mirror of
https://github.com/penpot/penpot.git
synced 2026-09-23 20:36:15 +00:00
* ✨ Enable closed schemas for RPC methods * 🐛 Fix duplicate make-dummy-request test helper definition The branch added a variadic DummyRequest/make-dummy-request pair but left the pre-existing single-arg definition in place. Because it was loaded last, zero-arg (make-dummy-request) calls added by prepare-rpc-params and rpc-nitrate-test threw ArityException, which broke 384 tests and caused 14 downstream assertion failures. Remove the stale duplicate so the variadic definition is the only one, and drop the now-unused yrq alias and duplicate yres alias. AI-assisted-by: deepseek-v4.1-flash * ✨ Add focused tests for make-dummy-request helper Pin the call contract of make-dummy-request, which the suite uses in three styles: no arguments, a single options map, and keyword arguments. The helper's redefinition shadowing in 8ca95adb98 was only caught by a full-suite run with hundreds of unrelated errors; these tests fail locally in a focused --focus run. Cover the zero-arg defaults, map and keyword overrides, the :body-bytes -> ByteArrayInputStream wrapping, :body-stream precedence, and cookie readback. Also clarify the docstring to list all supported call styles. AI-assisted-by: deepseek-v4.1-flash * 🚑 Prevent RPC client params from overriding auth context Strip qualified keys from decoded request params before merging them with the server-built auth context, so transit bodies can no longer override ::profile-id, ::auth-type or ::token-perms. Adds a regression test proving the override and the fix. AI-assisted-by: muse-spark-1.3-contributor * 📚 Merge backend subtleties memories under generic name Rename rpc-db-worker-subtleties to subtleties and fold in http-storage-filedata-subtleties, so the name no longer enumerates topics. Update all mem: references accordingly. AI-assisted-by: muse-spark-1.3-contributor * ✨ Add realistic tests for RPC auth override Cover the transit wire vector and the real wrapped :get-profile method with two database profiles, proving a session cannot read another profile by smuggling :app.rpc/profile-id in the body. AI-assisted-by: muse-spark-1.3-contributor * ✨ Add e2e test for RPC auth context override Parametrize rpcPost with contentType, accept and query so e2e can send hand-written transit bodies without new dependencies. The new test proves a transit-smuggled :app.rpc/profile-id no longer overrides the session in get-profile. Also fix the demo email assertion in auth-flow to the current uuid format. AI-assisted-by: muse-spark-1.3-contributor
91 lines
2.2 KiB
JavaScript
91 lines
2.2 KiB
JavaScript
import config from "../config.mjs";
|
|
|
|
async function parseResponse(response) {
|
|
const contentType = response.headers.get("content-type") || "";
|
|
const setCookie = response.headers.get("set-cookie") || null;
|
|
|
|
let body;
|
|
if (contentType.includes("application/json")) {
|
|
body = await response.json();
|
|
} else {
|
|
body = await response.text();
|
|
}
|
|
|
|
return {
|
|
status: response.status,
|
|
headers: response.headers,
|
|
body,
|
|
setCookie,
|
|
};
|
|
}
|
|
|
|
export function extractCookie(setCookieHeader, name = "auth-token") {
|
|
if (!setCookieHeader) return null;
|
|
const match = setCookieHeader.match(new RegExp(`${name}=([^;]+)`));
|
|
return match ? match[1] : null;
|
|
}
|
|
|
|
export async function rpcPost(method, body = {}, { cookieToken, accessToken, contentType, accept, query } = {}) {
|
|
const headers = {
|
|
"Content-Type": contentType || "application/json",
|
|
Accept: accept || "application/json",
|
|
};
|
|
if (cookieToken) {
|
|
headers.Cookie = `auth-token=${cookieToken}`;
|
|
}
|
|
if (accessToken) {
|
|
headers.Authorization = `Token ${accessToken}`;
|
|
}
|
|
|
|
const url = query
|
|
? `${config.baseUrl}/api/main/methods/${method}?${query}`
|
|
: `${config.baseUrl}/api/main/methods/${method}`;
|
|
|
|
const response = await fetch(url, {
|
|
method: "POST",
|
|
headers,
|
|
body: typeof body === "string" ? body : JSON.stringify(body),
|
|
});
|
|
|
|
return parseResponse(response);
|
|
}
|
|
|
|
export async function multipartPost(method, formData, { cookieToken } = {}) {
|
|
const headers = {
|
|
Accept: "application/json",
|
|
};
|
|
if (cookieToken) {
|
|
headers.Cookie = `auth-token=${cookieToken}`;
|
|
}
|
|
|
|
const response = await fetch(`${config.baseUrl}/api/main/methods/${method}`, {
|
|
method: "POST",
|
|
headers,
|
|
body: formData,
|
|
});
|
|
|
|
return parseResponse(response);
|
|
}
|
|
|
|
export async function getAsset(
|
|
id,
|
|
{ cookieToken, accessToken, redirect = "manual" } = {}
|
|
) {
|
|
const headers = { Accept: "application/json" };
|
|
if (cookieToken) {
|
|
headers.Cookie = `auth-token=${cookieToken}`;
|
|
}
|
|
if (accessToken) {
|
|
headers.Authorization = `Token ${accessToken}`;
|
|
}
|
|
|
|
const response = await fetch(`${config.baseUrl}/assets/by-id/${id}`, {
|
|
method: "GET",
|
|
headers,
|
|
redirect,
|
|
});
|
|
|
|
return parseResponse(response);
|
|
}
|
|
|