2021-10-08 07:06:44 -04:00
|
|
|
/*
|
2022-09-24 20:05:30 -04:00
|
|
|
* SPDX-FileCopyrightText: 2022 The HedgeDoc developers (see AUTHORS file)
|
2021-10-08 07:06:44 -04:00
|
|
|
*
|
|
|
|
* SPDX-License-Identifier: AGPL-3.0-only
|
|
|
|
*/
|
|
|
|
import request from 'supertest';
|
|
|
|
|
2022-12-30 06:48:24 -05:00
|
|
|
import {
|
|
|
|
password1,
|
|
|
|
password2,
|
|
|
|
TestSetup,
|
|
|
|
TestSetupBuilder,
|
|
|
|
username1,
|
|
|
|
username2,
|
|
|
|
} from '../test-setup';
|
2021-10-08 07:06:44 -04:00
|
|
|
|
|
|
|
describe('Tokens', () => {
|
2021-10-14 14:17:28 -04:00
|
|
|
let testSetup: TestSetup;
|
2021-10-08 07:06:44 -04:00
|
|
|
let agent: request.SuperAgentTest;
|
2021-10-14 14:17:28 -04:00
|
|
|
|
2021-10-08 07:06:44 -04:00
|
|
|
let keyId: string;
|
|
|
|
|
|
|
|
beforeAll(async () => {
|
2022-06-26 17:26:21 -04:00
|
|
|
testSetup = await TestSetupBuilder.create().withUsers().build();
|
2021-10-14 14:17:28 -04:00
|
|
|
await testSetup.app.init();
|
|
|
|
|
|
|
|
agent = request.agent(testSetup.app.getHttpServer());
|
2021-10-08 07:06:44 -04:00
|
|
|
await agent
|
2021-10-15 10:44:43 -04:00
|
|
|
.post('/api/private/auth/local/login')
|
2022-12-30 06:48:24 -05:00
|
|
|
.send({ username: username1, password: password1 })
|
2021-10-08 07:06:44 -04:00
|
|
|
.expect(201);
|
|
|
|
});
|
|
|
|
|
2022-03-04 07:13:46 -05:00
|
|
|
afterAll(async () => {
|
|
|
|
await testSetup.cleanup();
|
|
|
|
});
|
|
|
|
|
2021-10-08 07:06:44 -04:00
|
|
|
it(`POST /tokens`, async () => {
|
|
|
|
const tokenName = 'testToken';
|
|
|
|
const response = await agent
|
2021-10-15 10:44:43 -04:00
|
|
|
.post('/api/private/tokens')
|
2021-10-08 07:06:44 -04:00
|
|
|
.send({
|
|
|
|
label: tokenName,
|
2022-03-04 12:01:45 -05:00
|
|
|
validUntil: 0,
|
2021-10-08 07:06:44 -04:00
|
|
|
})
|
|
|
|
.expect('Content-Type', /json/)
|
|
|
|
.expect(201);
|
|
|
|
keyId = response.body.keyId;
|
|
|
|
expect(response.body.label).toBe(tokenName);
|
2022-03-04 12:01:45 -05:00
|
|
|
expect(new Date(response.body.validUntil).getTime()).toBeGreaterThan(
|
|
|
|
Date.now(),
|
|
|
|
);
|
2022-01-16 15:52:15 -05:00
|
|
|
expect(response.body.lastUsedAt).toBe(null);
|
2024-03-22 20:14:41 -04:00
|
|
|
expect(response.body.secret.length).toBe(102);
|
2021-10-08 07:06:44 -04:00
|
|
|
});
|
|
|
|
|
|
|
|
it(`GET /tokens`, async () => {
|
2022-06-26 17:26:21 -04:00
|
|
|
const tokenName = 'test';
|
2021-10-08 07:06:44 -04:00
|
|
|
const response = await agent
|
2021-10-15 10:44:43 -04:00
|
|
|
.get('/api/private/tokens/')
|
2021-10-08 07:06:44 -04:00
|
|
|
.expect('Content-Type', /json/)
|
|
|
|
.expect(200);
|
|
|
|
expect(response.body[0].label).toBe(tokenName);
|
2022-03-04 12:01:45 -05:00
|
|
|
expect(new Date(response.body[0].validUntil).getTime()).toBeGreaterThan(
|
|
|
|
Date.now(),
|
|
|
|
);
|
2022-01-16 15:52:15 -05:00
|
|
|
expect(response.body[0].lastUsedAt).toBe(null);
|
2021-10-08 07:06:44 -04:00
|
|
|
expect(response.body[0].secret).not.toBeDefined();
|
|
|
|
});
|
|
|
|
it(`DELETE /tokens/:keyid`, async () => {
|
2022-06-26 17:26:21 -04:00
|
|
|
// try to delete token with wrong user
|
|
|
|
const agent2 = request.agent(testSetup.app.getHttpServer());
|
|
|
|
await agent2
|
|
|
|
.post('/api/private/auth/local/login')
|
2022-12-30 06:48:24 -05:00
|
|
|
.send({ username: username2, password: password2 })
|
2022-06-26 17:26:21 -04:00
|
|
|
.expect(201);
|
|
|
|
let response = await agent2
|
2021-10-15 10:44:43 -04:00
|
|
|
.delete('/api/private/tokens/' + keyId)
|
2022-06-26 17:26:21 -04:00
|
|
|
.expect(401);
|
|
|
|
expect(response.body.statusCode).toEqual(401);
|
|
|
|
|
|
|
|
// delete token with correct user
|
|
|
|
response = await agent.delete('/api/private/tokens/' + keyId).expect(204);
|
2021-10-08 07:06:44 -04:00
|
|
|
expect(response.body).toStrictEqual({});
|
2022-06-26 17:26:21 -04:00
|
|
|
|
|
|
|
// token should be deleted
|
|
|
|
response = await agent
|
2021-10-15 10:44:43 -04:00
|
|
|
.get('/api/private/tokens/')
|
2021-10-08 07:06:44 -04:00
|
|
|
.expect('Content-Type', /json/)
|
|
|
|
.expect(200);
|
2022-09-11 12:19:20 -04:00
|
|
|
const tokenList: { keyId: string }[] = response.body;
|
2022-06-26 17:26:21 -04:00
|
|
|
expect(
|
2022-09-11 12:19:20 -04:00
|
|
|
tokenList.find((token) => {
|
2022-06-26 17:26:21 -04:00
|
|
|
return token.keyId === keyId;
|
|
|
|
}),
|
|
|
|
).toBeUndefined();
|
2021-10-08 07:06:44 -04:00
|
|
|
});
|
|
|
|
});
|