Files
galaxy/test/integration/test_web_framework_config.py
T
John Chilton c46ff97123 FastAPI/ASGI CORS handling.
- Some tests to clarify existing behavior (at least where they don't diverge). Including frameworks enhancements to allow integration tests to force on server type or the other.
- In WSGI-land return a 400 if an invalid origin is specified (to bring inline with CORSMiddleware).
- In ASGI-land, override CORSMiddleware to use Galaxy's logic for checking an origin against the config object.
- When building a WSGI webapp for FastAPI, skip CORS handling at that level so it can be handled by FastAPI app.
2021-01-27 19:55:48 -05:00

85 lines
3.2 KiB
Python

"""Integration tests for framework configuration code."""
from requests import options
from galaxy_test.driver import integration_util
class BaseWebFrameworkTestCase(integration_util.IntegrationTestCase):
def _options(self, headers=None):
url = self._api_url("licenses")
options_response = options(url, headers=headers or {})
return options_response
class CorsDefaultIntegrationTestCase(BaseWebFrameworkTestCase):
use_uvicorn = True
def test_options(self):
headers = {
"Access-Control-Request-Method": "GET",
"origin": "http://192.168.0.101:8083",
}
options_response = self._options(headers)
assert options_response.status_code == 200
assert 'access-control-allow-origin' not in options_response.headers
def test_origin_not_allowed_default(self):
headers = {
"Access-Control-Request-Method": "GET",
"Access-Control-Request-Headers": "Authorization",
"origin": "http://192.168.0.101:8083",
}
options_response = self._options(headers)
assert options_response.status_code == 200
assert 'access-control-allow-origin' not in options_response.headers
class AllowOriginIntegrationTestCase(BaseWebFrameworkTestCase):
use_uvicorn = True
@classmethod
def handle_galaxy_config_kwds(cls, config):
config["allowed_origin_hostnames"] = "192.168.0.101,/.*.galaxyproject.org/"
def test_origin_allowed_if_configured(self):
headers = {
"Access-Control-Request-Method": "GET",
"origin": "http://192.168.0.101:8083",
"Access-Control-Request-Headers": "Authorization",
}
options_response = self._options(headers)
options_response.raise_for_status()
assert 'access-control-allow-origin' in options_response.headers
assert options_response.headers['access-control-allow-origin'] == "http://192.168.0.101:8083"
assert options_response.headers['access-control-max-age'] == "600"
def test_origin_allowed_if_configured_via_regex(self):
headers = {
"Access-Control-Request-Method": "GET",
"origin": "http://rna.galaxyproject.org",
"Access-Control-Request-Headers": "Authorization",
}
options_response = self._options(headers)
options_response.raise_for_status()
assert 'access-control-allow-origin' in options_response.headers
assert options_response.headers['access-control-allow-origin'] == "http://rna.galaxyproject.org"
assert options_response.headers['access-control-max-age'] == "600"
def test_origin_not_allowed_if_not_in_configured_list(self):
headers = {
"Access-Control-Request-Method": "GET",
"origin": "http://192.168.0.102:8083", # swapped ip by one
"Access-Control-Request-Headers": "Authorization",
}
options_response = self._options(headers)
assert options_response.status_code == 400
class AllowOriginPasteIntegrationTestCase(AllowOriginIntegrationTestCase):
use_uvicorn = False
class CorsDefaultPasteIntegrationTestCase(CorsDefaultIntegrationTestCase):
use_uvicorn = False