test_server.py 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377
  1. # Copyright 2018 New Vector Ltd
  2. #
  3. # Licensed under the Apache License, Version 2.0 (the "License");
  4. # you may not use this file except in compliance with the License.
  5. # You may obtain a copy of the License at
  6. #
  7. # http://www.apache.org/licenses/LICENSE-2.0
  8. #
  9. # Unless required by applicable law or agreed to in writing, software
  10. # distributed under the License is distributed on an "AS IS" BASIS,
  11. # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  12. # See the License for the specific language governing permissions and
  13. # limitations under the License.
  14. import logging
  15. import re
  16. from io import StringIO
  17. from twisted.internet.defer import Deferred
  18. from twisted.python.failure import Failure
  19. from twisted.test.proto_helpers import AccumulatingProtocol
  20. from twisted.web.resource import Resource
  21. from twisted.web.server import NOT_DONE_YET
  22. from synapse.api.errors import Codes, RedirectException, SynapseError
  23. from synapse.config.server import parse_listener_def
  24. from synapse.http.server import (
  25. DirectServeResource,
  26. JsonResource,
  27. OptionsResource,
  28. wrap_html_request_handler,
  29. )
  30. from synapse.http.site import SynapseSite, logger
  31. from synapse.logging.context import make_deferred_yieldable
  32. from synapse.util import Clock
  33. from tests import unittest
  34. from tests.server import (
  35. FakeTransport,
  36. ThreadedMemoryReactorClock,
  37. make_request,
  38. render,
  39. setup_test_homeserver,
  40. )
  41. class JsonResourceTests(unittest.TestCase):
  42. def setUp(self):
  43. self.reactor = ThreadedMemoryReactorClock()
  44. self.hs_clock = Clock(self.reactor)
  45. self.homeserver = setup_test_homeserver(
  46. self.addCleanup, http_client=None, clock=self.hs_clock, reactor=self.reactor
  47. )
  48. def test_handler_for_request(self):
  49. """
  50. JsonResource.handler_for_request gives correctly decoded URL args to
  51. the callback, while Twisted will give the raw bytes of URL query
  52. arguments.
  53. """
  54. got_kwargs = {}
  55. def _callback(request, **kwargs):
  56. got_kwargs.update(kwargs)
  57. return 200, kwargs
  58. res = JsonResource(self.homeserver)
  59. res.register_paths(
  60. "GET",
  61. [re.compile("^/_matrix/foo/(?P<room_id>[^/]*)$")],
  62. _callback,
  63. "test_servlet",
  64. )
  65. request, channel = make_request(
  66. self.reactor, b"GET", b"/_matrix/foo/%E2%98%83?a=%E2%98%83"
  67. )
  68. render(request, res, self.reactor)
  69. self.assertEqual(request.args, {b"a": ["\N{SNOWMAN}".encode("utf8")]})
  70. self.assertEqual(got_kwargs, {"room_id": "\N{SNOWMAN}"})
  71. def test_callback_direct_exception(self):
  72. """
  73. If the web callback raises an uncaught exception, it will be translated
  74. into a 500.
  75. """
  76. def _callback(request, **kwargs):
  77. raise Exception("boo")
  78. res = JsonResource(self.homeserver)
  79. res.register_paths(
  80. "GET", [re.compile("^/_matrix/foo$")], _callback, "test_servlet"
  81. )
  82. request, channel = make_request(self.reactor, b"GET", b"/_matrix/foo")
  83. render(request, res, self.reactor)
  84. self.assertEqual(channel.result["code"], b"500")
  85. def test_callback_indirect_exception(self):
  86. """
  87. If the web callback raises an uncaught exception in a Deferred, it will
  88. be translated into a 500.
  89. """
  90. def _throw(*args):
  91. raise Exception("boo")
  92. def _callback(request, **kwargs):
  93. d = Deferred()
  94. d.addCallback(_throw)
  95. self.reactor.callLater(1, d.callback, True)
  96. return make_deferred_yieldable(d)
  97. res = JsonResource(self.homeserver)
  98. res.register_paths(
  99. "GET", [re.compile("^/_matrix/foo$")], _callback, "test_servlet"
  100. )
  101. request, channel = make_request(self.reactor, b"GET", b"/_matrix/foo")
  102. render(request, res, self.reactor)
  103. self.assertEqual(channel.result["code"], b"500")
  104. def test_callback_synapseerror(self):
  105. """
  106. If the web callback raises a SynapseError, it returns the appropriate
  107. status code and message set in it.
