const expect = require('chai').expect const should = require('chai').should const utils = require('./utils') const rp = require('request-promise') const assert = require('chai').assert const util = require('util') util.inspect.defaultOptions = { depth: 1 } const LOCALHOST = 'http://localhost:5000' should() const context = {} describe('Users', () => { before(async () => { utils.cleanDb() }) describe('POST /users', () => { it('should reject signup when data is incomplete', async () => { try { const options = { method: 'POST', uri: `${LOCALHOST}/users`, resolveWithFullResponse: true, json: true, body: { username: 'supercoolname' } } let result = await rp(options) console.log(`result stringified: ${JSON.stringify(result, null, 2)}`) assert(false, 'Unexpected result') } catch (err) { if (err.statusCode === 422) { assert(err.statusCode === 422, 'Error code 422 expected.') } else if (err.statusCode === 401) { assert(err.statusCode === 401, 'Error code 401 expected.') } else { console.error('Error: ', err) console.log('Error stringified: ' + JSON.stringify(err, null, 2)) throw err } } }) it('should sign up', async () => { try { const options = { method: 'POST', uri: `${LOCALHOST}/users`, resolveWithFullResponse: true, json: true, body: { user: { username: 'supercoolname', password: 'supersecretpassword' } } } let result = await rp(options) result.body.user.should.have.property('username') result.body.user.username.should.equal('supercoolname') expect(result.body.user.password).to.not.exist context.user = result.body.user context.token = result.body.token } catch (err) { console.log( 'Error authenticating test user: ' + JSON.stringify(err, null, 2) ) throw err } }) }) describe('GET /users', () => { it('should not fetch users if the authorization header is missing', async () => { try { const options = { method: 'GET', uri: `${LOCALHOST}/users`, resolveWithFullResponse: true, json: true, headers: { Accept: 'application/json' } } await rp(options) assert.equal(true, false, 'Unexpected behavior') } catch (err) { assert.equal(err.statusCode, 401) } }) it('should not fetch users if the authorization header is missing the scheme', async () => { try { const options = { method: 'GET', uri: `${LOCALHOST}/users`, resolveWithFullResponse: true, json: true, headers: { Accept: 'application/json', Authorization: '1' } } await rp(options) assert.equal(true, false, 'Unexpected behavior') } catch (err) { assert.equal(err.statusCode, 401) } }) it('should not fetch users if the authorization header has invalid scheme', async () => { const { token } = context try { const options = { method: 'GET', uri: `${LOCALHOST}/users`, resolveWithFullResponse: true, json: true, headers: { Accept: 'application/json', Authorization: `Unknown ${token}` } } await rp(options) assert.equal(true, false, 'Unexpected behavior') } catch (err) { assert.equal(err.statusCode, 401) } }) it('should not fetch users if token is invalid', async () => { try { const options = { method: 'GET', uri: `${LOCALHOST}/users`, resolveWithFullResponse: true, json: true, headers: { Accept: 'application/json', Authorization: `Bearer 1` } } await rp(options) assert.equal(true, false, 'Unexpected behavior') } catch (err) { assert.equal(err.statusCode, 401) } }) it('should fetch all users', async () => { const { token } = context const options = { method: 'GET', uri: `${LOCALHOST}/users`, resolveWithFullResponse: true, json: true, headers: { Accept: 'application/json', Authorization: `Bearer ${token}` } } const result = await rp(options) const users = result.body.users // console.log(`users: ${util.inspect(users)}`) assert.hasAnyKeys(users[0], ['type', '_id', 'username']) assert.equal(users.length, 1) }) }) describe('GET /users/:id', () => { it('should not fetch user if token is invalid', async () => { try { const options = { method: 'GET', uri: `${LOCALHOST}/users/1`, resolveWithFullResponse: true, json: true, headers: { Accept: 'application/json', Authorization: `Bearer 1` } } await rp(options) assert.equal(true, false, 'Unexpected behavior') } catch (err) { assert.equal(err.statusCode, 401) } }) it("should throw 404 if user doesn't exist", async () => { const { token } = context try { const options = { method: 'GET', uri: `${LOCALHOST}/users/1`, resolveWithFullResponse: true, json: true, headers: { Accept: 'application/json', Authorization: `Bearer ${token}` } } await rp(options) assert.equal(true, false, 'Unexpected behavior') } catch (err) { assert.equal(err.statusCode, 404) } }) it('should fetch user', async () => { const { user: { _id }, token } = context const options = { method: 'GET', uri: `${LOCALHOST}/users/${_id}`, resolveWithFullResponse: true, json: true, headers: { Accept: 'application/json', Authorization: `Bearer ${token}` } } const result = await rp(options) const user = result.body.user // console.log(`user: ${util.inspect(user)}`) assert.hasAnyKeys(user, ['type', '_id', 'username']) assert.equal(user._id, _id) assert.notProperty( user, 'password', 'Password property should not be returned' ) }) }) describe('PUT /users/:id', () => { it('should not update user if token is invalid', async () => { try { const options = { method: 'PUT', uri: `${LOCALHOST}/users/1`, resolveWithFullResponse: true, json: true, headers: { Accept: 'application/json', Authorization: `Bearer 1` } } await rp(options) assert.equal(true, false, 'Unexpected behavior') } catch (err) { assert.equal(err.statusCode, 401) } }) it("should throw 404 if user doesn't exist", async () => { const { token } = context try { const options = { method: 'PUT', uri: `${LOCALHOST}/users/1`, resolveWithFullResponse: true, json: true, headers: { Accept: 'application/json', Authorization: `Bearer ${token}` } } await rp(options) assert.equal(true, false, 'Unexpected behavior') } catch (err) { assert.equal(err.statusCode, 404) } }) it('should update user', async () => { const { user: { _id }, token } = context const options = { method: 'PUT', uri: `${LOCALHOST}/users/${_id}`, resolveWithFullResponse: true, json: true, headers: { Accept: 'application/json', Authorization: `Bearer ${token}` }, body: { user: { username: 'updatedcoolname' } } } const result = await rp(options) const user = result.body.user // console.log(`user: ${util.inspect(user)}`) assert.hasAnyKeys(user, ['type', '_id', 'username']) assert.equal(user._id, _id) assert.notProperty( user, 'password', 'Password property should not be returned' ) assert.equal(user.username, 'updatedcoolname') }) }) describe('DELETE /users/:id', () => { it('should not delete user if token is invalid', async () => { try { const options = { method: 'DELETE', uri: `${LOCALHOST}/users/1`, resolveWithFullResponse: true, json: true, headers: { Accept: 'application/json', Authorization: `Bearer 1` } } await rp(options) assert.equal(true, false, 'Unexpected behavior') } catch (err) { assert.equal(err.statusCode, 401) } }) it('should throw 404 if user doesn\'t exist', async () => { const { token } = context try { const options = { method: 'DELETE', uri: `${LOCALHOST}/users/1`, resolveWithFullResponse: true, json: true, headers: { Accept: 'application/json', Authorization: `Bearer ${token}` } } await rp(options) assert.equal(true, false, 'Unexpected behavior') } catch (err) { assert.equal(err.statusCode, 404) } }) it('should delete user', async () => { const { user: { _id }, token } = context const options = { method: 'DELETE', uri: `${LOCALHOST}/users/${_id}`, resolveWithFullResponse: true, json: true, headers: { Accept: 'application/json', Authorization: `Bearer ${token}` } } const result = await rp(options) // console.log(`result: ${util.inspect(result.body)}`) assert.equal(result.body.success, true) }) }) })