Created middleware to retrieve JWT token from header

This commit is contained in:
Chris Troutner
2019-10-20 11:55:46 -07:00
parent 532f06cec1
commit 4032e66be3
7 changed files with 436 additions and 184 deletions
+113 -81
View File
@@ -14,8 +14,11 @@ const axios = require("axios")
const util = require("util")
util.inspect.defaultOptions = { depth: 1 }
const SERVER = `http://192.168.0.36:12400/v3/`
//const SERVER = `http://localhost:3000/v2/`
// const SERVER = `http://192.168.0.36:12400/v3/`
const SERVER = `http://localhost:3000/v3/`
const TEST_JWT =
"eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6IjVkYTc5ZDk4OTYyMjRjNjM2MmQwYzkwMiIsImlhdCI6MTU3MTUzOTU1MSwiZXhwIjoxNTc0MTMxNTUxfQ.PfPW_Z2NYT1O2zUHXopcz2aLGHSGudaKOIGnt7SuAi4"
describe("#rate limits", () => {
it("should get control/getNetworkInfo() with no auth", async () => {
@@ -32,102 +35,131 @@ describe("#rate limits", () => {
assert.hasAnyKeys(result.data, ["version"])
})
it("should trigger rate-limit handler if rate limits exceeds 30 request per minute", async () => {
// it("should trigger rate-limit handler if rate limits exceeds 30 request per minute", async () => {
// try {
// // Actual rate limit is 60 per minute X 4 nodes = 240 rpm.
// const options = {
// method: "GET",
// url: `${SERVER}control/getNetworkInfo`
// }
//
// const promises = []
// for (let i = 0; i < 30; i++) {
// const promise = axios(options)
// promises.push(promise)
// }
//
// await Promise.all(promises)
//
// assert.equal(true, false, "Unexpected result!")
// } catch (err) {
// //console.log(`err.response: ${util.inspect(err.response)}`)
//
// assert.equal(err.response.status, 429)
// assert.include(err.response.data.error, "Too many requests")
// }
// })
// it("should not trigger rate-limit handler if correct pro-tier password is used", async () => {
// try {
// const username = "BITBOX"
//
// // Pro-tier is accessed by using the right password.
// const password = "BITBOX"
// //const password = "something"
//
// const combined = `${username}:${password}`
// const base64Credential = Buffer.from(combined).toString("base64")
// const readyCredential = `Basic ${base64Credential}`
//
// const options = {
// method: "GET",
// url: `${SERVER}control/getNetworkInfo`,
// headers: { Authorization: readyCredential }
// }
//
// const promises = []
// for (let i = 0; i < 30; i++) {
// const promise = axios(options)
// promises.push(promise)
// }
//
// await Promise.all(promises)
//
// assert.equal(true, true, "Not throwing an error is a pass!")
// } catch (err) {
// // console.log(`err.response: ${util.inspect(err.response)}`)
//
// assert.equal(
// true,
// false,
// "This error handler should not have been triggered. Is the password correct?"
// )
// }
// })
// it("should trigger rate-limit handler if rate limits exceeds pro-tier limit", async () => {
// try {
// const username = "BITBOX"
//
// // Pro-tier is accessed by using the right password.
// const password = "BITBOX"
// //const password = "something"
//
// const combined = `${username}:${password}`
// const base64Credential = Buffer.from(combined).toString("base64")
// const readyCredential = `Basic ${base64Credential}`
//
// // Actual rate limit is 60 per minute X 4 nodes = 240 rpm.
// const options = {
// method: "GET",
// url: `${SERVER}control/getNetworkInfo`,
// headers: { Authorization: readyCredential }
// }
//
// const promises = []
// for (let i = 0; i < 80; i++) {
// const promise = axios(options)
// promises.push(promise)
// }
//
// await Promise.all(promises)
//
// assert.equal(true, false, "Unexpected result!")
// } catch (err) {
// //console.log(`err.response: ${util.inspect(err.response)}`)
//
// assert.equal(err.response.status, 429)
// assert.include(err.response.data.error, "Too many requests")
// }
// })
it("should unlock pro-tier for a valid JWT token", async () => {
try {
// Actual rate limit is 60 per minute X 4 nodes = 240 rpm.
const options = {
method: "GET",
url: `${SERVER}control/getNetworkInfo`
}
const promises = []
for (let i = 0; i < 30; i++) {
const promise = axios(options)
promises.push(promise)
}
await Promise.all(promises)
assert.equal(true, false, "Unexpected result!")
} catch (err) {
//console.log(`err.response: ${util.inspect(err.response)}`)
assert.equal(err.response.status, 429)
assert.include(err.response.data.error, "Too many requests")
}
})
it("should not trigger rate-limit handler if correct pro-tier password is used", async () => {
try {
const username = "BITBOX"
// Pro-tier is accessed by using the right password.
const password = "BITBOX"
//const password = "something"
const combined = `${username}:${password}`
const base64Credential = Buffer.from(combined).toString("base64")
const readyCredential = `Basic ${base64Credential}`
const options = {
method: "GET",
url: `${SERVER}control/getNetworkInfo`,
headers: { Authorization: readyCredential }
headers: {
Authorization: `Token ${TEST_JWT}`
}
}
const promises = []
for (let i = 0; i < 30; i++) {
for (let i = 0; i < 1; i++) {
const promise = axios(options)
promises.push(promise)
}
await Promise.all(promises)
//assert.equal(true, false, "Unexpected result!")
assert.equal(true, true, "Not throwing an error is a pass!")
} catch (err) {
// console.log(`err.response: ${util.inspect(err.response)}`)
assert.equal(
true,
false,
"This error handler should not have been triggered. Is the password correct?"
)
}
})
it("should trigger rate-limit handler if rate limits exceeds pro-tier limit", async () => {
try {
const username = "BITBOX"
// Pro-tier is accessed by using the right password.
const password = "BITBOX"
//const password = "something"
const combined = `${username}:${password}`
const base64Credential = Buffer.from(combined).toString("base64")
const readyCredential = `Basic ${base64Credential}`
// Actual rate limit is 60 per minute X 4 nodes = 240 rpm.
const options = {
method: "GET",
url: `${SERVER}control/getNetworkInfo`,
headers: { Authorization: readyCredential }
}
const promises = []
for (let i = 0; i < 80; i++) {
const promise = axios(options)
promises.push(promise)
}
await Promise.all(promises)
console.log(`err.response: ${util.inspect(err.response)}`)
assert.equal(true, false, "Unexpected result!")
} catch (err) {
//console.log(`err.response: ${util.inspect(err.response)}`)
assert.equal(err.response.status, 429)
assert.include(err.response.data.error, "Too many requests")
}
})
// Override default timeout for this test.
}).timeout(20000)
})