27
server/routes/api/middlewares/apiWrapper.js
Normal file
27
server/routes/api/middlewares/apiWrapper.js
Normal file
@@ -0,0 +1,27 @@
|
||||
// @flow
|
||||
import stream from "stream";
|
||||
import { type Context } from "koa";
|
||||
|
||||
export default function apiWrapper() {
|
||||
return async function apiWrapperMiddleware(
|
||||
ctx: Context,
|
||||
next: () => Promise<*>
|
||||
) {
|
||||
await next();
|
||||
|
||||
const ok = ctx.status < 400;
|
||||
|
||||
if (
|
||||
typeof ctx.body !== "string" &&
|
||||
!(ctx.body instanceof stream.Readable)
|
||||
) {
|
||||
// $FlowFixMe
|
||||
ctx.body = {
|
||||
// $FlowFixMe
|
||||
...ctx.body,
|
||||
status: ctx.status,
|
||||
ok,
|
||||
};
|
||||
}
|
||||
};
|
||||
}
|
||||
27
server/routes/api/middlewares/editor.js
Normal file
27
server/routes/api/middlewares/editor.js
Normal file
@@ -0,0 +1,27 @@
|
||||
// @flow
|
||||
import { type Context } from "koa";
|
||||
import pkg from "rich-markdown-editor/package.json";
|
||||
import semver from "semver";
|
||||
import { EditorUpdateError } from "../../../errors";
|
||||
|
||||
export default function editor() {
|
||||
return async function editorMiddleware(ctx: Context, next: () => Promise<*>) {
|
||||
const clientVersion = ctx.headers["x-editor-version"];
|
||||
|
||||
// If the editor version on the client is behind the current version being
|
||||
// served in production by either a minor (new features), or major (breaking
|
||||
// changes) then force a client reload.
|
||||
if (clientVersion) {
|
||||
const parsedClientVersion = semver.parse(clientVersion);
|
||||
const parsedCurrentVersion = semver.parse(pkg.version);
|
||||
|
||||
if (
|
||||
parsedClientVersion.major < parsedCurrentVersion.major ||
|
||||
parsedClientVersion.minor < parsedCurrentVersion.minor
|
||||
) {
|
||||
throw new EditorUpdateError();
|
||||
}
|
||||
}
|
||||
return next();
|
||||
};
|
||||
}
|
||||
70
server/routes/api/middlewares/pagination.js
Normal file
70
server/routes/api/middlewares/pagination.js
Normal file
@@ -0,0 +1,70 @@
|
||||
// @flow
|
||||
import querystring from "querystring";
|
||||
import { type Context } from "koa";
|
||||
import { InvalidRequestError } from "../../../errors";
|
||||
|
||||
export default function pagination(options?: Object) {
|
||||
return async function paginationMiddleware(
|
||||
ctx: Context,
|
||||
next: () => Promise<*>
|
||||
) {
|
||||
const opts = {
|
||||
defaultLimit: 15,
|
||||
defaultOffset: 0,
|
||||
maxLimit: 100,
|
||||
...options,
|
||||
};
|
||||
|
||||
let query = ctx.request.query;
|
||||
let body = ctx.request.body;
|
||||
|
||||
// $FlowFixMe
|
||||
let limit = query.limit || body.limit;
|
||||
// $FlowFixMe
|
||||
let offset = query.offset || body.offset;
|
||||
|
||||
if (limit && isNaN(limit)) {
|
||||
throw new InvalidRequestError(`Pagination limit must be a valid number`);
|
||||
}
|
||||
if (offset && isNaN(offset)) {
|
||||
throw new InvalidRequestError(`Pagination offset must be a valid number`);
|
||||
}
|
||||
|
||||
limit = parseInt(limit || opts.defaultLimit, 10);
|
||||
offset = parseInt(offset || opts.defaultOffset, 10);
|
||||
|
||||
if (limit > opts.maxLimit) {
|
||||
throw new InvalidRequestError(
|
||||
`Pagination limit is too large (max ${opts.maxLimit})`
|
||||
);
|
||||
}
|
||||
if (limit <= 0) {
|
||||
throw new InvalidRequestError(`Pagination limit must be greater than 0`);
|
||||
}
|
||||
if (offset < 0) {
|
||||
throw new InvalidRequestError(
|
||||
`Pagination offset must be greater than or equal to 0`
|
||||
);
|
||||
}
|
||||
|
||||
/* $FlowFixMeNowPlease This comment suppresses an error found when upgrading
|
||||
* flow-bin@0.104.0. To view the error, delete this comment and run Flow. */
|
||||
ctx.state.pagination = {
|
||||
limit,
|
||||
offset,
|
||||
};
|
||||
|
||||
// $FlowFixMe
|
||||
query.limit = ctx.state.pagination.limit;
|
||||
// $FlowFixMe
|
||||
query.offset = ctx.state.pagination.offset + query.limit;
|
||||
|
||||
/* $FlowFixMeNowPlease This comment suppresses an error found when upgrading
|
||||
* flow-bin@0.104.0. To view the error, delete this comment and run Flow. */
|
||||
ctx.state.pagination.nextPath = `/api${
|
||||
ctx.request.path
|
||||
}?${querystring.stringify(query)}`;
|
||||
|
||||
return next();
|
||||
};
|
||||
}
|
||||
56
server/routes/api/middlewares/pagination.test.js
Normal file
56
server/routes/api/middlewares/pagination.test.js
Normal file
@@ -0,0 +1,56 @@
|
||||
/* eslint-disable flowtype/require-valid-file-annotation */
|
||||
import TestServer from "fetch-test-server";
|
||||
import webService from "../../../services/web";
|
||||
import { flushdb, seed } from "../../../test/support";
|
||||
const app = webService();
|
||||
const server = new TestServer(app.callback());
|
||||
|
||||
beforeEach(() => flushdb());
|
||||
afterAll(() => server.close());
|
||||
|
||||
describe("#pagination", () => {
|
||||
it("should allow offset and limit", async () => {
|
||||
const { user } = await seed();
|
||||
const res = await server.post("/api/users.list", {
|
||||
body: { token: user.getJwtToken(), limit: 1, offset: 1 },
|
||||
});
|
||||
|
||||
expect(res.status).toEqual(200);
|
||||
});
|
||||
|
||||
it("should not allow negative limit", async () => {
|
||||
const { user } = await seed();
|
||||
const res = await server.post("/api/users.list", {
|
||||
body: { token: user.getJwtToken(), limit: -1 },
|
||||
});
|
||||
|
||||
expect(res.status).toEqual(400);
|
||||
});
|
||||
|
||||
it("should not allow non-integer limit", async () => {
|
||||
const { user } = await seed();
|
||||
const res = await server.post("/api/users.list", {
|
||||
body: { token: user.getJwtToken(), limit: "blah" },
|
||||
});
|
||||
|
||||
expect(res.status).toEqual(400);
|
||||
});
|
||||
|
||||
it("should not allow negative offset", async () => {
|
||||
const { user } = await seed();
|
||||
const res = await server.post("/api/users.list", {
|
||||
body: { token: user.getJwtToken(), offset: -1 },
|
||||
});
|
||||
|
||||
expect(res.status).toEqual(400);
|
||||
});
|
||||
|
||||
it("should not allow non-integer offset", async () => {
|
||||
const { user } = await seed();
|
||||
const res = await server.post("/api/users.list", {
|
||||
body: { token: user.getJwtToken(), offset: "blah" },
|
||||
});
|
||||
|
||||
expect(res.status).toEqual(400);
|
||||
});
|
||||
});
|
||||
Reference in New Issue
Block a user