Add coordinates validation to specific endpoints
This commit is contained in:
@@ -1,6 +1,7 @@
|
||||
const cors = require('../../middleware/cors');
|
||||
const user = require('../../middleware/user');
|
||||
const layergroupToken = require('../../middleware/layergroup-token');
|
||||
const coordinates = require('../../middleware/coordinates');
|
||||
const cleanUpQueryParams = require('../../middleware/clean-up-query-params');
|
||||
const credentials = require('../../middleware/credentials');
|
||||
const dbConnSetup = require('../../middleware/db-conn-setup');
|
||||
@@ -43,6 +44,7 @@ module.exports = class StaticController {
|
||||
cors(),
|
||||
user(),
|
||||
layergroupToken(),
|
||||
coordinates({ z: true, x: false, y: false }),
|
||||
credentials(),
|
||||
authorize(this.authApi),
|
||||
dbConnSetup(this.pgConnection),
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
const cors = require('../../middleware/cors');
|
||||
const user = require('../../middleware/user');
|
||||
const layergroupToken = require('../../middleware/layergroup-token');
|
||||
const coordinates = require('../../middleware/coordinates');
|
||||
const cleanUpQueryParams = require('../../middleware/clean-up-query-params');
|
||||
const credentials = require('../../middleware/credentials');
|
||||
const dbConnSetup = require('../../middleware/db-conn-setup');
|
||||
@@ -51,6 +52,7 @@ module.exports = class TileController {
|
||||
cors(),
|
||||
user(),
|
||||
layergroupToken(),
|
||||
coordinates(),
|
||||
credentials(),
|
||||
authorize(this.authApi),
|
||||
dbConnSetup(this.pgConnection),
|
||||
@@ -79,6 +81,7 @@ module.exports = class TileController {
|
||||
cors(),
|
||||
user(),
|
||||
layergroupToken(),
|
||||
coordinates(),
|
||||
credentials(),
|
||||
authorize(this.authApi),
|
||||
dbConnSetup(this.pgConnection),
|
||||
@@ -108,6 +111,7 @@ module.exports = class TileController {
|
||||
cors(),
|
||||
user(),
|
||||
layergroupToken(),
|
||||
coordinates(),
|
||||
credentials(),
|
||||
authorize(this.authApi),
|
||||
dbConnSetup(this.pgConnection),
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
const cors = require('../middleware/cors');
|
||||
const user = require('../middleware/user');
|
||||
const cleanUpQueryParams = require('../middleware/clean-up-query-params');
|
||||
const coordinates = require('../middleware/coordinates');
|
||||
const credentials = require('../middleware/credentials');
|
||||
const dbConnSetup = require('../middleware/db-conn-setup');
|
||||
const authorize = require('../middleware/authorize');
|
||||
@@ -56,6 +57,7 @@ NamedMapsController.prototype.register = function(app) {
|
||||
`${templateBasePath}/:template_id/:layer/:z/:x/:y.(:format)`,
|
||||
cors(),
|
||||
user(),
|
||||
coordinates(),
|
||||
credentials(),
|
||||
authorize(this.authApi),
|
||||
dbConnSetup(this.pgConnection),
|
||||
|
||||
@@ -0,0 +1,32 @@
|
||||
module.exports = function coordinates (validate = { z: true, x: true, y: true }) {
|
||||
const positiveIntegerNumber = /^\d+$/;
|
||||
const integerNumber = /^-?\d+$/;
|
||||
|
||||
return function coordinatesMiddleware (req, res, next) {
|
||||
const { z, x, y } = req.params;
|
||||
|
||||
if (validate.z && !positiveIntegerNumber.test(z)) {
|
||||
const err = new Error(`Invalid zoom value (${z}). It should be a positive number`);
|
||||
err.http_status = 400;
|
||||
|
||||
return next(err);
|
||||
}
|
||||
|
||||
// Negatives values for x param are valid. The x param is wrapped
|
||||
if (validate.x && !integerNumber.test(x)) {
|
||||
