forgejo/tests/integration
Jack Hay 18de83b2a3
Redesign Scoped Access Tokens (#24767)
## Changes
- Adds the following high level access scopes, each with `read` and
`write` levels:
    - `activitypub`
    - `admin` (hidden if user is not a site admin)
    - `misc`
    - `notification`
    - `organization`
    - `package`
    - `issue`
    - `repository`
    - `user`
- Adds new middleware function `tokenRequiresScopes()` in addition to
`reqToken()`
  -  `tokenRequiresScopes()` is used for each high-level api section
- _if_ a scoped token is present, checks that the required scope is
included based on the section and HTTP method
  - `reqToken()` is used for individual routes
- checks that required authentication is present (but does not check
scope levels as this will already have been handled by
`tokenRequiresScopes()`
- Adds migration to convert old scoped access tokens to the new set of
scopes
- Updates the user interface for scope selection

### User interface example
<img width="903" alt="Screen Shot 2023-05-31 at 1 56 55 PM"
src="https://github.com/go-gitea/gitea/assets/23248839/654766ec-2143-4f59-9037-3b51600e32f3">
<img width="917" alt="Screen Shot 2023-05-31 at 1 56 43 PM"
src="https://github.com/go-gitea/gitea/assets/23248839/1ad64081-012c-4a73-b393-66b30352654c">

## tokenRequiresScopes  Design Decision
- `tokenRequiresScopes()` was added to more reliably cover api routes.
For an incoming request, this function uses the given scope category
(say `AccessTokenScopeCategoryOrganization`) and the HTTP method (say
`DELETE`) and verifies that any scoped tokens in use include
`delete:organization`.
- `reqToken()` is used to enforce auth for individual routes that
require it. If a scoped token is not present for a request,
`tokenRequiresScopes()` will not return an error

## TODO
- [x] Alphabetize scope categories
- [x] Change 'public repos only' to a radio button (private vs public).
Also expand this to organizations
- [X] Disable token creation if no scopes selected. Alternatively, show
warning
- [x] `reqToken()` is missing from many `POST/DELETE` routes in the api.
`tokenRequiresScopes()` only checks that a given token has the correct
scope, `reqToken()` must be used to check that a token (or some other
auth) is present.
   -  _This should be addressed in this PR_
- [x] The migration should be reviewed very carefully in order to
minimize access changes to existing user tokens.
   - _This should be addressed in this PR_
- [x] Link to api to swagger documentation, clarify what
read/write/delete levels correspond to
- [x] Review cases where more than one scope is needed as this directly
deviates from the api definition.
   - _This should be addressed in this PR_
   - For example: 
   ```go
	m.Group("/users/{username}/orgs", func() {
		m.Get("", reqToken(), org.ListUserOrgs)
		m.Get("/{org}/permissions", reqToken(), org.GetUserOrgsPermissions)
}, tokenRequiresScopes(auth_model.AccessTokenScopeCategoryUser,
auth_model.AccessTokenScopeCategoryOrganization),
context_service.UserAssignmentAPI())
   ```

## Future improvements
- [ ] Add required scopes to swagger documentation
- [ ] Redesign `reqToken()` to be opt-out rather than opt-in
- [ ] Subdivide scopes like `repository`
- [ ] Once a token is created, if it has no scopes, we should display
text instead of an empty bullet point
- [ ] If the 'public repos only' option is selected, should read
categories be selected by default

