-
Notifications
You must be signed in to change notification settings - Fork 141
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Merge pull request #763 from zalando/714-rules-to-aos--AvoidLinkHeade…
…rsRule 714-rules-to-aos--AvoidLinkHeadersRule
- Loading branch information
Showing
6 changed files
with
206 additions
and
46 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
31 changes: 16 additions & 15 deletions
31
server/src/main/java/de/zalando/zally/rule/zalando/AvoidLinkHeadersRule.kt
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,31 +1,32 @@ | ||
package de.zalando.zally.rule.zalando | ||
|
||
import com.typesafe.config.Config | ||
import de.zalando.zally.rule.Context | ||
import de.zalando.zally.rule.HttpHeadersRule | ||
import de.zalando.zally.rule.api.Check | ||
import de.zalando.zally.rule.api.Rule | ||
import de.zalando.zally.rule.api.Severity | ||
import de.zalando.zally.rule.api.Violation | ||
import de.zalando.zally.rule.api.Rule | ||
import io.swagger.models.Swagger | ||
import de.zalando.zally.util.getAllHeaders | ||
import org.springframework.beans.factory.annotation.Autowired | ||
|
||
@Rule( | ||
ruleSet = ZalandoRuleSet::class, | ||
id = "166", | ||
severity = Severity.MUST, | ||
title = "Avoid Link in Header Rule" | ||
ruleSet = ZalandoRuleSet::class, | ||
id = "166", | ||
severity = Severity.MUST, | ||
title = "Avoid Link in Header Rule" | ||
) | ||
class AvoidLinkHeadersRule(@Autowired rulesConfig: Config) : HttpHeadersRule(rulesConfig) { | ||
private val description = "Do Not Use Link Headers with JSON entities" | ||
class AvoidLinkHeadersRule(@Autowired rulesConfig: Config) { | ||
|
||
@Check(severity = Severity.MUST) | ||
override fun validate(swagger: Swagger): Violation? { | ||
return super.validate(swagger) | ||
} | ||
private val headersWhitelist = rulesConfig.getStringList(HttpHeadersRule::class.simpleName + ".whitelist").toSet() | ||
|
||
override fun isViolation(header: String) = header == "Link" | ||
private val description = "Do Not Use Link Headers with JSON entities" | ||
|
||
override fun createViolation(paths: List<String>): Violation { | ||
return Violation(description, paths) | ||
@Check(severity = Severity.MUST) | ||
fun validate(context: Context): List<Violation> { | ||
val allHeaders = context.api.getAllHeaders() | ||
return allHeaders | ||
.filter { it.name !in headersWhitelist && it.name == "Link" } | ||
.map { context.violation(description, it.element) } // createViolation(context, it) } | ||
} | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,37 @@ | ||
package de.zalando.zally.util | ||
|
||
import io.swagger.v3.oas.models.OpenAPI | ||
import io.swagger.v3.oas.models.parameters.Parameter | ||
import io.swagger.v3.oas.models.responses.ApiResponse | ||
|
||
data class HeaderElement( | ||
val name: String, | ||
val element: Any | ||
) | ||
|
||
fun OpenAPI.getAllHeaders(): Set<HeaderElement> { | ||
|
||
fun Collection<Parameter>?.extractHeaders() = orEmpty() | ||
.filter { it.`in` == "header" } | ||
.map { HeaderElement(it.name, it) } | ||
.toSet() | ||
|
||
fun Collection<ApiResponse>?.extractHeaders() = orEmpty() | ||
.flatMap { it.headers.orEmpty().entries } | ||
.map { HeaderElement(it.key, it.value) } | ||
.toSet() | ||
|
||
val fromParams = components.parameters.orEmpty().values.extractHeaders() | ||
|
||
val fromPaths = paths.orEmpty().flatMap { (_, path) -> | ||
val fromPathParameters = path.parameters.extractHeaders() | ||
val fromOperations = path.readOperations().flatMap { operation -> | ||
val fromOpParams = operation.parameters.extractHeaders() | ||
val fromOpResponses = operation.responses.orEmpty().values.extractHeaders() | ||
fromOpParams + fromOpResponses | ||
} | ||
fromPathParameters + fromOperations | ||
} | ||
|
||
return fromParams + fromPaths | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
130 changes: 117 additions & 13 deletions
130
server/src/test/java/de/zalando/zally/rule/zalando/AvoidLinkHeadersRuleTest.kt
