From 06ca789f92ad2f4dfaffc36d3fa0bafb3c74920d Mon Sep 17 00:00:00 2001 From: John Chilton Date: Wed, 9 Aug 2017 15:35:15 -0400 Subject: [PATCH] Configuration tests for the last few upload enhancements. --- test-data/1.sam.gz | Bin 0 -> 1249 bytes test-data/bad.html.gz | Bin 0 -> 78 bytes test-data/random-file | Bin 0 -> 1024 bytes .../tools/sample_datatypes_conf.xml | 1 + .../test_upload_configuration_options.py | 129 ++++++++++++++++++ 5 files changed, 130 insertions(+) create mode 100644 test-data/1.sam.gz create mode 100644 test-data/bad.html.gz create mode 100644 test-data/random-file create mode 100644 test/integration/test_upload_configuration_options.py diff --git a/test-data/1.sam.gz b/test-data/1.sam.gz new file mode 100644 index 0000000000000000000000000000000000000000..542e9b365b7e271ca1b24b255f95aedb229147a9 GIT binary patch literal 1249 zcmV<71RnbziwFpbXK+{m12HahVQm1dR>@N1NDw{O{DqNZ13k2BlS**qY7hcKWnnjh)Vz zyRYq>HS@=YHTd#=algG|i@O<{E$st)n)=^_GUZN)ostzRDt5^@9GCHGYwKKH*Lc<* zuinGGXIYYb871KZ_elyzlAb3Aa6+jgJo@j5;|LB;@A1kI0x{AdL8c=DOwx#F;9pt3 zjn5+zfH**L-dcyx)_azW0v<${A#|FCSP${u1{i_@2nwzClrTK8BnFg3pzbaJ%6uoe z%HIa)eC+~M2-7-GR5D;~6hVerl0kqOy*k9}V-NvpKP<)SC`w|G_5yGy*>n6F4zmbY z?u_BAtk~cG{1W2pzd!$)h%2GA&ZR0fGg2s_@`5SDglWWm-msgOw~&Z+7`q2SSUQ1f z_+p%oxf~4mcq}C6Qt-h*>#<;KKe3Y~bIs)EM6v~50NUb}vo(hc{6>VQCOkcbOHG&N zcCwvFc@VuQ#Yf?DCiPL|fqO>>ZUoT=?^p_Y&4{p!Hk6dI-%_P^qSCMhLgAt^t|_&w zav^ku(MWA7kP$4Z8j4KrBa=#3xzbDvBY4H}N3e3=!KSnM^RjtdZ|2kGdb3`w7f*|A z+XM>dfkGZAL?duJ`OYHaysGuR4iM}W~=RHIe*@))@{34 z`^Bbhx1XAe-kGwmRr%1NP@&YP@Wx}MrBoKMx5G3ETl}iEM7W+pLo6ybZ&CKB8&7xu zmu94v&;mkV7)Cs(+(LnBa$>rOES6;{jm$L@RbfPFI-+m77lvJlURI%LFk^D9Cf9kM zoaw>vrYdwUO8fnQRoTa?4mAdm1!m<*W@G54IvKh-4juYvzqY+&4|hg$d3&q$kB5mg z_RqWT-?Wk+>p>Rz{}6))VV6ap7+~)$m3b!zYLy^{bDec9yzA-EFAv~)#DHjZ99EuW zLGz2H*?u6Pw!+gW83nvt>;zB*YB2AVRK=B+T9o_7_4GmcRqaW8^};)c!i!t(sc3;cO9MQ*fGoIzxw41;V@Z;Gq+miq$0Y_js z58!&-5h{`lpzkaQiW100tl{1ug$m2Eh*wB(Gt%_ABit@@Z0M74*RV`M;OF36(qIXL zIf`|4h}Y{c(Okwa@`mKV*kzJj{65AMFEDeFCZp^tWd0hkXQ)uZ!D5AsDR~GG20+*Q z;pT$!fAJ0-Uf)y+0ChAaA!7(|3`yRccXm3t06&;s!8S!eG^|z5q5*o-nq^^BB@}-d z-<$Z8+!zBQ)+~oc3>YeyTo8drim*Uj=+-r}+tq5jXa{Gr$Mv>-p0#Z|mTmj-m{A8( zJvn5$Ohh40hY8itxvEp?qIN8b8u>)qj%~|1)~=o*{C2f!_n+yq%Vl{mcuv;cJLBg+ Le0;NNzO=ARMNDz(TB>|=tC6hgLQEM0RCm8sXYJy05eh|bN~PV literal 0 HcmV?d00001 diff --git a/test-data/random-file b/test-data/random-file new file mode 100644 index 0000000000000000000000000000000000000000..9f53451616d7db16dda09e13eb5981d33c3003a6 GIT binary patch literal 1024 zcmV+b1poVL8Jrz<;S`_N<&@WzTrgmQHshY?&~ysRv_VZ)!~2slOe>cDr*XU!V}I<@ zzy52`y180gjFhQ~40SaD2p#(X{(*zbY8pJ&__I#1R)k6O%=K z{l5W2GjNjrj_KC5x($YIAuTC&NQuN7gKYLgm_!=HxNYz-csKMDemB34v{-H zP)y5DM;S3QWjjFRTQ#HDRj2dpJoOiaC1daWg_4fDf0@Cd$iD zj>Iq>mgXt5gCLh6cE|>{XUdg?R=fj1(oNLKUUq6u<$g^l@p0)yDn`HJH!