,
275 description=description,
276 enabled=str(en).lower())
277 resp, body = self.post('domains', str(common.Document(post_body)))
David Kranze9d2f422014-07-02 13:57:41 -0400278 self.expected_success(201, resp.status)
nayna-patel4df72dc2013-05-29 10:27:24 +0000279 body = self._parse_body(etree.fromstring(body))
280 return resp, body
281
282 def list_domains(self):
283 """Get the list of domains."""
Valeriy Ponomaryov88686d82014-02-16 12:24:51 +0200284 resp, body = self.get("domains")
David Kranze9d2f422014-07-02 13:57:41 -0400285 self.expected_success(200, resp.status)
nayna-patel4df72dc2013-05-29 10:27:24 +0000286 body = self._parse_domains(etree.fromstring(body))
287 return resp, body
288
289 def delete_domain(self, domain_id):
290 """Delete a domain."""
Valeriy Ponomaryov88686d82014-02-16 12:24:51 +0200291 resp, body = self.delete('domains/%s' % domain_id)
David Kranze9d2f422014-07-02 13:57:41 -0400292 self.expected_success(204, resp.status)
nayna-patel4df72dc2013-05-29 10:27:24 +0000293 return resp, body
294
295 def update_domain(self, domain_id, **kwargs):
296 """Updates a domain."""
David Kranze9d2f422014-07-02 13:57:41 -0400297 _, body = self.get_domain(domain_id)
nayna-patel4df72dc2013-05-29 10:27:24 +0000298 description = kwargs.get('description', body['description'])
299 en = kwargs.get('enabled', body['enabled'])
300 name = kwargs.get('name', body['name'])
Haiwei Xuaad85db2014-03-05 05:17:39 +0900301 post_body = common.Element("domain",
302 xmlns=XMLNS,
303 name=name,
304 description=description,
305 enabled=str(en).lower())
nayna-patel4df72dc2013-05-29 10:27:24 +0000306 resp, body = self.patch('domains/%s' % domain_id,
Haiwei Xuaad85db2014-03-05 05:17:39 +0900307 str(common.Document(post_body)))
David Kranze9d2f422014-07-02 13:57:41 -0400308 self.expected_success(200, resp.status)
nayna-patel4df72dc2013-05-29 10:27:24 +0000309 body = self._parse_body(etree.fromstring(body))
310 return resp, body
311
312 def get_domain(self, domain_id):
313 """Get Domain details."""
Valeriy Ponomaryov88686d82014-02-16 12:24:51 +0200314 resp, body = self.get('domains/%s' % domain_id)
David Kranze9d2f422014-07-02 13:57:41 -0400315 self.expected_success(200, resp.status)
nayna-patel4df72dc2013-05-29 10:27:24 +0000316 body = self._parse_body(etree.fromstring(body))
317 return resp, body
nayna-patelb35f7232013-06-28 07:08:44 +0000318
319 def get_token(self, resp_token):
320 """GET a Token Details."""
321 headers = {'Content-Type': 'application/xml',
322 'Accept': 'application/xml',
323 'X-Subject-Token': resp_token}
324 resp, body = self.get("auth/tokens", headers=headers)
David Kranze9d2f422014-07-02 13:57:41 -0400325 self.expected_success(200, resp.status)
nayna-patelb35f7232013-06-28 07:08:44 +0000326 body = self._parse_body(etree.fromstring(body))
327 return resp, body
328
329 def delete_token(self, resp_token):
330 """Delete a Given Token."""
331 headers = {'X-Subject-Token': resp_token}
332 resp, body = self.delete("auth/tokens", headers=headers)
David Kranze9d2f422014-07-02 13:57:41 -0400333 self.expected_success(204, resp.status)
nayna-patelb35f7232013-06-28 07:08:44 +0000334 return resp, body
335
nayna-patel755d8142013-07-16 06:45:34 +0000336 def create_group(self, name, **kwargs):
337 """Creates a group."""
