2018-06-21 16:33:20 -05:00
|
|
|
import {buildToken} from "../../../src/lib/utils";
|
2018-06-24 03:11:52 -05:00
|
|
|
import {API_ERROR, HTTP_STATUS, TOKEN_BASIC} from "../../../src/lib/constants";
|
|
|
|
import {CREDENTIALS} from "../config.functional";
|
2018-06-21 16:33:20 -05:00
|
|
|
|
2017-12-01 19:50:09 -05:00
|
|
|
export default function(server) {
|
2015-04-21 11:41:50 -05:00
|
|
|
|
2017-12-01 19:50:09 -05:00
|
|
|
describe('package access control', () => {
|
2018-06-21 16:33:20 -05:00
|
|
|
const buildAccesToken = (auth) => {
|
|
|
|
return buildToken(TOKEN_BASIC, `${(new Buffer(auth).toString('base64'))}`);
|
2017-07-01 17:05:58 -05:00
|
|
|
};
|
2015-04-21 11:41:50 -05:00
|
|
|
|
2017-07-01 17:05:58 -05:00
|
|
|
/**
|
|
|
|
* Check whether the user is allowed to fetch packages
|
|
|
|
* @param auth {object} disable auth
|
|
|
|
* @param pkg {string} package name
|
|
|
|
* @param ok {boolean}
|
|
|
|
*/
|
|
|
|
function checkAccess(auth, pkg, ok) {
|
2017-12-01 19:50:09 -05:00
|
|
|
test(
|
2018-06-24 03:11:52 -05:00
|
|
|
`${(ok ? 'allows' : 'forbids')} access ${auth} to ${pkg}`, () => {
|
2018-06-21 16:33:20 -05:00
|
|
|
server.authstr = auth ? buildAccesToken(auth) : undefined;
|
|
|
|
const req = server.getPackage(pkg);
|
2018-06-24 03:11:52 -05:00
|
|
|
|
2017-12-01 19:50:09 -05:00
|
|
|
if (ok) {
|
2018-06-24 03:11:52 -05:00
|
|
|
return req.status(HTTP_STATUS.NOT_FOUND).body_error(API_ERROR.NO_PACKAGE);
|
2017-12-01 19:50:09 -05:00
|
|
|
} else {
|
2018-06-24 03:11:52 -05:00
|
|
|
return req.status(HTTP_STATUS.FORBIDDEN).body_error(API_ERROR.NOT_ALLOWED);
|
2017-12-01 19:50:09 -05:00
|
|
|
}
|
2015-04-21 11:41:50 -05:00
|
|
|
}
|
2017-12-01 19:50:09 -05:00
|
|
|
);
|
2015-04-21 11:41:50 -05:00
|
|
|
}
|
|
|
|
|
2017-07-01 17:05:58 -05:00
|
|
|
/**
|
|
|
|
* Check whether the user is allowed to publish packages
|
|
|
|
* @param auth {object} disable auth
|
|
|
|
* @param pkg {string} package name
|
|
|
|
* @param ok {boolean}
|
|
|
|
*/
|
|
|
|
function checkPublish(auth, pkg, ok) {
|
2017-12-01 19:50:09 -05:00
|
|
|
test(`${(ok ? 'allows' : 'forbids')} publish ${auth} to ${pkg}`, () => {
|
2018-06-21 16:33:20 -05:00
|
|
|
server.authstr = auth ? buildAccesToken(auth) : undefined;
|
2017-08-06 14:54:15 -05:00
|
|
|
const req = server.putPackage(pkg, require('../fixtures/package')(pkg));
|
2015-04-21 11:41:50 -05:00
|
|
|
if (ok) {
|
2018-06-21 16:33:20 -05:00
|
|
|
return req.status(HTTP_STATUS.NOT_FOUND).body_error(/this package cannot be added/);
|
2015-04-21 11:41:50 -05:00
|
|
|
} else {
|
2018-06-21 16:33:20 -05:00
|
|
|
return req.status(HTTP_STATUS.FORBIDDEN).body_error(/not allowed to publish package/);
|
2015-04-21 11:41:50 -05:00
|
|
|
}
|
2017-04-19 14:15:28 -05:00
|
|
|
});
|
2015-04-21 11:41:50 -05:00
|
|
|
}
|
2017-07-01 17:05:58 -05:00
|
|
|
|
|
|
|
// credentials
|
|
|
|
const badCredentials = 'test:badpass';
|
|
|
|
// test user is logged by default
|
2018-06-21 16:33:20 -05:00
|
|
|
const validCredentials = `${CREDENTIALS.user}:${CREDENTIALS.password}`;
|
2017-07-01 17:05:58 -05:00
|
|
|
|
|
|
|
// defined on server1 configuration
|
2017-04-19 14:15:28 -05:00
|
|
|
const testAccessOnly = 'test-access-only';
|
|
|
|
const testPublishOnly = 'test-publish-only';
|
|
|
|
const testOnlyTest = 'test-only-test';
|
|
|
|
const testOnlyAuth = 'test-only-auth';
|
2015-04-21 11:41:50 -05:00
|
|
|
|
2017-07-01 17:05:58 -05:00
|
|
|
// all are allowed to access
|
|
|
|
checkAccess(validCredentials, testAccessOnly, true);
|
|
|
|
checkAccess(undefined, testAccessOnly, true);
|
|
|
|
checkAccess(badCredentials, testAccessOnly, true);
|
|
|
|
checkPublish(validCredentials, testAccessOnly, false);
|
|
|
|
checkPublish(undefined, testAccessOnly, false);
|
|
|
|
checkPublish(badCredentials, testAccessOnly, false);
|
|
|
|
|
2018-01-27 20:40:07 -05:00
|
|
|
// all are allowed to publish
|
2017-07-01 17:05:58 -05:00
|
|
|
checkAccess(validCredentials, testPublishOnly, false);
|
|
|
|
checkAccess(undefined, testPublishOnly, false);
|
|
|
|
checkAccess(badCredentials, testPublishOnly, false);
|
|
|
|
checkPublish(validCredentials, testPublishOnly, true);
|
|
|
|
checkPublish(undefined, testPublishOnly, true);
|
|
|
|
checkPublish(badCredentials, testPublishOnly, true);
|
2015-04-21 11:41:50 -05:00
|
|
|
|
2017-07-01 17:05:58 -05:00
|
|
|
// only user "test" is allowed to publish and access
|
|
|
|
checkAccess(validCredentials, testOnlyTest, true);
|
|
|
|
checkAccess(undefined, testOnlyTest, false);
|
|
|
|
checkAccess(badCredentials, testOnlyTest, false);
|
|
|
|
checkPublish(validCredentials, testOnlyTest, true);
|
|
|
|
checkPublish(undefined, testOnlyTest, false);
|
|
|
|
checkPublish(badCredentials, testOnlyTest, false);
|
2015-04-21 11:41:50 -05:00
|
|
|
|
2017-07-01 17:05:58 -05:00
|
|
|
// only authenticated users are allowed
|
|
|
|
checkAccess(validCredentials, testOnlyAuth, true);
|
|
|
|
checkAccess(undefined, testOnlyAuth, false);
|
|
|
|
checkAccess(badCredentials, testOnlyAuth, false);
|
|
|
|
checkPublish(validCredentials, testOnlyAuth, true);
|
|
|
|
checkPublish(undefined, testOnlyAuth, false);
|
|
|
|
checkPublish(badCredentials, testOnlyAuth, false);
|
2017-04-19 14:15:28 -05:00
|
|
|
});
|
2017-12-01 19:50:09 -05:00
|
|
|
}
|