2015-09-15 05:19:47 -05:00
|
|
|
package middleware
|
|
|
|
|
|
|
|
import (
|
2019-04-30 07:42:01 -05:00
|
|
|
"context"
|
2015-09-18 01:36:58 -05:00
|
|
|
"testing"
|
|
|
|
|
2015-09-15 05:19:47 -05:00
|
|
|
"github.com/grafana/grafana/pkg/bus"
|
2020-02-28 05:50:58 -06:00
|
|
|
"github.com/grafana/grafana/pkg/models"
|
2019-04-08 06:31:46 -05:00
|
|
|
"github.com/grafana/grafana/pkg/services/auth"
|
|
|
|
"github.com/grafana/grafana/pkg/services/quota"
|
2015-09-15 05:19:47 -05:00
|
|
|
"github.com/grafana/grafana/pkg/setting"
|
|
|
|
. "github.com/smartystreets/goconvey/convey"
|
|
|
|
)
|
|
|
|
|
|
|
|
func TestMiddlewareQuota(t *testing.T) {
|
|
|
|
Convey("Given the grafana quota middleware", t, func() {
|
2015-09-18 01:36:58 -05:00
|
|
|
setting.AnonymousEnabled = false
|
2015-09-15 05:19:47 -05:00
|
|
|
setting.Quota = setting.QuotaSettings{
|
|
|
|
Enabled: true,
|
|
|
|
Org: &setting.OrgQuota{
|
|
|
|
User: 5,
|
|
|
|
Dashboard: 5,
|
|
|
|
DataSource: 5,
|
|
|
|
ApiKey: 5,
|
|
|
|
},
|
|
|
|
User: &setting.UserQuota{
|
|
|
|
Org: 5,
|
|
|
|
},
|
|
|
|
Global: &setting.GlobalQuota{
|
|
|
|
Org: 5,
|
|
|
|
User: 5,
|
|
|
|
Dashboard: 5,
|
|
|
|
DataSource: 5,
|
|
|
|
ApiKey: 5,
|
|
|
|
Session: 5,
|
|
|
|
},
|
|
|
|
}
|
|
|
|
|
2019-03-08 08:15:17 -06:00
|
|
|
fakeAuthTokenService := auth.NewFakeUserAuthTokenService()
|
2019-02-11 14:12:01 -06:00
|
|
|
qs := "a.QuotaService{
|
|
|
|
AuthTokenService: fakeAuthTokenService,
|
|
|
|
}
|
|
|
|
QuotaFn := Quota(qs)
|
|
|
|
|
2019-04-08 06:31:46 -05:00
|
|
|
middlewareScenario(t, "with user not logged in", func(sc *scenarioContext) {
|
2020-02-28 05:50:58 -06:00
|
|
|
bus.AddHandler("globalQuota", func(query *models.GetGlobalQuotaByTargetQuery) error {
|
|
|
|
query.Result = &models.GlobalQuotaDTO{
|
2015-09-15 05:19:47 -05:00
|
|
|
Target: query.Target,
|
|
|
|
Limit: query.Default,
|
|
|
|
Used: 4,
|
|
|
|
}
|
|
|
|
return nil
|
|
|
|
})
|
2019-02-11 14:12:01 -06:00
|
|
|
|
2015-09-15 05:19:47 -05:00
|
|
|
Convey("global quota not reached", func() {
|
2019-02-11 14:12:01 -06:00
|
|
|
sc.m.Get("/user", QuotaFn("user"), sc.defaultHandler)
|
2015-09-15 05:19:47 -05:00
|
|
|
sc.fakeReq("GET", "/user").exec()
|
|
|
|
So(sc.resp.Code, ShouldEqual, 200)
|
|
|
|
})
|
2019-02-11 14:12:01 -06:00
|
|
|
|
2015-09-15 05:19:47 -05:00
|
|
|
Convey("global quota reached", func() {
|
|
|
|
setting.Quota.Global.User = 4
|
2019-02-11 14:12:01 -06:00
|
|
|
sc.m.Get("/user", QuotaFn("user"), sc.defaultHandler)
|
2015-09-15 05:19:47 -05:00
