mirror of
https://github.com/prowler-cloud/prowler.git
synced 2026-10-09 21:14:22 +00:00
feat(exceptions): modify custom exceptions (#5451)
This commit is contained in:
@@ -28,8 +28,8 @@ from prowler.providers.aws.config import (
|
||||
)
|
||||
from prowler.providers.aws.exceptions.exceptions import (
|
||||
AWSArgumentTypeValidationError,
|
||||
AWSIAMRoleARNInvalidResourceType,
|
||||
AWSInvalidAccountCredentials,
|
||||
AWSIAMRoleARNInvalidResourceTypeError,
|
||||
AWSInvalidProviderIdError,
|
||||
AWSNoCredentialsError,
|
||||
)
|
||||
from prowler.providers.aws.lib.arn.models import ARN
|
||||
@@ -1265,7 +1265,7 @@ aws:
|
||||
) # No profile to avoid ProfileNotFound error
|
||||
|
||||
assert exception.type == AWSNoCredentialsError
|
||||
assert "AWSNoCredentialsError[1904]: No AWS credentials found" in str(
|
||||
assert "AWSNoCredentialsError[1002]: No AWS credentials found" in str(
|
||||
exception.value
|
||||
)
|
||||
|
||||
@@ -1307,7 +1307,7 @@ aws:
|
||||
assert exception.type == AWSArgumentTypeValidationError
|
||||
assert (
|
||||
exception.value.args[0]
|
||||
== "[1905] Session Duration must be between 900 and 43200 seconds."
|
||||
== "[1003] Session Duration must be between 900 and 43200 seconds."
|
||||
)
|
||||
|
||||
@mock_aws
|
||||
@@ -1327,7 +1327,7 @@ aws:
|
||||
assert isinstance(connection.error, AWSArgumentTypeValidationError)
|
||||
assert (
|
||||
connection.error.args[0]
|
||||
== "[1905] Session Duration must be between 900 and 43200 seconds."
|
||||
== "[1003] Session Duration must be between 900 and 43200 seconds."
|
||||
)
|
||||
|
||||
@mock_aws
|
||||
@@ -1343,7 +1343,7 @@ aws:
|
||||
assert exception.type == AWSArgumentTypeValidationError
|
||||
assert (
|
||||
exception.value.args[0]
|
||||
== "[1905] Role Session Name must be between 2 and 64 characters and may contain alphanumeric characters, periods, hyphens, and underscores."
|
||||
== "[1003] Role Session Name must be between 2 and 64 characters and may contain alphanumeric characters, periods, hyphens, and underscores."
|
||||
)
|
||||
|
||||
@mock_aws
|
||||
@@ -1351,13 +1351,13 @@ aws:
|
||||
role_name = "test-role"
|
||||
role_arn = f"arn:{AWS_COMMERCIAL_PARTITION}:iam::{AWS_ACCOUNT_NUMBER}:not-role/{role_name}"
|
||||
|
||||
with raises(AWSIAMRoleARNInvalidResourceType) as exception:
|
||||
with raises(AWSIAMRoleARNInvalidResourceTypeError) as exception:
|
||||
AwsProvider.test_connection(role_arn=role_arn)
|
||||
|
||||
assert exception.type == AWSIAMRoleARNInvalidResourceType
|
||||
assert exception.type == AWSIAMRoleARNInvalidResourceTypeError
|
||||
assert (
|
||||
exception.value.args[0]
|
||||
== "[1912] AWS IAM Role ARN resource type is invalid"
|
||||
== "[1010] AWS IAM Role ARN resource type is invalid"
|
||||
)
|
||||
|
||||
@mock_aws
|
||||
@@ -1429,13 +1429,13 @@ aws:
|
||||
"provider_id": "111122223333",
|
||||
}
|
||||
|
||||
with raises(AWSInvalidAccountCredentials) as exception:
|
||||
with raises(AWSInvalidProviderIdError) as exception:
|
||||
AwsProvider.test_connection(**session_credentials)
|
||||
|
||||
assert exception.type == AWSInvalidAccountCredentials
|
||||
assert exception.type == AWSInvalidProviderIdError
|
||||
assert (
|
||||
exception.value.args[0]
|
||||
