mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-10-08 08:36:37 +08:00
refactor(openflare): migrate console APIs to v1 and centralize routing
Move OpenFlare management endpoints to /api/v1/custom/openflare with Wavelet response envelopes and Abort* error handling. Keep agent, relay, and flared protocol routes on /api/* with the legacy compat format. - Add apiutil helpers and Swagger annotations for console handlers - Register all OpenFlare routes in internal/router/openflare (not apps) - Switch frontend services to OpenFlareBaseService and v1 paths - Remove dead auth/compat code and legacy-base.service.ts - Update integration tests and changelog
This commit is contained in:
@@ -10,11 +10,11 @@ import (
|
||||
"testing"
|
||||
|
||||
"github.com/Rain-kl/Wavelet/internal/apps/openflare/agent"
|
||||
oflegacy "github.com/Rain-kl/Wavelet/internal/apps/openflare/legacy"
|
||||
ofnode "github.com/Rain-kl/Wavelet/internal/apps/openflare/node"
|
||||
"github.com/Rain-kl/Wavelet/internal/apps/openflare/option"
|
||||
"github.com/Rain-kl/Wavelet/internal/db"
|
||||
"github.com/Rain-kl/Wavelet/internal/model"
|
||||
"github.com/Rain-kl/Wavelet/internal/testhelper"
|
||||
"github.com/gin-gonic/gin"
|
||||
"github.com/glebarez/sqlite"
|
||||
"github.com/stretchr/testify/assert"
|
||||
@@ -58,10 +58,8 @@ func setupProtocolTestEnv(t *testing.T) (*gin.Engine, func()) {
|
||||
option.ResetInitializationForTest()
|
||||
agent.ResetAuthCacheForTest()
|
||||
|
||||
gin.SetMode(gin.TestMode)
|
||||
engine := gin.New()
|
||||
apiGroup := engine.Group("/api")
|
||||
oflegacy.RegisterRoutes(apiGroup)
|
||||
engine := testhelper.NewTestGinEngine()
|
||||
mountOpenFlareTestRoutes(engine)
|
||||
|
||||
cleanup := func() {
|
||||
db.SetDB(nil)
|
||||
|
||||
@@ -8,13 +8,14 @@ import (
|
||||
"net/http"
|
||||
"testing"
|
||||
|
||||
"github.com/Rain-kl/Wavelet/internal/apps/admin"
|
||||
"github.com/Rain-kl/Wavelet/internal/apps/cap"
|
||||
"github.com/Rain-kl/Wavelet/internal/apps/oauth"
|
||||
"github.com/Rain-kl/Wavelet/internal/apps/openflare/compat"
|
||||
oflegacy "github.com/Rain-kl/Wavelet/internal/apps/openflare/legacy"
|
||||
"github.com/Rain-kl/Wavelet/internal/apps/openflare/option"
|
||||
"github.com/Rain-kl/Wavelet/internal/config"
|
||||
"github.com/Rain-kl/Wavelet/internal/db/idgen"
|
||||
"github.com/Rain-kl/Wavelet/internal/model"
|
||||
"github.com/Rain-kl/Wavelet/internal/repository"
|
||||
"github.com/Rain-kl/Wavelet/internal/testhelper"
|
||||
"github.com/gin-contrib/sessions"
|
||||
"github.com/gin-contrib/sessions/cookie"
|
||||
@@ -28,11 +29,6 @@ type statusPayload struct {
|
||||
SystemName string `json:"system_name"`
|
||||
}
|
||||
|
||||
type legacyUserPayload struct {
|
||||
Username string `json:"username"`
|
||||
Token string `json:"token"`
|
||||
}
|
||||
|
||||
func setupAuthOptionIntegration(t *testing.T) (*gorm.DB, *gin.Engine) {
|
||||
t.Helper()
|
||||
|
||||
@@ -43,6 +39,12 @@ func setupAuthOptionIntegration(t *testing.T) (*gorm.DB, *gin.Engine) {
|
||||
option.ResetInitializationForTest()
|
||||
t.Cleanup(option.ResetInitializationForTest)
|
||||
|
||||
require.NoError(t, dbConn.Model(&model.SystemConfig{}).
|
||||
Where("key = ?", model.ConfigKeyCapLoginEnabled).
|
||||
Update("value", "false").Error)
|
||||
require.NoError(t, repository.InvalidateSystemConfigCache(context.Background(), model.ConfigKeyCapLoginEnabled))
|
||||
cap.InvalidateRuntimeSettings()
|
||||
|
||||
oldCookieName := config.Config.App.SessionCookieName
|
||||
oldSecret := config.Config.App.SessionSecret
|
||||
oldDomain := config.Config.App.SessionDomain
|
||||
@@ -65,9 +67,7 @@ func setupAuthOptionIntegration(t *testing.T) (*gorm.DB, *gin.Engine) {
|
||||
store := cookie.NewStore([]byte(config.Config.App.SessionSecret))
|
||||
store.Options(oauth.GetSessionOptions(3600))
|
||||
r := testhelper.NewTestGinEngine(sessions.Sessions(config.Config.App.SessionCookieName, store))
|
||||
|
||||
api := r.Group("/api")
|
||||
oflegacy.RegisterRoutes(api)
|
||||
mountOpenFlareTestRoutes(r)
|
||||
|
||||
return dbConn, r
|
||||
}
|
||||
@@ -88,134 +88,88 @@ func seedUser(t *testing.T, dbConn *gorm.DB, username, password string, isAdmin
|
||||
return user
|
||||
}
|
||||
|
||||
func seedUserWithAccessToken(t *testing.T, dbConn *gorm.DB, username, password string, isAdmin bool) string {
|
||||
t.Helper()
|
||||
|
||||
user := seedUser(t, dbConn, username, password, isAdmin)
|
||||
|
||||
token, err := model.GenerateTokenString()
