test(audit_info): refactor route53 (#3141)

This commit is contained in:
Nacho Rivera
2023-12-05 12:28:12 +01:00
committed by GitHub
parent 828a6f4696
commit 6ff864fc04
6 changed files with 82 additions and 173 deletions

View File

@@ -1,15 +1,14 @@
from unittest.mock import patch
import botocore
from boto3 import client, session
from boto3 import client
from moto import mock_logs, mock_route53
from prowler.providers.aws.lib.audit_info.audit_info import AWS_Audit_Info
from prowler.providers.aws.services.route53.route53_service import Route53
from prowler.providers.common.models import Audit_Metadata
# Mock Test Region
AWS_REGION = "us-east-1"
from tests.providers.aws.audit_info_utils import (
AWS_REGION_US_EAST_1,
set_mocked_aws_audit_info,
)
# Mocking Access Analyzer Calls
make_api_call = botocore.client.BaseClient._make_api_call
@@ -35,60 +34,30 @@ def mock_make_api_call(self, operation_name, kwarg):
# Patch every AWS call using Boto3 and generate_regional_clients to have 1 client
@patch("botocore.client.BaseClient._make_api_call", new=mock_make_api_call)
class Test_Route53_Service:
# Mocked Audit Info
def set_mocked_audit_info(self):
audit_info = AWS_Audit_Info(
session_config=None,
original_session=None,
audit_session=session.Session(
profile_name=None,
botocore_session=None,
),
audited_account=None,
audited_account_arn=None,
audited_user_id=None,
audited_partition="aws",
audited_identity_arn=None,
profile=None,
profile_region=AWS_REGION,
credentials=None,
assumed_role_info=None,
audited_regions=None,
organizations_metadata=None,
audit_resources=None,
mfa_enabled=False,
audit_metadata=Audit_Metadata(
services_scanned=0,
expected_checks=[],
completed_checks=0,
audit_progress=0,
),
)
return audit_info
# Test Route53 Client
@mock_route53
def test__get_client__(self):
route53 = Route53(self.set_mocked_audit_info())
route53 = Route53(set_mocked_aws_audit_info([AWS_REGION_US_EAST_1]))
assert route53.client.__class__.__name__ == "Route53"
# Test Route53 Session
@mock_route53
def test__get_session__(self):
route53 = Route53(self.set_mocked_audit_info())
route53 = Route53(set_mocked_aws_audit_info([AWS_REGION_US_EAST_1]))
assert route53.session.__class__.__name__ == "Session"
# Test Route53 Service
@mock_route53
def test__get_service__(self):
route53 = Route53(self.set_mocked_audit_info())
route53 = Route53(set_mocked_aws_audit_info([AWS_REGION_US_EAST_1]))
assert route53.service == "route53"
@mock_route53
@mock_logs
def test__list_hosted_zones__private_with_logging(self):
# Create Hosted Zone
r53_client = client("route53", region_name=AWS_REGION)
r53_client = client("route53", region_name=AWS_REGION_US_EAST_1)
hosted_zone_name = "testdns.aws.com."
response = r53_client.create_hosted_zone(
Name=hosted_zone_name,
@@ -98,7 +67,7 @@ class Test_Route53_Service:
hosted_zone_id = response["HostedZone"]["Id"].replace("/hostedzone/", "")
hosted_zone_name = response["HostedZone"]["Name"]
# CloudWatch Client
logs_client = client("logs", region_name=AWS_REGION)
logs_client = client("logs", region_name=AWS_REGION_US_EAST_1)
log_group_name = "test-log-group"
_ = logs_client.create_log_group(logGroupName=log_group_name)
log_group_arn = logs_client.describe_log_groups()["logGroups"][0]["arn"]
@@ -109,7 +78,7 @@ class Test_Route53_Service:
)
# Set partition for the service
route53 = Route53(self.set_mocked_audit_info())
route53 = Route53(set_mocked_aws_audit_info([AWS_REGION_US_EAST_1]))
assert len(route53.hosted_zones) == 1
assert route53.hosted_zones[hosted_zone_id]
assert route53.hosted_zones[hosted_zone_id].id == hosted_zone_id
@@ -124,7 +93,7 @@ class Test_Route53_Service:
route53.hosted_zones[hosted_zone_id].logging_config.cloudwatch_log_group_arn
== log_group_arn
)
assert route53.hosted_zones[hosted_zone_id].region == AWS_REGION
assert route53.hosted_zones[hosted_zone_id].region == AWS_REGION_US_EAST_1
assert route53.hosted_zones[hosted_zone_id].tags == [
{"Key": "test", "Value": "test"},
]
@@ -133,7 +102,7 @@ class Test_Route53_Service:
@mock_logs
def test__list_hosted_zones__public_with_logging(self):
# Create Hosted Zone
r53_client = client("route53", region_name=AWS_REGION)
r53_client = client("route53", region_name=AWS_REGION_US_EAST_1)
