Really fix setting or deleting styles from unauth. request

Closes #44
This commit is contained in:
Sandro Santilli
2012-08-14 16:15:41 +02:00
parent 39bc387f97
commit fb3f3a312e
3 changed files with 33 additions and 8 deletions
+8
View File
@@ -25,6 +25,14 @@ var CartodbWindshaft = function(serverOptions) {
}
}
serverOptions.beforeStateChange = function(req, callback) {
var err = null;
if ( ! req.params.hasOwnProperty('dbuser') ) {
err = new Error("map state cannot be changed by unauthenticated request!");
}
callback(err, req);
}
serverOptions.afterStyleChange = function(req, data, callback) {
if ( req.params.hasOwnProperty('dbuser') ) {
// also change the style of the anonim. request
+1 -1
View File
@@ -23,7 +23,7 @@
"node-varnish": "0.1.1",
"underscore" : "1.1.x",
"grainstore" : "~0.3.0",
"windshaft" : "~0.4.10",
"windshaft" : "~0.4.11",
"step": "0.0.x",
"generic-pool": "1.0.x",
"redis": "0.6.7",
+24 -7
View File
@@ -93,7 +93,7 @@ suite('server', function() {
test("post'ing bad style returns 400 with error", function(done){
assert.response(server, {
url: '/tiles/my_table3/style',
url: '/tiles/my_table3/style?map_key=1234',
method: 'POST',
headers: {host: 'vizzuality.localhost.lan', 'Content-Type': 'application/x-www-form-urlencoded' },
data: querystring.stringify({style: '#my_table3{backgxxxxxround-color:#fff;}'})
@@ -105,7 +105,7 @@ suite('server', function() {
test("post'ing multiple bad styles returns 400 with error array", function(done){
assert.response(server, {
url: '/tiles/my_table4/style',
url: '/tiles/my_table4/style?map_key=1234',
method: 'POST',
headers: {host: 'vizzuality.localhost.lan', 'Content-Type': 'application/x-www-form-urlencoded' },
data: querystring.stringify({style: '#my_table4{backgxxxxxround-color:#fff;foo:bar}'})
@@ -133,12 +133,21 @@ suite('server', function() {
url: '/tiles/my_table5/style',
method: 'POST',
headers: {host: 'vizzuality.localhost.lan', 'Content-Type': 'application/x-www-form-urlencoded' },
data: querystring.stringify({style: 'Map {background-color:#fff;}'})
data: querystring.stringify({style: 'Map {background-color:#aaa;}'})
},{}, function(res) {
// fixme: we should really return a 403 here
assert.equal(res.statusCode, 500, res.body);
assert.ok(res.body.indexOf('map style cannot be changed by unauthenticated request') != -1, res.body);
done();
assert.ok(res.body.indexOf('map state cannot be changed by unauthenticated request') != -1, res.body);
assert.response(server, {
headers: {host: 'vizzuality.localhost.lan'},
url: '/tiles/my_table5/style',
method: 'GET'
},{
status: 200,
body: JSON.stringify({style: 'Map {background-color:#fff;}'})
}, function() { done(); });
});
});
@@ -183,8 +192,16 @@ suite('server', function() {
},{}, function(res) {
// fixme: we should really return a 403 here
assert.equal(res.statusCode, 500, res.body);
assert.ok(res.body.indexOf('map style cannot be deleted by unauthenticated request') != -1, res.body);
done();
assert.ok(res.body.indexOf('map state cannot be changed by unauthenticated request') != -1, res.body);
// check that the style wasn't really deleted !
assert.response(server, {
headers: {host: 'vizzuality'},
url: '/tiles/my_table5/style?map_key=1234',
method: 'GET'
},{
status: 200,
body: JSON.stringify({style: 'Map {background-color:#fff;}'})
}, function() { done(); });
});
});