|
||||
require.NoError(t, err)
|
||||
|
||||
tokenRecord := model.AccessToken{
|
||||
UserID: user.ID,
|
||||
Name: username + "-integration-token",
|
||||
TokenHash: model.HashToken(token),
|
||||
MaskedToken: model.MaskTokenString(token),
|
||||
IsAdmin: isAdmin,
|
||||
}
|
||||
require.NoError(t, dbConn.Create(&tokenRecord).Error)
|
||||
return token
|
||||
}
|
||||
|
||||
func TestGETStatusReturnsSuccessEnvelope(t *testing.T) {
|
||||
_, r := setupAuthOptionIntegration(t)
|
||||
|
||||
w := performJSONRequest(t, r, http.MethodGet, "/api/status", nil, nil)
|
||||
w := performJSONRequest(t, r, http.MethodGet, apiPath("/status"), nil, nil)
|
||||
|
||||
assert.Equal(t, http.StatusOK, w.Code)
|
||||
env := decodeEnvelope(t, w)
|
||||
assert.True(t, env.Success, "message=%s", env.Message)
|
||||
resp := requireAPIOK(t, w)
|
||||
|
||||
var status statusPayload
|
||||
unmarshalEnvelopeData(t, env.Data, &status)
|
||||
unmarshalAPIData(t, resp.Data, &status)
|
||||
assert.NotEmpty(t, status.SystemName)
|
||||
}
|
||||
|
||||
func TestPOSTUserLoginWithSeededUser(t *testing.T) {
|
||||
dbConn, r := setupAuthOptionIntegration(t)
|
||||
seedUser(t, dbConn, "testuser", "password123", false)
|
||||
|
||||
w := performJSONRequest(t, r, http.MethodPost, "/api/user/login", map[string]string{
|
||||
"username": "testuser",
|
||||
"password": "password123",
|
||||
}, nil)
|
||||
|
||||
assert.Equal(t, http.StatusOK, w.Code)
|
||||
env := decodeEnvelope(t, w)
|
||||
assert.True(t, env.Success, "message=%s", env.Message)
|
||||
|
||||
var user legacyUserPayload
|
||||
unmarshalEnvelopeData(t, env.Data, &user)
|
||||
assert.Equal(t, "testuser", user.Username)
|
||||
assert.NotEmpty(t, user.Token)
|
||||
}
|
||||
|
||||
func TestGETUserSelfWithToken(t *testing.T) {
|
||||
dbConn, r := setupAuthOptionIntegration(t)
|
||||
seedUser(t, dbConn, "selfuser", "password123", false)
|
||||
|
||||
loginResp := performJSONRequest(t, r, http.MethodPost, "/api/user/login", map[string]string{
|
||||
"username": "selfuser",
|
||||
"password": "password123",
|
||||
}, nil)
|
||||
loginEnv := decodeEnvelope(t, loginResp)
|
||||
require.True(t, loginEnv.Success, "login failed: %s", loginEnv.Message)
|
||||
|
||||
var loginUser legacyUserPayload
|
||||
unmarshalEnvelopeData(t, loginEnv.Data, &loginUser)
|
||||
require.NotEmpty(t, loginUser.Token)
|
||||
|
||||
w := performJSONRequest(t, r, http.MethodGet, "/api/user/self", nil, map[string]string{
|
||||
compat.OpenFlareTokenHeader(): loginUser.Token,
|
||||
})
|
||||
|
||||
assert.Equal(t, http.StatusOK, w.Code)
|
||||
env := decodeEnvelope(t, w)
|
||||
assert.True(t, env.Success, "message=%s", env.Message)
|
||||
|
||||
var self legacyUserPayload
|
||||
unmarshalEnvelopeData(t, env.Data, &self)
|
||||
assert.Equal(t, "selfuser", self.Username)
|
||||
}
|
||||
|
||||
func TestGETOptionRequiresRootAuth(t *testing.T) {
|
||||
dbConn, r := setupAuthOptionIntegration(t)
|
||||
seedUser(t, dbConn, "commonuser", "password123", false)
|
||||
seedUser(t, dbConn, "rootuser", "password123", true)
|
||||
|
||||
commonToken := loginAndGetToken(t, r, "commonuser", "password123")
|
||||
rootToken := loginAndGetToken(t, r, "rootuser", "password123")
|
||||
commonToken := seedUserWithAccessToken(t, dbConn, "commonuser", "password123", false)
|
||||
rootToken := seedUserWithAccessToken(t, dbConn, "rootuser", "password123", true)
|
||||
|
||||
t.Run("unauthenticated", func(t *testing.T) {
|
||||
w := performJSONRequest(t, r, http.MethodGet, "/api/option/", nil, nil)
|
||||
w := performJSONRequest(t, r, http.MethodGet, apiPath("/option/"), nil, nil)
|
||||
assert.Equal(t, http.StatusUnauthorized, w.Code)
|
||||
env := decodeEnvelope(t, w)
|
||||
assert.False(t, env.Success)
|
||||
resp := decodeAPIResponse(t, w)
|
||||
assert.NotEmpty(t, resp.ErrorMsg)
|
||||
})
|
||||
|
||||
t.Run("common user forbidden", func(t *testing.T) {
|
||||
w := performJSONRequest(t, r, http.MethodGet, "/api/option/", nil, map[string]string{
|
||||
compat.OpenFlareTokenHeader(): commonToken,
|
||||
})
|
||||
assert.Equal(t, http.StatusOK, w.Code)
|
||||
env := decodeEnvelope(t, w)
|
||||
assert.False(t, env.Success)
|
||||
assert.Contains(t, env.Message, "权限不足")
|
||||
w := performJSONRequest(t, r, http.MethodGet, apiPath("/option/"), nil, adminAuthHeaders(commonToken))
|
||||
assert.Equal(t, http.StatusNotFound, w.Code)
|
||||
resp := decodeAPIResponse(t, w)
|
||||
assert.Equal(t, admin.TokenAdminRequired, resp.ErrorMsg)