hosted_zone_name = "testdns.aws.com."
response = r53_client.create_hosted_zone(
Name=hosted_zone_name,
@@ -143,7 +112,7 @@ class Test_Route53_Service:
hosted_zone_id = response["HostedZone"]["Id"].replace("/hostedzone/", "")
hosted_zone_name = response["HostedZone"]["Name"]
# CloudWatch Client
logs_client = client("logs", region_name=AWS_REGION)
logs_client = client("logs", region_name=AWS_REGION_US_EAST_1)
log_group_name = "test-log-group"
_ = logs_client.create_log_group(logGroupName=log_group_name)
log_group_arn = logs_client.describe_log_groups()["logGroups"][0]["arn"]
@@ -154,7 +123,7 @@ class Test_Route53_Service:
)
# Set partition for the service
route53 = Route53(self.set_mocked_audit_info())
route53 = Route53(set_mocked_aws_audit_info([AWS_REGION_US_EAST_1]))
assert len(route53.hosted_zones) == 1
assert route53.hosted_zones[hosted_zone_id]
assert route53.hosted_zones[hosted_zone_id].id == hosted_zone_id
@@ -169,13 +138,13 @@ class Test_Route53_Service:
route53.hosted_zones[hosted_zone_id].logging_config.cloudwatch_log_group_arn
== log_group_arn
)
assert route53.hosted_zones[hosted_zone_id].region == AWS_REGION
assert route53.hosted_zones[hosted_zone_id].region == AWS_REGION_US_EAST_1
@mock_route53
@mock_logs
def test__list_hosted_zones__private_without_logging(self):
# Create Hosted Zone
r53_client = client("route53", region_name=AWS_REGION)
r53_client = client("route53", region_name=AWS_REGION_US_EAST_1)
hosted_zone_name = "testdns.aws.com."
response = r53_client.create_hosted_zone(
Name=hosted_zone_name,
@@ -186,7 +155,7 @@ class Test_Route53_Service:
hosted_zone_name = response["HostedZone"]["Name"]
# Set partition for the service
route53 = Route53(self.set_mocked_audit_info())
route53 = Route53(set_mocked_aws_audit_info([AWS_REGION_US_EAST_1]))
assert len(route53.hosted_zones) == 1
assert route53.hosted_zones[hosted_zone_id]
assert route53.hosted_zones[hosted_zone_id].id == hosted_zone_id
@@ -197,13 +166,13 @@ class Test_Route53_Service:
assert route53.hosted_zones[hosted_zone_id].name == hosted_zone_name
assert route53.hosted_zones[hosted_zone_id].private_zone
assert not route53.hosted_zones[hosted_zone_id].logging_config
assert route53.hosted_zones[hosted_zone_id].region == AWS_REGION
assert route53.hosted_zones[hosted_zone_id].region == AWS_REGION_US_EAST_1
@mock_route53
@mock_logs
def test__list_hosted_zones__public_without_logging(self):
# Create Hosted Zone
r53_client = client("route53", region_name=AWS_REGION)
r53_client = client("route53", region_name=AWS_REGION_US_EAST_1)
hosted_zone_name = "testdns.aws.com."
response = r53_client.create_hosted_zone(
Name=hosted_zone_name,
@@ -214,7 +183,7 @@ class Test_Route53_Service:
hosted_zone_name = response["HostedZone"]["Name"]
# Set partition for the service
route53 = Route53(self.set_mocked_audit_info())
route53 = Route53(set_mocked_aws_audit_info([AWS_REGION_US_EAST_1]))
assert len(route53.hosted_zones) == 1
assert route53.hosted_zones[hosted_zone_id]
assert route53.hosted_zones[hosted_zone_id].id == hosted_zone_id
@@ -226,12 +195,12 @@ class Test_Route53_Service:
assert not route53.hosted_zones[hosted_zone_id].private_zone
assert not route53.hosted_zones[hosted_zone_id].logging_config
assert route53.hosted_zones[hosted_zone_id].region == AWS_REGION
assert route53.hosted_zones[hosted_zone_id].region == AWS_REGION_US_EAST_1
@mock_route53
def test__list_resource_record_sets__(self):
# Create Hosted Zone
r53_client = client("route53", region_name=AWS_REGION)
r53_client = client("route53", region_name=AWS_REGION_US_EAST_1)
zone = r53_client.create_hosted_zone(
Name="testdns.aws.com", CallerReference=str(hash("foo"))
)
@@ -254,7 +223,7 @@ class Test_Route53_Service:
)
# Set partition for the service
route53 = Route53(self.set_mocked_audit_info())
route53 = Route53(set_mocked_aws_audit_info([AWS_REGION_US_EAST_1]))
assert (
len(route53.record_sets) == 3
) # Default NS and SOA records plus the A record just created
@@ -265,4 +234,4 @@ class Test_Route53_Service:
assert not set.is_alias
assert set.records == ["1.2.3.4"]
assert set.hosted_zone_id == zone_id.replace("/hostedzone/", "")
assert set.region == AWS_REGION
assert set.region == AWS_REGION_US_EAST_1