Add ACME cert profile creation feature

This commit is contained in:
Fang-Pen Lin
2025-11-07 09:19:58 -08:00
parent 3a84e9a50e
commit ebb4260386
5 changed files with 80 additions and 0 deletions
+8
View File
@@ -4,12 +4,20 @@ import httpx
from behave.runner import Context
BASE_URL = os.environ.get("INFISICAL_API_URL", "http://localhost:8080")
PROJECT_ID = os.environ.get("PROJECT_ID", "c051e74c-48a7-4724-832c-d5b496698546")
CERT_CA_ID = os.environ.get("CERT_CA_ID", "2f0d9820-e5a8-48bb-aac8-deed9d868a1e")
CERT_TEMPLATE_ID = os.environ.get(
"CERT_TEMPLATE_ID", "4dbf6bb0-6e86-4ee6-8550-9171428c8e82"
)
AUTH_TOKEN = os.environ.get("INFISICAL_TOKEN")
def before_all(context: Context):
context.vars = {
"BASE_URL": BASE_URL,
"PROJECT_ID": PROJECT_ID,
"CERT_CA_ID": CERT_CA_ID,
"CERT_TEMPLATE_ID": CERT_TEMPLATE_ID,
}
context.http_client = httpx.Client(
base_url=BASE_URL, # headers={"Authorization": f"Bearer {AUTH_TOKEN}"}
@@ -0,0 +1,23 @@
Feature: ACME Cert Profile
Scenario: Create a cert profile
Given I make a random slug as profile_slug
When I send a POST request to "/api/v1/pki/certificate-profiles" with JSON payload
"""
{
"projectId": "{PROJECT_ID}",
"slug": "{profile_slug}",
"description": "",
"enrollmentType": "acme",
"caId": "{CA_ID}",
"certificateTemplateId": "{CERT_TEMPLATE_ID}",
"acmeConfig": {}
}
"""
Then the value response.status should be equal to 201
Then the value response with jq .eab_kid should be present
Then the value response with jq .eab_secret should be present
Then the value response with jq .slug should be equal to {profile_slug}
Then the value response with jq .caId should be equal to {CA_ID}
Then the value response with jq .certificateTemplateId should be equal to {CERT_TEMPLATE_ID}
Then the value response with jq .enrollmentTYpe should be equal to acme
+25
View File
@@ -2,6 +2,7 @@ import json
import re
import threading
import faker
import jq
import requests
import glom
@@ -107,6 +108,11 @@ def eval_var(context: Context, var_path: str, as_json: bool = True):
return value
@given("I make a random {faker_type} as {var_name}")
def step_impl(context: Context, faker_type: str, var_name: str):
context.vars[var_name] = getattr(faker, faker_type)()
@given('I have an ACME cert profile as "{profile_var}"')
def step_impl(context: Context, profile_var: str):
# TODO: Fixed value for now, just to make test much easier,
@@ -121,6 +127,13 @@ def step_impl(context: Context, method: str, url: str):
context.response = context.http_client.request(method, url.format(**context.vars))
@when('I send a {method} request to "{url}" with JSON payload')
def step_impl(context: Context, method: str, url: str):
context.response = context.http_client.request(
method, url.format(**context.vars), json_payload=context.text
)
@when("I have an ACME client connecting to {url}")
def step_impl(context: Context, url: str):
private_key = rsa.generate_private_key(
@@ -260,6 +273,18 @@ def step_impl(context: Context, var_path: str, jq_query: str):
)
@then("the value {var_path} with jq {jq_query} should be present")
def step_impl(context: Context, var_path: str, jq_query: str):
value, result = apply_value_with_jq(
context=context,
var_path=var_path,
jq_query=jq_query,
)
assert result, (
f"{json.dumps(value)!r} with jq {jq_query!r}, the result {json.dumps(result)!r} is not present"
)
@then("the value {var_path} with jq {jq_query} should be equal to {expected}")
def step_impl(context: Context, var_path: str, jq_query: str, expected: str):
value, result = apply_value_with_jq(