|
||||
})
|
||||
|
||||
t.Run("root user allowed", func(t *testing.T) {
|
||||
w := performJSONRequest(t, r, http.MethodGet, "/api/option/", nil, map[string]string{
|
||||
compat.OpenFlareTokenHeader(): rootToken,
|
||||
})
|
||||
w := performJSONRequest(t, r, http.MethodGet, apiPath("/option/"), nil, adminAuthHeaders(rootToken))
|
||||
assert.Equal(t, http.StatusOK, w.Code)
|
||||
env := decodeEnvelope(t, w)
|
||||
assert.True(t, env.Success, "message=%s", env.Message)
|
||||
requireAPIOK(t, w)
|
||||
})
|
||||
}
|
||||
|
||||
func TestGETNodesWithOpenFlareToken(t *testing.T) {
|
||||
func TestGETNodesWithAccessToken(t *testing.T) {
|
||||
dbConn, r := setupAuthOptionIntegration(t)
|
||||
require.NoError(t, dbConn.AutoMigrate(&model.OpenFlareNode{}))
|
||||
seedUser(t, dbConn, "admin", "password123", true)
|
||||
rootToken := loginAndGetToken(t, r, "admin", "password123")
|
||||
rootToken := seedUserWithAccessToken(t, dbConn, "admin", "password123", true)
|
||||
|
||||
w := performJSONRequest(t, r, http.MethodGet, "/api/nodes/", nil, map[string]string{
|
||||
compat.OpenFlareTokenHeader(): rootToken,
|
||||
})
|
||||
w := performJSONRequest(t, r, http.MethodGet, apiPath("/nodes/"), nil, adminAuthHeaders(rootToken))
|
||||
|
||||
assert.Equal(t, http.StatusOK, w.Code)
|
||||
env := decodeEnvelope(t, w)
|
||||
assert.True(t, env.Success, "message=%s", env.Message)
|
||||
requireAPIOK(t, w)
|
||||
}
|
||||
|
||||
func TestOptionHotReloadAfterUpdate(t *testing.T) {
|
||||
dbConn, r := setupAuthOptionIntegration(t)
|
||||
seedUser(t, dbConn, "admin", "password123", true)
|
||||
rootToken := loginAndGetToken(t, r, "admin", "password123")
|
||||
rootToken := seedUserWithAccessToken(t, dbConn, "admin", "password123", true)
|
||||
|
||||
statusBefore := getStatusSystemName(t, r, nil)
|
||||
assert.NotEmpty(t, statusBefore)
|
||||
|
||||
updateResp := performJSONRequest(t, r, http.MethodPost, "/api/option/update", map[string]string{
|
||||
updateResp := performJSONRequest(t, r, http.MethodPost, apiPath("/option/update"), map[string]string{
|
||||
"key": "SystemName",
|
||||
"value": "HotReloadIntegration",
|
||||
}, map[string]string{
|
||||
compat.OpenFlareTokenHeader(): rootToken,
|
||||
})
|
||||
}, adminAuthHeaders(rootToken))
|
||||
assert.Equal(t, http.StatusOK, updateResp.Code)
|
||||
updateEnv := decodeEnvelope(t, updateResp)
|
||||
assert.True(t, updateEnv.Success, "message=%s", updateEnv.Message)
|
||||
requireAPIOK(t, updateResp)
|
||||
|
||||
statusAfter := getStatusSystemName(t, r, nil)
|
||||
assert.Equal(t, "HotReloadIntegration", statusAfter)
|
||||
@@ -226,31 +180,14 @@ func TestOptionHotReloadAfterUpdate(t *testing.T) {
|
||||
assert.Equal(t, "HotReloadIntegration", model.OptionValue("SystemName"))
|
||||
}
|
||||
|
||||
func loginAndGetToken(t *testing.T, r http.Handler, username, password string) string {
|
||||
t.Helper()
|
||||
|
||||
w := performJSONRequest(t, r, http.MethodPost, "/api/user/login", map[string]string{
|
||||
"username": username,
|
||||
"password": password,
|
||||
}, nil)
|
||||
env := decodeEnvelope(t, w)
|
||||
require.True(t, env.Success, "login failed: %s", env.Message)
|
||||
|
||||
var user legacyUserPayload
|
||||
unmarshalEnvelopeData(t, env.Data, &user)
|
||||
require.NotEmpty(t, user.Token)
|
||||
return user.Token
|
||||
}
|
||||
|
||||
func getStatusSystemName(t *testing.T, r http.Handler, headers map[string]string) string {
|
||||
t.Helper()
|
||||
|
||||
w := performJSONRequest(t, r, http.MethodGet, "/api/status", nil, headers)
|
||||
w := performJSONRequest(t, r, http.MethodGet, apiPath("/status"), nil, headers)
|
||||
require.Equal(t, http.StatusOK, w.Code)
|
||||
env := decodeEnvelope(t, w)
|
||||
require.True(t, env.Success, "message=%s", env.Message)
|
||||
resp := requireAPIOK(t, w)
|
||||
|
||||
var status statusPayload
|
||||
unmarshalEnvelopeData(t, env.Data, &status)
|
||||
unmarshalAPIData(t, resp.Data, &status)
|
||||
return status.SystemName
|
||||
}
|
||||
}
|
||||
@@ -9,10 +9,10 @@ import (
|
||||
"time"
|
||||
|
||||
"github.com/Rain-kl/Wavelet/internal/apps/openflare/agent"
|
||||
oflegacy "github.com/Rain-kl/Wavelet/internal/apps/openflare/legacy"
|
||||
"github.com/Rain-kl/Wavelet/internal/apps/openflare/option"
|
||||
"github.com/Rain-kl/Wavelet/internal/db"
|
||||
"github.com/Rain-kl/Wavelet/internal/model"
|
||||
"github.com/Rain-kl/Wavelet/internal/testhelper"
|
||||
"github.com/gin-gonic/gin"
