View Javadoc
1   /*
2    * This file is part of dependency-check-core.
3    *
4    * Licensed under the Apache License, Version 2.0 (the "License");
5    * you may not use this file except in compliance with the License.
6    * You may obtain a copy of the License at
7    *
8    *     http://www.apache.org/licenses/LICENSE-2.0
9    *
10   * Unless required by applicable law or agreed to in writing, software
11   * distributed under the License is distributed on an "AS IS" BASIS,
12   * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13   * See the License for the specific language governing permissions and
14   * limitations under the License.
15   *
16   * Copyright (c) 2017 The OWASP Foundation. All Rights Reserved.
17   */
18  package org.owasp.dependencycheck;
19  
20  import org.apache.commons.cli.ParseException;
21  import org.apache.commons.cli.UnrecognizedOptionException;
22  import org.junit.jupiter.api.Test;
23  import org.owasp.dependencycheck.utils.InvalidSettingException;
24  import org.owasp.dependencycheck.utils.Settings;
25  import org.owasp.dependencycheck.utils.Settings.KEYS;
26  
27  import java.io.File;
28  import java.io.FileNotFoundException;
29  import java.util.HashMap;
30  import java.util.Map;
31  
32  import static org.hamcrest.MatcherAssert.assertThat;
33  import static org.hamcrest.core.Is.is;
34  import static org.junit.jupiter.api.Assertions.assertFalse;
35  import static org.junit.jupiter.api.Assertions.assertThrows;
36  import static org.junit.jupiter.api.Assertions.assertTrue;
37  
38  /**
39   * Tests for the {@link AppTest} class.
40   */
41  class AppTest extends BaseTest {
42  
43      /**
44       * Test of ensureCanonicalPath method, of class App.
45       */
46      @Test
47      void testEnsureCanonicalPath() {
48          String file = "../*.jar";
49          App instance = new App(getSettings());
50          String result = instance.ensureCanonicalPath(file);
51          assertFalse(result.contains(".."));
52          assertTrue(result.endsWith("*.jar"));
53  
54          file = "../some/skip/../path/file.txt";
55          String expResult = "/some/path/file.txt";
56          result = instance.ensureCanonicalPath(file);
57          assertTrue(result.endsWith(expResult), "result=" + result);
58      }
59  
60      /**
61       * Assert that properties can be set on the CLI and parsed into the
62       * {@link Settings}.
63       *
64       * @throws Exception the unexpected {@link Exception}.
65       */
66      @Test
67      void testPopulateSettings() throws Exception {
68          File prop = new File(this.getClass().getClassLoader().getResource("sample.properties").toURI().getPath());
69          String[] args = {"-P", prop.getAbsolutePath()};
70          Map<String, Boolean> expected = new HashMap<>();
71          expected.put(Settings.KEYS.AUTO_UPDATE, Boolean.FALSE);
72          expected.put(Settings.KEYS.ANALYZER_ARCHIVE_ENABLED, Boolean.TRUE);
73  
74          assertTrue(testBooleanProperties(args, expected));
75  
76          String[] args2 = {"-n"};
77          expected.put(Settings.KEYS.AUTO_UPDATE, Boolean.FALSE);
78          expected.put(Settings.KEYS.ANALYZER_ARCHIVE_ENABLED, Boolean.TRUE);
79          assertTrue(testBooleanProperties(args2, expected));
80  
81          String[] args3 = {"-h"};
82          expected.put(Settings.KEYS.AUTO_UPDATE, Boolean.TRUE);
83          expected.put(Settings.KEYS.ANALYZER_ARCHIVE_ENABLED, Boolean.TRUE);
84          assertTrue(testBooleanProperties(args3, expected));
85  
86          String[] args4 = {"--disableArchive"};
87          expected.put(Settings.KEYS.AUTO_UPDATE, Boolean.TRUE);
88          expected.put(Settings.KEYS.ANALYZER_ARCHIVE_ENABLED, Boolean.FALSE);
89          assertTrue(testBooleanProperties(args4, expected));
90  
91          String[] args5 = {"-P", prop.getAbsolutePath(), "--disableArchive"};
92          expected.put(Settings.KEYS.AUTO_UPDATE, Boolean.FALSE);
93          expected.put(Settings.KEYS.ANALYZER_ARCHIVE_ENABLED, Boolean.FALSE);
94          assertTrue(testBooleanProperties(args5, expected));
95  
96          prop = new File(this.getClass().getClassLoader().getResource("sample2.properties").toURI().getPath());
97          String[] args6 = {"-P", prop.getAbsolutePath(), "--disableArchive"};
98          expected.put(Settings.KEYS.AUTO_UPDATE, Boolean.TRUE);
99          expected.put(Settings.KEYS.ANALYZER_ARCHIVE_ENABLED, Boolean.FALSE);
100         assertTrue(testBooleanProperties(args6, expected));
101 
102         String[] args7 = {"-P", prop.getAbsolutePath(), "--noupdate"};
103         expected.put(Settings.KEYS.AUTO_UPDATE, Boolean.FALSE);
104         expected.put(Settings.KEYS.ANALYZER_ARCHIVE_ENABLED, Boolean.FALSE);
105         assertTrue(testBooleanProperties(args7, expected));
106 
107         String[] args8 = {"-P", prop.getAbsolutePath(), "--noupdate", "--disableArchive"};
108         expected.put(Settings.KEYS.AUTO_UPDATE, Boolean.FALSE);
109         expected.put(Settings.KEYS.ANALYZER_ARCHIVE_ENABLED, Boolean.FALSE);
110         assertTrue(testBooleanProperties(args8, expected));
111     }
112 
113     /**
114      * Assert that an {@link UnrecognizedOptionException} is thrown when a
115      * property that is not supported is specified on the CLI.
