Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Added test for missing authentication token #5450

Merged
merged 8 commits into from
Feb 17, 2023
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
fixed comments
  • Loading branch information
klakhov committed Feb 17, 2023
commit 13201a65e69bbdefdc89c00f17e2074a12edb7b6
62 changes: 28 additions & 34 deletions cvat-core/src/server-proxy.ts
Original file line number Diff line number Diff line change
Expand Up @@ -42,11 +42,6 @@ function configureStorage(storage: Storage, useDefaultLocation = false): Partial
};
}

function removeToken() {
Axios.defaults.headers.common.Authorization = '';
store.remove('token');
}

function waitFor(frequencyHz, predicate) {
return new Promise<void>((resolve, reject) => {
if (typeof predicate !== 'function') {
Expand Down Expand Up @@ -236,6 +231,27 @@ if (token) {
Axios.defaults.headers.common.Authorization = `Token ${token}`;
}

function setAuthData(response) {
if (response.headers['set-cookie']) {
// Browser itself setup cookie and header is none
// In NodeJS we need do it manually
const cookies = response.headers['set-cookie'].join(';');
Axios.defaults.headers.common.Cookie = cookies;
}

if (response.data.key) {
token = response.data.key;
store.set('token', token);
Axios.defaults.headers.common.Authorization = `Token ${token}`;
}
}

function removeAuthData() {
Axios.defaults.headers.common.Authorization = '';
store.remove('token');
token = null;
}

async function about() {
const { backendAPI } = config;

Expand Down Expand Up @@ -334,18 +350,7 @@ async function register(username, firstName, lastName, email, password, confirma
'Content-Type': 'application/json',
},
});
if (response.headers['set-cookie']) {
// Browser itself setup cookie and header is none
// In NodeJS we need do it manually
const cookies = response.headers['set-cookie'].join(';');
Axios.defaults.headers.common.Cookie = cookies;
}
// if email verification isn't required
if (response.data.key) {
token = response.data.key;
store.set('token', token);
Axios.defaults.headers.common.Authorization = `Token ${token}`;
}
setAuthData(response);
} catch (errorData) {
throw generateError(errorData);
}
Expand All @@ -361,7 +366,7 @@ async function login(credential, password) {
.join('&')
.replace(/%20/g, '+');

removeToken();
removeAuthData();
let authenticationResponse = null;
try {
authenticationResponse = await Axios.post(`${config.backendAPI}/auth/login`, authenticationData, {
Expand All @@ -371,16 +376,7 @@ async function login(credential, password) {
throw generateError(errorData);
}

if (authenticationResponse.headers['set-cookie']) {
// Browser itself setup cookie and header is none
// In NodeJS we need do it manually
const cookies = authenticationResponse.headers['set-cookie'].join(';');
Axios.defaults.headers.common.Cookie = cookies;
}

token = authenticationResponse.data.key;
store.set('token', token);
Axios.defaults.headers.common.Authorization = `Token ${token}`;
setAuthData(authenticationResponse);
}

async function loginWithSocialAccount(
Expand All @@ -390,7 +386,7 @@ async function loginWithSocialAccount(
process?: string,
scope?: string,
) {
removeToken();
removeAuthData();
const data = {
code,
...(process ? { process } : {}),
Expand All @@ -407,17 +403,15 @@ async function loginWithSocialAccount(
throw generateError(errorData);
}

token = authenticationResponse.data.key;
store.set('token', token);
Axios.defaults.headers.common.Authorization = `Token ${token}`;
setAuthData(authenticationResponse);
}

async function logout() {
try {
await Axios.post(`${config.backendAPI}/auth/logout`, {
proxy: config.proxy,
});
removeToken();
removeAuthData();
} catch (errorData) {
throw generateError(errorData);
}
Expand Down Expand Up @@ -497,7 +491,7 @@ async function authorized() {
// At first we check if authentication token is present
// Request in getSelf will provide correct authentication cookies
if (!store.get('token')) {
await logout();
removeAuthData();
return false;
}
await getSelf();
Expand Down
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
// Copyright (C) 2020-2022 Intel Corporation
// Copyright (C) 2022 CVAT.ai Corporation
// Copyright (C) 2022-2023 CVAT.ai Corporation
//
// SPDX-License-Identifier: MIT

Expand Down
Original file line number Diff line number Diff line change
@@ -1,10 +1,10 @@
// Copyright (C) 2022 CVAT.ai Corporation
// Copyright (C) 2023 CVAT.ai Corporation
//
// SPDX-License-Identifier: MIT

/// <reference types="cypress" />

context('Check behavior in case of missing authentication data', () => {
context('Check behavior in case of missing authentification data', () => {
const prId = '5331';

before(() => {
Expand Down