== "[1917] The provided AWS credentials belong to a different account"
|
||||
== "[1015] The provided AWS credentials belong to a different account"
|
||||
)
|
||||
|
||||
@mock_aws
|
||||
@@ -1456,12 +1456,12 @@ aws:
|
||||
|
||||
assert isinstance(connection, Connection)
|
||||
assert not connection.is_connected
|
||||
assert isinstance(connection.error, AWSInvalidAccountCredentials)
|
||||
assert isinstance(connection.error, AWSInvalidProviderIdError)
|
||||
assert (
|
||||
connection.error.message
|
||||
== "The provided AWS credentials belong to a different account"
|
||||
)
|
||||
assert connection.error.code == 1917
|
||||
assert connection.error.code == 1015
|
||||
|
||||
@mock_aws
|
||||
def test_create_sts_session(self):
|
||||
|
||||
@@ -1,13 +1,13 @@
|
||||
from pytest import raises
|
||||
|
||||
from prowler.providers.aws.exceptions.exceptions import (
|
||||
AWSIAMRoleARNEmptyResource,
|
||||
AWSIAMRoleARNInvalidAccountID,
|
||||
AWSIAMRoleARNInvalidResourceType,
|
||||
AWSIAMRoleARNMissingFields,
|
||||
AWSIAMRoleARNPartitionEmpty,
|
||||
AWSIAMRoleARNRegionNotEmtpy,
|
||||
AWSIAMRoleARNServiceNotIAMnorSTS,
|
||||
AWSIAMRoleARNEmptyResourceError,
|
||||
AWSIAMRoleARNInvalidAccountIDError,
|
||||
AWSIAMRoleARNInvalidResourceTypeError,
|
||||
AWSIAMRoleARNMissingFieldsError,
|
||||
AWSIAMRoleARNPartitionEmptyError,
|
||||
AWSIAMRoleARNRegionNotEmtpyError,
|
||||
AWSIAMRoleARNServiceNotIAMnorSTSError,
|
||||
)
|
||||
from prowler.providers.aws.lib.arn.arn import is_valid_arn, parse_iam_credentials_arn
|
||||
from prowler.providers.aws.lib.arn.models import ARN
|
||||
@@ -327,54 +327,54 @@ class Test_ARN_Parsing:
|
||||
self,
|
||||
):
|
||||
input_arn = ""
|
||||
with raises(AWSIAMRoleARNMissingFields) as error:
|
||||
with raises(AWSIAMRoleARNMissingFieldsError) as error:
|
||||
parse_iam_credentials_arn(input_arn)
|
||||
|
||||
assert error._excinfo[0] == AWSIAMRoleARNMissingFields
|
||||
assert error._excinfo[0] == AWSIAMRoleARNMissingFieldsError
|
||||
|
||||
def test_iam_credentials_arn_parsing_raising_AWSIAMRoleARNRegionNotEmtpy(self):
|
||||
input_arn = "arn:aws:iam:eu-west-1:111111111111:user/prowler"
|
||||
with raises(AWSIAMRoleARNRegionNotEmtpy) as error:
|
||||
with raises(AWSIAMRoleARNRegionNotEmtpyError) as error:
|
||||
parse_iam_credentials_arn(input_arn)
|
||||
|
||||
assert error._excinfo[0] == AWSIAMRoleARNRegionNotEmtpy
|
||||
assert error._excinfo[0] == AWSIAMRoleARNRegionNotEmtpyError
|
||||
|
||||
def test_iam_credentials_arn_parsing_raising_AWSIAMRoleARNPartitionEmpty(self):
|
||||
input_arn = "arn::iam::111111111111:user/prowler"
|
||||
with raises(AWSIAMRoleARNPartitionEmpty) as error:
|
||||
with raises(AWSIAMRoleARNPartitionEmptyError) as error:
|
||||
parse_iam_credentials_arn(input_arn)
|
||||
|
||||
assert error._excinfo[0] == AWSIAMRoleARNPartitionEmpty
|
||||
assert error._excinfo[0] == AWSIAMRoleARNPartitionEmptyError
|
||||
|
||||
def test_iam_credentials_arn_parsing_raising_AWSIAMRoleARNServiceNotIAMnorSTS(self):
|
||||
input_arn = "arn:aws:s3::111111111111:user/prowler"
|
||||
with raises(AWSIAMRoleARNServiceNotIAMnorSTS) as error:
|
||||
with raises(AWSIAMRoleARNServiceNotIAMnorSTSError) as error:
|
||||
parse_iam_credentials_arn(input_arn)
|
||||
|
||||
assert error._excinfo[0] == AWSIAMRoleARNServiceNotIAMnorSTS
