]> review.fuel-infra Code Review - openstack-build/neutron-build.git/commitdiff
Validate rule uuids provided for update_policy
authorEugene Nikanorov <enikanorov@mirantis.com>
Mon, 17 Feb 2014 12:35:09 +0000 (16:35 +0400)
committerThomas Goirand <thomas@goirand.fr>
Thu, 13 Mar 2014 07:20:23 +0000 (15:20 +0800)
Add corresponding validation method to fwaas extension

Change-Id: I643c10a996813d251684d3b5de04c8826729129f
Closes-Bug: #1281083

neutron/extensions/firewall.py
neutron/tests/unit/db/firewall/test_db_firewall.py
neutron/tests/unit/test_extension_firewall.py

index 847914197fbdd5dcad8a3d52d156467276cf68a7..b3279bb431190904c52c0dce373e83c3a02eaede 100644 (file)
@@ -243,6 +243,7 @@ RESOURCE_ATTRIBUTE_MAP = {
                    'is_visible': True, 'required_by_policy': True,
                    'enforce_policy': True},
         'firewall_rules': {'allow_post': True, 'allow_put': True,
+                           'validate': {'type:uuid_list': None},
                            'convert_to': attr.convert_none_to_empty_list,
                            'default': None, 'is_visible': True},
         'audited': {'allow_post': True, 'allow_put': True,
index 5a862f6afe581123d3cbbbeadd30b4813004e6d9..aa7f3efa6ff41a95ed0c7c205ca959efa719c202 100644 (file)
@@ -29,6 +29,7 @@ from neutron.db.firewall import firewall_db as fdb
 import neutron.extensions
 from neutron.extensions import firewall
 from neutron.openstack.common import importutils
+from neutron.openstack.common import uuidutils
 from neutron.plugins.common import constants
 from neutron.tests.unit import test_db_plugin
 
@@ -477,7 +478,8 @@ class TestFirewallDBPlugin(FirewallPluginDbTestCase):
                                    self.firewall_rule(name='fwr2',
                                                       no_delete=True)) as fr:
                 fw_rule_ids = [r['firewall_rule']['id'] for r in fr]
-                fw_rule_ids.append('12345')  # non-existent rule
+                # appending non-existent rule
+                fw_rule_ids.append(uuidutils.generate_uuid())
                 data = {'firewall_policy':
                         {'firewall_rules': fw_rule_ids}}
                 req = self.new_update_request('firewall_policies', data,
index 486f20f03b8e31aba0e7d3f9bdee39e91c0da2b6..be0b3ac2a0300fabbe1115f5bce2f51d45660c3c 100644 (file)
@@ -378,6 +378,17 @@ class FirewallExtensionTestCase(testlib_api.WebTestCase):
         self.assertIn('firewall_policy', res)
         self.assertEqual(res['firewall_policy'], return_value)
 
+    def test_firewall_policy_update_malformed_rules(self):
+        # emulating client request when no rule uuids are provided for
+        # --firewall_rules parameter
+        update_data = {'firewall_policy': {'firewall_rules': True}}
+        # have to check for generic AppError
+        self.assertRaises(
+            webtest.AppError,
+            self.api.put,
+            _get_path('fw/firewall_policies', id=_uuid(), fmt=self.fmt),
+            self.serialize(update_data))
+
     def test_firewall_policy_delete(self):
         self._test_entity_delete('firewall_policy')