|
|
|
sc.fakeReq("GET", "/user").exec()
|
|
|
|
So(sc.resp.Code, ShouldEqual, 403)
|
|
|
|
})
|
2019-02-11 14:12:01 -06:00
|
|
|
|
2015-09-15 05:19:47 -05:00
|
|
|
Convey("global session quota not reached", func() {
|
|
|
|
setting.Quota.Global.Session = 10
|
2019-02-11 14:12:01 -06:00
|
|
|
sc.m.Get("/user", QuotaFn("session"), sc.defaultHandler)
|
2015-09-15 05:19:47 -05:00
|
|
|
sc.fakeReq("GET", "/user").exec()
|
|
|
|
So(sc.resp.Code, ShouldEqual, 200)
|
|
|
|
})
|
2019-02-11 14:12:01 -06:00
|
|
|
|
2015-09-15 05:19:47 -05:00
|
|
|
Convey("global session quota reached", func() {
|
|
|
|
setting.Quota.Global.Session = 1
|
2019-02-11 14:12:01 -06:00
|
|
|
sc.m.Get("/user", QuotaFn("session"), sc.defaultHandler)
|
2015-09-15 05:19:47 -05:00
|
|
|
sc.fakeReq("GET", "/user").exec()
|
|
|
|
So(sc.resp.Code, ShouldEqual, 403)
|
|
|
|
})
|
|
|
|
})
|
|
|
|
|
2019-04-08 06:31:46 -05:00
|
|
|
middlewareScenario(t, "with user logged in", func(sc *scenarioContext) {
|
2019-02-04 16:44:28 -06:00
|
|
|
sc.withTokenSessionCookie("token")
|
2020-02-28 05:50:58 -06:00
|
|
|
bus.AddHandler("test", func(query *models.GetSignedInUserQuery) error {
|
|
|
|
query.Result = &models.SignedInUser{OrgId: 2, UserId: 12}
|
2019-02-04 16:44:28 -06:00
|
|
|
return nil
|
|
|
|
})
|
|
|
|
|
2020-02-28 05:50:58 -06:00
|
|
|
sc.userAuthTokenService.LookupTokenProvider = func(ctx context.Context, unhashedToken string) (*models.UserToken, error) {
|
|
|
|
return &models.UserToken{
|
2019-02-06 09:21:16 -06:00
|
|
|
UserId: 12,
|
|
|
|
UnhashedToken: "",
|
2019-02-04 16:44:28 -06:00
|
|
|
}, nil
|
2019-01-22 06:51:55 -06:00
|
|
|
}
|
2015-09-15 05:19:47 -05:00
|
|
|
|
2020-02-28 05:50:58 -06:00
|
|
|
bus.AddHandler("globalQuota", func(query *models.GetGlobalQuotaByTargetQuery) error {
|
|
|
|
query.Result = &models.GlobalQuotaDTO{
|
2015-09-15 05:19:47 -05:00
|
|
|
Target: query.Target,
|
|
|
|
Limit: query.Default,
|
|
|
|
Used: 4,
|
|
|
|
}
|
|
|
|
return nil
|
|
|
|
})
|
2019-02-11 14:12:01 -06:00
|
|
|
|
2020-02-28 05:50:58 -06:00
|
|
|
bus.AddHandler("userQuota", func(query *models.GetUserQuotaByTargetQuery) error {
|
|
|
|
query.Result = &models.UserQuotaDTO{
|
2015-09-15 05:19:47 -05:00
|
|
|
Target: query.Target,
|
|
|
|
Limit: query.Default,
|
|
|
|
Used: 4,
|
|
|
|
}
|
|
|
|
return nil
|
|
|
|
})
|
2019-02-11 14:12:01 -06:00
|
|
|
|
2020-02-28 05:50:58 -06:00
|
|
|
bus.AddHandler("orgQuota", func(query *models.GetOrgQuotaByTargetQuery) error {
|
|
|
|
query.Result = &models.OrgQuotaDTO{