Closes #24501
Closes #24799

Co-authored-by: Jonathan Tran <jon@allspice.io>
Co-authored-by: Kyle D <kdumontnu@gmail.com>
Co-authored-by: silverwind <me@silverwind.io>
2023-06-04 20:57:16 +02:00
..
migration-test Rewrite logger system (#24726) 2023-05-21 22:35:11 +00:00
schemas
admin_config_test.go Fix admin config page error, use tests to cover the admin config and 500 error page (#24965) 2023-05-29 15:00:21 +00:00
admin_user_test.go
api_actions_artifact_test.go Implement actions artifacts (#22738) 2023-05-19 21:37:57 +08:00
api_activitypub_person_test.go Use User.ID instead of User.Name in ActivityPub API for Person IRI (#23823) 2023-04-04 10:08:23 +08:00
api_admin_org_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_admin_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_branch_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_comment_attachment_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_comment_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_feed_user_test.go
api_fork_test.go
api_gitignore_templates_test.go Add API for gitignore templates (#22783) 2023-04-27 11:51:20 +08:00
api_gpg_keys_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_helper_for_declarative_test.go
api_httpsig_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_issue_attachment_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_issue_config_test.go Use more specific test methods (#24265) 2023-04-22 17:56:27 -04:00
api_issue_label_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_issue_milestone_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_issue_pin_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_issue_reaction_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_issue_stopwatch_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_issue_subscription_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_issue_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_issue_tracked_time_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_keys_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_label_templates_test.go Add API for Label templates (#24602) 2023-05-23 18:10:23 +08:00
api_license_templates_test.go Add API for License templates (#23009) 2023-04-26 02:08:28 -04:00
api_nodeinfo_test.go Support "." char as user name for User/Orgs in RSS/ATOM/GPG/KEYS path ... (#23874) 2023-04-07 18:08:36 +08:00
api_notification_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_oauth2_apps_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_org_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_packages_alpine_test.go Add v3.18 to TestPackageAlpine (#24972) 2023-05-29 15:45:32 +00:00
api_packages_cargo_test.go Implement Cargo HTTP index (#24452) 2023-05-03 16:58:43 -04:00
api_packages_chef_test.go Use minio/sha256-simd for accelerated SHA256 (#23052) 2023-02-22 14:21:46 -05:00
api_packages_composer_test.go Remove all package data after tests (#22984) 2023-02-23 22:11:56 +08:00
api_packages_conan_test.go Remove all package data after tests (#22984) 2023-02-23 22:11:56 +08:00
api_packages_conda_test.go Add Conda package registry (#22262) 2023-02-01 12:30:39 -06:00
api_packages_container_test.go Display image size for multiarch container images (#23821) 2023-04-02 17:53:37 +08:00
api_packages_cran_test.go Add CRAN package registry (#22331) 2023-05-22 10:57:49 +08:00
api_packages_debian_test.go Add Debian package registry (#24426) 2023-05-02 12:31:35 -04:00
api_packages_generic_test.go Remove all package data after tests (#22984) 2023-02-23 22:11:56 +08:00
api_packages_goproxy_test.go Add Go package registry (#24687) 2023-05-14 23:38:40 +08:00
api_packages_helm_test.go Remove all package data after tests (#22984) 2023-02-23 22:11:56 +08:00
api_packages_maven_test.go Remove all package data after tests (#22984) 2023-02-23 22:11:56 +08:00
api_packages_npm_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_packages_nuget_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_packages_pub_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_packages_pypi_test.go Remove all package data after tests (#22984) 2023-02-23 22:11:56 +08:00
api_packages_rpm_test.go Add RPM registry (#23380) 2023-05-05 20:33:37 +00:00
api_packages_rubygems_test.go Remove all package data after tests (#22984) 2023-02-23 22:11:56 +08:00
api_packages_swift_test.go Add Swift package registry (#22404) 2023-03-13 15:28:39 -05:00
api_packages_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_packages_vagrant_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_private_serv_test.go Refactor internal API for git commands, use meaningful messages instead of "Internal Server Error" (#23687) 2023-03-29 14:32:26 +08:00
api_pull_commits_test.go
api_pull_review_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_pull_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_releases_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_repo_archive_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_repo_collaborator_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_repo_edit_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_repo_file_create_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_repo_file_delete_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_repo_file_get_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_repo_file_helpers.go API endpoint for changing/creating/deleting multiple files (#24887) 2023-05-29 17:41:35 +08:00
