Simple tests for data source responses.

- Verify a simple data source works when responding via the API.
- Verify a data source sending back a file:// parameter is blocked (GX-2017-0004/GX-2017-0003 - it is tracked different ways in the commit message and in the security issue tracker).
This commit is contained in:
John Chilton
2017-10-25 14:46:16 -04:00
parent 9b3d217a2e
commit 162bddd96c
4 changed files with 85 additions and 0 deletions
+50
View File
@@ -1,5 +1,6 @@
# Test tools API.
import json
import os
from base import api
from base.populators import (
@@ -78,6 +79,55 @@ class ToolsTestCase(api.ApiTestCase):
assert f2_info["min"] is None
assert f2_info["max"] is None
@skip_without_tool("test_data_source")
def test_data_source_ok_request(self):
with self.dataset_populator.test_history() as history_id:
payload = self.dataset_populator.run_tool_payload(
tool_id="test_data_source",
inputs={
"URL": "https://raw.githubusercontent.com/galaxyproject/galaxy/dev/test-data/1.bed",
"URL_method": "get",
"data_type": "bed",
},
history_id=history_id,
)
create_response = self._post("tools", data=payload)
self._assert_status_code_is(create_response, 200)
create_object = create_response.json()
self._assert_has_keys(create_object, "outputs")
assert len(create_object["outputs"]) == 1
output = create_object["outputs"][0]
self.dataset_populator.wait_for_history(history_id, assert_ok=True)
output_content = self.dataset_populator.get_history_dataset_content(history_id, dataset=output)
assert output_content.startswith("chr1\t147962192\t147962580")
output_details = self.dataset_populator.get_history_dataset_details(history_id, dataset=output)
assert output_details["file_ext"] == "bed"
@skip_without_tool("test_data_source")
def test_data_sources_block_file_parameters(self):
with self.dataset_populator.test_history() as history_id:
payload = self.dataset_populator.run_tool_payload(
tool_id="test_data_source",
inputs={
"URL": "file://%s" % os.path.join(os.getcwd(), "README.rst"),
"URL_method": "get",
"data_type": "bed",
},
history_id=history_id,
)
create_response = self._post("tools", data=payload)
self._assert_status_code_is(create_response, 200)
create_object = create_response.json()
self._assert_has_keys(create_object, "outputs")
assert len(create_object["outputs"]) == 1
output = create_object["outputs"][0]
self.dataset_populator.wait_for_history(history_id, assert_ok=False)
output_details = self.dataset_populator.get_history_dataset_details(history_id, dataset=output, wait=False)
assert output_details["state"] == "error", output_details
assert "has not sent back a URL parameter" in output_details["misc_info"], output_details
def _show_valid_tool(self, tool_id):
tool_show_response = self._get("tools/%s" % tool_id, data=dict(io_details=True))
self._assert_status_code_is(tool_show_response, 200)
+1
View File
@@ -0,0 +1 @@
../../../tools/data_source/data_source.py
@@ -1,6 +1,7 @@
<?xml version="1.0"?>
<toolbox tool_path="${tool_conf_dir}" is_shed_conf="false">
<tool file="upload.xml"/>
<tool file="test_data_source.xml"/>
<tool file="simple_constructs.xml" />
<tool file="color_param.xml" />
<tool file="inheritance_simple.xml" />
@@ -0,0 +1,33 @@
<?xml version="1.0"?>
<!--
If the value of 'URL_method' is 'get', the request will consist of the value of 'URL' coming back in
the initial response. If value of 'URL_method' is 'post', any additional params coming back in the
initial response ( in addition to 'URL' ) will be encoded and appended to URL and a post will be performed.
-->
<tool name="test_data_source" id="test_data_source" tool_type="data_source" version="1.0.0">
<command interpreter="python">data_source.py $output $__app__.config.output_size_limit</command>
<inputs action="http://ratmine.mcw.edu/ratmine/begin.do" check_values="false" method="get">
<display>go to Ratmine server $GALAXY_URL</display>
<param name="GALAXY_URL" type="baseurl" value="/tool_runner?tool_id=ratmine" />
</inputs>
<request_param_translation>
<request_param galaxy_name="URL_method" remote_name="URL_method" missing="post" />
<request_param galaxy_name="URL" remote_name="URL" missing="" />
<request_param galaxy_name="dbkey" remote_name="db" missing="?" />
<request_param galaxy_name="organism" remote_name="organism" missing="" />
<request_param galaxy_name="table" remote_name="table" missing="" />
<request_param galaxy_name="description" remote_name="description" missing="" />
<request_param galaxy_name="name" remote_name="name" missing="My Awesome Data Source Data" />
<request_param galaxy_name="info" remote_name="info" missing="" />
<request_param galaxy_name="data_type" remote_name="data_type" missing="auto" >
<value_translation>
<value galaxy_value="auto" remote_value="txt" /> <!-- intermine currently always provides 'txt', make this auto detect -->
</value_translation>
</request_param>
</request_param_translation>
<uihints minwidth="800"/>
<outputs>
<data name="output" format="txt" />
</outputs>
<options sanitize="False" refresh="True"/>
</tool>