Skip to content

Commit

Permalink
test: add new integration test for invalid policy exception constrain…
Browse files Browse the repository at this point in the history
…ts (#451)

Signed-off-by: Darren Murray <darren.murray@lacework.net>
  • Loading branch information
dmurray-lacework authored Mar 1, 2023
1 parent 51fad26 commit 4c7ad87
Show file tree
Hide file tree
Showing 2 changed files with 20 additions and 2 deletions.
4 changes: 2 additions & 2 deletions examples/resource_lacework_policy_exception/main.tf
Original file line number Diff line number Diff line change
Expand Up @@ -10,12 +10,12 @@ resource "lacework_policy_exception" "example" {
policy_id = "lacework-global-39"
description = var.description
constraint {
field_key = "accountIds"
field_key = var.field_key
field_values = ["*"]
}

constraint {
field_key = "resourceNames"
field_key = "resourceTags"
field_value_map {
key = "test"
value = "test"
Expand Down
18 changes: 18 additions & 0 deletions integration/resource_lacework_policy_exception_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -52,3 +52,21 @@ func TestPolicyExceptionCreate(t *testing.T) {

assert.Equal(t, "Policy Exception Created via Terraform Updated", actualDescription)
}

// TestPolicyExceptionInvalidConstraint tests an invalid constraint returns an error and lists valid constraint fields
func TestPolicyExceptionInvalidConstraint(t *testing.T) {
terraformOptions := terraform.WithDefaultRetryableErrors(t, &terraform.Options{
TerraformDir: "../examples/resource_lacework_policy_exception",
EnvVars: tokenEnvVar,
Vars: map[string]interface{}{
"policy_id": "lacework-global-46",
"description": "Policy Exception Created via Terraform",
"field_key": "invalid",
"field_values": []string{"*"},
},
})
defer terraform.Destroy(t, terraformOptions)

_, err := terraform.InitAndApplyE(t, terraformOptions)
assert.ErrorContains(t, err, "[400] fieldKey: invalid is not applicable to policy lacework-global-39. Valid fieldKey are [accountIds, resourceNames, resourceTags]")
}

0 comments on commit 4c7ad87

Please sign in to comment.