|
2015-09-15 05:19:47 -05:00
|
|
|
Target: query.Target,
|
|
|
|
Limit: query.Default,
|
|
|
|
Used: 4,
|
|
|
|
}
|
|
|
|
return nil
|
|
|
|
})
|
2019-02-11 14:12:01 -06:00
|
|
|
|
2015-09-15 05:19:47 -05:00
|
|
|
Convey("global datasource quota reached", func() {
|
|
|
|
setting.Quota.Global.DataSource = 4
|
2019-02-11 14:12:01 -06:00
|
|
|
sc.m.Get("/ds", QuotaFn("data_source"), sc.defaultHandler)
|
2015-09-15 05:19:47 -05:00
|
|
|
sc.fakeReq("GET", "/ds").exec()
|
|
|
|
So(sc.resp.Code, ShouldEqual, 403)
|
|
|
|
})
|
2019-02-11 14:12:01 -06:00
|
|
|
|
2015-09-15 05:19:47 -05:00
|
|
|
Convey("user Org quota not reached", func() {
|
|
|
|
setting.Quota.User.Org = 5
|
2019-02-11 14:12:01 -06:00
|
|
|
sc.m.Get("/org", QuotaFn("org"), sc.defaultHandler)
|
2015-09-15 05:19:47 -05:00
|
|
|
sc.fakeReq("GET", "/org").exec()
|
|
|
|
So(sc.resp.Code, ShouldEqual, 200)
|
|
|
|
})
|
2019-02-11 14:12:01 -06:00
|
|
|
|
2015-09-15 05:19:47 -05:00
|
|
|
Convey("user Org quota reached", func() {
|
|
|
|
setting.Quota.User.Org = 4
|
2019-02-11 14:12:01 -06:00
|
|
|
sc.m.Get("/org", QuotaFn("org"), sc.defaultHandler)
|
2015-09-15 05:19:47 -05:00
|
|
|
sc.fakeReq("GET", "/org").exec()
|
|
|
|
So(sc.resp.Code, ShouldEqual, 403)
|
|
|
|
})
|
2019-02-11 14:12:01 -06:00
|
|
|
|
2015-09-15 05:19:47 -05:00
|
|
|
Convey("org dashboard quota not reached", func() {
|
|
|
|
setting.Quota.Org.Dashboard = 10
|
2019-02-11 14:12:01 -06:00
|
|
|
sc.m.Get("/dashboard", QuotaFn("dashboard"), sc.defaultHandler)
|
2015-09-15 05:19:47 -05:00
|
|
|
sc.fakeReq("GET", "/dashboard").exec()
|
|
|
|
So(sc.resp.Code, ShouldEqual, 200)
|
|
|
|
})
|
2019-02-11 14:12:01 -06:00
|
|
|
|
2015-09-15 05:19:47 -05:00
|
|
|
Convey("org dashboard quota reached", func() {
|
|
|
|
setting.Quota.Org.Dashboard = 4
|
2019-02-11 14:12:01 -06:00
|
|
|
sc.m.Get("/dashboard", QuotaFn("dashboard"), sc.defaultHandler)
|
2015-09-15 05:19:47 -05:00
|
|
|
sc.fakeReq("GET", "/dashboard").exec()
|
|
|
|
So(sc.resp.Code, ShouldEqual, 403)
|
|
|
|
})
|
2019-02-11 14:12:01 -06:00
|
|
|
|
2015-09-15 05:19:47 -05:00
|
|
|
Convey("org dashboard quota reached but quotas disabled", func() {
|
|
|
|
setting.Quota.Org.Dashboard = 4
|
|
|
|
setting.Quota.Enabled = false
|
2019-02-11 14:12:01 -06:00
|
|
|
sc.m.Get("/dashboard", QuotaFn("dashboard"), sc.defaultHandler)
|
2015-09-15 05:19:47 -05:00
|
|
|
sc.fakeReq("GET", "/dashboard").exec()
|
|
|
|
So(sc.resp.Code, ShouldEqual, 200)
|
|
|
|
})
|
|
|
|
})
|
|
|
|
})
|
|
|
|
}
|