Koha/t/db_dependent/api/v1/auth.t
Tomas Cohen Arazi ee2931a7b0 Bug 22061: Add a /public namespace that can be switched on/off
This patch adds a check in Koha::REST::V1::Auth::under to catch all
routes that begin with 'public' (inside /api/v1). If they match, and the
RESTPublicAPI syspref is off, then an exception is thrown, rendering a
403 error to the consumer.

Otherwise the routes are processed as usual. This is THE on/off switch
for the public REST API. The target use case: people not wanting an OPAC
or public interaction with the API besides privileged users.

In order to test, the rest of the patches are needed because the only
way to test a route is having it in the spec.

To test:
- Apply the patches
- Run:
  $ kshell
 k$ prove t/db_dependent/api/v1/auth.t
=> SUCCESS: tests pass!
- Sign off :-D

Signed-off-by: Josef Moravec <josef.moravec@gmail.com>

Signed-off-by: Kyle M Hall <kyle@bywatersolutions.com>

Signed-off-by: Nick Clemens <nick@bywatersolutions.com>
2019-01-28 15:45:54 +00:00

131 lines
4.3 KiB
Perl

#!/usr/bin/env perl
# This file is part of Koha.
#
# Koha is free software; you can redistribute it and/or modify it under the
# terms of the GNU General Public License as published by the Free Software
# Foundation; either version 3 of the License, or (at your option) any later
# version.
#
# Koha is distributed in the hope that it will be useful, but WITHOUT ANY
# WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR
# A PARTICULAR PURPOSE. See the GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License along
# with Koha; if not, write to the Free Software Foundation, Inc.,
# 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
use Modern::Perl;
use Test::More tests => 1;
use Test::Mojo;
use Test::Warn;
use t::lib::TestBuilder;
use t::lib::Mocks;
use C4::Auth;
use Koha::Database;
my $schema = Koha::Database->new->schema;
my $builder = t::lib::TestBuilder->new;
# FIXME: sessionStorage defaults to mysql, but it seems to break transaction handling
# this affects the other REST api tests
t::lib::Mocks::mock_preference( 'SessionStorage', 'tmp' );
my $remote_address = '127.0.0.1';
my $t = Test::Mojo->new('Koha::REST::V1');
my $tx;
subtest 'under() tests' => sub {
plan tests => 20;
$schema->storage->txn_begin;
my ($borrowernumber, $session_id) = create_user_and_session();
# disable the /public namespace
t::lib::Mocks::mock_preference( 'RESTPublicAPI', 0 );
$tx = $t->ua->build_tx( POST => "/api/v1/public/patrons/$borrowernumber/password" );
$tx->req->env( { REMOTE_ADDR => $remote_address } );
$t->request_ok($tx)
->status_is(403)
->json_is('/error', 'Configuration prevents the usage of this endpoint by unprivileged users');
# enable the /public namespace
t::lib::Mocks::mock_preference( 'RESTPublicAPI', 1 );
$tx = $t->ua->build_tx( GET => "/api/v1/public/patrons/$borrowernumber/password" );
$tx->req->env( { REMOTE_ADDR => $remote_address } );
$t->request_ok($tx)->status_is(404);
# 401 (no authentication)
$tx = $t->ua->build_tx( GET => "/api/v1/patrons" );
$tx->req->env( { REMOTE_ADDR => $remote_address } );
$t->request_ok($tx)
->status_is(401)
->json_is('/error', 'Authentication failure.');
# 403 (no permission)
$tx = $t->ua->build_tx( GET => "/api/v1/patrons" );
$tx->req->cookies(
{ name => 'CGISESSID', value => $session_id } );
$tx->req->env( { REMOTE_ADDR => $remote_address } );
$t->request_ok($tx)
->status_is(403)
->json_is('/error', 'Authorization failure. Missing required permission(s).');
# 401 (session expired)
t::lib::Mocks::mock_preference( 'timeout', '1' );
($borrowernumber, $session_id) = create_user_and_session();
$tx = $t->ua->build_tx( GET => "/api/v1/patrons" );
$tx->req->cookies(
{ name => 'CGISESSID', value => $session_id } );
$tx->req->env( { REMOTE_ADDR => $remote_address } );
sleep(2);
$t->request_ok($tx)
->status_is(401)
->json_is('/error', 'Session has been expired.');
# 503 (under maintenance & pending update)
t::lib::Mocks::mock_preference('Version', 1);
$tx = $t->ua->build_tx( GET => "/api/v1/patrons" );
$tx->req->env( { REMOTE_ADDR => $remote_address } );
$t->request_ok($tx)
->status_is(503)
->json_is('/error', 'System is under maintenance.');
# 503 (under maintenance & database not installed)
t::lib::Mocks::mock_preference('Version', undef);
$tx = $t->ua->build_tx( GET => "/api/v1/patrons" );
$tx->req->env( { REMOTE_ADDR => $remote_address } );
$t->request_ok($tx)
->status_is(503)
->json_is('/error', 'System is under maintenance.');
$schema->storage->txn_rollback;
};
sub create_user_and_session {
my $user = $builder->build(
{
source => 'Borrower',
value => {
flags => 0
}
}
);
# Create a session for the authorized user
my $session = C4::Auth::get_session('');
$session->param( 'number', $user->{borrowernumber} );
$session->param( 'id', $user->{userid} );
$session->param( 'ip', '127.0.0.1' );
$session->param( 'lasttime', time() );
$session->flush;
return ( $user->{borrowernumber}, $session->id );
}
1;