2011-08-25 03:47:10 +08:00
|
|
|
/**
|
|
|
|
*
|
|
|
|
* Requires the database and tables setup in config/environments/test.js to exist
|
|
|
|
* Ensure the user is present in the pgbouncer auth file too
|
|
|
|
* TODO: Add OAuth tests.
|
|
|
|
*
|
|
|
|
* To run this test, ensure that cartodb_test_user_1_db metadata exists in Redis for the vizziality.cartodb.com domain
|
|
|
|
*
|
|
|
|
* SELECT 5
|
|
|
|
* HSET rails:users:vizzuality id 1
|
|
|
|
* HSET rails:users:vizzuality database_name cartodb_dev_user_1_db
|
|
|
|
*
|
|
|
|
*/
|
2011-06-13 11:23:02 +08:00
|
|
|
require('../helper');
|
2011-09-07 19:05:10 +08:00
|
|
|
|
2011-08-25 03:47:10 +08:00
|
|
|
var app = require(global.settings.app_root + '/app/controllers/app')
|
|
|
|
, assert = require('assert')
|
2011-09-07 19:05:10 +08:00
|
|
|
, tests = module.exports = {}
|
|
|
|
, querystring = require('querystring');
|
2011-06-13 11:23:02 +08:00
|
|
|
|
2011-08-25 03:47:10 +08:00
|
|
|
var real_oauth_header = 'OAuth realm="http://vizzuality.testhost.lan/",oauth_consumer_key="fZeNGv5iYayvItgDYHUbot1Ukb5rVyX6QAg8GaY2",oauth_token="l0lPbtP68ao8NfStCiA3V3neqfM03JKhToxhUQTR",oauth_signature_method="HMAC-SHA1", oauth_signature="o4hx4hWP6KtLyFwggnYB4yPK8xI%3D",oauth_timestamp="1313581372",oauth_nonce="W0zUmvyC4eVL8cBd4YwlH1nnPTbxW0QBYcWkXTwe4",oauth_version="1.0"';
|
2011-06-20 21:39:12 +08:00
|
|
|
|
2011-09-07 19:05:10 +08:00
|
|
|
tests['GET /api/v1/sql'] = function(){
|
2011-08-25 03:47:10 +08:00
|
|
|
assert.response(app, {
|
2011-09-07 19:05:10 +08:00
|
|
|
url: '/api/v1/sql',
|
2011-08-25 03:47:10 +08:00
|
|
|
method: 'GET'
|
|
|
|
},{
|
|
|
|
body: '{"error":["You must indicate a sql query"]}',
|
|
|
|
status: 400
|
|
|
|
});
|
|
|
|
};
|
2011-06-10 00:34:02 +08:00
|
|
|
|
2011-09-07 19:05:10 +08:00
|
|
|
tests['GET /api/v1/sql with SQL parameter on SELECT only. No oAuth included '] = function(){
|
2011-08-25 03:47:10 +08:00
|
|
|
assert.response(app, {
|
2011-09-07 19:05:10 +08:00
|
|
|
url: '/api/v1/sql?q=SELECT%20*%20FROM%20untitle_table_4&database=cartodb_dev_user_1_db',
|
2011-08-25 03:47:10 +08:00
|
|
|
method: 'GET'
|
|
|
|
},{
|
|
|
|
status: 200
|
|
|
|
});
|
|
|
|
};
|
2011-08-18 00:27:45 +08:00
|
|
|
|
2011-09-07 19:05:10 +08:00
|
|
|
tests['GET /api/v1/sql with SQL parameter on SELECT only. no database param, just id using headers'] = function(){
|
2011-08-25 03:47:10 +08:00
|
|
|
assert.response(app, {
|
2011-09-07 19:05:10 +08:00
|
|
|
url: '/api/v1/sql?q=SELECT%20*%20FROM%20untitle_table_4',
|
2011-08-25 03:47:10 +08:00
|
|
|
headers: {host: 'vizzuality.cartodb.com'},
|
|
|
|
method: 'GET'
|
|
