feat(exceptions): modify custom exceptions (#5451)

This commit is contained in:
Pedro Martín
2024-10-18 09:28:58 +02:00
committed by GitHub
parent 98cb954f74
commit e65b346afd
14 changed files with 342 additions and 269 deletions
+14 -14
View File
@@ -28,8 +28,8 @@ from prowler.providers.aws.config import (
)
from prowler.providers.aws.exceptions.exceptions import (
AWSArgumentTypeValidationError,
AWSIAMRoleARNInvalidResourceType,
AWSInvalidAccountCredentials,
AWSIAMRoleARNInvalidResourceTypeError,
AWSInvalidProviderIdError,
AWSNoCredentialsError,
)
from prowler.providers.aws.lib.arn.models import ARN
@@ -1265,7 +1265,7 @@ aws:
) # No profile to avoid ProfileNotFound error
assert exception.type == AWSNoCredentialsError
assert "AWSNoCredentialsError[1904]: No AWS credentials found" in str(
assert "AWSNoCredentialsError[1002]: No AWS credentials found" in str(
exception.value
)
@@ -1307,7 +1307,7 @@ aws:
assert exception.type == AWSArgumentTypeValidationError
assert (
exception.value.args[0]
== "[1905] Session Duration must be between 900 and 43200 seconds."
== "[1003] Session Duration must be between 900 and 43200 seconds."
)
@mock_aws
@@ -1327,7 +1327,7 @@ aws:
assert isinstance(connection.error, AWSArgumentTypeValidationError)
assert (
connection.error.args[0]
== "[1905] Session Duration must be between 900 and 43200 seconds."
== "[1003] Session Duration must be between 900 and 43200 seconds."
)
@mock_aws
@@ -1343,7 +1343,7 @@ aws:
assert exception.type == AWSArgumentTypeValidationError
assert (
exception.value.args[0]
== "[1905] Role Session Name must be between 2 and 64 characters and may contain alphanumeric characters, periods, hyphens, and underscores."
== "[1003] Role Session Name must be between 2 and 64 characters and may contain alphanumeric characters, periods, hyphens, and underscores."
)
@mock_aws
@@ -1351,13 +1351,13 @@ aws:
role_name = "test-role"
role_arn = f"arn:{AWS_COMMERCIAL_PARTITION}:iam::{AWS_ACCOUNT_NUMBER}:not-role/{role_name}"
with raises(AWSIAMRoleARNInvalidResourceType) as exception:
with raises(AWSIAMRoleARNInvalidResourceTypeError) as exception:
AwsProvider.test_connection(role_arn=role_arn)
assert exception.type == AWSIAMRoleARNInvalidResourceType
assert exception.type == AWSIAMRoleARNInvalidResourceTypeError
assert (
exception.value.args[0]
== "[1912] AWS IAM Role ARN resource type is invalid"
== "[1010] AWS IAM Role ARN resource type is invalid"
)
@mock_aws
@@ -1429,13 +1429,13 @@ aws:
"provider_id": "111122223333",
}
with raises(AWSInvalidAccountCredentials) as exception:
with raises(AWSInvalidProviderIdError) as exception:
AwsProvider.test_connection(**session_credentials)
assert exception.type == AWSInvalidAccountCredentials
assert exception.type == AWSInvalidProviderIdError
assert (
exception.value.args[0]
== "[1917] The provided AWS credentials belong to a different account"
== "[1015] The provided AWS credentials belong to a different account"
)
@mock_aws
@@ -1456,12 +1456,12 @@ aws:
assert isinstance(connection, Connection)
assert not connection.is_connected
assert isinstance(connection.error, AWSInvalidAccountCredentials)
assert isinstance(connection.error, AWSInvalidProviderIdError)
assert (
connection.error.message
== "The provided AWS credentials belong to a different account"
)
assert connection.error.code == 1917
assert connection.error.code == 1015
@mock_aws
def test_create_sts_session(self):
+21 -21
View File
@@ -1,13 +1,13 @@
from pytest import raises
from prowler.providers.aws.exceptions.exceptions import (
AWSIAMRoleARNEmptyResource,
AWSIAMRoleARNInvalidAccountID,
AWSIAMRoleARNInvalidResourceType,
AWSIAMRoleARNMissingFields,
AWSIAMRoleARNPartitionEmpty,
