Andrey Antukh 2255266d45
Enable closed schemas for RPC methods (#11136)
*  Enable closed schemas for RPC methods

* 🐛 Fix duplicate make-dummy-request test helper definition

The branch added a variadic DummyRequest/make-dummy-request pair but
left the pre-existing single-arg definition in place. Because it was
loaded last, zero-arg (make-dummy-request) calls added by
prepare-rpc-params and rpc-nitrate-test threw ArityException, which
broke 384 tests and caused 14 downstream assertion failures.

Remove the stale duplicate so the variadic definition is the only
one, and drop the now-unused yrq alias and duplicate yres alias.

AI-assisted-by: deepseek-v4.1-flash

*  Add focused tests for make-dummy-request helper

Pin the call contract of make-dummy-request, which the suite uses
in three styles: no arguments, a single options map, and keyword
arguments. The helper's redefinition shadowing in 8ca95adb98 was
only caught by a full-suite run with hundreds of unrelated errors;
these tests fail locally in a focused --focus run.

Cover the zero-arg defaults, map and keyword overrides, the
:body-bytes -> ByteArrayInputStream wrapping, :body-stream
precedence, and cookie readback. Also clarify the docstring to
list all supported call styles.

AI-assisted-by: deepseek-v4.1-flash

* 🚑 Prevent RPC client params from overriding auth context

Strip qualified keys from decoded request params before merging
them with the server-built auth context, so transit bodies can
no longer override ::profile-id, ::auth-type or ::token-perms.
Adds a regression test proving the override and the fix.

AI-assisted-by: muse-spark-1.3-contributor

* 📚 Merge backend subtleties memories under generic name

Rename rpc-db-worker-subtleties to subtleties and fold in
http-storage-filedata-subtleties, so the name no longer
enumerates topics. Update all mem: references accordingly.

AI-assisted-by: muse-spark-1.3-contributor

*  Add realistic tests for RPC auth override

Cover the transit wire vector and the real wrapped :get-profile
method with two database profiles, proving a session cannot read
another profile by smuggling :app.rpc/profile-id in the body.

AI-assisted-by: muse-spark-1.3-contributor

*  Add e2e test for RPC auth context override

Parametrize rpcPost with contentType, accept and query so e2e
can send hand-written transit bodies without new dependencies.
The new test proves a transit-smuggled :app.rpc/profile-id no
longer overrides the session in get-profile. Also fix the demo
email assertion in auth-flow to the current uuid format.

AI-assisted-by: muse-spark-1.3-contributor
2026-09-22 14:03:02 +02:00

91 lines
2.2 KiB
JavaScript

import config from "../config.mjs";
async function parseResponse(response) {
const contentType = response.headers.get("content-type") || "";
const setCookie = response.headers.get("set-cookie") || null;
let body;
if (contentType.includes("application/json")) {
body = await response.json();
} else {
body = await response.text();
}
return {
status: response.status,
headers: response.headers,
body,
setCookie,
};
}
export function extractCookie(setCookieHeader, name = "auth-token") {
if (!setCookieHeader) return null;
const match = setCookieHeader.match(new RegExp(`${name}=([^;]+)`));
return match ? match[1] : null;
}
export async function rpcPost(method, body = {}, { cookieToken, accessToken, contentType, accept, query } = {}) {
const headers = {
"Content-Type": contentType || "application/json",
Accept: accept || "application/json",
};
if (cookieToken) {
headers.Cookie = `auth-token=${cookieToken}`;
}
if (accessToken) {
headers.Authorization = `Token ${accessToken}`;
}
const url = query
? `${config.baseUrl}/api/main/methods/${method}?${query}`
: `${config.baseUrl}/api/main/methods/${method}`;
const response = await fetch(url, {
method: "POST",
headers,
body: typeof body === "string" ? body : JSON.stringify(body),
});
return parseResponse(response);
}
export async function multipartPost(method, formData, { cookieToken } = {}) {
const headers = {
Accept: "application/json",
};
if (cookieToken) {
headers.Cookie = `auth-token=${cookieToken}`;
}
const response = await fetch(`${config.baseUrl}/api/main/methods/${method}`, {
method: "POST",
headers,
body: formData,
});
return parseResponse(response);
}
export async function getAsset(
id,
{ cookieToken, accessToken, redirect = "manual" } = {}
) {
const headers = { Accept: "application/json" };
if (cookieToken) {
headers.Cookie = `auth-token=${cookieToken}`;
}
if (accessToken) {
headers.Authorization = `Token ${accessToken}`;
}
const response = await fetch(`${config.baseUrl}/assets/by-id/${id}`, {
method: "GET",
headers,
redirect,
});
return parseResponse(response);
}