api_repo_file_update_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_repo_files_change_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_repo_get_contents_list_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_repo_get_contents_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_repo_git_blobs_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_repo_git_commits_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_repo_git_hook_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_repo_git_notes_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_repo_git_ref_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_repo_git_tags_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_repo_git_trees_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_repo_hook_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_repo_languages_test.go
api_repo_lfs_locks_test.go
api_repo_lfs_migrate_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_repo_lfs_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_repo_raw_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_repo_tags_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_repo_teams_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_repo_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_repo_topic_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_settings_test.go
api_team_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_team_user_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_token_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_user_email_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_user_follow_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_user_heatmap_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_user_info_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_user_org_perm_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_user_orgs_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_user_search_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_user_star_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_user_watch_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
api_wiki_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
attachment_test.go Fix users cannot visit issue attachment bug (#25019) 2023-05-31 19:06:17 +02:00
auth_ldap_test.go Use more specific test methods (#24265) 2023-04-22 17:56:27 -04:00
benchmarks_test.go
branches_test.go
change_default_branch_test.go
cmd_keys_test.go
compare_test.go Use beforeCommit instead of baseCommit (#22949) 2023-02-20 11:56:07 +08:00
cors_test.go Use more specific test methods (#24265) 2023-04-22 17:56:27 -04:00
create_no_session_test.go
csrf_test.go
delete_user_test.go
download_test.go
dump_restore_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
editor_test.go Use double quotes consistently in en-US (#24141) 2023-04-17 18:04:26 -04:00
empty_repo_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
eventsource_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
explore_repos_test.go
git_clone_wiki_test.go
git_helper_for_declarative_test.go Refactor git command package to improve security and maintainability (#22678) 2023-02-04 10:30:43 +08:00
git_smart_http_test.go
git_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
goget_test.go Support SSH for go get (#24664) 2023-05-12 09:44:37 +00:00
gpg_git_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
html_helper.go
incoming_email_test.go
integration_test.go Rewrite logger system (#24726) 2023-05-21 22:35:11 +00:00
issue_test.go Make Issue/PR/projects more compact, misc CSS tweaks (#24459) 2023-05-03 17:58:59 -04:00
lfs_getobject_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
lfs_local_endpoint_test.go
lfs_view_test.go
links_test.go
markup_external_test.go Drop "unrolled/render" package (#23965) 2023-04-08 14:21:50 +08:00
migrate_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
mirror_pull_test.go
mirror_push_test.go Refactor cookie (#24107) 2023-04-13 15:45:33 -04:00
nonascii_branches_test.go
oauth_test.go Allow for PKCE flow without client secret + add docs (#25033) 2023-06-03 05:59:28 +02:00
org_count_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
org_team_invite_test.go
org_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
private-testing.key
privateactivity_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
pull_compare_test.go Rework header bar on issue, pull requests and milestone (#24420) 2023-04-29 23:33:25 -04:00
pull_create_test.go Improve RSS (#24335) 2023-04-25 22:53:44 -04:00
pull_merge_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
pull_review_test.go
pull_status_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
pull_update_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
README.md replace drone exec to act_runner exec in test README.md (#24791) 2023-05-18 19:48:47 +00:00
README_ZH.md replace drone exec to act_runner exec in test README.md (#24791) 2023-05-18 19:48:47 +00:00
release_test.go fix: release page for empty or non-existing target (#24470) 2023-05-10 11:43:55 +08:00
rename_branch_test.go
repo_activity_test.go
repo_branch_test.go
repo_commits_search_test.go
repo_commits_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
repo_fork_test.go
repo_generate_test.go
repo_migrate_test.go
repo_search_test.go
repo_tag_test.go
repo_test.go In TestViewRepo2, convert computed timezones to local time (#24579) 2023-05-08 21:07:41 +08:00
repo_topic_test.go
repo_watch_test.go
repofiles_change_test.go API endpoint for changing/creating/deleting multiple files (#24887) 2023-05-29 17:41:35 +08:00
setting_test.go Sort users and orgs on explore by recency by default (#24279) 2023-05-06 22:04:55 +08:00
signin_test.go
signout_test.go
signup_test.go
ssh_key_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
timetracking_test.go
user_avatar_test.go Reserve ".png" suffix for user/org names (#23992) 2023-04-10 16:14:16 -04:00
user_test.go Redesign Scoped Access Tokens (#24767) 2023-06-04 20:57:16 +02:00
version_test.go
view_test.go
webfinger_test.go Use User.ID instead of User.Name in ActivityPub API for Person IRI (#23823) 2023-04-04 10:08:23 +08:00
xss_test.go