AWSIAMRoleARNRegionNotEmtpy,
AWSIAMRoleARNServiceNotIAMnorSTS,
AWSIAMRoleARNEmptyResourceError,
AWSIAMRoleARNInvalidAccountIDError,
AWSIAMRoleARNInvalidResourceTypeError,
AWSIAMRoleARNMissingFieldsError,
AWSIAMRoleARNPartitionEmptyError,
AWSIAMRoleARNRegionNotEmtpyError,
AWSIAMRoleARNServiceNotIAMnorSTSError,
)
from prowler.providers.aws.lib.arn.arn import is_valid_arn, parse_iam_credentials_arn
from prowler.providers.aws.lib.arn.models import ARN
@@ -327,54 +327,54 @@ class Test_ARN_Parsing:
self,
):
input_arn = ""
with raises(AWSIAMRoleARNMissingFields) as error:
with raises(AWSIAMRoleARNMissingFieldsError) as error:
parse_iam_credentials_arn(input_arn)
assert error._excinfo[0] == AWSIAMRoleARNMissingFields
assert error._excinfo[0] == AWSIAMRoleARNMissingFieldsError
def test_iam_credentials_arn_parsing_raising_AWSIAMRoleARNRegionNotEmtpy(self):
input_arn = "arn:aws:iam:eu-west-1:111111111111:user/prowler"
with raises(AWSIAMRoleARNRegionNotEmtpy) as error:
with raises(AWSIAMRoleARNRegionNotEmtpyError) as error:
parse_iam_credentials_arn(input_arn)
assert error._excinfo[0] == AWSIAMRoleARNRegionNotEmtpy
assert error._excinfo[0] == AWSIAMRoleARNRegionNotEmtpyError
def test_iam_credentials_arn_parsing_raising_AWSIAMRoleARNPartitionEmpty(self):
input_arn = "arn::iam::111111111111:user/prowler"
with raises(AWSIAMRoleARNPartitionEmpty) as error:
with raises(AWSIAMRoleARNPartitionEmptyError) as error:
parse_iam_credentials_arn(input_arn)
assert error._excinfo[0] == AWSIAMRoleARNPartitionEmpty
assert error._excinfo[0] == AWSIAMRoleARNPartitionEmptyError
def test_iam_credentials_arn_parsing_raising_AWSIAMRoleARNServiceNotIAMnorSTS(self):
input_arn = "arn:aws:s3::111111111111:user/prowler"
with raises(AWSIAMRoleARNServiceNotIAMnorSTS) as error:
with raises(AWSIAMRoleARNServiceNotIAMnorSTSError) as error:
parse_iam_credentials_arn(input_arn)
assert error._excinfo[0] == AWSIAMRoleARNServiceNotIAMnorSTS
assert error._excinfo[0] == AWSIAMRoleARNServiceNotIAMnorSTSError
def test_iam_credentials_arn_parsing_raising_AWSIAMRoleARNInvalidAccountID(self):
input_arn = "arn:aws:iam::AWS_ACCOUNT_ID:user/prowler"
with raises(AWSIAMRoleARNInvalidAccountID) as error:
with raises(AWSIAMRoleARNInvalidAccountIDError) as error:
parse_iam_credentials_arn(input_arn)
assert error._excinfo[0] == AWSIAMRoleARNInvalidAccountID
assert error._excinfo[0] == AWSIAMRoleARNInvalidAccountIDError
def test_iam_credentials_arn_parsing_raising_AWSIAMRoleARNInvalidResourceType(
self,
):
input_arn = "arn:aws:iam::111111111111:account/prowler"
with raises(AWSIAMRoleARNInvalidResourceType) as error:
with raises(AWSIAMRoleARNInvalidResourceTypeError) as error:
parse_iam_credentials_arn(input_arn)
assert error._excinfo[0] == AWSIAMRoleARNInvalidResourceType
assert error._excinfo[0] == AWSIAMRoleARNInvalidResourceTypeError
def test_iam_credentials_arn_parsing_raising_AWSIAMRoleARNEmptyResource(self):
input_arn = "arn:aws:iam::111111111111:role/"
with raises(AWSIAMRoleARNEmptyResource) as error:
with raises(AWSIAMRoleARNEmptyResourceError) as error:
parse_iam_credentials_arn(input_arn)
assert error._excinfo[0] == AWSIAMRoleARNEmptyResource
assert error._excinfo[0] == AWSIAMRoleARNEmptyResourceError
def test_is_valid_arn(self):
assert is_valid_arn("arn:aws:iam::012345678910:user/test")
+7 -9
View File
@@ -15,7 +15,7 @@ from prowler.providers.azure.azure_provider import AzureProvider
from prowler.providers.azure.exceptions.exceptions import (
AzureBrowserAuthNoTenantIDError,
AzureHTTPResponseError,
AzureInvalidAccountCredentialsError,
AzureInvalidProviderIdError,
AzureNoAuthenticationMethodError,
AzureTenantIDNoBrowserAuthError,
)
