From 2e3165cb7fcce6f81cea2c4f81737f1625d1db28 Mon Sep 17 00:00:00 2001 From: John Chilton Date: Sun, 26 May 2019 14:34:56 -0400 Subject: [PATCH] clean-fix-page-api - integration API test case ensure DB contains unencoded IDs --- .../test_page_revision_json_encoding.py | 40 +++++++++++++++++++ 1 file changed, 40 insertions(+) create mode 100644 test/integration/test_page_revision_json_encoding.py diff --git a/test/integration/test_page_revision_json_encoding.py b/test/integration/test_page_revision_json_encoding.py new file mode 100644 index 00000000000..f509c9b8c10 --- /dev/null +++ b/test/integration/test_page_revision_json_encoding.py @@ -0,0 +1,40 @@ +"""Test pages save JSON with unencoded IDs. + +Verifies the database doesn't get saved with encoded IDs (that would be bad because +the security parameter to encode IDs may be changed by admins). Test case also verifies +exported API values are encoded though. +""" + +from base import api_asserts +from base import integration_util +from base.populators import ( + DatasetPopulator, +) +from galaxy import model # noqa: I101,I201 + + +class PageJsonEncodingIntegrationTestCase(integration_util.IntegrationTestCase): + + def setUp(self): + super(PageJsonEncodingIntegrationTestCase, self).setUp() + self.dataset_populator = DatasetPopulator(self.galaxy_interactor) + + def test_page_encoding(self): + history_id = self.dataset_populator.new_history() + request = dict( + slug="mypage", + title="MY PAGE", + content='''

Page!

''' % history_id, + ) + page_response = self._post("pages", request) + api_asserts.assert_status_code_is_ok(page_response) + sa_session = self._app.model.context + page_revision = sa_session.query(model.PageRevision).all()[0] + assert '''id="History-1"''' in page_revision.content, page_revision.content + assert '''id="History-%s"''' % history_id not in page_revision.content, page_revision.content + + show_page_response = self._get("pages/%s" % page_response.json()["id"]) + api_asserts.assert_status_code_is_ok(show_page_response) + content = show_page_response.json()["content"] + assert '''id="History-1"''' not in content, content + assert '''id="History-%s"''' % history_id in content, content