const err = new Error(`Invalid coodinate 'x' value (${x}). It should be a number`);
|
||||
err.http_status = 400;
|
||||
|
||||
return next(err);
|
||||
}
|
||||
|
||||
if (validate.y && !positiveIntegerNumber.test(y)) {
|
||||
const err = new Error(`Invalid coodinate 'y' value (${y}). It should be a positive number`);
|
||||
err.http_status = 400;
|
||||
|
||||
return next(err);
|
||||
}
|
||||
|
||||
next();
|
||||
};
|
||||
};
|
||||
@@ -905,7 +905,7 @@ TestClient.prototype.getLayergroup = function (params, callback) {
|
||||
TestClient.prototype.getStaticCenter = function (params, callback) {
|
||||
var self = this;
|
||||
|
||||
let { layergroupid, z, lat, lng, width, height, format } = params;
|
||||
let { layergroupid, zoom, lat, lng, width, height, format } = params;
|
||||
|
||||
var url = `/api/v1/map/`;
|
||||
|
||||
@@ -954,7 +954,7 @@ TestClient.prototype.getStaticCenter = function (params, callback) {
|
||||
self.keysToDelete['map_cfg|' + LayergroupToken.parse(layergroupId).token] = 0;
|
||||
self.keysToDelete['user:localhost:mapviews:global'] = 5;
|
||||
|
||||
url = `/api/v1/map/static/center/${layergroupId}/${z}/${lat}/${lng}/${width}/${height}.${format}`;
|
||||
url = `/api/v1/map/static/center/${layergroupId}/${zoom}/${lat}/${lng}/${width}/${height}.${format}`;
|
||||
|
||||
if (self.apiKey) {
|
||||
url += '?' + qs.stringify({api_key: self.apiKey});
|
||||
|
||||
@@ -0,0 +1,215 @@
|
||||
const assert = require('assert');
|
||||
const coordinates = require('../../../../lib/cartodb/middleware/coordinates');
|
||||
|
||||
describe('coordinates middleware', function () {
|
||||
it('should return error: invalid zoom paramenter (-1)', function (done) {
|
||||
const coords = coordinates();
|
||||
const req = {
|
||||
params: {
|
||||
z: '-1',
|
||||
x: '0',
|
||||
y: '0'
|
||||
}
|
||||
};
|
||||
const res = {};
|
||||
|
||||
coords(req, res, function (err) {
|
||||
assert.equal(err.message, 'Invalid zoom value (-1). It should be a positive number');
|
||||
assert.equal(err.http_status, 400);
|
||||
done();
|
||||
});
|
||||
});
|
||||
|
||||
it('should return error: invalid zoom paramenter (1.1)', function (done) {
|
||||
const coords = coordinates();
|
||||
const req = {
|
||||
params: {
|
||||
z: '1.1',
|
||||
x: '0',
|
||||
y: '0'
|
||||
}
|
||||
};
|
||||
const res = {};
|
||||
|
||||
coords(req, res, function (err) {
|
||||
assert.equal(err.message, 'Invalid zoom value (1.1). It should be a positive number');
|
||||
assert.equal(err.http_status, 400);
|
||||
done();
|
||||
});
|
||||
});
|
||||
|
||||
it('should return error: invalid zoom paramenter (wadus)', function (done) {
|
||||
const coords = coordinates();
|
||||
const req = {
|
||||
params: {
|
||||
z: 'wadus',
|
||||
x: '0',
|
||||
y: '0'
|
||||
}
|
||||
};
|
||||
const res = {};
|
||||
|
||||
coords(req, res, function (err) {
|
||||
assert.equal(err.message, 'Invalid zoom value (wadus). It should be a positive number');
|
||||
assert.equal(err.http_status, 400);
|
||||
done();
|
||||
});
|
||||
});
|
||||
|
||||
it('should NOT return error: \'zoom\' paramenter (1)', function (done) {
|
||||
const coords = coordinates();
|
||||
const req = {
|
||||
params: {
|
||||
z: '1',
|
||||
x: '1',
|
||||
y: '0'
|
||||
}
|
||||
};
|
||||
const res = {};
|
||||
|
||||
coords(req, res, function (err) {
|
||||
assert.ifError(err);
|
||||
done();
|
||||
});
|
||||
});
|
||||
|
||||
it('should return error: invalid coordinate \'x\' paramenter (1.1)', function (done) {
|
||||
const coords = coordinates();
|
||||
const req = {
|
||||
params: {
|
||||
