TASK22224: harden setupcontainer hash compatibility parity
This commit is contained in:
@@ -1,10 +1,4 @@
|
|||||||
import {
|
import { createContainer } from "../../../actions/azurestorage";
|
||||||
createContainer,
|
|
||||||
createContainerSas,
|
|
||||||
getContainers,
|
|
||||||
getBlobs,
|
|
||||||
uploadFile
|
|
||||||
} from "../../../actions/azurestorage";
|
|
||||||
import { hashAPIPath } from "../../../actions/core/hash";
|
import { hashAPIPath } from "../../../actions/core/hash";
|
||||||
import { consoleLogger } from "../../../actions/core/logger";
|
import { consoleLogger } from "../../../actions/core/logger";
|
||||||
import { respondError, respondSuccess } from "../middleware/apiResponse";
|
import { respondError, respondSuccess } from "../middleware/apiResponse";
|
||||||
@@ -16,8 +10,8 @@ const ApiProxy = nextConnect();
|
|||||||
ApiProxy.use(middleware);
|
ApiProxy.use(middleware);
|
||||||
|
|
||||||
ApiProxy.get(async (req, res) => {
|
ApiProxy.get(async (req, res) => {
|
||||||
var containerName = req.query.ident;
|
const containerName = req.query.ident;
|
||||||
var checkHash = req.query.hash;
|
const checkHash = req.query.hash;
|
||||||
|
|
||||||
if (
|
if (
|
||||||
typeof containerName === "undefined" ||
|
typeof containerName === "undefined" ||
|
||||||
@@ -32,9 +26,19 @@ ApiProxy.get(async (req, res) => {
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
var checkquerypath = "/api/file/setupcontainer?ident=" + containerName;
|
const containerNameTrimmed = containerName.trim();
|
||||||
|
|
||||||
if (hashAPIPath(checkquerypath) != "&hash=" + checkHash) {
|
const hashCandidatePaths = [
|
||||||
|
"/api/file/setupcontainer?ident=" + containerNameTrimmed,
|
||||||
|
"/api/file/setupcontainer?ident=" +
|
||||||
|
encodeURIComponent(containerNameTrimmed)
|
||||||
|
];
|
||||||
|
|
||||||
|
const isHashValid = hashCandidatePaths.some(
|
||||||
|
(candidatePath) => hashAPIPath(candidatePath) == "&hash=" + checkHash
|
||||||
|
);
|
||||||
|
|
||||||
|
if (!isHashValid) {
|
||||||
return respondError(res, {
|
return respondError(res, {
|
||||||
status: 400,
|
status: 400,
|
||||||
code: "INVALID_HASH",
|
code: "INVALID_HASH",
|
||||||
@@ -42,18 +46,17 @@ ApiProxy.get(async (req, res) => {
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
await createContainer(containerName)
|
try {
|
||||||
.then((data) => {
|
const data = await createContainer(containerNameTrimmed);
|
||||||
return respondSuccess(res, { data: "success", output: data });
|
return respondSuccess(res, { data: "success", output: data });
|
||||||
})
|
} catch (error) {
|
||||||
.catch((error) => {
|
consoleLogger(error);
|
||||||
consoleLogger(error);
|
return respondError(res, {
|
||||||
return respondError(res, {
|
status: 400,
|
||||||
status: 400,
|
code: "SETUP_CONTAINER_FAILED",
|
||||||
code: "SETUP_CONTAINER_FAILED",
|
message: "Failed to setup container"
|
||||||
message: "Failed to setup container"
|
|
||||||
});
|
|
||||||
});
|
});
|
||||||
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
export const config = {
|
export const config = {
|
||||||
|
|||||||
@@ -596,6 +596,31 @@ test("setupcontainer handler returns MISSING_REQUIRED_QUERY when ident missing",
|
|||||||
assert.strictEqual(res.state.jsonBody.error.code, "MISSING_REQUIRED_QUERY");
|
assert.strictEqual(res.state.jsonBody.error.code, "MISSING_REQUIRED_QUERY");
|
||||||
});
|
});
|
||||||
|
|
||||||
|
test("setupcontainer handler accepts encoded ident hash variant", async () => {
|
||||||
|
const mod = loadModule("pages/api/file/setupcontainer.js", {
|
||||||
|
nextConnect: createNextConnectMock(),
|
||||||
|
middleware: () => {},
|
||||||
|
hashAPIPath: (queryPath) =>
|
||||||
|
queryPath.includes("ident=container%2Fname")
|
||||||
|
? "&hash=expected"
|
||||||
|
: "&hash=other",
|
||||||
|
consoleLogger: () => {},
|
||||||
|
respondError: respondErrorMock,
|
||||||
|
respondSuccess: respondSuccessMock,
|
||||||
|
createContainer: async () => ({ created: true })
|
||||||
|
});
|
||||||
|
|
||||||
|
const req = { query: { ident: "container/name", hash: "expected" } };
|
||||||
|
const res = createRes();
|
||||||
|
await mod.default.handler(req, res);
|
||||||
|
|
||||||
|
assert.strictEqual(res.state.statusCode, 200);
|
||||||
|
assert.deepStrictEqual(JSON.parse(JSON.stringify(res.state.jsonBody)), {
|
||||||
|
data: "success",
|
||||||
|
output: { created: true }
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
test("upload handler success returns data payload with 200", async () => {
|
test("upload handler success returns data payload with 200", async () => {
|
||||||
const mod = loadModule("pages/api/file/upload.js", {
|
const mod = loadModule("pages/api/file/upload.js", {
|
||||||
nextConnect: createNextConnectMock(),
|
nextConnect: createNextConnectMock(),
|
||||||
|
|||||||
Reference in New Issue
Block a user