&(u0xdoK z#CIuJOKuDGoeJg@*R51o)BI9kJth3-?Pn`P~OwPN2i;4m8>kTLz z9Jmpu`XU+bo7cEKufE{9lDPL2BvEZaL8fMc9}I8#|6{BN1!&+Ozua{SmzZv>K#KkukqF~p zac3nBm!T)WK{|j+jOI?S1N8p;)C9hyz(d7V;`9?+>4bu!rDC)cOK< z)|3x8uF9Mn&W)XhO@ECB!k;`l4l_Xo+Tqd(#ggKzRmFOM&IFpc+PTK2JKy9NI^K#s u*#j9ZDV%Ud;|{eOVPCZ*0EuE*EQHf|#x{infZjZ#RiU3~# literal 0 HcmV?d00001 diff --git a/test/functional/tools/sample_datatypes_conf.xml b/test/functional/tools/sample_datatypes_conf.xml index 0431842db02..75e562603b9 100644 --- a/test/functional/tools/sample_datatypes_conf.xml +++ b/test/functional/tools/sample_datatypes_conf.xml @@ -24,5 +24,6 @@ + diff --git a/test/integration/test_upload_configuration_options.py b/test/integration/test_upload_configuration_options.py new file mode 100644 index 00000000000..c006b667897 --- /dev/null +++ b/test/integration/test_upload_configuration_options.py @@ -0,0 +1,129 @@ +"""Integration tests various upload aspects. + +This file checks upload options that require different non-default Galaxy +configuration options. More vanilla upload options and behaviors are tested +with the API test framework (located in test_tools.py). + +These options include: + - The config optiond check_upload_content and allow_path_paste. + - The upload API parameter auto_decompress. + - Checking for malicious content in uploads of compressed files. + - Restricting file:// uploads to admins and allowing them only when + allow_path_paste is set to True. +""" + +import os + +from base import integration_util +from base.populators import DatasetPopulator + +SCRIPT_DIR = os.path.normpath(os.path.dirname(__file__)) +TEST_DATA_DIRECTORY = os.path.join(SCRIPT_DIR, os.pardir, os.pardir, "test-data") + + +class BaseCheckUploadContentConfigurationTestCase(integration_util.IntegrationTestCase): + + framework_tool_and_types = True + + def setUp(self): + super(BaseCheckUploadContentConfigurationTestCase, self).setUp() + self.dataset_populator = DatasetPopulator(self.galaxy_interactor) + self.history_id = self.dataset_populator.new_history() + + +class NonAdminsCannotPasteFilePathTestCase(BaseCheckUploadContentConfigurationTestCase): + + @classmethod + def handle_galaxy_config_kwds(cls, config): + config["allow_path_paste"] = True + + def test(self): + payload = self.dataset_populator.upload_payload( + self.history_id, 'file://%s/1.RData' % TEST_DATA_DIRECTORY, ext="binary" + ) + create_response = self._post( "tools", data=payload ) + # Ideally this would be 403 but the tool API endpoint isn't using + # the newer API decorator that handles those details. + assert create_response.status_code >= 400 + + +class AdminsCanPasteFilePathsTestCase(BaseCheckUploadContentConfigurationTestCase): + + require_admin_user = True + + @classmethod + def handle_galaxy_config_kwds(cls, config): + config["allow_path_paste"] = True + + def test(self): + payload = self.dataset_populator.upload_payload( + self.history_id, 'file://%s/random-file' % TEST_DATA_DIRECTORY, + ) + create_response = self._post( "tools", data=payload ) + # Ideally this would be 403 but the tool API endpoint isn't using + # the newer API decorator that handles those details. + assert create_response.status_code == 200 + + +class DefaultBinaryContentFiltersTestCase(BaseCheckUploadContentConfigurationTestCase): + + require_admin_user = True + + @classmethod + def handle_galaxy_config_kwds(cls, config): + config["allow_path_paste"] = True + + def test_random_binary_allowed(self): + dataset = self.dataset_populator.new_dataset( + self.history_id, 'file://%s/random-file' % TEST_DATA_DIRECTORY, file_type="auto", wait=True + ) + dataset = self.dataset_populator.get_history_dataset_details(self.history_id, dataset=dataset) + assert dataset["file_ext"] == "data", dataset + + def test_gzipped_html_content_blocked_by_default(self): + dataset = self.dataset_populator.new_dataset( + self.history_id, 'file://%s/bad.html.gz' % TEST_DATA_DIRECTORY, file_type="auto", wait=True + ) + dataset = self.dataset_populator.get_history_dataset_details(self.history_id, dataset=dataset) + assert dataset["file_size"] == 0 + + +class DisableContentCheckingTestCase(BaseCheckUploadContentConfigurationTestCase): + + require_admin_user = True + + @classmethod + def handle_galaxy_config_kwds(cls, config): + config["allow_path_paste"] = True + config["check_upload_content"] = False + + def test_gzipped_html_content_now_allowed(self): + dataset = self.dataset_populator.new_dataset( + self.history_id, 'file://%s/bad.html.gz' % TEST_DATA_DIRECTORY, file_type="auto", wait=True + ) + dataset = self.dataset_populator.get_history_dataset_details(self.history_id, dataset=dataset) + # Same file was empty above! + assert dataset["file_size"] != 0 + + +class AutoDecompressTestCase(BaseCheckUploadContentConfigurationTestCase): + + require_admin_user = True + + @classmethod + def handle_galaxy_config_kwds(cls, config): + config["allow_path_paste"] = True + + def test_auto_decompress_off(self): + dataset = self.dataset_populator.new_dataset( + self.history_id, 'file://%s/1.sam.gz' % TEST_DATA_DIRECTORY, file_type="auto", auto_decompress=False, wait=True + ) + dataset = self.dataset_populator.get_history_dataset_details(self.history_id, dataset=dataset) + assert dataset["file_ext"] == "data", dataset + + def test_auto_decompress_on(self): + dataset = self.dataset_populator.new_dataset( + self.history_id, 'file://%s/1.sam.gz' % TEST_DATA_DIRECTORY, file_type="auto", wait=True + ) + dataset = self.dataset_populator.get_history_dataset_details(self.history_id, dataset=dataset) + assert dataset["file_ext"] == "sam", dataset