|
||||
"github.com/glebarez/sqlite"
|
||||
"github.com/stretchr/testify/assert"
|
||||
@@ -59,10 +59,8 @@ func setupCoreChainTest(t *testing.T) (*gin.Engine, adminSeed, func()) {
|
||||
seed, err := seedAdminWithAccessToken(sqliteDB)
|
||||
require.NoError(t, err)
|
||||
|
||||
gin.SetMode(gin.TestMode)
|
||||
engine := gin.New()
|
||||
apiGroup := engine.Group("/api")
|
||||
oflegacy.RegisterRoutes(apiGroup)
|
||||
engine := testhelper.NewTestGinEngine()
|
||||
mountOpenFlareTestRoutes(engine)
|
||||
|
||||
cleanup := func() {
|
||||
db.SetDB(nil)
|
||||
@@ -125,7 +123,7 @@ func TestCoreChainMigrationFlow(t *testing.T) {
|
||||
)
|
||||
|
||||
t.Run("create origin", func(t *testing.T) {
|
||||
rec := performJSONRequest(t, engine, http.MethodPost, "/api/origins/", map[string]any{
|
||||
rec := performJSONRequest(t, engine, http.MethodPost, apiPath("/origins/"), map[string]any{
|
||||
"name": "Primary Origin",
|
||||
"address": "origin.core-chain.internal",
|
||||
"remark": "integration upstream",
|
||||
@@ -134,10 +132,8 @@ func TestCoreChainMigrationFlow(t *testing.T) {
|
||||
})
|
||||
require.Equal(t, http.StatusOK, rec.Code)
|
||||
|
||||
envelope := decodeEnvelope(t, rec)
|
||||
require.True(t, envelope.Success, envelope.Message)
|
||||
|
||||
data := unmarshalEnvelopeMap(t, envelope.Data)
|
||||
resp := requireAPIOK(t, rec)
|
||||
data := unmarshalAPIMap(t, resp.Data)
|
||||
originID = uint(data["id"].(float64))
|
||||
assert.NotZero(t, originID)
|
||||
assert.Equal(t, "Primary Origin", data["name"])
|
||||
@@ -145,7 +141,7 @@ func TestCoreChainMigrationFlow(t *testing.T) {
|
||||
})
|
||||
|
||||
t.Run("create proxy route linked to origin", func(t *testing.T) {
|
||||
rec := performJSONRequest(t, engine, http.MethodPost, "/api/proxy-routes/", map[string]any{
|
||||
rec := performJSONRequest(t, engine, http.MethodPost, apiPath("/proxy-routes/"), map[string]any{
|
||||
"site_name": "core-chain-site",
|
||||
"domain": "core-chain.example.com",
|
||||
"origin_id": originID,
|
||||
@@ -157,10 +153,8 @@ func TestCoreChainMigrationFlow(t *testing.T) {
|
||||
})
|
||||
require.Equal(t, http.StatusOK, rec.Code)
|
||||
|
||||
envelope := decodeEnvelope(t, rec)
|
||||
require.True(t, envelope.Success, envelope.Message)
|
||||
|
||||
data := unmarshalEnvelopeMap(t, envelope.Data)
|
||||
resp := requireAPIOK(t, rec)
|
||||
data := unmarshalAPIMap(t, resp.Data)
|
||||
proxyRouteID = uint(data["id"].(float64))
|
||||
assert.NotZero(t, proxyRouteID)
|
||||
assert.Equal(t, "core-chain-site", data["site_name"])
|
||||
@@ -170,35 +164,32 @@ func TestCoreChainMigrationFlow(t *testing.T) {
|
||||
})
|
||||
|
||||
t.Run("publish config version", func(t *testing.T) {
|
||||
rec := performJSONRequest(t, engine, http.MethodPost, "/api/config-versions/publish", nil, map[string]string{
|
||||
rec := performJSONRequest(t, engine, http.MethodPost, apiPath("/config-versions/publish"), nil, map[string]string{
|
||||
"X-Access-Token": seed.Token,
|
||||
})
|
||||
require.Equal(t, http.StatusOK, rec.Code)
|
||||
|
||||
envelope := decodeEnvelope(t, rec)
|
||||
require.True(t, envelope.Success, envelope.Message)
|
||||
|
||||
data := unmarshalEnvelopeMap(t, envelope.Data)
|
||||
resp := requireAPIOK(t, rec)
|
||||
data := unmarshalAPIMap(t, resp.Data)
|
||||
configVersion, _ = data["version"].(string)
|
||||
configChecksum, _ = data["checksum"].(string)
|
||||
assert.NotEmpty(t, configVersion)
|
||||
assert.NotEmpty(t, configChecksum)
|
||||
assert.Equal(t, true, data["is_active"])
|
||||
|
||||
activeRec := performJSONRequest(t, engine, http.MethodGet, "/api/config-versions/active", nil, map[string]string{
|
||||
activeRec := performJSONRequest(t, engine, http.MethodGet, apiPath("/config-versions/active"), nil, map[string]string{
|
||||
"X-Access-Token": seed.Token,
|
||||
})
|
||||
require.Equal(t, http.StatusOK, activeRec.Code)
|
||||
activeEnvelope := decodeEnvelope(t, activeRec)
|
||||
require.True(t, activeEnvelope.Success, activeEnvelope.Message)
|
||||
activeResp := requireAPIOK(t, activeRec)
|
||||
|
||||
activeData := unmarshalEnvelopeMap(t, activeEnvelope.Data)
|
||||
activeData := unmarshalAPIMap(t, activeResp.Data)
|
||||
assert.Equal(t, configVersion, activeData["version"])
|
||||
assert.Equal(t, configChecksum, activeData["checksum"])
|
||||
})
|
||||
|
||||
t.Run("create node", func(t *testing.T) {
|
||||
rec := performJSONRequest(t, engine, http.MethodPost, "/api/nodes/", map[string]any{
|
||||
