PD Guard: модуль безопасности персональных данных
This commit is contained in:
@@ -0,0 +1,90 @@
|
||||
package ru.pdguard;
|
||||
|
||||
import com.fasterxml.jackson.databind.ObjectMapper;
|
||||
import org.junit.jupiter.api.Test;
|
||||
import org.junit.jupiter.api.io.TempDir;
|
||||
import ru.pdguard.config.SystemPolicy;
|
||||
import ru.pdguard.config.SystemsConfig;
|
||||
import ru.pdguard.mask.MaskMode;
|
||||
|
||||
import java.io.IOException;
|
||||
import java.nio.charset.StandardCharsets;
|
||||
import java.nio.file.Files;
|
||||
import java.nio.file.Path;
|
||||
|
||||
import static org.junit.jupiter.api.Assertions.assertEquals;
|
||||
import static org.junit.jupiter.api.Assertions.assertFalse;
|
||||
import static org.junit.jupiter.api.Assertions.assertTrue;
|
||||
|
||||
/** Чтение и горячая перезагрузка списка систем. */
|
||||
class SystemsConfigTest {
|
||||
|
||||
private static final String CONTENT = """
|
||||
{
|
||||
"default": { "enabled": true, "demask": true, "maskMode": "MASK", "types": ["*"] },
|
||||
"crm": { "enabled": true, "demask": false, "maskMode": "TOKEN", "types": ["FIO"] },
|
||||
"old": { "enabled": false }
|
||||
}
|
||||
""";
|
||||
|
||||
private SystemsConfig configAt(Path file) {
|
||||
return new SystemsConfig(file.toString(), new ObjectMapper());
|
||||
}
|
||||
|
||||
@Test
|
||||
void readsPoliciesFromFile(@TempDir Path dir) throws IOException {
|
||||
Path file = dir.resolve("systems.json");
|
||||
Files.writeString(file, CONTENT, StandardCharsets.UTF_8);
|
||||
|
||||
SystemsConfig config = configAt(file);
|
||||
SystemPolicy crm = config.policyFor("crm");
|
||||
|
||||
assertEquals(MaskMode.TOKEN, crm.maskMode());
|
||||
assertFalse(crm.demask());
|
||||
assertTrue(crm.allows("FIO"));
|
||||
assertFalse(crm.allows("CARD"));
|
||||
assertFalse(config.policyFor("old").enabled());
|
||||
}
|
||||
|
||||
@Test
|
||||
void unknownSystemGetsDefaultPolicy(@TempDir Path dir) throws IOException {
|
||||
Path file = dir.resolve("systems.json");
|
||||
Files.writeString(file, CONTENT, StandardCharsets.UTF_8);
|
||||
|
||||
SystemPolicy policy = configAt(file).policyFor("никому-не-известная");
|
||||
assertTrue(policy.enabled());
|
||||
assertTrue(policy.allows("CARD"));
|
||||
}
|
||||
|
||||
@Test
|
||||
void worksWithoutConfigFile(@TempDir Path dir) {
|
||||
SystemsConfig config = configAt(dir.resolve("нет-такого-файла.json"));
|
||||
assertEquals(SystemPolicy.DEFAULT, config.policyFor("любая"));
|
||||
}
|
||||
|
||||
@Test
|
||||
void picksUpChangesWithoutRestart(@TempDir Path dir) throws IOException {
|
||||
Path file = dir.resolve("systems.json");
|
||||
Files.writeString(file, CONTENT, StandardCharsets.UTF_8);
|
||||
SystemsConfig config = configAt(file);
|
||||
assertEquals(MaskMode.TOKEN, config.policyFor("crm").maskMode());
|
||||
|
||||
Files.writeString(file, CONTENT.replace("\"TOKEN\"", "\"SYNTHETIC\""), StandardCharsets.UTF_8);
|
||||
config.reload();
|
||||
|
||||
assertEquals(MaskMode.SYNTHETIC, config.policyFor("crm").maskMode());
|
||||
}
|
||||
|
||||
@Test
|
||||
void brokenFileKeepsPreviousSettings(@TempDir Path dir) throws IOException {
|
||||
Path file = dir.resolve("systems.json");
|
||||
Files.writeString(file, CONTENT, StandardCharsets.UTF_8);
|
||||
SystemsConfig config = configAt(file);
|
||||
|
||||
Files.writeString(file, "{ это не json", StandardCharsets.UTF_8);
|
||||
config.reload();
|
||||
|
||||
assertEquals(MaskMode.TOKEN, config.policyFor("crm").maskMode(),
|
||||
"сломанный файл не должен ронять работающий сервис");
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user