This is the one.

This commit is contained in:
zkldi
2021-04-18 03:08:05 +01:00
parent 870aa5840a
commit fc62580696
7 changed files with 49 additions and 6 deletions
BIN
View File
Binary file not shown.
@@ -3,10 +3,14 @@ import mockApi from "../../test-utils/mock-api";
import { TestingIIDXEamusementCSV26 } from "../../test-utils/test-data";
import { CloseAllConnections } from "../../test-utils/close-connections";
import { RequireNeutralAuthentication } from "../../test-utils/api-common";
import { CreateFakeAuthCookie } from "../../test-utils/fake-session";
import ResetDBState from "../../test-utils/reset-db-state";
t.test("POST /internal-api/import/file", (t) => {
t.test("POST /internal-api/import/file", async (t) => {
t.beforeEach(ResetDBState);
const cookie = await CreateFakeAuthCookie();
function PostImportFile() {
return mockApi.post("/internal-api/import/file");
return mockApi.post("/internal-api/import/file").set("Cookie", cookie);
}
RequireNeutralAuthentication(t, "/internal-api/import/file", "POST");
@@ -1,7 +1,14 @@
import { NextFunction, Request, Response } from "express";
import CreateLogCtx from "../logger";
const logger = CreateLogCtx("require-logged-in.ts");
export function RequireLoggedIn(req: Request, res: Response, next: NextFunction) {
if (!req.session.ktchi?.userID) {
logger.info(`Received unauthorised request from ${req.ip} from ${req.originalUrl}`, {
auth: req.session,
});
return res.status(401).json({
success: false,
description: `You are not authorised to perform this action.`,
+1 -1
View File
@@ -14,7 +14,7 @@ const logger = CreateLogCtx("scripts/initialise-counters.ts");
await db.counters.insert({
counterName: "users",
value: 0,
value: 1,
});
logger.info("Successfully initialised counter documents. Exiting.");
@@ -0,0 +1,4 @@
/* eslint-disable no-console */
import bcrypt from "bcrypt";
console.log(bcrypt.hashSync("password", 12));
+28
View File
@@ -0,0 +1,28 @@
import mockApi from "./mock-api";
import assert from "assert";
import db from "../db/db";
import ResetDBState from "./reset-db-state";
import CreateLogCtx from "../logger";
const logger = CreateLogCtx("fake-session.ts");
export async function CreateFakeAuthCookie() {
await ResetDBState();
// possible security issue, ask hazel
let res = await mockApi.post("/internal-api/auth/login").send({
username: "test_zkldi",
password: "password",
captcha: "asdf",
});
if (res.status !== 200) {
logger.crit("Failed to login. Cannot generate auth cookie.");
throw res.body;
}
return res.headers["set-cookie"] as string[];
}
export async function DestroyFakeAuthToken(cookie: string) {
// stub
}
+3 -3
View File
@@ -1,8 +1,8 @@
[
{
"username": "zkldi",
"usernameLowercase": "zkldi",
"password": "$2y$12$u2FK6QJAv/WDF/ExGUWI9OoIks8Q0ExT1qjPMBu6zCZ5z72swQ01K",
"username": "test_zkldi",
"usernameLowercase": "test_zkldi",
"password": "$2b$12$QRFCAxvFoNI2spszFPgt/e.qLy55GvYWlSHioa0AujRbFpChLwHmu",
"email": "thepasswordis@password.com",
"id": 1,
"settings": {