rec := performJSONRequest(t, engine, http.MethodPost, apiPath("/nodes/"), map[string]any{
|
||||
"name": "edge-core-chain",
|
||||
"ip": "10.10.0.1",
|
||||
"auto_update_enabled": true,
|
||||
@@ -207,10 +198,8 @@ func TestCoreChainMigrationFlow(t *testing.T) {
|
||||
})
|
||||
require.Equal(t, http.StatusOK, rec.Code)
|
||||
|
||||
envelope := decodeEnvelope(t, rec)
|
||||
require.True(t, envelope.Success, envelope.Message)
|
||||
|
||||
data := unmarshalEnvelopeMap(t, envelope.Data)
|
||||
resp := requireAPIOK(t, rec)
|
||||
data := unmarshalAPIMap(t, resp.Data)
|
||||
nodeID = uint(data["id"].(float64))
|
||||
nodePublicID, _ = data["node_id"].(string)
|
||||
agentToken, _ = data["access_token"].(string)
|
||||
@@ -248,7 +237,7 @@ func TestCoreChainMigrationFlow(t *testing.T) {
|
||||
t,
|
||||
engine,
|
||||
http.MethodGet,
|
||||
"/api/apply-logs/?node_id="+nodePublicID+"&pageNo=1&pageSize=10",
|
||||
apiPath("/apply-logs/?node_id="+nodePublicID+"&pageNo=1&pageSize=10"),
|
||||
nil,
|
||||
map[string]string{
|
||||
"X-Access-Token": seed.Token,
|
||||
@@ -256,10 +245,8 @@ func TestCoreChainMigrationFlow(t *testing.T) {
|
||||
)
|
||||
require.Equal(t, http.StatusOK, listRec.Code)
|
||||
|
||||
listEnvelope := decodeEnvelope(t, listRec)
|
||||
require.True(t, listEnvelope.Success, listEnvelope.Message)
|
||||
|
||||
listData := unmarshalEnvelopeMap(t, listEnvelope.Data)
|
||||
listResp := requireAPIOK(t, listRec)
|
||||
listData := unmarshalAPIMap(t, listResp.Data)
|
||||
assert.Equal(t, float64(1), listData["total"])
|
||||
|
||||
rows, ok := listData["rows"].([]any)
|
||||
@@ -271,14 +258,13 @@ func TestCoreChainMigrationFlow(t *testing.T) {
|
||||
assert.Equal(t, configVersion, row["version"])
|
||||
assert.Equal(t, "success", row["result"])
|
||||
|
||||
nodeRec := performJSONRequest(t, engine, http.MethodGet, "/api/nodes/", nil, map[string]string{
|
||||
nodeRec := performJSONRequest(t, engine, http.MethodGet, apiPath("/nodes/"), nil, map[string]string{
|
||||
"X-Access-Token": seed.Token,
|
||||
})
|
||||
require.Equal(t, http.StatusOK, nodeRec.Code)
|
||||
nodeEnvelope := decodeEnvelope(t, nodeRec)
|
||||
require.True(t, nodeEnvelope.Success, nodeEnvelope.Message)
|
||||
nodeResp := requireAPIOK(t, nodeRec)
|
||||
|
||||
nodes := unmarshalEnvelopeSlice(t, nodeEnvelope.Data)
|
||||
nodes := unmarshalAPISlice(t, nodeResp.Data)
|
||||
require.Len(t, nodes, 1)
|
||||
nodeView, ok := nodes[0].(map[string]any)
|
||||
require.True(t, ok)
|
||||
@@ -288,4 +274,4 @@ func TestCoreChainMigrationFlow(t *testing.T) {
|
||||
assert.Equal(t, configChecksum, nodeView["latest_apply_checksum"])
|
||||
assert.Equal(t, float64(2), nodeView["latest_support_file_count"])
|
||||
})
|
||||
}
|
||||
}
|
||||
@@ -11,9 +11,29 @@ import (
|
||||
"testing"
|
||||
|
||||
"github.com/Rain-kl/Wavelet/internal/apps/openflare/compat"
|
||||
"github.com/Rain-kl/Wavelet/internal/common/response"
|
||||
v1 "github.com/Rain-kl/Wavelet/internal/router/v1"
|
||||
ofrouter "github.com/Rain-kl/Wavelet/internal/router/v1/openflare"
|
||||
"github.com/gin-gonic/gin"
|
||||
"github.com/stretchr/testify/require"
|
||||
)
|
||||
|
||||
func decodeAPIResponse(t *testing.T, rec *httptest.ResponseRecorder) response.Any {
|
||||
t.Helper()
|
||||
|
||||
var resp response.Any
|
||||
require.NoError(t, json.Unmarshal(rec.Body.Bytes(), &resp))
|
||||
return resp
|
||||
}
|
||||
|
||||
func requireAPIOK(t *testing.T, rec *httptest.ResponseRecorder) response.Any {
|
||||
t.Helper()
|
||||
|
||||
resp := decodeAPIResponse(t, rec)
|
||||
require.Empty(t, resp.ErrorMsg, "unexpected API error: %s", resp.ErrorMsg)
|
||||
return resp
|
||||
}
|
||||
|
||||
func decodeEnvelope(t *testing.T, rec *httptest.ResponseRecorder) compat.Envelope {
|
||||
t.Helper()
|
||||
|
||||
@@ -22,7 +42,7 @@ func decodeEnvelope(t *testing.T, rec *httptest.ResponseRecorder) compat.Envelop
|
||||
return envelope
|
||||
}
|
||||
|
||||
func unmarshalEnvelopeData(t *testing.T, data any, target any) {
|
||||
func unmarshalAPIData(t *testing.T, data any, target any) {
|
||||
t.Helper()
|
||||
|
||||
payload, err := json.Marshal(data)
|
||||
@@ -30,20 +50,47 @@ func unmarshalEnvelopeData(t *testing.T, data any, target any) {
|
||||
require.NoError(t, json.Unmarshal(payload, target))
|
||||
}
|
||||
|
||||
func unmarshalEnvelopeMap(t *testing.T, data any) map[string]any {
|
||||
func unmarshalEnvelopeData(t *testing.T, data any, target any) {
|
||||
t.Helper()
|
