From 6a92fd3170df2f45960c282c75b6e6b2789b3b10 Mon Sep 17 00:00:00 2001 From: Sandro Santilli Date: Tue, 7 Aug 2012 14:02:42 +0200 Subject: [PATCH] Propagate style changes to caches for unauthenticated requests Closes #41, does it implementing the new afterStyleChange and afterStyleDelete callbacks in Windshaft 0.4.10. Adds automated testcases for the bug. --- lib/cartodb/cartodb_windshaft.js | 33 +++++++++++++++++++++++++++ package.json | 2 +- test/acceptance/server.js | 38 ++++++++++++++++++++++++++++++++ 3 files changed, 72 insertions(+), 1 deletion(-) diff --git a/lib/cartodb/cartodb_windshaft.js b/lib/cartodb/cartodb_windshaft.js index ba331fc3..fafcbce6 100644 --- a/lib/cartodb/cartodb_windshaft.js +++ b/lib/cartodb/cartodb_windshaft.js @@ -25,6 +25,39 @@ var CartodbWindshaft = function(serverOptions) { } } + serverOptions.afterStyleChange = function(req, data, callback) { + if ( req.params.hasOwnProperty('dbuser') ) { + // also change the style of the anonim. request + var params = _.extend(req.params); // make a copy here + delete params.dbuser; + var style = req.body.style; + var that = this; + this.setStyle(params, style, function(err, data) { + if ( err ) callback(err, null); + else that.afterStateChange(req, data, callback); + }); + } else { + console.log("WARNING: map style changed by unauthenticated request!"); + this.afterStateChange(req, data, callback); + } + } + + serverOptions.afterStyleDelete = function(req, data, callback) { + if ( req.params.hasOwnProperty('dbuser') ) { + // also change the style of the anonim. request + var params = _.extend(req.params); // make a copy here + delete params.dbuser; + var that = this; + this.delStyle(params, function(err, data) { + if ( err ) callback(err, null); + else that.afterStateChange(req, data, callback); + }); + } else { + console.log("WARNING: map style deleted by unauthenticated request!"); + this.afterStateChange(req, data, callback); + } + } + // boot diff --git a/package.json b/package.json index 85f4e3e4..7425cfc0 100644 --- a/package.json +++ b/package.json @@ -23,7 +23,7 @@ "node-varnish": "0.1.1", "underscore" : "1.1.x", "grainstore" : "~0.3.0", - "windshaft" : "~0.4.9", + "windshaft" : "~0.4.10", "step": "0.0.x", "generic-pool": "1.0.x", "redis": "0.6.7", diff --git a/test/acceptance/server.js b/test/acceptance/server.js index 23ab46f9..81baceec 100644 --- a/test/acceptance/server.js +++ b/test/acceptance/server.js @@ -103,6 +103,44 @@ suite('server', function() { }); }); + + // TODO: test that unauthenticated DELETE should fail + // See https://github.com/Vizzuality/cartodb-management/issues/155 + + test("delete'ing style returns 200 then getting returns default style", function(done){ + // this is the default style + var style = '#my_table5 {marker-fill: #FF6600;marker-opacity: 1;marker-width: 8;marker-line-color: white;marker-line-width: 3;marker-line-opacity: 0.9;marker-placement: point;marker-type: ellipse;marker-allow-overlap: true;}' + assert.response(server, { + url: '/tiles/my_table5/style?map_key=1234', + method: 'DELETE', + headers: {host: 'localhost'}, + },{}, function(res) { + assert.equal(res.statusCode, 200, res.body); + + // Retrive style with authenticated request + assert.response(server, { + headers: {host: 'localhost'}, + url: '/tiles/my_table5/style?map_key=1234', + method: 'GET' + },{}, function(res) { + assert.equal(res.statusCode, 200, res.body); + assert.deepEqual(JSON.parse(res.body).style, style); + + // Now retrive style with unauthenticated request + assert.response(server, { + headers: {host: 'localhost'}, + url: '/tiles/my_table5/style', + method: 'GET' + }, {}, function(res) { + assert.equal(res.statusCode, 200, res.body); + assert.deepEqual(JSON.parse(res.body).style, style); + + done(); + }); + }); + + }); + }); test("get'ing blank infowindow returns blank", function(done){ assert.response(server, {