|
|
},{
|
|
|
|
status: 200
|
|
|
|
});
|
|
|
|
};
|
|
|
|
|
2011-09-07 19:05:10 +08:00
|
|
|
tests['POST /api/v1/sql with SQL parameter on SELECT only. no database param, just id using headers'] = function(){
|
|
|
|
assert.response(app, {
|
|
|
|
url: '/api/v1/sql',
|
|
|
|
data: querystring.stringify({q: "SELECT * FROM untitle_table_4"}),
|
|
|
|
headers: {host: 'vizzuality.cartodb.com', 'Content-Type': 'application/x-www-form-urlencoded' },
|
|
|
|
method: 'POST'
|
|
|
|
},{
|
|
|
|
status: 200
|
|
|
|
});
|
|
|
|
};
|
|
|
|
|
|
|
|
tests['GET /api/v1/sql with SQL parameter on INSERT only. oAuth not used, so public user - should fail'] = function(){
|
2011-08-25 03:47:10 +08:00
|
|
|
assert.response(app, {
|
2011-09-07 19:05:10 +08:00
|
|
|
url: "/api/v1/sql?q=INSERT%20INTO%20untitle_table_4%20(id)%20VALUES%20(1)&database=cartodb_dev_user_1_db",
|
2011-08-25 03:47:10 +08:00
|
|
|
method: 'GET'
|
|
|
|
},{
|
|
|
|
status: 400
|
|
|
|
});
|
|
|
|
};
|
2011-08-18 00:27:45 +08:00
|
|
|
|
2011-09-07 19:05:10 +08:00
|
|
|
tests['GET /api/v1/sql with SQL parameter on DROP DATABASE only. oAuth not used, so public user - should fail'] = function(){
|
2011-06-21 00:03:29 +08:00
|
|
|
assert.response(app, {
|
2011-09-07 19:05:10 +08:00
|
|
|
url: "/api/v1/sql?q=DROP%20TABLE%20untitle_table_4&database=cartodb_dev_user_1_db",
|
2011-08-25 03:47:10 +08:00
|
|
|
method: 'GET'
|
2011-06-21 00:03:29 +08:00
|
|
|
},{
|
2011-08-25 03:47:10 +08:00
|
|
|
status: 400
|
2011-06-21 00:03:29 +08:00
|
|
|
});
|
2011-08-25 03:47:10 +08:00
|
|
|
};
|
|
|
|
|
2011-09-07 19:05:10 +08:00
|
|
|
tests['GET /api/v1/sql with SQL parameter on INSERT only. header based db - should fail'] = function(){
|
2011-06-21 00:22:46 +08:00
|
|
|
assert.response(app, {
|
2011-09-07 19:05:10 +08:00
|
|
|
url: "/api/v1/sql?q=INSERT%20INTO%20untitle_table_4%20(id)%20VALUES%20(1)",
|
2011-08-25 03:47:10 +08:00
|
|
|
headers: {host: 'vizzuality.cartodb.com'},
|
|
|
|
method: 'GET'
|
2011-06-21 00:22:46 +08:00
|
|
|
},{
|
2011-08-25 03:47:10 +08:00
|
|
|
status: 400
|
2011-06-21 00:22:46 +08:00
|
|
|
});
|
2011-06-13 11:23:02 +08:00
|
|
|
};
|
2011-08-25 03:47:10 +08:00
|
|
|
|
2011-09-07 19:05:10 +08:00
|
|
|
tests['GET /api/v1/sql with SQL parameter on DROP DATABASE only.header based db - should fail'] = function(){
|
2011-08-25 03:47:10 +08:00
|
|
|
assert.response(app, {
|
2011-09-07 19:05:10 +08:00
|
|
|
url: "/api/v1/sql?q=DROP%20TABLE%20untitle_table_4",
|
2011-08-25 03:47:10 +08:00
|
|
|
headers: {host: 'vizzuality.cartodb.com'},
|
|
|
|
method: 'GET'
|
|
|
|
},{
|
|
|
|
status: 400
|
|
|
|
});
|
|
|
|
};
|