summaryrefslogtreecommitdiff
path: root/jstests/noPassthrough/queryStats/documentSourceQueryStats_redaction_parameters.js
diff options
context:
space:
mode:
Diffstat (limited to 'jstests/noPassthrough/queryStats/documentSourceQueryStats_redaction_parameters.js')
-rw-r--r--jstests/noPassthrough/queryStats/documentSourceQueryStats_redaction_parameters.js126
1 files changed, 126 insertions, 0 deletions
diff --git a/jstests/noPassthrough/queryStats/documentSourceQueryStats_redaction_parameters.js b/jstests/noPassthrough/queryStats/documentSourceQueryStats_redaction_parameters.js
new file mode 100644
index 00000000000..40db2885967
--- /dev/null
+++ b/jstests/noPassthrough/queryStats/documentSourceQueryStats_redaction_parameters.js
@@ -0,0 +1,126 @@
+/**
+ * Test the $queryStats hmac properties.
+ * @tags: [requires_fcv_60]
+ */
+
+load("jstests/aggregation/extras/utils.js"); // For assertAdminDBErrCodeAndErrMsgContains.
+load("jstests/libs/query_stats_utils.js"); // For getQueryStatsFindCmd
+
+(function() {
+"use strict";
+
+// Assert the expected queryStats key with no hmac.
+function assertQueryStatsKeyWithoutHmac(queryStatsKey) {
+ assert.eq(queryStatsKey.filter, {"foo": {"$lte": "?number"}});
+ assert.eq(queryStatsKey.sort, {"bar": -1});
+ assert.eq(queryStatsKey.limit, "?number");
+}
+
+function runTest(conn) {
+ const testDB = conn.getDB('test');
+ const coll = testDB[jsTestName()];
+ coll.drop();
+
+ coll.insert({foo: 1});
+ coll.find({foo: {$lte: 2}}).sort({bar: -1}).limit(2).toArray();
+ // Default is no hmac.
+ assertQueryStatsKeyWithoutHmac(getQueryStatsFindCmd(conn)[0].key.queryShape);
+
+ // Turning on hmac should apply hmac to all field names on all entries, even previously cached
+ // ones.
+ const queryStatsKey = getQueryStatsFindCmd(conn, {transformIdentifiers: true})[0]["key"];
+ assert.eq(queryStatsKey.queryShape.filter,
+ {"fNWkKfogMv6MJ77LpBcuPrO7Nq+R+7TqtD+Lgu3Umc4=": {"$lte": "?number"}});
+ assert.eq(queryStatsKey.queryShape.sort, {"CDDQIXZmDehLKmQcRxtdOQjMqoNqfI2nGt2r4CgJ52o=": -1});
+ assert.eq(queryStatsKey.queryShape.limit, "?number");
+
+ // Turning hmac back off should preserve field names on all entries, even previously cached
+ // ones.
+ const queryStats = getQueryStatsFindCmd(conn)[0]["key"];
+ assertQueryStatsKeyWithoutHmac(queryStats.queryShape);
+
+ // Explicitly set transformIdentifiers to false.
+ assertQueryStatsKeyWithoutHmac(
+ getQueryStatsFindCmd(conn, {transformIdentifiers: false})[0]["key"].queryShape);
+
+ // Wrong parameter name throws error.
+ let pipeline = [{$queryStats: {redactFields: true}}];
+ assertAdminDBErrCodeAndErrMsgContains(
+ coll, pipeline, 40415, "BSON field '$queryStats.redactFields' is an unknown field.");
+
+ // Wrong parameter name throws error.
+ pipeline = [{$queryStats: {algorithm: "hmac-sha-256"}}];
+ assertAdminDBErrCodeAndErrMsgContains(
+ coll, pipeline, 40415, "BSON field '$queryStats.algorithm' is an unknown field.");
+
+ // Wrong parameter type throws error.
+ pipeline = [{$queryStats: {transformIdentifiers: {algorithm: 1}}}];
+ assertAdminDBErrCodeAndErrMsgContains(
+ coll,
+ pipeline,
+ ErrorCodes.TypeMismatch,
+ "BSON field '$queryStats.transformIdentifiers.algorithm' is the wrong type 'double', expected type 'string'");
+
+ pipeline = [{$queryStats: {transformIdentifiers: {algorithm: "hmac-sha-256", hmacKey: 1}}}];
+ assertAdminDBErrCodeAndErrMsgContains(
+ coll,
+ pipeline,
+ ErrorCodes.TypeMismatch,
+ "BSON field '$queryStats.transformIdentifiers.hmacKey' is the wrong type 'double', expected type 'binData'");
+
+ // Unsupported algorithm throws error.
+ pipeline = [{$queryStats: {transformIdentifiers: {algorithm: "hmac-sha-1"}}}];
+ assertAdminDBErrCodeAndErrMsgContains(
+ coll,
+ pipeline,
+ ErrorCodes.BadValue,
+ "Enumeration value 'hmac-sha-1' for field '$queryStats.transformIdentifiers.algorithm' is not a valid value.");
+
+ // TransformIdentifiers with missing algorithm throws error.
+ pipeline = [{$queryStats: {transformIdentifiers: {}}}];
+ assertAdminDBErrCodeAndErrMsgContains(
+ coll,
+ pipeline,
+ 40414,
+ "BSON field '$queryStats.transformIdentifiers.algorithm' is missing but a required field");
+
+ // TransformIdentifiers with algorithm but missing hmacKey throws error.
+ pipeline = [{$queryStats: {transformIdentifiers: {algorithm: "hmac-sha-256"}}}];
+ assertAdminDBErrCodeAndErrMsgContains(
+ coll,
+ pipeline,
+ ErrorCodes.FailedToParse,
+ "The 'hmacKey' parameter of the $queryStats stage must be specified when applying the hmac-sha-256 algorithm");
+
+ // Parameter object with unrecognized key throws error.
+ pipeline =
+ [{$queryStats: {transformIdentifiers: {algorithm: "hmac-sha-256", hmacStrategy: "on"}}}];
+ assertAdminDBErrCodeAndErrMsgContains(
+ coll,
+ pipeline,
+ 40415,
+ "BSON field '$queryStats.transformIdentifiers.hmacStrategy' is an unknown field.");
+}
+
+const conn = MongoRunner.runMongod({
+ setParameter: {
+ internalQueryStatsRateLimit: -1,
+ }
+});
+runTest(conn);
+MongoRunner.stopMongod(conn);
+
+const st = new ShardingTest({
+ mongos: 1,
+ shards: 1,
+ config: 1,
+ rs: {nodes: 1},
+ mongosOptions: {
+ setParameter: {
+ internalQueryStatsRateLimit: -1,
+ }
+ },
+});
+runTest(st.s);
+st.stop();
+}());