2021-10-08 11:06:44 +00:00
|
|
|
/*
|
|
|
|
* SPDX-FileCopyrightText: 2021 The HedgeDoc developers (see AUTHORS file)
|
|
|
|
*
|
|
|
|
* SPDX-License-Identifier: AGPL-3.0-only
|
|
|
|
*/
|
|
|
|
import request from 'supertest';
|
|
|
|
|
|
|
|
import { AuthConfig } from '../../src/config/auth.config';
|
|
|
|
import { User } from '../../src/users/user.entity';
|
|
|
|
import { setupSessionMiddleware } from '../../src/utils/session';
|
2022-01-06 20:41:36 +00:00
|
|
|
import { TestSetup, TestSetupBuilder } from '../test-setup';
|
2021-10-08 11:06:44 +00:00
|
|
|
|
|
|
|
describe('Tokens', () => {
|
2021-10-14 18:17:28 +00:00
|
|
|
let testSetup: TestSetup;
|
2021-10-08 11:06:44 +00:00
|
|
|
let agent: request.SuperAgentTest;
|
2021-10-14 18:17:28 +00:00
|
|
|
|
|
|
|
let user: User;
|
2021-10-08 11:06:44 +00:00
|
|
|
let keyId: string;
|
|
|
|
|
|
|
|
beforeAll(async () => {
|
2022-01-06 20:41:36 +00:00
|
|
|
testSetup = await TestSetupBuilder.create().build();
|
2021-10-14 18:17:28 +00:00
|
|
|
|
|
|
|
user = await testSetup.userService.createUser('hardcoded', 'Testy');
|
|
|
|
await testSetup.identityService.createLocalIdentity(user, 'test');
|
|
|
|
|
|
|
|
const authConfig = testSetup.configService.get('authConfig') as AuthConfig;
|
|
|
|
setupSessionMiddleware(testSetup.app, authConfig);
|
|
|
|
|
|
|
|
await testSetup.app.init();
|
|
|
|
|
|
|
|
agent = request.agent(testSetup.app.getHttpServer());
|
2021-10-08 11:06:44 +00:00
|
|
|
await agent
|
2021-10-15 14:44:43 +00:00
|
|
|
.post('/api/private/auth/local/login')
|
2021-10-08 11:06:44 +00:00
|
|
|
.send({ username: 'hardcoded', password: 'test' })
|
|
|
|
.expect(201);
|
|
|
|
});
|
|
|
|
|
2022-03-04 12:13:46 +00:00
|
|
|
afterAll(async () => {
|
|
|
|
await testSetup.cleanup();
|
|
|
|
});
|
|
|
|
|
2021-10-08 11:06:44 +00:00
|
|
|
it(`POST /tokens`, async () => {
|
|
|
|
const tokenName = 'testToken';
|
|
|
|
const response = await agent
|
2021-10-15 14:44:43 +00:00
|
|
|
.post('/api/private/tokens')
|
2021-10-08 11:06:44 +00:00
|
|
|
.send({
|
|
|
|
label: tokenName,
|
|
|
|
})
|
|
|
|
.expect('Content-Type', /json/)
|
|
|
|
.expect(201);
|
|
|
|
keyId = response.body.keyId;
|
|
|
|
expect(response.body.label).toBe(tokenName);
|
|
|
|
expect(response.body.validUntil).toBe(null);
|
2022-01-16 20:52:15 +00:00
|
|
|
expect(response.body.lastUsedAt).toBe(null);
|
2021-12-09 22:04:00 +00:00
|
|
|
expect(response.body.secret.length).toBe(98);
|
2021-10-08 11:06:44 +00:00
|
|
|
});
|
|
|
|
|
|
|
|
it(`GET /tokens`, async () => {
|
|
|
|
const tokenName = 'testToken';
|
|
|
|
const response = await agent
|
2021-10-15 14:44:43 +00:00
|
|
|
.get('/api/private/tokens/')
|
2021-10-08 11:06:44 +00:00
|
|
|
.expect('Content-Type', /json/)
|
|
|
|
.expect(200);
|
|
|
|
expect(response.body[0].label).toBe(tokenName);
|
|
|
|
expect(response.body[0].validUntil).toBe(null);
|
2022-01-16 20:52:15 +00:00
|
|
|
expect(response.body[0].lastUsedAt).toBe(null);
|
2021-10-08 11:06:44 +00:00
|
|
|
expect(response.body[0].secret).not.toBeDefined();
|
|
|
|
});
|
|
|
|
it(`DELETE /tokens/:keyid`, async () => {
|
2021-10-15 14:44:43 +00:00
|
|
|
const response = await agent
|
|
|
|
.delete('/api/private/tokens/' + keyId)
|
|
|
|
.expect(204);
|
2021-10-08 11:06:44 +00:00
|
|
|
expect(response.body).toStrictEqual({});
|
|
|
|
});
|
|
|
|
it(`GET /tokens 2`, async () => {
|
|
|
|
const response = await agent
|
2021-10-15 14:44:43 +00:00
|
|
|
.get('/api/private/tokens/')
|
2021-10-08 11:06:44 +00:00
|
|
|
.expect('Content-Type', /json/)
|
|
|
|
.expect(200);
|
|
|
|
expect(response.body).toStrictEqual([]);
|
|
|
|
});
|
|
|
|
});
|