package com.amazonaws.iot.certificate; import org.junit.jupiter.api.Assertions; import org.junit.jupiter.api.BeforeEach; import org.junit.jupiter.api.Test; import org.junit.jupiter.api.extension.ExtendWith; import org.mockito.Mock; import org.mockito.MockitoAnnotations; import org.mockito.junit.jupiter.MockitoExtension; import software.amazon.awssdk.services.iot.model.CertificateMode; import software.amazon.awssdk.services.iot.model.CreateCertificateFromCsrRequest; import software.amazon.awssdk.services.iot.model.CreateCertificateFromCsrResponse; import software.amazon.awssdk.services.iot.model.InternalException; import software.amazon.awssdk.services.iot.model.InvalidRequestException; import software.amazon.awssdk.services.iot.model.RegisterCertificateRequest; import software.amazon.awssdk.services.iot.model.RegisterCertificateResponse; import software.amazon.awssdk.services.iot.model.RegisterCertificateWithoutCaRequest; import software.amazon.awssdk.services.iot.model.RegisterCertificateWithoutCaResponse; import software.amazon.awssdk.services.iot.model.ResourceAlreadyExistsException; import software.amazon.awssdk.services.iot.model.ThrottlingException; import software.amazon.cloudformation.exceptions.CfnAlreadyExistsException; import software.amazon.cloudformation.exceptions.CfnInvalidRequestException; import software.amazon.cloudformation.exceptions.CfnServiceInternalErrorException; import software.amazon.cloudformation.exceptions.CfnThrottlingException; import software.amazon.cloudformation.proxy.AmazonWebServicesClientProxy; import software.amazon.cloudformation.proxy.Logger; import software.amazon.cloudformation.proxy.OperationStatus; import software.amazon.cloudformation.proxy.ProgressEvent; import software.amazon.cloudformation.proxy.ResourceHandlerRequest; import static org.assertj.core.api.Assertions.assertThat; import static org.mockito.ArgumentMatchers.any; import static org.mockito.Mockito.doReturn; import static org.mockito.Mockito.doThrow; @ExtendWith(MockitoExtension.class) public class CreateHandlerTest extends CertificateTestBase { private CreateHandler handler; @Mock private AmazonWebServicesClientProxy proxy; @Mock private Logger logger; @BeforeEach public void setup() { MockitoAnnotations.initMocks(this); handler = new CreateHandler(); } @Test public void handleRequest_SuccessWithCsr() { final ResourceModel model = ResourceModel.builder() .certificateMode(CertificateMode.DEFAULT.toString()) .certificateSigningRequest(CERT_CSR) .build(); final ResourceHandlerRequest request = defaultRequestBuilder(model).build(); doReturn(CreateCertificateFromCsrResponse.builder() .certificateArn(CERT_ARN) .certificateId(CERT_ID) .certificatePem("PEM") .build()) .when(proxy) .injectCredentialsAndInvokeV2(any(CreateCertificateFromCsrRequest.class), any()); final ProgressEvent response = handler.handleRequest(proxy, request, null, logger); assertThat(response).isNotNull(); assertThat(response.getStatus()).isEqualTo(OperationStatus.SUCCESS); assertThat(response.getCallbackContext()).isNull(); assertThat(response.getCallbackDelaySeconds()).isEqualTo(0); assertThat(response.getResourceModel()).isEqualTo(request.getDesiredResourceState()); assertThat(response.getResourceModels()).isNull(); assertThat(response.getMessage()).isNull(); assertThat(response.getErrorCode()).isNull(); assertThat(response.getResourceModel().getId()).isEqualTo(CERT_ID); assertThat(response.getResourceModel().getArn()).isEqualTo(CERT_ARN); } @Test public void handleRequest_SuccessWithCaPem() { final ResourceModel model = ResourceModel.builder() .cACertificatePem(CERT_CA_PEM) .certificatePem(CERT_PEM) .certificateMode(CertificateMode.DEFAULT.toString()) .build(); final ResourceHandlerRequest request = defaultRequestBuilder(model).build(); doReturn(RegisterCertificateResponse.builder() .certificateArn(CERT_ARN) .certificateId(CERT_ID) .build()) .when(proxy) .injectCredentialsAndInvokeV2(any(RegisterCertificateRequest.class), any()); final ProgressEvent response = handler.handleRequest(proxy, request, null, logger); assertThat(response).isNotNull(); assertThat(response.getStatus()).isEqualTo(OperationStatus.SUCCESS); assertThat(response.getCallbackContext()).isNull(); assertThat(response.getCallbackDelaySeconds()).isEqualTo(0); assertThat(response.getResourceModel()).isEqualTo(request.getDesiredResourceState()); assertThat(response.getResourceModels()).isNull(); assertThat(response.getMessage()).isNull(); assertThat(response.getErrorCode()).isNull(); assertThat(response.getResourceModel().getId()).isEqualTo(CERT_ID); assertThat(response.getResourceModel().getArn()).isEqualTo(CERT_ARN); } @Test public void handleRequest_SuccessWithMultiAccountRegistration() { final ResourceModel model = ResourceModel.builder() .certificatePem(CERT_PEM) .certificateMode(CertificateMode.SNI_ONLY.toString()) .build(); final ResourceHandlerRequest request = defaultRequestBuilder(model).build(); doReturn(RegisterCertificateWithoutCaResponse.builder() .certificateArn(CERT_ARN) .certificateId(CERT_ID) .build()) .when(proxy) .injectCredentialsAndInvokeV2(any(RegisterCertificateWithoutCaRequest.class), any()); final ProgressEvent response = handler.handleRequest(proxy, request, null, logger); assertThat(response).isNotNull(); assertThat(response.getStatus()).isEqualTo(OperationStatus.SUCCESS); assertThat(response.getCallbackContext()).isNull(); assertThat(response.getCallbackDelaySeconds()).isEqualTo(0); assertThat(response.getResourceModel()).isEqualTo(request.getDesiredResourceState()); assertThat(response.getResourceModels()).isNull(); assertThat(response.getMessage()).isNull(); assertThat(response.getErrorCode()).isNull(); assertThat(response.getResourceModel().getId()).isEqualTo(CERT_ID); assertThat(response.getResourceModel().getArn()).isEqualTo(CERT_ARN); } @Test public void handleRequest_ResourceConflictFails() { final ResourceModel model = defaultModelBuilder().build(); final ResourceHandlerRequest request = defaultRequestBuilder(model).build(); doThrow(ResourceAlreadyExistsException.builder().resourceId(CERT_ID).build()) .when(proxy) .injectCredentialsAndInvokeV2(any(CreateCertificateFromCsrRequest.class), any()); Assertions.assertThrows(CfnAlreadyExistsException.class, () -> handler.handleRequest(proxy, request, null, logger)); } @Test public void handleRequest_InvalidRequestFails() { final ResourceModel model = defaultModelBuilder().build(); final ResourceHandlerRequest request = defaultRequestBuilder(model).build(); doThrow(InvalidRequestException.builder().build()) .when(proxy) .injectCredentialsAndInvokeV2(any(CreateCertificateFromCsrRequest.class), any()); Assertions.assertThrows(CfnInvalidRequestException.class, () -> handler.handleRequest(proxy, request, null, logger)); } @Test public void handleRequest_InternalExceptionFails() { final ResourceModel model = defaultModelBuilder().build(); final ResourceHandlerRequest request = defaultRequestBuilder(model).build(); doThrow(InternalException.builder().build()) .when(proxy) .injectCredentialsAndInvokeV2(any(CreateCertificateFromCsrRequest.class), any()); Assertions.assertThrows(CfnServiceInternalErrorException.class, () -> handler.handleRequest(proxy, request, null, logger)); } @Test public void handleRequest_ThrottlingFails() { final ResourceModel model = defaultModelBuilder().build(); final ResourceHandlerRequest request = defaultRequestBuilder(model).build(); doThrow(ThrottlingException.builder().build()) .when(proxy) .injectCredentialsAndInvokeV2(any(CreateCertificateFromCsrRequest.class), any()); Assertions.assertThrows(CfnThrottlingException.class, () -> handler.handleRequest(proxy, request, null, logger)); } }