  108. """
  109. def _callback(request, **kwargs):
  110. raise SynapseError(403, "Forbidden!!one!", Codes.FORBIDDEN)
  111. res = JsonResource(self.homeserver)
  112. res.register_paths(
  113. "GET", [re.compile("^/_matrix/foo$")], _callback, "test_servlet"
  114. )
  115. request, channel = make_request(self.reactor, b"GET", b"/_matrix/foo")
  116. render(request, res, self.reactor)
  117. self.assertEqual(channel.result["code"], b"403")
  118. self.assertEqual(channel.json_body["error"], "Forbidden!!one!")
  119. self.assertEqual(channel.json_body["errcode"], "M_FORBIDDEN")
  120. def test_no_handler(self):
  121. """
  122. If there is no handler to process the request, Synapse will return 400.
  123. """
  124. def _callback(request, **kwargs):
  125. """
  126. Not ever actually called!
  127. """
  128. self.fail("shouldn't ever get here")
  129. res = JsonResource(self.homeserver)
  130. res.register_paths(
  131. "GET", [re.compile("^/_matrix/foo$")], _callback, "test_servlet"
  132. )
  133. request, channel = make_request(self.reactor, b"GET", b"/_matrix/foobar")
  134. render(request, res, self.reactor)
  135. self.assertEqual(channel.result["code"], b"400")
  136. self.assertEqual(channel.json_body["error"], "Unrecognized request")
  137. self.assertEqual(channel.json_body["errcode"], "M_UNRECOGNIZED")
  138. class OptionsResourceTests(unittest.TestCase):
  139. def setUp(self):
  140. self.reactor = ThreadedMemoryReactorClock()
  141. class DummyResource(Resource):
  142. isLeaf = True
  143. def render(self, request):
  144. return request.path
  145. # Setup a resource with some children.
  146. self.resource = OptionsResource()
  147. self.resource.putChild(b"res", DummyResource())
  148. def _make_request(self, method, path):
  149. """Create a request from the method/path and return a channel with the response."""
  150. request, channel = make_request(self.reactor, method, path, shorthand=False)
  151. request.prepath = [] # This doesn't get set properly by make_request.
  152. # Create a site and query for the resource.
  153. site = SynapseSite(
  154. "test",
  155. "site_tag",
  156. parse_listener_def({"type": "http", "port": 0}),
  157. self.resource,
  158. "1.0",
  159. )
  160. request.site = site
  161. resource = site.getResourceFor(request)
  162. # Finally, render the resource and return the channel.
  163. render(request, resource, self.reactor)
  164. return channel
  165. def test_unknown_options_request(self):
  166. """An OPTIONS requests to an unknown URL still returns 200 OK."""
  167. channel = self._make_request(b"OPTIONS", b"/foo/")
  168. self.assertEqual(channel.result["code"], b"200")
  169. self.assertEqual(channel.result["body"], b"{}")
  170. # Ensure the correct CORS headers have been added
  171. self.assertTrue(
  172. channel.headers.hasHeader(b"Access-Control-Allow-Origin"),
  173. "has CORS Origin header",
  174. )
  175. self.assertTrue(
  176. channel.headers.hasHeader(b"Access-Control-Allow-Methods"),
  177. "has CORS Methods header",
  178. )
  179. self.assertTrue(
  180. channel.headers.hasHeader(b"Access-Control-Allow-Headers"),
  181. "has CORS Headers header",
  182. )
  183. def test_known_options_request(self):
  184. """An OPTIONS requests to an known URL still returns 200 OK."""
  185. channel = self._make_request(b"OPTIONS", b"/res/")
  186. self.assertEqual(channel.result["code"], b"200")
  187. self.assertEqual(channel.result["body"], b"{}")
  188. # Ensure the correct CORS headers have been added
  189. self.assertTrue(
  190. channel.headers.hasHeader(b"Access-Control-Allow-Origin"),
  191. "has CORS Origin header",
  192. )
  193. self.assertTrue(
  194. channel.headers.hasHeader(b"Access-Control-Allow-Methods"),
  195. "has CORS Methods header",
  196. )
  197. self.assertTrue(
  198. channel.headers.hasHeader(b"Access-Control-Allow-Headers"),
  199. "has CORS Headers header",
  200. )
  201. def test_unknown_request(self):
  202. """A non-OPTIONS request to an unknown URL should 404."""
  203. channel = self._make_request(b"GET", b"/foo/")
  204. self.assertEqual(channel.result["code"], b"404")
  205. def test_known_request(self):
  206. """A non-OPTIONS request to an known URL should query the proper resource."""