Integration tests

Integration tests can be run with make commands for the appropriate backends, namely:

make test-sqlite
make test-pgsql
make test-mysql
make test-mysql8
make test-mssql

Make sure to perform a clean build before running tests:

make clean build

Run tests via local act_runner

Run all jobs

act_runner exec -W ./.github/workflows/pull-db-tests.yml --event=pull_request --default-actions-url="https://github.com" -i catthehacker/ubuntu:runner-latest

Warning: This file defines many jobs, so it will be resource-intensive and therefor not recommended.

Run single job

act_runner exec -W ./.github/workflows/pull-db-tests.yml --event=pull_request --default-actions-url="https://github.com" -i catthehacker/ubuntu:runner-latest -j <job_name>

You can list all job names via:

act_runner exec -W ./.github/workflows/pull-db-tests.yml --event=pull_request --default-actions-url="https://github.com" -i catthehacker/ubuntu:runner-latest -l

Run sqlite integration tests

Start tests

make test-sqlite

Run MySQL integration tests

Setup a MySQL database inside docker

docker run -e "MYSQL_DATABASE=test" -e "MYSQL_ALLOW_EMPTY_PASSWORD=yes" -p 3306:3306 --rm --name mysql mysql:latest #(just ctrl-c to stop db and clean the container)
docker run -p 9200:9200 -p 9300:9300 -e "discovery.type=single-node" --rm --name elasticsearch elasticsearch:7.6.0 #(in a second terminal, just ctrl-c to stop db and clean the container)

Start tests based on the database container

TEST_MYSQL_HOST=localhost:3306 TEST_MYSQL_DBNAME=test TEST_MYSQL_USERNAME=root TEST_MYSQL_PASSWORD='' make test-mysql

Run pgsql integration tests

Setup a pgsql database inside docker

docker run -e "POSTGRES_DB=test" -p 5432:5432 --rm --name pgsql postgres:latest #(just ctrl-c to stop db and clean the container)

Start tests based on the database container

TEST_PGSQL_HOST=localhost:5432 TEST_PGSQL_DBNAME=test TEST_PGSQL_USERNAME=postgres TEST_PGSQL_PASSWORD=postgres make test-pgsql

Run mssql integration tests

Setup a mssql database inside docker

docker run -e "ACCEPT_EULA=Y" -e "MSSQL_PID=Standard" -e "SA_PASSWORD=MwantsaSecurePassword1" -p 1433:1433 --rm --name mssql microsoft/mssql-server-linux:latest #(just ctrl-c to stop db and clean the container)

Start tests based on the database container

TEST_MSSQL_HOST=localhost:1433 TEST_MSSQL_DBNAME=gitea_test TEST_MSSQL_USERNAME=sa TEST_MSSQL_PASSWORD=MwantsaSecurePassword1 make test-mssql

Running individual tests

Example command to run GPG test:

For SQLite:

make test-sqlite#GPG

For other databases(replace mssql to mysql, mysql8 or pgsql):

TEST_MSSQL_HOST=localhost:1433 TEST_MSSQL_DBNAME=test TEST_MSSQL_USERNAME=sa TEST_MSSQL_PASSWORD=MwantsaSecurePassword1 make test-mssql#GPG

Setting timeouts for declaring long-tests and long-flushes

We appreciate that some testing machines may not be very powerful and the default timeouts for declaring a slow test or a slow clean-up flush may not be appropriate.

You can either:

  • Within the test ini file set the following section:
[integration-tests]
SLOW_TEST = 10s ; 10s is the default value
SLOW_FLUSH = 5S ; 5s is the default value
  • Set the following environment variables:
GITEA_SLOW_TEST_TIME="10s" GITEA_SLOW_FLUSH_TIME="5s" make test-sqlite