116      *
117      */
118     @Test
119     void testPopulateSettingsException() {
120         String[] args = {"-invalidPROPERTY"};
121         UnrecognizedOptionException exception = assertThrows(UnrecognizedOptionException.class, () -> testBooleanProperties(args, null));
122         assertTrue(exception.getMessage().contains("Unrecognized option: -invalidPROPERTY"));
123     }
124 
125     /**
126      * Assert that a single suppression file can be set using the CLI.
127      *
128      * @throws Exception the unexpected {@link Exception}.
129      */
130     @Test
131     void testPopulatingSuppressionSettingsWithASingleFile() throws Exception {
132         // GIVEN CLI properties with the mandatory arguments
133         File prop = new File(this.getClass().getClassLoader().getResource("sample.properties").toURI().getPath());
134 
135         // AND a single suppression file
136         String[] args = {"-P", prop.getAbsolutePath(), "--suppression", "another-file.xml"};
137 
138         // WHEN parsing the CLI arguments
139         final CliParser cli = new CliParser(getSettings());
140         cli.parse(args);
141         final App classUnderTest = new App(getSettings());
142         classUnderTest.populateSettings(cli);
143 
144         // THEN the suppression file is set in the settings for use in the application core
145         String[] suppressionFiles = getSettings().getArray(KEYS.SUPPRESSION_FILE);
146         assertThat("Expected the suppression file to be set in the Settings", suppressionFiles[0], is("another-file.xml"));
147     }
148 
149     /**
150      * Assert that multiple suppression files can be set using the CLI.
151      *
152      * @throws Exception the unexpected {@link Exception}.
153      */
154     @Test
155     void testPopulatingSuppressionSettingsWithMultipleFiles() throws Exception {
156         // GIVEN CLI properties with the mandatory arguments
157         File prop = new File(this.getClass().getClassLoader().getResource("sample.properties").toURI().getPath());
158 
159         // AND a single suppression file
160         String[] args = {"-P", prop.getAbsolutePath(), "--suppression", "first-file.xml", "--suppression", "another-file.xml"};
161 
162         // WHEN parsing the CLI arguments
163         final CliParser cli = new CliParser(getSettings());
164         cli.parse(args);
165         final App classUnderTest = new App(getSettings());
166         classUnderTest.populateSettings(cli);
167 
168         // THEN the suppression file is set in the settings for use in the application core
169         assertThat("Expected the suppression files to be set in the Settings with a separator", getSettings().getString(KEYS.SUPPRESSION_FILE), is("[\"first-file.xml\",\"another-file.xml\"]"));
170     }
171 
172 
173     private boolean testBooleanProperties(String[] args, Map<String, Boolean> expected) throws FileNotFoundException, ParseException, InvalidSettingException {
174         this.reloadSettings();
175         final CliParser cli = new CliParser(getSettings());
176         cli.parse(args);
177         App instance = new App(getSettings());
178         instance.populateSettings(cli);
179         boolean results = true;
180         for (Map.Entry<String, Boolean> entry : expected.entrySet()) {
181             results &= getSettings().getBoolean(entry.getKey()) == entry.getValue();
182         }
183         return results;
184     }
185 }