338 description = kwargs.get('description', None)
339 domain_id = kwargs.get('domain_id', 'default')
340 project_id = kwargs.get('project_id', None)
Haiwei Xuaad85db2014-03-05 05:17:39 +0900341 post_body = common.Element("group",
342 xmlns=XMLNS,
343 name=name,
344 description=description,
345 domain_id=domain_id,
346 project_id=project_id)
347 resp, body = self.post('groups', str(common.Document(post_body)))
David Kranze9d2f422014-07-02 13:57:41 -0400348 self.expected_success(201, resp.status)
nayna-patel755d8142013-07-16 06:45:34 +0000349 body = self._parse_body(etree.fromstring(body))
350 return resp, body
351
Zhi Kun Liue8136f02014-01-07 18:56:28 +0800352 def get_group(self, group_id):
353 """Get group details."""
Valeriy Ponomaryov88686d82014-02-16 12:24:51 +0200354 resp, body = self.get('groups/%s' % group_id)
David Kranze9d2f422014-07-02 13:57:41 -0400355 self.expected_success(200, resp.status)
Zhi Kun Liue8136f02014-01-07 18:56:28 +0800356 body = self._parse_body(etree.fromstring(body))
357 return resp, body
358
359 def update_group(self, group_id, **kwargs):
360 """Updates a group."""
David Kranze9d2f422014-07-02 13:57:41 -0400361 _, body = self.get_group(group_id)
Zhi Kun Liue8136f02014-01-07 18:56:28 +0800362 name = kwargs.get('name', body['name'])
363 description = kwargs.get('description', body['description'])
Haiwei Xuaad85db2014-03-05 05:17:39 +0900364 post_body = common.Element("group",
365 xmlns=XMLNS,
366 name=name,
367 description=description)
Zhi Kun Liue8136f02014-01-07 18:56:28 +0800368 resp, body = self.patch('groups/%s' % group_id,
Haiwei Xuaad85db2014-03-05 05:17:39 +0900369 str(common.Document(post_body)))
David Kranze9d2f422014-07-02 13:57:41 -0400370 self.expected_success(200, resp.status)
Zhi Kun Liue8136f02014-01-07 18:56:28 +0800371 body = self._parse_body(etree.fromstring(body))
372 return resp, body
373
nayna-patel755d8142013-07-16 06:45:34 +0000374 def delete_group(self, group_id):
375 """Delete a group."""
Valeriy Ponomaryov88686d82014-02-16 12:24:51 +0200376 resp, body = self.delete('groups/%s' % group_id)
David Kranze9d2f422014-07-02 13:57:41 -0400377 self.expected_success(204, resp.status)
nayna-patel755d8142013-07-16 06:45:34 +0000378 return resp, body
379
Zhi Kun Liue8136f02014-01-07 18:56:28 +0800380 def add_group_user(self, group_id, user_id):
381 """Add user into group."""
Valeriy Ponomaryov88686d82014-02-16 12:24:51 +0200382 resp, body = self.put('groups/%s/users/%s' % (group_id, user_id), '')
David Kranze9d2f422014-07-02 13:57:41 -0400383 self.expected_success(204, resp.status)
Zhi Kun Liue8136f02014-01-07 18:56:28 +0800384 return resp, body
385
386 def list_group_users(self, group_id):
387 """List users in group."""
Valeriy Ponomaryov88686d82014-02-16 12:24:51 +0200388 resp, body = self.get('groups/%s/users' % group_id)
David Kranze9d2f422014-07-02 13:57:41 -0400389 self.expected_success(200, resp.status)
Zhi Kun Liue8136f02014-01-07 18:56:28 +0800390 body = self._parse_group_users(etree.fromstring(body))
391 return resp, body
392
wanglianmin29b0f4c2014-03-06 19:09:16 +0800393 def list_user_groups(self, user_id):
394 """Lists the groups which a user belongs to."""
395 resp, body = self.get('users/%s/groups' % user_id)
David Kranze9d2f422014-07-02 13:57:41 -0400396 self.expected_success(200, resp.status)
wanglianmin29b0f4c2014-03-06 19:09:16 +0800397 body = self._parse_groups(etree.fromstring(body))
398 return resp, body
399
Zhi Kun Liue8136f02014-01-07 18:56:28 +0800400 def delete_group_user(self, group_id, user_id):
401 """Delete user in group."""
Valeriy Ponomaryov88686d82014-02-16 12:24:51 +0200402 resp, body = self.delete('groups/%s/users/%s' % (group_id, user_id))
David Kranze9d2f422014-07-02 13:57:41 -0400403 self.expected_success(204, resp.status)
Zhi Kun Liue8136f02014-01-07 18:56:28 +0800404 return resp, body
405
nayna-patel755d8142013-07-16 06:45:34 +0000406 def assign_user_role_on_project(self, project_id, user_id, role_id):
407 """Add roles to a user on a project."""
