mirror of
https://github.com/zkldi/Tachi.git
synced 2026-10-11 16:58:25 +03:00
update how perms work
This commit is contained in:
@@ -1,24 +1,48 @@
|
||||
import t from "tap";
|
||||
import mockApi from "./mock-api";
|
||||
import { APIPermissions } from "tachi-common";
|
||||
import db from "../external/mongo/db";
|
||||
import ResetDBState from "./resets";
|
||||
|
||||
export function RequireNeutralAuthentication(url: string, method: "GET" | "POST" = "GET") {
|
||||
t.test(`Testing authentication for ${method} ${url}.`, async (t) => {
|
||||
let res;
|
||||
export function RequireAuthPerms(
|
||||
url: string,
|
||||
perms: APIPermissions | APIPermissions[],
|
||||
method: "GET" | "POST" | "PATCH" | "PUT" | "DELETE" = "GET"
|
||||
) {
|
||||
t.test(`Testing permissions for ${method} ${url} [${perms}]`, async (t) => {
|
||||
const m = method.toLowerCase() as Lowercase<typeof method>;
|
||||
|
||||
if (method === "GET") {
|
||||
res = await mockApi.get(url);
|
||||
} else {
|
||||
res = await mockApi.post(url);
|
||||
}
|
||||
const res = await mockApi[m](url);
|
||||
|
||||
t.equal(res.status, 403, "Should return 403 immediately.");
|
||||
t.equal(
|
||||
res.body.description,
|
||||
"You are not authorised to perform this action.",
|
||||
"Should return an appropriate error message."
|
||||
);
|
||||
// 401 if no auth given
|
||||
t.equal(res.statusCode, 401);
|
||||
|
||||
// CloseAllConnections();
|
||||
await db["api-tokens"].insert({
|
||||
identifier: "temp_auth_perms",
|
||||
permissions: {},
|
||||
token: "temp_auth",
|
||||
userID: 1,
|
||||
});
|
||||
|
||||
const resAuth = await mockApi[m](url).set("Authorization", "Bearer temp_auth");
|
||||
|
||||
t.equal(resAuth.statusCode, 403);
|
||||
|
||||
const prm = Array.isArray(perms) ? perms : [perms];
|
||||
|
||||
await db["api-tokens"].insert({
|
||||
identifier: "temp_auth_perms2",
|
||||
permissions: Object.fromEntries(prm.map((e) => [e, true])),
|
||||
token: "temp_auth2",
|
||||
userID: 1,
|
||||
});
|
||||
|
||||
const resAuthed = await mockApi[m](url).set("Authorization", "Bearer temp_auth2");
|
||||
|
||||
t.not(resAuthed.statusCode, 401);
|
||||
t.not(resAuthed.statusCode, 403);
|
||||
|
||||
await ResetDBState();
|
||||
|
||||
t.end();
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user