Add Query String Support #2
@@ -178,10 +178,12 @@ class ClientsController < ApplicationController
|
|||||||
# check if the api is valid and has the appropriate prefix
|
# check if the api is valid and has the appropriate prefix
|
||||||
def parse_api_key_header
|
def parse_api_key_header
|
||||||
# TODO: move api_key checks and formatting to helper class
|
# TODO: move api_key checks and formatting to helper class
|
||||||
# check if api key is present and can be split into 3 parts: <prefix>.<name_id>.<api_key>
|
# check if api key is present in header or param and can be split into 3 parts: <prefix>.<name_id>.<api_key>
|
||||||
# NOTE: .compact is more for got measure than really necessary, but this ensures no nil values in the array
|
# NOTE: .compact is more for got measure than really necessary, but this ensures no nil values in the array
|
||||||
api_key_header = request.headers[RynDNS::Application::API_KEY_HEADER].split('.').compact unless
|
api_key_header = request.headers[RynDNS::Application::API_KEY_HEADER].split('.').compact unless
|
||||||
request.headers[RynDNS::Application::API_KEY_HEADER].nil?
|
request.headers[RynDNS::Application::API_KEY_HEADER].nil?
|
||||||
|
api_key_header ||= params[RynDNS::Application::API_KEY_HEADER].split('.').compact if
|
||||||
|
params.has_key?(RynDNS::Application::API_KEY_HEADER)
|
||||||
return head(401) if api_key_header.nil? || api_key_header.length < 3
|
return head(401) if api_key_header.nil? || api_key_header.length < 3
|
||||||
|
|
||||||
prefix, @name_id, @api_key = api_key_header
|
prefix, @name_id, @api_key = api_key_header
|
||||||
|
|||||||
@@ -12,7 +12,7 @@ RSpec.describe 'Clients', type: :request do
|
|||||||
let(:valid_client) do
|
let(:valid_client) do
|
||||||
{
|
{
|
||||||
name: 'clientA',
|
name: 'clientA',
|
||||||
description: 'Client across the river',
|
description: 'Client&across the=river', # added &= for query string test
|
||||||
permission: 'rw',
|
permission: 'rw',
|
||||||
public_ip: false
|
public_ip: false
|
||||||
}
|
}
|
||||||
@@ -78,31 +78,18 @@ RSpec.describe 'Clients', type: :request do
|
|||||||
context 'when sending a valid request' do
|
context 'when sending a valid request' do
|
||||||
before { post '/admin/client', params: valid_client, headers: api_key_header(admin_client) }
|
before { post '/admin/client', params: valid_client, headers: api_key_header(admin_client) }
|
||||||
|
|
||||||
it 'creates client that can read/write and returns 201' do
|
it_behaves_like 'POST /admin/client 201'
|
||||||
expect(json_response).not_to be_empty
|
|
||||||
expect(json_response['name']).to eq valid_client[:name]
|
|
||||||
expect(json_response['api_key'].length).to eq 82
|
|
||||||
expect(response).to have_http_status(201)
|
|
||||||
api_key = json_response['api_key']
|
|
||||||
# check if request was parsed properly
|
|
||||||
get "/admin/clients/#{valid_client[:name]}", headers: api_key_header(admin_client)
|
|
||||||
expect(json_response).not_to be_empty
|
|
||||||
expect(json_response['name']).to eq valid_client[:name]
|
|
||||||
expect(json_response['description']).to eq valid_client[:description]
|
|
||||||
expect(json_response['permission']).to eq valid_client[:permission]
|
|
||||||
expect(json_response['public_ip']).to eq valid_client[:public_ip]
|
|
||||||
expect(response).to have_http_status(200)
|
|
||||||
# test the new client write
|
|
||||||
put '/client', headers: api_key_header(nil, api_key)
|
|
||||||
expect(json_response).not_to be_empty