408 resp, body = self.put('projects/%s/users/%s/roles/%s' %
Valeriy Ponomaryov88686d82014-02-16 12:24:51 +0200409 (project_id, user_id, role_id), '')
David Kranze9d2f422014-07-02 13:57:41 -0400410 self.expected_success(204, resp.status)
nayna-patel755d8142013-07-16 06:45:34 +0000411 return resp, body
412
413 def assign_user_role_on_domain(self, domain_id, user_id, role_id):
414 """Add roles to a user on a domain."""
415 resp, body = self.put('domains/%s/users/%s/roles/%s' %
Valeriy Ponomaryov88686d82014-02-16 12:24:51 +0200416 (domain_id, user_id, role_id), '')
David Kranze9d2f422014-07-02 13:57:41 -0400417 self.expected_success(204, resp.status)
nayna-patel755d8142013-07-16 06:45:34 +0000418 return resp, body
419
420 def list_user_roles_on_project(self, project_id, user_id):
421 """list roles of a user on a project."""
422 resp, body = self.get('projects/%s/users/%s/roles' %
Valeriy Ponomaryov88686d82014-02-16 12:24:51 +0200423 (project_id, user_id))
David Kranze9d2f422014-07-02 13:57:41 -0400424 self.expected_success(200, resp.status)
nayna-patel755d8142013-07-16 06:45:34 +0000425 body = self._parse_roles(etree.fromstring(body))
426 return resp, body
427
428 def list_user_roles_on_domain(self, domain_id, user_id):
429 """list roles of a user on a domain."""
430 resp, body = self.get('domains/%s/users/%s/roles' %
Valeriy Ponomaryov88686d82014-02-16 12:24:51 +0200431 (domain_id, user_id))
David Kranze9d2f422014-07-02 13:57:41 -0400432 self.expected_success(200, resp.status)
nayna-patel755d8142013-07-16 06:45:34 +0000433 body = self._parse_roles(etree.fromstring(body))
434 return resp, body
435
436 def revoke_role_from_user_on_project(self, project_id, user_id, role_id):
437 """Delete role of a user on a project."""
438 resp, body = self.delete('projects/%s/users/%s/roles/%s' %
Valeriy Ponomaryov88686d82014-02-16 12:24:51 +0200439 (project_id, user_id, role_id))
David Kranze9d2f422014-07-02 13:57:41 -0400440 self.expected_success(204, resp.status)
nayna-patel755d8142013-07-16 06:45:34 +0000441 return resp, body
442
443 def revoke_role_from_user_on_domain(self, domain_id, user_id, role_id):
444 """Delete role of a user on a domain."""
445 resp, body = self.delete('domains/%s/users/%s/roles/%s' %
Valeriy Ponomaryov88686d82014-02-16 12:24:51 +0200446 (domain_id, user_id, role_id))
David Kranze9d2f422014-07-02 13:57:41 -0400447 self.expected_success(204, resp.status)
nayna-patel755d8142013-07-16 06:45:34 +0000448 return resp, body
449
450 def assign_group_role_on_project(self, project_id, group_id, role_id):
451 """Add roles to a user on a project."""
452 resp, body = self.put('projects/%s/groups/%s/roles/%s' %
Valeriy Ponomaryov88686d82014-02-16 12:24:51 +0200453 (project_id, group_id, role_id), '')
David Kranze9d2f422014-07-02 13:57:41 -0400454 self.expected_success(204, resp.status)
nayna-patel755d8142013-07-16 06:45:34 +0000455 return resp, body
456
457 def assign_group_role_on_domain(self, domain_id, group_id, role_id):
458 """Add roles to a user on a domain."""
459 resp, body = self.put('domains/%s/groups/%s/roles/%s' %
Valeriy Ponomaryov88686d82014-02-16 12:24:51 +0200460 (domain_id, group_id, role_id), '')
David Kranze9d2f422014-07-02 13:57:41 -0400461 self.expected_success(204, resp.status)
nayna-patel755d8142013-07-16 06:45:34 +0000462 return resp, body
463
464 def list_group_roles_on_project(self, project_id, group_id):
465 """list roles of a user on a project."""