@@ -158,7 +158,7 @@ class TestAzureProvider:
assert exception.type == AzureBrowserAuthNoTenantIDError
assert (
exception.value.args[0]
== "[1918] Azure Tenant ID (--tenant-id) is required for browser authentication mode"
== "[2004] Azure Tenant ID (--tenant-id) is required for browser authentication mode"
)
def test_azure_provider_not_browser_auth_but_tenant_id(self):
@@ -197,7 +197,7 @@ class TestAzureProvider:
assert exception.type == AzureTenantIDNoBrowserAuthError
assert (
exception.value.args[0]
== "[1919] Azure Tenant ID (--tenant-id) is required for browser authentication mode"
== "[2005] Azure Tenant ID (--tenant-id) is required for browser authentication mode"
)
def test_test_connection_browser_auth(self):
@@ -370,9 +370,7 @@ class TestAzureProvider:
)
assert test_connection.error is not None
assert isinstance(
test_connection.error, AzureInvalidAccountCredentialsError
)
assert isinstance(test_connection.error, AzureInvalidProviderIdError)
assert (
"The provided credentials are not valid for the specified Azure subscription."
in test_connection.error.args[0]
@@ -390,7 +388,7 @@ class TestAzureProvider:
assert exception.type == AzureHTTPResponseError
assert (
exception.value.args[0]
== f"[1924] Error in HTTP response from Azure - Authentication failed: Unable to get authority configuration for https://login.microsoftonline.com/{tenant_id}. Authority would typically be in a format of https://login.microsoftonline.com/your_tenant or https://tenant_name.ciamlogin.com or https://tenant_name.b2clogin.com/tenant.onmicrosoft.com/policy. Also please double check your tenant name or GUID is correct."
== f"[2010] Error in HTTP response from Azure - Authentication failed: Unable to get authority configuration for https://login.microsoftonline.com/{tenant_id}. Authority would typically be in a format of https://login.microsoftonline.com/your_tenant or https://tenant_name.ciamlogin.com or https://tenant_name.b2clogin.com/tenant.onmicrosoft.com/policy. Also please double check your tenant name or GUID is correct."
)
def test_test_connection_without_any_method(self):
@@ -399,7 +397,7 @@ class TestAzureProvider:
assert exception.type == AzureNoAuthenticationMethodError
assert (
"[1917] Azure provider requires at least one authentication method set: [--az-cli-auth | --sp-env-auth | --browser-auth | --managed-identity-auth]"
"[2003] Azure provider requires at least one authentication method set: [--az-cli-auth | --sp-env-auth | --browser-auth | --managed-identity-auth]"
in exception.value.args[0]
)
@@ -424,7 +422,7 @@ class TestAzureProvider:
assert exception.type == AzureHTTPResponseError
assert (
exception.value.args[0]
== "[1924] Error in HTTP response from Azure - Simulated HttpResponseError"
== "[2010] Error in HTTP response from Azure - Simulated HttpResponseError"
)
def test_test_connection_with_exception(self):
+3 -3
View File
@@ -13,7 +13,7 @@ from prowler.config.config import (
)
from prowler.providers.common.models import Connection
from prowler.providers.gcp.exceptions.exceptions import (
GCPInvalidAccountCredentials,
GCPInvalidProviderIdError,
GCPTestConnectionError,
)
from prowler.providers.gcp.gcp_provider import GcpProvider
@@ -593,7 +593,7 @@ class TestGCPProvider:
"prowler.providers.gcp.gcp_provider.GcpProvider.validate_project_id"
) as mock_validate_project_id:
mock_validate_project_id.side_effect = GCPInvalidAccountCredentials(
mock_validate_project_id.side_effect = GCPInvalidProviderIdError(
"Invalid project ID"
)
@@ -605,4 +605,4 @@ class TestGCPProvider:
provider_id="test-invalid-project",
)
assert e.type == GCPInvalidAccountCredentials
assert e.type == GCPInvalidProviderIdError