@@ -3,6 +3,11 @@
|
||||
All notable changes to this project will be documented in this file.
|
||||
This project adheres to [Semantic Versioning](http://semver.org/).
|
||||
|
||||
## Unreleased
|
||||
|
||||
### Fixed
|
||||
- Reject non-POSTs to rpc endpoints - @begriffs
|
||||
|
||||
## [0.3.0.3] - 2016-01-08
|
||||
|
||||
### Fixed
|
||||
|
||||
@@ -31,6 +31,7 @@ data Action = ActionCreate | ActionRead
|
||||
| ActionUnknown BS.ByteString deriving Eq
|
||||
-- | The target db object of a user action
|
||||
data Target = TargetIdent QualifiedIdentifier
|
||||
| TargetProc QualifiedIdentifier
|
||||
| TargetRoot
|
||||
| TargetUnknown [T.Text]
|
||||
-- | How to return the inserted data
|
||||
@@ -90,7 +91,7 @@ userApiRequest schema req reqBody =
|
||||
[] -> TargetRoot
|
||||
[table] -> TargetIdent
|
||||
$ QualifiedIdentifier schema table
|
||||
["rpc", proc] -> TargetIdent
|
||||
["rpc", proc] -> TargetProc
|
||||
$ QualifiedIdentifier schema proc
|
||||
other -> TargetUnknown other
|
||||
payload = case pickContentType (lookupHeader "content-type") of
|
||||
|
||||
@@ -155,7 +155,7 @@ app dbStructure conf reqBody req =
|
||||
filterCol _ _ _ = False
|
||||
return $ responseLBS status200 [jsonH, allOrigins] $ cs body
|
||||
|
||||
(ActionInvoke, TargetIdent qi,
|
||||
(ActionInvoke, TargetProc qi,
|
||||
Just (PayloadJSON (UniformObjects payload))) -> do
|
||||
exists <- H.query qi doesProcExist
|
||||
if exists
|
||||
@@ -178,6 +178,8 @@ app dbStructure conf reqBody req =
|
||||
|
||||
(ActionUnknown _, _, _) -> return notFound
|
||||
|
||||
(_, TargetProc _, _) -> return $ responseLBS status405 [] ""
|
||||
|
||||
(_, TargetUnknown _, _) -> return notFound
|
||||
|
||||
(_, _, Just (PayloadParseError e)) ->
|
||||
|
||||
@@ -386,6 +386,9 @@ spec struct c = around (withApp cfgDefault struct c) $ do
|
||||
post "/rpc/sayhello" [json| { "name": "world" } |] `shouldRespondWith`
|
||||
[json| [{"sayhello":"Hello, world"}] |]
|
||||
|
||||
it "currently supports POST only" $
|
||||
get "/rpc/fake" `shouldRespondWith` 405 -- method not allowed
|
||||
|
||||
describe "weird requests" $ do
|
||||
it "can query as normal" $ do
|
||||
get "/Escap3e;" `shouldRespondWith`
|
||||
|
||||
Reference in New Issue
Block a user