CartoDB-SQL-API/test/acceptance/system-queries-test.js

63 lines
2.3 KiB
JavaScript
Raw Normal View History

2018-10-24 21:42:33 +08:00
'use strict';
2016-12-09 17:56:50 +08:00
require('../helper');
var server = require('../../lib/server')();
2016-12-09 17:56:50 +08:00
var assert = require('../support/assert');
var querystring = require('querystring');
2019-12-24 01:19:08 +08:00
describe('system-queries', function () {
2016-12-09 17:56:50 +08:00
var systemQueriesSuitesToTest = [
{
desc: 'pg_ queries work with api_key and fail otherwise',
queries: [
'SELECT * FROM pg_attribute',
'SELECT * FROM PG_attribute',
'SELECT * FROM "pg_attribute"',
'SELECT a.* FROM untitle_table_4 a,pg_attribute',
'SELECT * FROM geometry_columns'
],
api_key_works: true,
no_api_key_works: false
},
{
desc: 'Possible false positive queries will work with api_key and without it',
queries: [
"SELECT 'pg_'",
'SELECT pg_attribute FROM ( select 1 as pg_attribute ) as f',
'SELECT * FROM cpg_test'
],
api_key_works: true,
no_api_key_works: true
}
];
2019-12-24 01:19:08 +08:00
systemQueriesSuitesToTest.forEach(function (suiteToTest) {
var apiKeyStatusErrorCode = suiteToTest.api_key_works ? 200 : 403;
2016-12-09 17:56:50 +08:00
testSystemQueries(suiteToTest.desc + ' with api_key', suiteToTest.queries, apiKeyStatusErrorCode, '1234');
2019-12-24 01:19:08 +08:00
var noApiKeyStatusErrorCode = suiteToTest.no_api_key_works ? 200 : 403;
2016-12-09 17:56:50 +08:00
testSystemQueries(suiteToTest.desc, suiteToTest.queries, noApiKeyStatusErrorCode);
});
2019-12-24 01:19:08 +08:00
function testSystemQueries (description, queries, statusErrorCode, apiKey) {
queries.forEach(function (query) {
it('[' + description + '] query: ' + query, function (done) {
var queryStringParams = { q: query };
if (apiKey) {
2016-12-09 17:56:50 +08:00
queryStringParams.api_key = apiKey;
}
var request = {
2019-12-24 01:19:08 +08:00
headers: { host: 'vizzuality.cartodb.com' },
2016-12-09 17:56:50 +08:00
method: 'GET',
url: '/api/v1/sql?' + querystring.stringify(queryStringParams)
};
2019-12-24 01:19:08 +08:00
assert.response(server, request, function (err, response) {
2019-12-26 21:51:09 +08:00
assert.ifError(err);
2019-12-26 21:01:18 +08:00
assert.strictEqual(response.statusCode, statusErrorCode);
2016-12-09 17:56:50 +08:00
done();
});
});
});
}
});