466 resp, body = self.get('projects/%s/groups/%s/roles' %
Valeriy Ponomaryov88686d82014-02-16 12:24:51 +0200467 (project_id, group_id))
David Kranze9d2f422014-07-02 13:57:41 -0400468 self.expected_success(200, resp.status)
nayna-patel755d8142013-07-16 06:45:34 +0000469 body = self._parse_roles(etree.fromstring(body))
470 return resp, body
471
472 def list_group_roles_on_domain(self, domain_id, group_id):
473 """list roles of a user on a domain."""
474 resp, body = self.get('domains/%s/groups/%s/roles' %
Valeriy Ponomaryov88686d82014-02-16 12:24:51 +0200475 (domain_id, group_id))
David Kranze9d2f422014-07-02 13:57:41 -0400476 self.expected_success(200, resp.status)
nayna-patel755d8142013-07-16 06:45:34 +0000477 body = self._parse_roles(etree.fromstring(body))
478 return resp, body
479
480 def revoke_role_from_group_on_project(self, project_id, group_id, role_id):
481 """Delete role of a user on a project."""
482 resp, body = self.delete('projects/%s/groups/%s/roles/%s' %
Valeriy Ponomaryov88686d82014-02-16 12:24:51 +0200483 (project_id, group_id, role_id))
David Kranze9d2f422014-07-02 13:57:41 -0400484 self.expected_success(204, resp.status)
nayna-patel755d8142013-07-16 06:45:34 +0000485 return resp, body
486
487 def revoke_role_from_group_on_domain(self, domain_id, group_id, role_id):
488 """Delete role of a user on a domain."""
489 resp, body = self.delete('domains/%s/groups/%s/roles/%s' %
Valeriy Ponomaryov88686d82014-02-16 12:24:51 +0200490 (domain_id, group_id, role_id))
David Kranze9d2f422014-07-02 13:57:41 -0400491 self.expected_success(204, resp.status)
nayna-patel755d8142013-07-16 06:45:34 +0000492 return resp, body
493
nayna-patelb35f7232013-06-28 07:08:44 +0000494
vponomaryov960eeb42014-02-22 18:25:25 +0200495class V3TokenClientXML(rest_client.RestClient):
496 TYPE = "xml"
nayna-patelb35f7232013-06-28 07:08:44 +0000497
Andrea Frittoli8bbdb162014-01-06 11:06:13 +0000498 def __init__(self):
499 super(V3TokenClientXML, self).__init__(None)
500 auth_url = CONF.identity.uri_v3
Matthew Treinishdb2c5972014-01-31 22:18:59 +0000501 if not auth_url and CONF.identity_feature_enabled.api_v3:
502 raise exceptions.InvalidConfiguration('you must specify a v3 uri '
503 'if using the v3 identity '
504 'api')
Andrea Frittoli8bbdb162014-01-06 11:06:13 +0000505 if 'auth/tokens' not in auth_url:
506 auth_url = auth_url.rstrip('/') + '/auth/tokens'
nayna-patelb35f7232013-06-28 07:08:44 +0000507
508 self.auth_url = auth_url
nayna-patelb35f7232013-06-28 07:08:44 +0000509
Brant Knudsonc5553292014-03-15 11:06:05 -0500510 def auth(self, user=None, password=None, tenant=None, user_type='id',
511 domain=None, token=None):
Andrea Frittoli8bbdb162014-01-06 11:06:13 +0000512 """
513 :param user: user id or name, as specified in user_type
Brant Knudsonc5553292014-03-15 11:06:05 -0500514 :param domain: the user and tenant domain
515 :param token: a token to re-scope.
