control API access grants

This commit is contained in:
Eneko Lakasta
2018-02-08 13:07:25 +01:00
parent b82d26527a
commit e1a2ee2381
4 changed files with 50 additions and 2 deletions
+28 -1
View File
@@ -44,7 +44,7 @@ describe('authorization', function() {
};
const testClient = new TestClient(mapConfig); //no apikey provided, using default
testClient.getLayergroup({response: {status:403}}, function (err, layergroupResult) {
testClient.getLayergroup({ response: { status: 403 } }, function (err, layergroupResult) { //TODO 401
assert.ifError(err);
assert.ok(layergroupResult.hasOwnProperty('errors'));
@@ -54,4 +54,31 @@ describe('authorization', function() {
testClient.drain(done);
});
});
it('should forbide access to API if API key does not grant access', function (done) {
const apikeyToken = 'regular2';
const mapConfig = {
version: '1.7.0',
layers: [
{
options: {
sql: 'select * FROM test_table_localhost_regular1',
cartocss: TestClient.CARTOCSS.POINTS,
cartocss_version: '2.3.0'
}
}
]
};
const testClient = new TestClient(mapConfig, apikeyToken);
testClient.getLayergroup({ response: { status: 403 } }, function (err, layergroupResult) {
assert.ifError(err);
assert.ok(layergroupResult.hasOwnProperty('errors'));
assert.equal(layergroupResult.errors.length, 1);
assert.ok(layergroupResult.errors[0].match(/Forbidden/), layergroupResult.errors[0]);
testClient.drain(done);
});
});
});