experimental: misc ergonomic checking

This commit is contained in:
zkldi
2022-05-06 04:16:23 +01:00
parent ba50d17846
commit 3f4a582ad7
13 changed files with 94 additions and 61 deletions
+33 -28
View File
@@ -9,43 +9,48 @@ export function RequireAuthPerms(
perms: APIPermissions | Array<APIPermissions>,
method: "DELETE" | "GET" | "PATCH" | "POST" | "PUT" = "GET"
) {
t.test(`Testing permissions for ${method} ${url} [${perms}]`, async (t) => {
const m = method.toLowerCase() as Lowercase<typeof method>;
return t.test(
`Testing permissions for ${method} ${url} [${
Array.isArray(perms) ? perms.join(", ") : perms
}]`,
async (t) => {
const m = method.toLowerCase() as Lowercase<typeof method>;
const res = await mockApi[m](url);
const res = await mockApi[m](url);
// 401 if no auth given
t.equal(res.statusCode, 401);
// 401 if no auth given
t.equal(res.statusCode, 401);
await db["api-tokens"].insert({
identifier: "temp_auth_perms",
permissions: {},
token: "temp_auth",
userID: 1,
fromAPIClient: null,
});
await db["api-tokens"].insert({
identifier: "temp_auth_perms",
permissions: {},
token: "temp_auth",
userID: 1,
fromAPIClient: null,
});
const resAuth = await mockApi[m](url).set("Authorization", "Bearer temp_auth");
const resAuth = await mockApi[m](url).set("Authorization", "Bearer temp_auth");
t.equal(resAuth.statusCode, 403);
t.equal(resAuth.statusCode, 403);
const prm = Array.isArray(perms) ? perms : [perms];
const prm = Array.isArray(perms) ? perms : [perms];
await db["api-tokens"].insert({
identifier: "temp_auth_perms2",
permissions: Object.fromEntries(prm.map((e) => [e, true])),
token: "temp_auth2",
userID: 1,
fromAPIClient: null,
});
await db["api-tokens"].insert({
identifier: "temp_auth_perms2",
permissions: Object.fromEntries(prm.map((e) => [e, true])),
token: "temp_auth2",
userID: 1,
fromAPIClient: null,
});
const resAuthed = await mockApi[m](url).set("Authorization", "Bearer temp_auth2");
const resAuthed = await mockApi[m](url).set("Authorization", "Bearer temp_auth2");
t.not(resAuthed.statusCode, 401);
t.not(resAuthed.statusCode, 403);
t.not(resAuthed.statusCode, 401);
t.not(resAuthed.statusCode, 403);
await ResetDBState();
await ResetDBState();
t.end();
});
t.end();
}
);
}