Andrea Frittoli8bbdb162014-01-06 11:06:13 +0000516
517 Accepts different combinations of credentials. Restrictions:
518 - tenant and domain are only name (no id)
519 - user domain and tenant domain are assumed identical
Brant Knudsonc5553292014-03-15 11:06:05 -0500520 - domain scope is not supported here
Andrea Frittoli8bbdb162014-01-06 11:06:13 +0000521 Sample sample valid combinations:
Brant Knudsonc5553292014-03-15 11:06:05 -0500522 - token
523 - token, tenant, domain
Andrea Frittoli8bbdb162014-01-06 11:06:13 +0000524 - user_id, password
525 - username, password, domain
526 - username, password, tenant, domain
527 Validation is left to the server side.
528 """
Andrea Frittoli8bbdb162014-01-06 11:06:13 +0000529
Haiwei Xuaad85db2014-03-05 05:17:39 +0900530 methods = common.Element('methods')
Haiwei Xuaad85db2014-03-05 05:17:39 +0900531 identity = common.Element('identity')
Brant Knudsonc5553292014-03-15 11:06:05 -0500532
533 if token:
534 method = common.Element('method')
535 method.append(common.Text('token'))
536 methods.append(method)
537
538 token = common.Element('token', id=token)
539 identity.append(token)
540
541 if user and password:
542 if user_type == 'id':
543 _user = common.Element('user', id=user, password=password)
544 else:
545 _user = common.Element('user', name=user, password=password)
546 if domain is not None:
547 _domain = common.Element('domain', name=domain)
548 _user.append(_domain)
549
550 password = common.Element('password')
551 password.append(_user)
552 method = common.Element('method')
553 method.append(common.Text('password'))
554 methods.append(method)
555 identity.append(password)
556
nayna-patelb35f7232013-06-28 07:08:44 +0000557 identity.append(methods)
Andrea Frittoli8bbdb162014-01-06 11:06:13 +0000558
Haiwei Xuaad85db2014-03-05 05:17:39 +0900559 auth = common.Element('auth')
nayna-patelb35f7232013-06-28 07:08:44 +0000560 auth.append(identity)
Andrea Frittoli8bbdb162014-01-06 11:06:13 +0000561
562 if tenant is not None:
Haiwei Xuaad85db2014-03-05 05:17:39 +0900563 project = common.Element('project', name=tenant)
Brant Knudsonc5553292014-03-15 11:06:05 -0500564 _domain = common.Element('domain', name=domain)
Andrea Frittoli8bbdb162014-01-06 11:06:13 +0000565 project.append(_domain)
Haiwei Xuaad85db2014-03-05 05:17:39 +0900566 scope = common.Element('scope')
Andrea Frittoli8bbdb162014-01-06 11:06:13 +0000567 scope.append(project)
568 auth.append(scope)
569
Haiwei Xuaad85db2014-03-05 05:17:39 +0900570 resp, body = self.post(self.auth_url, body=str(common.Document(auth)))
nayna-patelb35f7232013-06-28 07:08:44 +0000571 return resp, body
572
Sergey Murashov4fccd322014-03-22 09:58:52 +0400573 def request(self, method, url, extra_headers=False, headers=None,
574 body=None):
Andrea Frittoli8bbdb162014-01-06 11:06:13 +0000575 """A simple HTTP request interface."""
Valeriy Ponomaryov88686d82014-02-16 12:24:51 +0200576 if headers is None:
577 # Always accept 'json', for xml token client too.
578 # Because XML response is not easily
579 # converted to the corresponding JSON one
580 headers = self.get_headers(accept_type="json")
Sergey Murashov4fccd322014-03-22 09:58:52 +0400581 elif extra_headers:
582 try:
583 headers.update(self.get_headers(accept_type="json"))
584 except (ValueError, TypeError):
585 headers = self.get_headers(accept_type="json")
Andrea Frittoli8bbdb162014-01-06 11:06:13 +0000586 resp, resp_body = self.http_obj.request(url, method,
587 headers=headers, body=body)
Sean Dague89a85912014-03-19 16:37:29 -0400588 self._log_request(method, url, resp)
Andrea Frittoli8bbdb162014-01-06 11:06:13 +0000589
590 if resp.status in [401, 403]:
591 resp_body = json.loads(resp_body)
592 raise exceptions.Unauthorized(resp_body['error']['message'])
593 elif resp.status not in [200, 201, 204]:
594 raise exceptions.IdentityError(
595 'Unexpected status code {0}'.format(resp.status))
596
597 return resp, json.loads(resp_body)
598
599 def get_token(self, user, password, tenant, domain='Default',
600 auth_data=False):
601 """
602 :param user: username
603 Returns (token id, token data) for supplied credentials
604 """
605 resp, body = self.auth(user, password, tenant, user_type='name',
606 domain=domain)
607
608 token = resp.get('x-subject-token')
609 if auth_data:
610 return token, body['token']
611 else:
612 return token