-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Merge pull request #24 from MITLibraries/etd-436-smoke-tests
Add infrastructure permissions check
- Loading branch information
Showing
12 changed files
with
339 additions
and
18 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,29 @@ | ||
import logging | ||
from typing import List | ||
|
||
import boto3 | ||
|
||
logger = logging.getLogger(__name__) | ||
|
||
|
||
def check_s3_permissions(buckets: List[str]) -> str: | ||
"""Checks S3 ListObjectV2 and GetObject permissions for all buckets provided in the | ||
passed list. If either command is not allowed for any of the provided buckets, | ||
raises an Access Denied bocotore client error. | ||
""" | ||
s3 = boto3.client("s3") | ||
bucket_names = [] | ||
for bucket in buckets: | ||
response = s3.list_objects_v2(Bucket=bucket, MaxKeys=1) | ||
logger.debug(f"Successfully listed objects in bucket '{bucket}'") | ||
for object in response["Contents"]: | ||
s3.get_object(Bucket=bucket, Key=object["Key"]) | ||
bucket_names.append(bucket) | ||
logger.debug( | ||
f"Successfully retrieved object '{object['Key']}' from bucket " | ||
f"'{bucket}'" | ||
) | ||
return ( | ||
"S3 list objects and get object permissions confirmed for buckets: " | ||
f"{bucket_names}" | ||
) |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,29 @@ | ||
import os | ||
|
||
import boto3 | ||
import pytest | ||
from botocore.exceptions import ClientError | ||
from moto.core import set_initial_no_auth_action_count | ||
|
||
from submitter.s3 import check_s3_permissions | ||
|
||
|
||
def test_check_s3_permissions_success(mocked_s3): | ||
result = check_s3_permissions(["test-bucket"]) | ||
assert ( | ||
result == "S3 list objects and get object permissions confirmed for buckets: " | ||
"['test-bucket']" | ||
) | ||
|
||
|
||
@set_initial_no_auth_action_count(0) | ||
def test_check_s3_permissions_raises_error(mocked_s3, test_aws_user): | ||
os.environ["AWS_ACCESS_KEY_ID"] = test_aws_user["AccessKeyId"] | ||
os.environ["AWS_SECRET_ACCESS_KEY"] = test_aws_user["SecretAccessKey"] | ||
boto3.setup_default_session() | ||
with pytest.raises(ClientError) as e: | ||
check_s3_permissions(["test-bucket"]) | ||
assert ( | ||
"An error occurred (AccessDenied) when calling the GetObject operation: Access " | ||
"Denied" in str(e.value) | ||
) |
Oops, something went wrong.