||||
unmarshalAPIData(t, data, target)
|
||||
}
|
||||
|
||||
func unmarshalAPIMap(t *testing.T, data any) map[string]any {
|
||||
t.Helper()
|
||||
|
||||
var result map[string]any
|
||||
unmarshalEnvelopeData(t, data, &result)
|
||||
unmarshalAPIData(t, data, &result)
|
||||
return result
|
||||
}
|
||||
|
||||
func unmarshalEnvelopeMap(t *testing.T, data any) map[string]any {
|
||||
t.Helper()
|
||||
return unmarshalAPIMap(t, data)
|
||||
}
|
||||
|
||||
func unmarshalAPISlice(t *testing.T, data any) []any {
|
||||
t.Helper()
|
||||
|
||||
var result []any
|
||||
unmarshalAPIData(t, data, &result)
|
||||
return result
|
||||
}
|
||||
|
||||
func unmarshalEnvelopeSlice(t *testing.T, data any) []any {
|
||||
t.Helper()
|
||||
return unmarshalAPISlice(t, data)
|
||||
}
|
||||
|
||||
var result []any
|
||||
unmarshalEnvelopeData(t, data, &result)
|
||||
return result
|
||||
func mountOpenFlareTestRoutes(engine *gin.Engine) {
|
||||
api := engine.Group("/api")
|
||||
ofrouter.RegisterRoutes(api)
|
||||
|
||||
apiV1 := api.Group("/v1")
|
||||
v1.RegisterV1Routes(apiV1, api)
|
||||
}
|
||||
|
||||
func apiPath(subpath string) string {
|
||||
return ofrouter.V1BasePath + subpath
|
||||
}
|
||||
|
||||
func performJSONRequest(
|
||||
|
||||
@@ -15,7 +15,6 @@ import (
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/Rain-kl/Wavelet/internal/apps/openflare/legacy"
|
||||
"github.com/Rain-kl/Wavelet/internal/apps/openflare/option"
|
||||
"github.com/Rain-kl/Wavelet/internal/config"
|
||||
"github.com/Rain-kl/Wavelet/internal/db"
|
||||
@@ -59,8 +58,7 @@ func setupSecurityTest(t *testing.T) (*gin.Engine, adminSeed, func()) {
|
||||
config.Config.App.SessionSecret = "test_session_secret_for_security_integration"
|
||||
|
||||
engine := testhelper.NewTestGinEngine()
|
||||
apiGroup := engine.Group("/api")
|
||||
legacy.RegisterRoutes(apiGroup)
|
||||
mountOpenFlareTestRoutes(engine)
|
||||
|
||||
cleanup := func() {
|
||||
config.Config.App.SessionSecret = oldSecret
|
||||
@@ -110,7 +108,7 @@ func TestSecurityWAFTLSMigrationFlow(t *testing.T) {
|
||||
)
|
||||
|
||||
t.Run("WAF rule group create", func(t *testing.T) {
|
||||
rec := performLegacyRequest(t, engine, http.MethodPost, "/api/waf/rule-groups", map[string]any{
|
||||
rec := performLegacyRequest(t, engine, http.MethodPost, apiPath("/waf/rule-groups"), map[string]any{
|
||||
"name": "edge-security",
|
||||
"enabled": true,
|
||||
"block_status_code": 403,
|
||||
@@ -121,10 +119,8 @@ func TestSecurityWAFTLSMigrationFlow(t *testing.T) {
|
||||
}, adminAuthHeaders(seed.Token))
|
||||
require.Equal(t, http.StatusOK, rec.Code)
|
||||
|
||||
envelope := decodeEnvelope(t, rec)
|
||||
require.True(t, envelope.Success, envelope.Message)
|
||||
|
||||
data := unmarshalEnvelopeMap(t, envelope.Data)
|
||||
resp := requireAPIOK(t, rec)
|
||||
data := unmarshalAPIMap(t, resp.Data)
|
||||
ruleGroupID = uint(data["id"].(float64))
|
||||
assert.NotZero(t, ruleGroupID)
|
||||
assert.Equal(t, "edge-security", data["name"])
|
||||
@@ -133,13 +129,11 @@ func TestSecurityWAFTLSMigrationFlow(t *testing.T) {
|
||||
})
|
||||
|
||||
t.Run("WAF rule group list includes global and custom groups", func(t *testing.T) {
|
||||
rec := performLegacyRequest(t, engine, http.MethodGet, "/api/waf/rule-groups", nil, adminAuthHeaders(seed.Token))
|
||||
rec := performLegacyRequest(t, engine, http.MethodGet, apiPath("/waf/rule-groups"), nil, adminAuthHeaders(seed.Token))
|
||||
require.Equal(t, http.StatusOK, rec.Code)
|
||||
|
||||
envelope := decodeEnvelope(t, rec)
|
||||
require.True(t, envelope.Success, envelope.Message)
|
||||
|
||||
groups := unmarshalEnvelopeSlice(t, envelope.Data)
|
||||
resp := requireAPIOK(t, rec)
|
||||
groups := unmarshalAPISlice(t, resp.Data)
|
||||
require.GreaterOrEqual(t, len(groups), 2)
|
||||
|
||||
foundCustom := false
|
||||
@@ -164,16 +158,14 @@ func TestSecurityWAFTLSMigrationFlow(t *testing.T) {
|
||||
t,
|
||||
engine,
|
||||
http.MethodGet,
|
||||
fmt.Sprintf("/api/waf/rule-groups/%d", ruleGroupID),
|
||||
fmt.Sprintf("%s/waf/rule-groups/%d", apiPath(""), ruleGroupID),
|
||||
nil,
|
||||
adminAuthHeaders(seed.Token),
|
||||
)
|
||||
require.Equal(t, http.StatusOK, rec.Code)
|
||||
|
||||
envelope := decodeEnvelope(t, rec)
|
||||
require.True(t, envelope.Success, envelope.Message)
|
||||
|
||||
data := unmarshalEnvelopeMap(t, envelope.Data)
|
||||
resp := requireAPIOK(t, rec)
|
||||
data := unmarshalAPIMap(t, resp.Data)
|
||||