|
||||
assert error._excinfo[0] == AWSIAMRoleARNServiceNotIAMnorSTSError
|
||||
|
||||
def test_iam_credentials_arn_parsing_raising_AWSIAMRoleARNInvalidAccountID(self):
|
||||
input_arn = "arn:aws:iam::AWS_ACCOUNT_ID:user/prowler"
|
||||
with raises(AWSIAMRoleARNInvalidAccountID) as error:
|
||||
with raises(AWSIAMRoleARNInvalidAccountIDError) as error:
|
||||
parse_iam_credentials_arn(input_arn)
|
||||
|
||||
assert error._excinfo[0] == AWSIAMRoleARNInvalidAccountID
|
||||
assert error._excinfo[0] == AWSIAMRoleARNInvalidAccountIDError
|
||||
|
||||
def test_iam_credentials_arn_parsing_raising_AWSIAMRoleARNInvalidResourceType(
|
||||
self,
|
||||
):
|
||||
input_arn = "arn:aws:iam::111111111111:account/prowler"
|
||||
with raises(AWSIAMRoleARNInvalidResourceType) as error:
|
||||
with raises(AWSIAMRoleARNInvalidResourceTypeError) as error:
|
||||
parse_iam_credentials_arn(input_arn)
|
||||
|
||||
assert error._excinfo[0] == AWSIAMRoleARNInvalidResourceType
|
||||
assert error._excinfo[0] == AWSIAMRoleARNInvalidResourceTypeError
|
||||
|
||||
def test_iam_credentials_arn_parsing_raising_AWSIAMRoleARNEmptyResource(self):
|
||||
input_arn = "arn:aws:iam::111111111111:role/"
|
||||
with raises(AWSIAMRoleARNEmptyResource) as error:
|
||||
with raises(AWSIAMRoleARNEmptyResourceError) as error:
|
||||
parse_iam_credentials_arn(input_arn)
|
||||
|
||||
assert error._excinfo[0] == AWSIAMRoleARNEmptyResource
|
||||
assert error._excinfo[0] == AWSIAMRoleARNEmptyResourceError
|
||||
|
||||
def test_is_valid_arn(self):
|
||||
assert is_valid_arn("arn:aws:iam::012345678910:user/test")
|
||||
|
||||
@@ -15,7 +15,7 @@ from prowler.providers.azure.azure_provider import AzureProvider
|
||||
from prowler.providers.azure.exceptions.exceptions import (
|
||||
AzureBrowserAuthNoTenantIDError,
|
||||
AzureHTTPResponseError,
|
||||
AzureInvalidAccountCredentialsError,
|
||||
AzureInvalidProviderIdError,
|
||||
AzureNoAuthenticationMethodError,
|
||||
AzureTenantIDNoBrowserAuthError,
|
||||
)
|
||||
@@ -158,7 +158,7 @@ class TestAzureProvider:
|
||||
assert exception.type == AzureBrowserAuthNoTenantIDError
|
||||
assert (
|
||||
exception.value.args[0]
|
||||
== "[1918] Azure Tenant ID (--tenant-id) is required for browser authentication mode"
|
||||
== "[2004] Azure Tenant ID (--tenant-id) is required for browser authentication mode"
|
||||
)
|
||||
|
||||
def test_azure_provider_not_browser_auth_but_tenant_id(self):
|
||||
@@ -197,7 +197,7 @@ class TestAzureProvider:
|
||||
assert exception.type == AzureTenantIDNoBrowserAuthError
|
||||
assert (
|
||||
exception.value.args[0]
|
||||
== "[1919] Azure Tenant ID (--tenant-id) is required for browser authentication mode"
|
||||
== "[2005] Azure Tenant ID (--tenant-id) is required for browser authentication mode"
|
||||
)
|
||||
|
||||
def test_test_connection_browser_auth(self):
|
||||
@@ -370,9 +370,7 @@ class TestAzureProvider:
|
||||
)
|
||||
|
||||
assert test_connection.error is not None
|
||||
assert isinstance(
|
||||
test_connection.error, AzureInvalidAccountCredentialsError
|
||||
)
|
||||
assert isinstance(test_connection.error, AzureInvalidProviderIdError)
|
||||
assert (
|
||||
"The provided credentials are not valid for the specified Azure subscription."
