update how perms work

This commit is contained in:
zkldi
2021-06-27 22:21:02 +01:00
parent 0d7047393b
commit 3168d9d8e7
8 changed files with 70 additions and 102 deletions
+39 -15
View File
@@ -1,24 +1,48 @@
import t from "tap";
import mockApi from "./mock-api";
import { APIPermissions } from "tachi-common";
import db from "../external/mongo/db";
import ResetDBState from "./resets";
export function RequireNeutralAuthentication(url: string, method: "GET" | "POST" = "GET") {
t.test(`Testing authentication for ${method} ${url}.`, async (t) => {
let res;
export function RequireAuthPerms(
url: string,
perms: APIPermissions | APIPermissions[],
method: "GET" | "POST" | "PATCH" | "PUT" | "DELETE" = "GET"
) {
t.test(`Testing permissions for ${method} ${url} [${perms}]`, async (t) => {
const m = method.toLowerCase() as Lowercase<typeof method>;
if (method === "GET") {
res = await mockApi.get(url);
} else {
res = await mockApi.post(url);
}
const res = await mockApi[m](url);
t.equal(res.status, 403, "Should return 403 immediately.");
t.equal(
res.body.description,
"You are not authorised to perform this action.",
"Should return an appropriate error message."
);
// 401 if no auth given
t.equal(res.statusCode, 401);
// CloseAllConnections();
await db["api-tokens"].insert({
identifier: "temp_auth_perms",
permissions: {},
token: "temp_auth",
userID: 1,
});
const resAuth = await mockApi[m](url).set("Authorization", "Bearer temp_auth");
t.equal(resAuth.statusCode, 403);
const prm = Array.isArray(perms) ? perms : [perms];
await db["api-tokens"].insert({
identifier: "temp_auth_perms2",
permissions: Object.fromEntries(prm.map((e) => [e, true])),
token: "temp_auth2",
userID: 1,
});
const resAuthed = await mockApi[m](url).set("Authorization", "Bearer temp_auth2");
t.not(resAuthed.statusCode, 401);
t.not(resAuthed.statusCode, 403);
await ResetDBState();
t.end();
});