assert.Equal(t, float64(ruleGroupID), data["id"])
|
||||
assert.Equal(t, "edge-security", data["name"])
|
||||
})
|
||||
@@ -183,7 +175,7 @@ func TestSecurityWAFTLSMigrationFlow(t *testing.T) {
|
||||
t,
|
||||
engine,
|
||||
http.MethodPost,
|
||||
fmt.Sprintf("/api/waf/rule-groups/%d/update", ruleGroupID),
|
||||
fmt.Sprintf("%s/waf/rule-groups/%d/update", apiPath(""), ruleGroupID),
|
||||
map[string]any{
|
||||
"name": "edge-security-updated",
|
||||
"enabled": true,
|
||||
@@ -194,16 +186,14 @@ func TestSecurityWAFTLSMigrationFlow(t *testing.T) {
|
||||
)
|
||||
require.Equal(t, http.StatusOK, rec.Code)
|
||||
|
||||
envelope := decodeEnvelope(t, rec)
|
||||
require.True(t, envelope.Success, envelope.Message)
|
||||
|
||||
data := unmarshalEnvelopeMap(t, envelope.Data)
|
||||
resp := requireAPIOK(t, rec)
|
||||
data := unmarshalAPIMap(t, resp.Data)
|
||||
assert.Equal(t, "edge-security-updated", data["name"])
|
||||
assert.Equal(t, float64(451), data["block_status_code"])
|
||||
})
|
||||
|
||||
t.Run("WAF IP group create", func(t *testing.T) {
|
||||
rec := performLegacyRequest(t, engine, http.MethodPost, "/api/waf/ip-groups", map[string]any{
|
||||
rec := performLegacyRequest(t, engine, http.MethodPost, apiPath("/waf/ip-groups"), map[string]any{
|
||||
"name": "blocked-ips",
|
||||
"type": "manual",
|
||||
"enabled": true,
|
||||
@@ -212,10 +202,8 @@ func TestSecurityWAFTLSMigrationFlow(t *testing.T) {
|
||||
}, adminAuthHeaders(seed.Token))
|
||||
require.Equal(t, http.StatusOK, rec.Code)
|
||||
|
||||
envelope := decodeEnvelope(t, rec)
|
||||
require.True(t, envelope.Success, envelope.Message)
|
||||
|
||||
data := unmarshalEnvelopeMap(t, envelope.Data)
|
||||
resp := requireAPIOK(t, rec)
|
||||
data := unmarshalAPIMap(t, resp.Data)
|
||||
ipGroupID = uint(data["id"].(float64))
|
||||
assert.NotZero(t, ipGroupID)
|
||||
assert.Equal(t, "blocked-ips", data["name"])
|
||||
@@ -223,7 +211,7 @@ func TestSecurityWAFTLSMigrationFlow(t *testing.T) {
|
||||
})
|
||||
|
||||
t.Run("create proxy route for WAF binding", func(t *testing.T) {
|
||||
rec := performLegacyRequest(t, engine, http.MethodPost, "/api/proxy-routes/", map[string]any{
|
||||
rec := performLegacyRequest(t, engine, http.MethodPost, apiPath("/proxy-routes/"), map[string]any{
|
||||
"site_name": "security-site",
|
||||
"domain": "security.example.com",
|
||||
"origin_url": "http://origin.security.internal:8080",
|
||||
@@ -231,10 +219,8 @@ func TestSecurityWAFTLSMigrationFlow(t *testing.T) {
|
||||
}, adminAuthHeaders(seed.Token))
|
||||
require.Equal(t, http.StatusOK, rec.Code)
|
||||
|
||||
envelope := decodeEnvelope(t, rec)
|
||||
require.True(t, envelope.Success, envelope.Message)
|
||||
|
||||
data := unmarshalEnvelopeMap(t, envelope.Data)
|
||||
resp := requireAPIOK(t, rec)
|
||||
data := unmarshalAPIMap(t, resp.Data)
|
||||
proxyRouteID = uint(data["id"].(float64))
|
||||
assert.NotZero(t, proxyRouteID)
|
||||
assert.Equal(t, "security.example.com", data["domain"])
|
||||
@@ -245,7 +231,7 @@ func TestSecurityWAFTLSMigrationFlow(t *testing.T) {
|
||||
t,
|
||||
engine,
|
||||
http.MethodPost,
|
||||
fmt.Sprintf("/api/waf/sites/%d/rule-groups", proxyRouteID),
|
||||
fmt.Sprintf("%s/waf/sites/%d/rule-groups", apiPath(""), proxyRouteID),
|
||||
map[string]any{
|
||||
"ids": []uint{ruleGroupID},
|
||||
},
|
||||
@@ -253,10 +239,8 @@ func TestSecurityWAFTLSMigrationFlow(t *testing.T) {
|
||||
)
|
||||
require.Equal(t, http.StatusOK, rec.Code)
|
||||
|
||||
envelope := decodeEnvelope(t, rec)
|
||||
require.True(t, envelope.Success, envelope.Message)
|
||||
|
||||
data := unmarshalEnvelopeMap(t, envelope.Data)
|
||||
resp := requireAPIOK(t, rec)
|
||||
data := unmarshalAPIMap(t, resp.Data)
|
||||
assert.Equal(t, float64(proxyRouteID), data["route_id"])
|
||||
|
||||
appliedIDs, ok := data["applied_ids"].([]any)
|
||||
@@ -270,16 +254,14 @@ func TestSecurityWAFTLSMigrationFlow(t *testing.T) {
|
||||
t,
|
||||
engine,
|
||||
http.MethodGet,
|
||||
fmt.Sprintf("/api/waf/sites/%d/rule-groups", proxyRouteID),
|
||||
fmt.Sprintf("%s/waf/sites/%d/rule-groups", apiPath(""), proxyRouteID),
|
||||
nil,
|
||||
adminAuthHeaders(seed.Token),
|
||||
)
|
||||
require.Equal(t, http.StatusOK, rec.Code)
|
||||
|
||||
envelope := decodeEnvelope(t, rec)
|
||||
require.True(t, envelope.Success, envelope.Message)
|
||||
|
||||
data := unmarshalEnvelopeMap(t, envelope.Data)
|
||||
resp := requireAPIOK(t, rec)
|
||||
data := unmarshalAPIMap(t, resp.Data)