|
||||
in test_connection.error.args[0]
|
||||
@@ -390,7 +388,7 @@ class TestAzureProvider:
|
||||
assert exception.type == AzureHTTPResponseError
|
||||
assert (
|
||||
exception.value.args[0]
|
||||
== f"[1924] Error in HTTP response from Azure - Authentication failed: Unable to get authority configuration for https://login.microsoftonline.com/{tenant_id}. Authority would typically be in a format of https://login.microsoftonline.com/your_tenant or https://tenant_name.ciamlogin.com or https://tenant_name.b2clogin.com/tenant.onmicrosoft.com/policy. Also please double check your tenant name or GUID is correct."
|
||||
== f"[2010] Error in HTTP response from Azure - Authentication failed: Unable to get authority configuration for https://login.microsoftonline.com/{tenant_id}. Authority would typically be in a format of https://login.microsoftonline.com/your_tenant or https://tenant_name.ciamlogin.com or https://tenant_name.b2clogin.com/tenant.onmicrosoft.com/policy. Also please double check your tenant name or GUID is correct."
|
||||
)
|
||||
|
||||
def test_test_connection_without_any_method(self):
|
||||
@@ -399,7 +397,7 @@ class TestAzureProvider:
|
||||
|
||||
assert exception.type == AzureNoAuthenticationMethodError
|
||||
assert (
|
||||
"[1917] Azure provider requires at least one authentication method set: [--az-cli-auth | --sp-env-auth | --browser-auth | --managed-identity-auth]"
|
||||
"[2003] Azure provider requires at least one authentication method set: [--az-cli-auth | --sp-env-auth | --browser-auth | --managed-identity-auth]"
|
||||
in exception.value.args[0]
|
||||
)
|
||||
|
||||
@@ -424,7 +422,7 @@ class TestAzureProvider:
|
||||
assert exception.type == AzureHTTPResponseError
|
||||
assert (
|
||||
exception.value.args[0]
|
||||
== "[1924] Error in HTTP response from Azure - Simulated HttpResponseError"
|
||||
== "[2010] Error in HTTP response from Azure - Simulated HttpResponseError"
|
||||
)
|
||||
|
||||
def test_test_connection_with_exception(self):
|
||||
|
||||
@@ -13,7 +13,7 @@ from prowler.config.config import (
|
||||
)
|
||||
from prowler.providers.common.models import Connection
|
||||
from prowler.providers.gcp.exceptions.exceptions import (
|
||||
GCPInvalidAccountCredentials,
|
||||
GCPInvalidProviderIdError,
|
||||
GCPTestConnectionError,
|
||||
)
|
||||
from prowler.providers.gcp.gcp_provider import GcpProvider
|
||||
@@ -593,7 +593,7 @@ class TestGCPProvider:
|
||||
"prowler.providers.gcp.gcp_provider.GcpProvider.validate_project_id"
|
||||
) as mock_validate_project_id:
|
||||
|
||||
mock_validate_project_id.side_effect = GCPInvalidAccountCredentials(
|
||||
mock_validate_project_id.side_effect = GCPInvalidProviderIdError(
|
||||
"Invalid project ID"
|
||||
)
|
||||
|
||||
@@ -605,4 +605,4 @@ class TestGCPProvider:
|
||||
provider_id="test-invalid-project",
|
||||
)
|
||||
|
||||
assert e.type == GCPInvalidAccountCredentials
|
||||
assert e.type == GCPInvalidProviderIdError
|
||||
|
||||
Reference in New Issue
Block a user