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,31 +1,135 @@ | ||
package de.zalando.zally.rule.zalando | ||
|
||
import de.zalando.zally.getFixture | ||
import de.zalando.zally.rule.Context | ||
import de.zalando.zally.rule.ZallyAssertions.Companion.assertThat | ||
import de.zalando.zally.testConfig | ||
import org.assertj.core.api.Assertions.assertThat | ||
import org.intellij.lang.annotations.Language | ||
import org.junit.Test | ||
|
||
class AvoidLinkHeadersRuleTest { | ||
|
||
private val rule = AvoidLinkHeadersRule(testConfig) | ||
|
||
@Test | ||
fun positiveCaseSpp() { | ||
val swagger = getFixture("api_spp.json") | ||
assertThat(rule.validate(swagger)).isNull() | ||
fun `a Swagger API with no header called Link produces no violation`() { | ||
@Language("YAML") | ||
val context = Context.createSwaggerContext(""" | ||
swagger: 2.0 | ||
info: | ||
title: Clean Swagger API | ||
paths: | ||
/foo: | ||
get: | ||
description: Lorem Ipsum | ||
responses: | ||
202: | ||
description: Lorem Ipsum | ||
headers: | ||
Location: # should not violate since not called `Link` | ||
type: string | ||
format: url | ||
parameters: | ||
FlowId: # should not violate since not named `Link` | ||
name: X-Flow-Id | ||
in: header | ||
type: string | ||
Link: # should not violate since not a header | ||
name: Link | ||
in: query | ||
type: string | ||
ProductId: # should not violate since not a header nor named `Link` | ||
name: product_id | ||
in: path | ||
type: string | ||
""".trimIndent(), failOnParseErrors = true)!! | ||
val violations = rule.validate(context) | ||
assertThat(violations).isEmpty() | ||
} | ||
|
||
@Test | ||
fun positiveCaseSpa() { | ||
val swagger = getFixture("api_spa.yaml") | ||
assertThat(rule.validate(swagger)).isNull() | ||
fun `an OpenAPI 3 API with no header called Link produces no violation`() { | ||
@Language("YAML") | ||
val context = Context.createOpenApiContext(""" | ||
openapi: 3.0.0 | ||
info: | ||
title: Clean Swagger API | ||
version: 1.0.0 | ||
paths: | ||
/foo: | ||
get: | ||
description: Lorem Ipsum | ||
responses: | ||
202: | ||
description: Lorem Ipsum | ||
headers: | ||
Location: | ||
schema: | ||
type: string | ||
format: url | ||
components: | ||
parameters: | ||
FlowId: | ||
name: X-Flow-Id | ||
in: header | ||
required: false | ||
schema: | ||
type: string | ||
Authorization: | ||
name: Authorization | ||
in: header | ||
required: true | ||
schema: | ||
type: string | ||
ProductId: | ||
name: product_id | ||
in: path | ||
required: true | ||
schema: | ||
type: string | ||
""".trimIndent(), failOnParseErrors = true)!! | ||
val violations = rule.validate(context) | ||
assertThat(violations).isEmpty() | ||
} | ||
|
||
@Test | ||
fun negativeCase() { | ||
val swagger = getFixture("avoidLinkHeaderRuleInvalid.json") | ||
val violation = rule.validate(swagger)!! | ||
assertThat(violation.paths).hasSameElementsAs( | ||
listOf("/product-put-requests/{product_path} Link", "/products Link")) | ||
fun `an API with Link headers causes violations`() { | ||
@Language("YAML") | ||
val context = Context.createSwaggerContext(""" | ||
swagger: 2.0 | ||
info: | ||
title: Clean Swagger API | ||
paths: | ||
/foo: | ||
get: | ||
parameters: | ||
- name: Authorization | ||
in: header | ||
type: string | ||
- name: Link | ||
in: header | ||
type: string | ||
responses: | ||
202: | ||
description: Lorem Ipsum | ||
headers: | ||
Location: | ||
type: string | ||
format: url | ||
post: | ||
responses: | ||
202: | ||
description: Lorem Ipsum | ||
headers: | ||
Link: | ||
type: string | ||
format: url | ||
""".trimIndent(), failOnParseErrors = true)!! | ||
val violations = rule.validate(context) | ||
assertThat(violations) | ||
.descriptionsAllEqualTo("Do Not Use Link Headers with JSON entities") | ||
.pointersEqualTo( | ||
"/paths/~1foo/get/parameters/1", | ||
"/paths/~1foo/post/responses/202/headers/Link" | ||
) | ||
} | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters