1 package org.cacert.gigi.testUtils;
3 import static org.junit.Assert.*;
5 import java.io.IOException;
6 import java.io.OutputStream;
7 import java.net.HttpURLConnection;
9 import java.security.GeneralSecurityException;
10 import java.security.KeyPair;
11 import java.security.PrivateKey;
12 import java.security.cert.X509Certificate;
14 import org.cacert.gigi.GigiApiException;
15 import org.cacert.gigi.dbObjects.Certificate;
16 import org.cacert.gigi.dbObjects.Certificate.CSRType;
17 import org.cacert.gigi.dbObjects.Certificate.SANType;
18 import org.cacert.gigi.dbObjects.CertificateProfile;
19 import org.cacert.gigi.dbObjects.Digest;
20 import org.cacert.gigi.dbObjects.Group;
21 import org.cacert.gigi.dbObjects.Organisation;
22 import org.cacert.gigi.dbObjects.User;
23 import org.junit.BeforeClass;
25 public class RestrictedApiTest extends ClientTest {
27 protected static PrivateKey pk;
29 protected static X509Certificate ce;
31 public RestrictedApiTest() {
36 public static void initCert() {
39 User u = User.getById(createAssuranceUser("f", "l", createUniqueName() + "@email.com", TEST_PASSWORD));
40 grant(u.getEmail(), Group.ORGASSURER);
42 u = User.getById(u.getId());
43 Organisation o = new Organisation(Organisation.SELF_ORG_NAME, "NA", "NA", "NA", "contact@cacert.org", "", "", u);
44 assertTrue(o.isSelfOrganisation());
45 KeyPair kp = generateKeypair();
46 String key1 = generatePEMCSR(kp, "EMAIL=cats@cacert.org");
47 Certificate c = new Certificate(o, u, Certificate.buildDN("EMAIL", "cats@cacert.org"), Digest.SHA256, key1, CSRType.CSR, CertificateProfile.getByName("client-orga"), new Certificate.SubjectAlternateName(SANType.EMAIL, "cats@cacert.org"));
49 await(c.issue(null, "2y", u));
51 } catch (IOException e) {
53 } catch (GigiApiException e) {
55 } catch (GeneralSecurityException e) {
57 } catch (InterruptedException e) {
63 public HttpURLConnection doApi(String path, String content) throws IOException, GeneralSecurityException {
64 HttpURLConnection connection = (HttpURLConnection) new URL("https://" + getServerName().replaceFirst("^www.", "api.") + path).openConnection();
65 authenticateClientCert(pk, ce, connection);
66 connection.setDoOutput(true);
67 OutputStream os = connection.getOutputStream();
68 os.write(content.getBytes());