diff --git a/.github/workflows/zizmor.yaml b/.github/workflows/zizmor.yaml index 163ecb1..a81b9e9 100644 --- a/.github/workflows/zizmor.yaml +++ b/.github/workflows/zizmor.yaml @@ -27,4 +27,4 @@ jobs: persist-credentials: false - name: Run zizmor - uses: cerbos/actions/lint-actions@c19f023116079958e91290ea4af73e25296d7614 # main + uses: cerbos/actions/lint-actions@2f4fe1d07ce827af7fe5e70a35ec3fff72b734dc # main diff --git a/src/test/java/dev/cerbos/sdk/CerbosBlockingAdminClientTest.java b/src/test/java/dev/cerbos/sdk/CerbosBlockingAdminClientTest.java index c1563b5..b916910 100644 --- a/src/test/java/dev/cerbos/sdk/CerbosBlockingAdminClientTest.java +++ b/src/test/java/dev/cerbos/sdk/CerbosBlockingAdminClientTest.java @@ -36,20 +36,21 @@ class CerbosBlockingAdminClientTest extends CerbosClientTests { private static final ObjectMapper YAML_MAPPER = new ObjectMapper(new YAMLFactory()); private static final ObjectMapper JSON_MAPPER = new ObjectMapper(); @Container - private static final CerbosContainer cerbosContainer = - new CerbosContainer("dev") - .withClasspathResourceMapping("config", "/config", BindMode.READ_ONLY) - .withCommand("server", "--config=/config/admin-config.yaml") - .withLogConsumer(new Slf4jLogConsumer(LOG)); + private static final CerbosContainer cerbosContainer = new CerbosContainer("dev") + .withClasspathResourceMapping("config", "/config", BindMode.READ_ONLY) + .withCommand("server", "--config=/config/admin-config.yaml") + .withLogConsumer(new Slf4jLogConsumer(LOG)); CerbosBlockingAdminClient adminClient; @BeforeAll public void initClient() throws CerbosClientBuilder.InvalidClientConfigurationException, URISyntaxException { String target = cerbosContainer.getTarget(); - this.adminClient = new CerbosClientBuilder(target).withPlaintext().buildBlockingAdminClient("cerbos", "cerbosAdmin").withHeaders(Map.of("wibble", "wobble")); + this.adminClient = new CerbosClientBuilder(target).withPlaintext() + .buildBlockingAdminClient("cerbos", "cerbosAdmin").withHeaders(Map.of("wibble", "wobble")); this.client = new CerbosClientBuilder(target).withPlaintext().buildBlockingClient(); loadSchemas(); loadPolicies(); + this.adminClient.storeReload(true); } void loadSchemas() throws URISyntaxException { @@ -114,7 +115,8 @@ private void addPolicies(AddOrUpdatePolicyRequestBuilder requestBuilder, File fi requestBuilder.with(new FileReader(file)); } catch (ValidationException ve) { - ve.getViolations().stream().forEach(e -> System.out.printf("%s - %s\n", e.toProto().getField(), e.toProto().getMessage())); + ve.getViolations().stream() + .forEach(e -> System.out.printf("%s - %s\n", e.toProto().getField(), e.toProto().getMessage())); throw new RuntimeException(ve); } catch (Exception e) { throw new RuntimeException(e); @@ -130,10 +132,12 @@ void listPoliciesWithoutFilter() { @Test void listPoliciesWithFilter() { - List have = this.adminClient.listAllPolicies(Optional.of("leave"), Optional.empty(), Optional.of("acme")); + List have = this.adminClient.listAllPolicies(Optional.of("leave"), Optional.empty(), + Optional.of("acme")); Assertions.assertNotNull(have); Assertions.assertEquals(3, have.size()); - Assertions.assertIterableEquals(List.of("resource.leave_request.vdefault/acme", "resource.leave_request.vdefault/acme.hr", "resource.leave_request.vdefault/acme.hr.uk"), have); + Assertions.assertIterableEquals(List.of("resource.leave_request.vdefault/acme", + "resource.leave_request.vdefault/acme.hr", "resource.leave_request.vdefault/acme.hr.uk"), have); } @Test @@ -233,4 +237,4 @@ public boolean accept(File f) { return (fileName.endsWith(".yaml") || fileName.endsWith(".yml") || fileName.endsWith(".json")); } } -} \ No newline at end of file +} diff --git a/src/test/resources/config/admin-config.yaml b/src/test/resources/config/admin-config.yaml index 1e23e53..7923cf2 100644 --- a/src/test/resources/config/admin-config.yaml +++ b/src/test/resources/config/admin-config.yaml @@ -12,6 +12,14 @@ auxData: local: file: /config/verify_key.jwk +audit: + enabled: true + accessLogsEnabled: false + decisionLogsEnabled: true + backend: file + file: + path: stdout + engine: defaultPolicyVersion: "default"