From 30dab7df9f5717286e4660ee062817adb9e38ebc Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Daniel=20Garc=C3=ADa=20Aubert?= Date: Thu, 15 Mar 2018 18:48:29 +0100 Subject: [PATCH] Extract authorize middeware form prepareContext --- lib/cartodb/controllers/analyses.js | 5 ++++- lib/cartodb/controllers/layergroup.js | 15 ++++++++++++++- lib/cartodb/controllers/map.js | 5 ++++- lib/cartodb/controllers/named_maps.js | 6 +++++- lib/cartodb/middleware/{context => }/authorize.js | 0 lib/cartodb/middleware/context/index.js | 4 +--- lib/cartodb/server.js | 13 ++++++++----- test/unit/cartodb/prepare-context.test.js | 2 +- 8 files changed, 37 insertions(+), 13 deletions(-) rename lib/cartodb/middleware/{context => }/authorize.js (100%) diff --git a/lib/cartodb/controllers/analyses.js b/lib/cartodb/controllers/analyses.js index a04489c4..99c38fcb 100644 --- a/lib/cartodb/controllers/analyses.js +++ b/lib/cartodb/controllers/analyses.js @@ -1,11 +1,13 @@ var PSQL = require('cartodb-psql'); var cors = require('../middleware/cors'); var userMiddleware = require('../middleware/user'); +const authorize = require('../middleware/authorize'); const dbConnSetup = require('../middleware/db-conn-setup'); -function AnalysesController(prepareContext, pgConnection) { +function AnalysesController(prepareContext, pgConnection, authApi) { this.prepareContext = prepareContext; this.pgConnection = pgConnection; + this.authApi = authApi; } module.exports = AnalysesController; @@ -16,6 +18,7 @@ AnalysesController.prototype.register = function (app) { cors(), userMiddleware(), this.prepareContext, + authorize(this.authApi), dbConnSetup(this.pgConnection), createPGClient(), getDataFromQuery({ queryTemplate: catalogQueryTpl, key: 'catalog' }), diff --git a/lib/cartodb/controllers/layergroup.js b/lib/cartodb/controllers/layergroup.js index 30c425f4..834bb0b7 100644 --- a/lib/cartodb/controllers/layergroup.js +++ b/lib/cartodb/controllers/layergroup.js @@ -3,6 +3,7 @@ const userMiddleware = require('../middleware/user'); const allowQueryParams = require('../middleware/allow-query-params'); const vectorError = require('../middleware/vector-error'); const dbConnSetup = require('../middleware/db-conn-setup'); +const authorize = require('../middleware/authorize'); const DataviewBackend = require('../backends/dataview'); const AnalysisStatusBackend = require('../backends/analysis-status'); const MapStoreMapConfigProvider = require('../models/mapconfig/provider/map-store-provider'); @@ -30,7 +31,7 @@ const SUPPORTED_FORMATS = { * @constructor */ function LayergroupController(prepareContext, pgConnection, mapStore, tileBackend, previewBackend, attributesBackend, - surrogateKeysCache, userLimitsApi, layergroupAffectedTables, analysisBackend) { + surrogateKeysCache, userLimitsApi, layergroupAffectedTables, analysisBackend, authApi) { this.pgConnection = pgConnection; this.mapStore = mapStore; this.tileBackend = tileBackend; @@ -44,6 +45,7 @@ function LayergroupController(prepareContext, pgConnection, mapStore, tileBacken this.analysisStatusBackend = new AnalysisStatusBackend(); this.prepareContext = prepareContext; + this.authApi = authApi; } module.exports = LayergroupController; @@ -56,6 +58,7 @@ LayergroupController.prototype.register = function(app) { cors(), userMiddleware(), this.prepareContext, + authorize(this.authApi), dbConnSetup(this.pgConnection), createMapStoreMapConfigProvider(this.mapStore, this.userLimitsApi), getTile(this.tileBackend, 'map_tile'), @@ -76,6 +79,7 @@ LayergroupController.prototype.register = function(app) { cors(), userMiddleware(), this.prepareContext, + authorize(this.authApi), dbConnSetup(this.pgConnection), createMapStoreMapConfigProvider(this.mapStore, this.userLimitsApi), getTile(this.tileBackend, 'map_tile'), @@ -97,6 +101,7 @@ LayergroupController.prototype.register = function(app) { cors(), userMiddleware(), this.prepareContext, + authorize(this.authApi), dbConnSetup(this.pgConnection), createMapStoreMapConfigProvider(this.mapStore, this.userLimitsApi), getTile(this.tileBackend, 'maplayer_tile'), @@ -117,6 +122,7 @@ LayergroupController.prototype.register = function(app) { cors(), userMiddleware(), this.prepareContext, + authorize(this.authApi), dbConnSetup(this.pgConnection), createMapStoreMapConfigProvider(this.mapStore, this.userLimitsApi), getFeatureAttributes(this.attributesBackend), @@ -136,6 +142,7 @@ LayergroupController.prototype.register = function(app) { userMiddleware(), allowQueryParams(['layer']), this.prepareContext, + authorize(this.authApi), dbConnSetup(this.pgConnection), createMapStoreMapConfigProvider(this.mapStore, this.userLimitsApi, forcedFormat), getPreviewImageByCenter(this.previewBackend), @@ -153,6 +160,7 @@ LayergroupController.prototype.register = function(app) { userMiddleware(), allowQueryParams(['layer']), this.prepareContext, + authorize(this.authApi), dbConnSetup(this.pgConnection), createMapStoreMapConfigProvider(this.mapStore, this.userLimitsApi, forcedFormat), getPreviewImageByBoundingBox(this.previewBackend), @@ -188,6 +196,7 @@ LayergroupController.prototype.register = function(app) { userMiddleware(), allowQueryParams(allowedDataviewQueryParams), this.prepareContext, + authorize(this.authApi), dbConnSetup(this.pgConnection), createMapStoreMapConfigProvider(this.mapStore, this.userLimitsApi), getDataview(this.dataviewBackend), @@ -205,6 +214,7 @@ LayergroupController.prototype.register = function(app) { userMiddleware(), allowQueryParams(allowedDataviewQueryParams), this.prepareContext, + authorize(this.authApi), dbConnSetup(this.pgConnection), createMapStoreMapConfigProvider(this.mapStore, this.userLimitsApi), getDataview(this.dataviewBackend), @@ -222,6 +232,7 @@ LayergroupController.prototype.register = function(app) { userMiddleware(), allowQueryParams(allowedDataviewQueryParams), this.prepareContext, + authorize(this.authApi), dbConnSetup(this.pgConnection), createMapStoreMapConfigProvider(this.mapStore, this.userLimitsApi), dataviewSearch(this.dataviewBackend), @@ -239,6 +250,7 @@ LayergroupController.prototype.register = function(app) { userMiddleware(), allowQueryParams(allowedDataviewQueryParams), this.prepareContext, + authorize(this.authApi), dbConnSetup(this.pgConnection), createMapStoreMapConfigProvider(this.mapStore, this.userLimitsApi), dataviewSearch(this.dataviewBackend), @@ -255,6 +267,7 @@ LayergroupController.prototype.register = function(app) { cors(), userMiddleware(), this.prepareContext, + authorize(this.authApi), dbConnSetup(this.pgConnection), analysisNodeStatus(this.analysisStatusBackend), sendResponse() diff --git a/lib/cartodb/controllers/map.js b/lib/cartodb/controllers/map.js index 38f3845f..865b7361 100644 --- a/lib/cartodb/controllers/map.js +++ b/lib/cartodb/controllers/map.js @@ -8,6 +8,7 @@ const cors = require('../middleware/cors'); const userMiddleware = require('../middleware/user'); const allowQueryParams = require('../middleware/allow-query-params'); const dbConnSetup = require('../middleware/db-conn-setup'); +const authorize = require('../middleware/authorize'); const NamedMapsCacheEntry = require('../cache/model/named_maps_entry'); const NamedMapMapConfigProvider = require('../models/mapconfig/provider/named-map-provider'); const CreateLayergroupMapConfigProvider = require('../models/mapconfig/provider/create-layergroup-provider'); @@ -28,7 +29,7 @@ const LayergroupMetadata = require('../utils/layergroup-metadata'); */ function MapController(prepareContext, pgConnection, templateMaps, mapBackend, metadataBackend, surrogateKeysCache, userLimitsApi, layergroupAffectedTables, mapConfigAdapter, - statsBackend) { + statsBackend, authApi) { this.pgConnection = pgConnection; this.templateMaps = templateMaps; this.mapBackend = mapBackend; @@ -43,6 +44,7 @@ function MapController(prepareContext, pgConnection, templateMaps, mapBackend, m this.statsBackend = statsBackend; this.prepareContext = prepareContext; + this.authApi = authApi; } module.exports = MapController; @@ -70,6 +72,7 @@ MapController.prototype.composeCreateMapMiddleware = function (useTemplate = fal userMiddleware(), allowQueryParams(['aggregation']), this.prepareContext, + authorize(this.authApi), dbConnSetup(this.pgConnection), initProfiler(isTemplateInstantiation), checkJsonContentType(), diff --git a/lib/cartodb/controllers/named_maps.js b/lib/cartodb/controllers/named_maps.js index 720f79c1..315a4097 100644 --- a/lib/cartodb/controllers/named_maps.js +++ b/lib/cartodb/controllers/named_maps.js @@ -2,6 +2,7 @@ const NamedMapsCacheEntry = require('../cache/model/named_maps_entry'); const cors = require('../middleware/cors'); const userMiddleware = require('../middleware/user'); const dbConnSetup = require('../middleware/db-conn-setup'); +const authorize = require('../middleware/authorize'); const allowQueryParams = require('../middleware/allow-query-params'); const vectorError = require('../middleware/vector-error'); @@ -29,7 +30,7 @@ function getRequestParams(locals) { } function NamedMapsController(prepareContext, namedMapProviderCache, tileBackend, previewBackend, - surrogateKeysCache, tablesExtentApi, metadataBackend, pgConnection) { + surrogateKeysCache, tablesExtentApi, metadataBackend, pgConnection, authApi) { this.namedMapProviderCache = namedMapProviderCache; this.tileBackend = tileBackend; this.previewBackend = previewBackend; @@ -38,6 +39,7 @@ function NamedMapsController(prepareContext, namedMapProviderCache, tileBackend, this.metadataBackend = metadataBackend; this.prepareContext = prepareContext; this.pgConnection = pgConnection; + this.authApi = authApi; } module.exports = NamedMapsController; @@ -50,6 +52,7 @@ NamedMapsController.prototype.register = function(app) { cors(), userMiddleware(), this.prepareContext, + authorize(this.authApi), dbConnSetup(this.pgConnection), getNamedMapProvider({ namedMapProviderCache: this.namedMapProviderCache, @@ -75,6 +78,7 @@ NamedMapsController.prototype.register = function(app) { userMiddleware(), allowQueryParams(['layer', 'zoom', 'lon', 'lat', 'bbox']), this.prepareContext, + authorize(this.authApi), dbConnSetup(this.pgConnection), getNamedMapProvider({ namedMapProviderCache: this.namedMapProviderCache, diff --git a/lib/cartodb/middleware/context/authorize.js b/lib/cartodb/middleware/authorize.js similarity index 100% rename from lib/cartodb/middleware/context/authorize.js rename to lib/cartodb/middleware/authorize.js diff --git a/lib/cartodb/middleware/context/index.js b/lib/cartodb/middleware/context/index.js index 390dcb5e..59a6095b 100644 --- a/lib/cartodb/middleware/context/index.js +++ b/lib/cartodb/middleware/context/index.js @@ -2,14 +2,12 @@ const locals = require('./locals'); const cleanUpQueryParams = require('./clean-up-query-params'); const layergroupToken = require('./layergroup-token'); const credentials = require('./credentials'); -const authorize = require('./authorize'); -module.exports = function prepareContextMiddleware(authApi) { +module.exports = function prepareContextMiddleware() { return [ locals(), cleanUpQueryParams(), layergroupToken(), credentials(), - authorize(authApi) ]; }; diff --git a/lib/cartodb/server.js b/lib/cartodb/server.js index d2187930..fbbc3c53 100644 --- a/lib/cartodb/server.js +++ b/lib/cartodb/server.js @@ -217,7 +217,7 @@ module.exports = function(serverOptions) { const prepareContext = typeof serverOptions.req2params === 'function' ? serverOptions.req2params : - prepareContextMiddleware(authApi); + prepareContextMiddleware(); /******************************************************************************************************************* * Routing @@ -233,7 +233,8 @@ module.exports = function(serverOptions) { surrogateKeysCache, userLimitsApi, layergroupAffectedTablesCache, - analysisBackend + analysisBackend, + authApi ).register(app); new controller.Map( @@ -246,7 +247,8 @@ module.exports = function(serverOptions) { userLimitsApi, layergroupAffectedTablesCache, mapConfigAdapter, - statsBackend + statsBackend, + authApi ).register(app); new controller.NamedMaps( @@ -257,12 +259,13 @@ module.exports = function(serverOptions) { surrogateKeysCache, tablesExtentApi, metadataBackend, - pgConnection + pgConnection, + authApi ).register(app); new controller.NamedMapsAdmin(authApi, templateMaps).register(app); - new controller.Analyses(prepareContext, pgConnection).register(app); + new controller.Analyses(prepareContext, pgConnection, authApi).register(app); new controller.ServerInfo(versions).register(app); diff --git a/test/unit/cartodb/prepare-context.test.js b/test/unit/cartodb/prepare-context.test.js index 19afce21..ec38b954 100644 --- a/test/unit/cartodb/prepare-context.test.js +++ b/test/unit/cartodb/prepare-context.test.js @@ -8,7 +8,7 @@ var AuthApi = require('../../../lib/cartodb/api/auth_api'); var TemplateMaps = require('../../../lib/cartodb/backends/template_maps'); const cleanUpQueryParamsMiddleware = require('../../../lib/cartodb/middleware/context/clean-up-query-params'); -const authorizeMiddleware = require('../../../lib/cartodb/middleware/context/authorize'); +const authorizeMiddleware = require('../../../lib/cartodb/middleware/authorize'); const dbConnSetupMiddleware = require('../../../lib/cartodb/middleware/db-conn-setup'); const credentialsMiddleware = require('../../../lib/cartodb/middleware/context/credentials'); const localsMiddleware = require('../../../lib/cartodb/middleware/context/locals');