|
|
||||||
expect(response).to have_http_status(200)
|
|
||||||
ipv4 = json_response['ipv4']
|
|
||||||
# test the new client read
|
|
||||||
get "/clients/#{valid_client[:name]}", headers: api_key_header(nil, api_key)
|
|
||||||
expect(json_response).not_to be_empty
|
|
||||||
expect(response).to have_http_status(200)
|
|
||||||
expect(json_response['ipv4']).to eq ipv4
|
|
||||||
end
|
end
|
||||||
|
|
||||||
|
# TODO: add query string tests for all requests and use shared examples
|
||||||
|
context 'when sending a valid request as query string' do
|
||||||
|
before do
|
||||||
|
api_key = "#{RynDNS::Application::API_KEY_HEADER}=#{api_key_header(admin_client)[RynDNS::Application::API_KEY_HEADER]}"
|
||||||
|
body = hash_to_query_string(valid_client)
|
||||||
|
post "/admin/client?#{api_key}&#{body}"
|
||||||
|
end
|
||||||
|
|
||||||
|
it_behaves_like 'POST /admin/client 201'
|
||||||
end
|
end
|
||||||
|
|
||||||
context 'when sending a valid request without api_key' do
|
context 'when sending a valid request without api_key' do
|
||||||
|
|||||||
@@ -15,6 +15,15 @@ module RequestSpecHelper
|
|||||||
"#{'r' if perm_r}#{'w' if perm_w}#{'x' if perm_x}"
|
"#{'r' if perm_r}#{'w' if perm_w}#{'x' if perm_x}"
|
||||||
end
|
end
|
||||||
|
|
||||||
|
def hash_to_query_string(hash)
|
||||||
|
result = ''
|
||||||
|
hash.each do |k, v|
|
||||||
|
# escape value to be uri save
|
||||||
|
result += "#{k}=#{CGI.escape(v.to_s)}&"
|
||||||
|
end
|
||||||
|
result.delete_suffix('&')
|
||||||
|
end
|
||||||
|
|
||||||
def list_equals_db?(client_list)
|
def list_equals_db?(client_list)
|
||||||
return false unless Client.count == client_list.count
|
return false unless Client.count == client_list.count
|
||||||
|
|
||||||
|
|||||||
29
spec/support/request_spec_shared.rb
Normal file
29
spec/support/request_spec_shared.rb
Normal file
@@ -0,0 +1,29 @@
|
|||||||
|
# frozen_string_literal: true
|
||||||
|
|
||||||
|
RSpec.shared_examples 'POST /admin/client 201' do
|
||||||
|
it 'creates client that can read/write and returns 201' do
|
||||||
|
expect(json_response).not_to be_empty
|
||||||
|
expect(json_response['name']).to eq valid_client[:name]
|
||||||
|
expect(json_response['api_key'].length).to eq 82
|
||||||
|
expect(response).to have_http_status(201)
|
||||||
|
api_key = json_response['api_key']
|
||||||
|
# check if request was parsed properly
|
||||||
|
get "/admin/clients/#{valid_client[:name]}", headers: api_key_header(admin_client)
|
||||||
|
expect(json_response).not_to be_empty
|
||||||
|
expect(json_response['name']).to eq valid_client[:name]
|
||||||
|
expect(json_response['description']).to eq valid_client[:description]
|
||||||
|
expect(json_response['permission']).to eq valid_client[:permission]
|
||||||
|
expect(json_response['public_ip']).to eq valid_client[:public_ip]
|
||||||
|
expect(response).to have_http_status(200)
|
||||||
|
# test the new client write
|
||||||
|
put '/client', headers: api_key_header(nil, api_key)
|
||||||
|
expect(json_response).not_to be_empty
|
||||||
|
expect(response).to have_http_status(200)
|
||||||
|
ipv4 = json_response['ipv4']
|
||||||
|
# test the new client read
|
||||||
|
get "/clients/#{valid_client[:name]}", headers: api_key_header(nil, api_key)
|
||||||
|
expect(json_response).not_to be_empty
|
||||||
|
expect(response).to have_http_status(200)
|
||||||
|
expect(json_response['ipv4']).to eq ipv4
|
||||||
|
end
|
||||||
|
end
|
||||||
Reference in New Issue
Block a user