|
||||
assert.NotNil(t, data["global_rule_group"])
|
||||
|
||||
appliedGroups, ok := data["applied_rule_groups"].([]any)
|
||||
@@ -293,7 +275,7 @@ func TestSecurityWAFTLSMigrationFlow(t *testing.T) {
|
||||
t.Run("create TLS certificate with PEM", func(t *testing.T) {
|
||||
certPEM, keyPEM := generateSelfSignedCertificatePair(t, []string{"security.example.com"})
|
||||
|
||||
rec := performLegacyRequest(t, engine, http.MethodPost, "/api/tls-certificates/", map[string]any{
|
||||
rec := performLegacyRequest(t, engine, http.MethodPost, apiPath("/tls-certificates/"), map[string]any{
|
||||
"name": "security-cert",
|
||||
"cert_pem": certPEM,
|
||||
"key_pem": keyPEM,
|
||||
@@ -301,10 +283,8 @@ func TestSecurityWAFTLSMigrationFlow(t *testing.T) {
|
||||
}, adminAuthHeaders(seed.Token))
|
||||
require.Equal(t, http.StatusOK, rec.Code)
|
||||
|
||||
envelope := decodeEnvelope(t, rec)
|
||||
require.True(t, envelope.Success, envelope.Message)
|
||||
|
||||
data := unmarshalEnvelopeMap(t, envelope.Data)
|
||||
resp := requireAPIOK(t, rec)
|
||||
data := unmarshalAPIMap(t, resp.Data)
|
||||
certID = uint(data["id"].(float64))
|
||||
assert.NotZero(t, certID)
|
||||
assert.Equal(t, "security-cert", data["name"])
|
||||
@@ -312,7 +292,7 @@ func TestSecurityWAFTLSMigrationFlow(t *testing.T) {
|
||||
})
|
||||
|
||||
t.Run("create managed domain", func(t *testing.T) {
|
||||
rec := performLegacyRequest(t, engine, http.MethodPost, "/api/managed-domains/", map[string]any{
|
||||
rec := performLegacyRequest(t, engine, http.MethodPost, apiPath("/managed-domains/"), map[string]any{
|
||||
"domain": "security.example.com",
|
||||
"cert_id": certID,
|
||||
"enabled": true,
|
||||
@@ -320,10 +300,8 @@ func TestSecurityWAFTLSMigrationFlow(t *testing.T) {
|
||||
}, adminAuthHeaders(seed.Token))
|
||||
require.Equal(t, http.StatusOK, rec.Code)
|
||||
|
||||
envelope := decodeEnvelope(t, rec)
|
||||
require.True(t, envelope.Success, envelope.Message)
|
||||
|
||||
data := unmarshalEnvelopeMap(t, envelope.Data)
|
||||
resp := requireAPIOK(t, rec)
|
||||
data := unmarshalAPIMap(t, resp.Data)
|
||||
domainID = uint(data["id"].(float64))
|
||||
assert.NotZero(t, domainID)
|
||||
assert.Equal(t, "security.example.com", data["domain"])
|
||||
@@ -332,17 +310,15 @@ func TestSecurityWAFTLSMigrationFlow(t *testing.T) {
|
||||
})
|
||||
|
||||
t.Run("create DNS account", func(t *testing.T) {
|
||||
rec := performLegacyRequest(t, engine, http.MethodPost, "/api/dns-accounts/", map[string]any{
|
||||
rec := performLegacyRequest(t, engine, http.MethodPost, apiPath("/dns-accounts/"), map[string]any{
|
||||
"name": "cloudflare-dns",
|
||||
"type": "cloudflare",
|
||||
"authorization": "test-api-token-value",
|
||||
}, adminAuthHeaders(seed.Token))
|
||||
require.Equal(t, http.StatusOK, rec.Code)
|
||||
|
||||
envelope := decodeEnvelope(t, rec)
|
||||
require.True(t, envelope.Success, envelope.Message)
|
||||
|
||||
data := unmarshalEnvelopeMap(t, envelope.Data)
|
||||
resp := requireAPIOK(t, rec)
|
||||
data := unmarshalAPIMap(t, resp.Data)
|
||||
dnsAccountID = uint(data["id"].(float64))
|
||||
assert.NotZero(t, dnsAccountID)
|
||||
assert.Equal(t, "cloudflare-dns", data["name"])
|
||||
@@ -358,29 +334,27 @@ func TestSecurityWAFTLSMigrationFlow(t *testing.T) {
|
||||
t,
|
||||
engine,
|
||||
http.MethodPost,
|
||||
fmt.Sprintf("/api/waf/rule-groups/%d/delete", ruleGroupID),
|
||||
fmt.Sprintf("%s/waf/rule-groups/%d/delete", apiPath(""), ruleGroupID),
|
||||
nil,
|
||||
adminAuthHeaders(seed.Token),
|
||||
)
|
||||
require.Equal(t, http.StatusOK, rec.Code)
|
||||
|
||||
envelope := decodeEnvelope(t, rec)
|
||||
require.True(t, envelope.Success, envelope.Message)
|
||||
requireAPIOK(t, rec)
|
||||
|
||||
detailRec := performLegacyRequest(
|
||||
t,
|
||||
engine,
|
||||
http.MethodGet,
|
||||
fmt.Sprintf("/api/waf/rule-groups/%d", ruleGroupID),
|
||||
fmt.Sprintf("%s/waf/rule-groups/%d", apiPath(""), ruleGroupID),
|
||||
nil,
|
||||
adminAuthHeaders(seed.Token),
|
||||
)
|
||||
require.Equal(t, http.StatusOK, detailRec.Code)
|
||||
detailEnvelope := decodeEnvelope(t, detailRec)
|
||||
assert.False(t, detailEnvelope.Success)
|
||||
require.Equal(t, http.StatusNotFound, detailRec.Code)
|
||||
detailResp := decodeAPIResponse(t, detailRec)
|
||||
assert.NotEmpty(t, detailResp.ErrorMsg)
|
||||
})
|
||||
|
||||
_ = ipGroupID
|
||||
_ = domainID
|
||||
_ = dnsAccountID
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user