z: '1',
|
||||
x: '1.1',
|
||||
y: '0'
|
||||
}
|
||||
};
|
||||
const res = {};
|
||||
|
||||
coords(req, res, function (err) {
|
||||
assert.equal(err.message, `Invalid coodinate 'x' value (1.1). It should be a number`);
|
||||
assert.equal(err.http_status, 400);
|
||||
done();
|
||||
});
|
||||
});
|
||||
|
||||
it('should return error: invalid coordinate \'x\' paramenter (wadus)', function (done) {
|
||||
const coords = coordinates();
|
||||
const req = {
|
||||
params: {
|
||||
z: '1',
|
||||
x: 'wadus',
|
||||
y: '0'
|
||||
}
|
||||
};
|
||||
const res = {};
|
||||
|
||||
coords(req, res, function (err) {
|
||||
assert.equal(err.message, `Invalid coodinate 'x' value (wadus). It should be a number`);
|
||||
assert.equal(err.http_status, 400);
|
||||
done();
|
||||
});
|
||||
});
|
||||
|
||||
it('should NOT return error: \'x\' paramenter (-1)', function (done) {
|
||||
const coords = coordinates();
|
||||
const req = {
|
||||
params: {
|
||||
z: '1',
|
||||
x: '-3',
|
||||
y: '0'
|
||||
}
|
||||
};
|
||||
const res = {};
|
||||
|
||||
coords(req, res, function (err) {
|
||||
assert.ifError(err);
|
||||
done();
|
||||
});
|
||||
});
|
||||
|
||||
it('should return error: invalid coordinate \'y\' paramenter (-1)', function (done) {
|
||||
const coords = coordinates();
|
||||
const req = {
|
||||
params: {
|
||||
z: '1',
|
||||
x: '0',
|
||||
y: '-1'
|
||||
}
|
||||
};
|
||||
const res = {};
|
||||
|
||||
coords(req, res, function (err) {
|
||||
assert.equal(err.message, `Invalid coodinate 'y' value (-1). It should be a positive number`);
|
||||
assert.equal(err.http_status, 400);
|
||||
done();
|
||||
});
|
||||
});
|
||||
|
||||
it('should return error: invalid coordinate \'y\' paramenter (1.1)', function (done) {
|
||||
const coords = coordinates();
|
||||
const req = {
|
||||
params: {
|
||||
z: '1',
|
||||
x: '0',
|
||||
y: '1.1'
|
||||
}
|
||||
};
|
||||
const res = {};
|
||||
|
||||
coords(req, res, function (err) {
|
||||
assert.equal(err.message, `Invalid coodinate 'y' value (1.1). It should be a positive number`);
|
||||
assert.equal(err.http_status, 400);
|
||||
done();
|
||||
});
|
||||
});
|
||||
|
||||
it('should return error: invalid coordinate \'y\' paramenter (wadus)', function (done) {
|
||||
const coords = coordinates();
|
||||
const req = {
|
||||
params: {
|
||||
z: '1',
|
||||
x: '0',
|
||||
y: 'wadus'
|
||||
}
|
||||
};
|
||||
const res = {};
|
||||
|
||||
coords(req, res, function (err) {
|
||||
assert.equal(err.message, `Invalid coodinate 'y' value (wadus). It should be a positive number`);
|
||||
assert.equal(err.http_status, 400);
|
||||
done();
|
||||
});
|
||||
});
|
||||
|
||||
it('should NOT return error: \'y\' paramenter (1)', function (done) {
|
||||
const coords = coordinates();
|
||||
const req = {
|
||||
params: {
|
||||
z: '1',
|
||||
x: '1',
|
||||
y: '1'
|
||||
}
|
||||
};
|
||||
const res = {};
|
||||
|
||||
coords(req, res, function (err) {
|
||||
assert.ifError(err);
|
||||
done();
|
||||
});
|
||||
});
|
||||
|
||||
it('should validate zoom and should return error: invalid zoom paramenter (-1.1)', function (done) {
|
||||
const coords = coordinates({ z: true, x: false, y: false });
|
||||
const req = {
|
||||
params: {
|
||||
z: '-1.1'
|
||||
}
|
||||
};
|
||||
const res = {};
|
||||
|
||||
coords(req, res, function (err) {
|
||||
assert.equal(err.message, 'Invalid zoom value (-1.1). It should be a positive number');
|
||||
assert.equal(err.http_status, 400);
|
||||
done();
|
||||
});
|
||||
});
|
||||
});
|
||||
Reference in New Issue
Block a user