  207. channel = self._make_request(b"GET", b"/res/")
  208. self.assertEqual(channel.result["code"], b"200")
  209. self.assertEqual(channel.result["body"], b"/res/")
  210. class WrapHtmlRequestHandlerTests(unittest.TestCase):
  211. class TestResource(DirectServeResource):
  212. callback = None
  213. @wrap_html_request_handler
  214. async def _async_render_GET(self, request):
  215. return await self.callback(request)
  216. def setUp(self):
  217. self.reactor = ThreadedMemoryReactorClock()
  218. def test_good_response(self):
  219. def callback(request):
  220. request.write(b"response")
  221. request.finish()
  222. res = WrapHtmlRequestHandlerTests.TestResource()
  223. res.callback = callback
  224. request, channel = make_request(self.reactor, b"GET", b"/path")
  225. render(request, res, self.reactor)
  226. self.assertEqual(channel.result["code"], b"200")
  227. body = channel.result["body"]
  228. self.assertEqual(body, b"response")
  229. def test_redirect_exception(self):
  230. """
  231. If the callback raises a RedirectException, it is turned into a 30x
  232. with the right location.
  233. """
  234. def callback(request, **kwargs):
  235. raise RedirectException(b"/look/an/eagle", 301)
  236. res = WrapHtmlRequestHandlerTests.TestResource()
  237. res.callback = callback
  238. request, channel = make_request(self.reactor, b"GET", b"/path")
  239. render(request, res, self.reactor)
  240. self.assertEqual(channel.result["code"], b"301")
  241. headers = channel.result["headers"]
  242. location_headers = [v for k, v in headers if k == b"Location"]
  243. self.assertEqual(location_headers, [b"/look/an/eagle"])
  244. def test_redirect_exception_with_cookie(self):
  245. """
  246. If the callback raises a RedirectException which sets a cookie, that is
  247. returned too
  248. """
  249. def callback(request, **kwargs):
  250. e = RedirectException(b"/no/over/there", 304)
  251. e.cookies.append(b"session=yespls")
  252. raise e
  253. res = WrapHtmlRequestHandlerTests.TestResource()
  254. res.callback = callback
  255. request, channel = make_request(self.reactor, b"GET", b"/path")
  256. render(request, res, self.reactor)
  257. self.assertEqual(channel.result["code"], b"304")
  258. headers = channel.result["headers"]
  259. location_headers = [v for k, v in headers if k == b"Location"]
  260. self.assertEqual(location_headers, [b"/no/over/there"])
  261. cookies_headers = [v for k, v in headers if k == b"Set-Cookie"]
  262. self.assertEqual(cookies_headers, [b"session=yespls"])
  263. class SiteTestCase(unittest.HomeserverTestCase):
  264. def test_lose_connection(self):
  265. """
  266. We log the URI correctly redacted when we lose the connection.
  267. """
  268. class HangingResource(Resource):
  269. """
  270. A Resource that strategically hangs, as if it were processing an
  271. answer.
  272. """
  273. def render(self, request):
  274. return NOT_DONE_YET
  275. # Set up a logging handler that we can inspect afterwards
  276. output = StringIO()
  277. handler = logging.StreamHandler(output)
  278. logger.addHandler(handler)
  279. old_level = logger.level
  280. logger.setLevel(10)
  281. self.addCleanup(logger.setLevel, old_level)
  282. self.addCleanup(logger.removeHandler, handler)
  283. # Make a resource and a Site, the resource will hang and allow us to
  284. # time out the request while it's 'processing'
  285. base_resource = Resource()
  286. base_resource.putChild(b"", HangingResource())
  287. site = SynapseSite(
  288. "test", "site_tag", self.hs.config.listeners[0], base_resource, "1.0"
  289. )
  290. server = site.buildProtocol(None)
  291. client = AccumulatingProtocol()
  292. client.makeConnection(FakeTransport(server, self.reactor))
  293. server.makeConnection(FakeTransport(client, self.reactor))
  294. # Send a request with an access token that will get redacted
  295. server.dataReceived(b"GET /?access_token=bar HTTP/1.0\r\n\r\n")
  296. self.pump()
  297. # Lose the connection
  298. e = Failure(Exception("Failed123"))
  299. server.connectionLost(e)
  300. handler.flush()
  301. # Our access token is redacted and the failure reason is logged.
  302. self.assertIn("/?access_token=<redacted>", output.getvalue())
  303. self.assertIn("Failed123", output.getvalue())