CartoDB-SQL-API/test/acceptance/rate-limit.js

108 lines
3.0 KiB
JavaScript
Raw Normal View History

2018-10-24 21:42:33 +08:00
'use strict';
2018-03-02 20:18:19 +08:00
require('../helper');
const qs = require('querystring');
const assert = require('../support/assert');
const redis = require('redis');
const rateLimitMiddleware = require('../../app/middlewares/rate-limit');
const { RATE_LIMIT_ENDPOINTS_GROUPS } = rateLimitMiddleware;
2018-03-02 23:43:01 +08:00
const app = require('../../app/server');
let server;
2018-03-02 20:18:19 +08:00
let redisClient;
let keysToDelete = [];
const user = 'vizzuality';
var request = {
url: '/api/v1/sql?' + qs.stringify({
q: 'SELECT * FROM untitle_table_4'
}),
headers: {
host: 'vizzuality.cartodb.com'
},
method: 'GET'
};
function setLimit(count, period, burst) {
redisClient.SELECT(8, err => {
if (err) {
return;
}
2018-10-24 21:42:33 +08:00
const key = `limits:rate:store:${user}:sql:${RATE_LIMIT_ENDPOINTS_GROUPS.QUERY}`;
2018-03-02 20:18:19 +08:00
redisClient.rpush(key, burst);
redisClient.rpush(key, count);
redisClient.rpush(key, period);
keysToDelete.push(key);
});
}
2018-03-03 03:16:58 +08:00
function assertRequest (status, limit, remaining, reset, retry, done = null) {
2018-03-03 03:14:10 +08:00
assert.response(
2018-10-24 21:42:33 +08:00
server,
request,
{ status },
2018-03-03 03:14:10 +08:00
function(err, res) {
assert.ifError(err);
2018-03-14 19:17:26 +08:00
assert.equal(res.headers['carto-rate-limit-limit'], limit);
assert.equal(res.headers['carto-rate-limit-remaining'], remaining);
assert.equal(res.headers['carto-rate-limit-reset'], reset);
2018-03-23 22:09:16 +08:00
if (retry) {
assert.equal(res.headers['retry-after'], retry);
}
2018-03-03 03:14:10 +08:00
2018-10-24 21:42:33 +08:00
if(status === 429) {
const expectedResponse = {
2018-03-27 21:46:58 +08:00
error: ["You are over platform\'s limits. Please contact us to know more details"],
2018-10-24 21:42:33 +08:00
context: "limit",
detail: "rate-limit"
};
assert.deepEqual(JSON.parse(res.body), expectedResponse);
}
2018-03-03 03:14:10 +08:00
if (done) {
setTimeout(done, 1000);
}
}
);
}
2018-03-02 20:18:19 +08:00
describe('rate limit', function() {
before(function() {
global.settings.ratelimits.rateLimitsEnabled = true;
global.settings.ratelimits.endpoints.query = true;
2018-10-24 21:42:33 +08:00
2018-03-02 23:43:01 +08:00
server = app();
2018-03-02 20:18:19 +08:00
redisClient = redis.createClient(global.settings.redis_port);
const count = 1;
const period = 1;
const burst = 1;
setLimit(count, period, burst);
});
after(function() {
global.settings.ratelimits.rateLimitsEnabled = false;
global.settings.ratelimits.endpoints.query = false;
keysToDelete.forEach( key => {
redisClient.del(key);
});
});
it("1 req/sec: 2 req/seg should be limited", function(done) {
2018-10-24 21:42:33 +08:00
assertRequest(200, 2, 1, 1);
2018-03-23 22:09:16 +08:00
setTimeout( () => assertRequest(200, 2, 0, 1, null), 250 );
setTimeout( () => assertRequest(429, 2, 0, 1, 1), 500 );
setTimeout( () => assertRequest(429, 2, 0, 1, 1), 750 );
setTimeout( () => assertRequest(429, 2, 0, 1, 1), 950 );
setTimeout( () => assertRequest(200, 2, 0, 1, null, done), 1050 );
2018-03-02 20:18:19 +08:00
});
});