kibana/x-pack/test/api_integration/apis/spaces/space_attributes.ts
Christiane (Tina) Heiligers 3a68f8b3ae
[http] api_integration tests handle internal route restriction (#192407)
fix https://github.com/elastic/kibana/issues/192052
## Summary

Internal APIs will be
[restricted](https://github.com/elastic/kibana/issues/163654) from
public access as of 9.0.0. In non-serverless environments, this breaking
change will result in a 400 error if an external request is made to an
internal Kibana API (route `access` option as `"internal"` or
`"public"`).
This PR allows API owners of non-xpack plugins to run their `ftr` API
integration tests against the restriction and adds examples of how to
handle it.

### Checklist
- [x] [Unit or functional
tests](https://www.elastic.co/guide/en/kibana/master/development-tests.html)
were updated or added to match the most common scenarios


Note to reviewers: The header needed to allow access to internal apis
shouldn't change your test output, with or without the restriction
enabled.

### How to test the changes work:
#### Non x-pack:
1. Set `server.restrictInternalApis: true` in `test/common/config.js`
2. Ensure your tests pass

#### x-pack:
1. Set `server.restrictInternalApis: true` in
`x-pack/test/api_integration/apis/security/config.ts`
2. Ensure the spaces tests pass

---------

Co-authored-by: Elastic Machine <elasticmachine@users.noreply.github.com>
2024-09-12 09:23:10 +02:00

76 lines
3.9 KiB
TypeScript

/*
* Copyright Elasticsearch B.V. and/or licensed to Elasticsearch B.V. under one
* or more contributor license agreements. Licensed under the Elastic License
* 2.0; you may not use this file except in compliance with the Elastic License
* 2.0.
*/
import { X_ELASTIC_INTERNAL_ORIGIN_REQUEST } from '@kbn/core-http-common';
import { FtrProviderContext } from '../../ftr_provider_context';
export default function ({ getService }: FtrProviderContext) {
const supertest = getService('supertest');
describe('space attributes', () => {
it('should allow a space to be created with a mixed-case hex color code', async () => {
await supertest
.post('/api/spaces/space')
.set('kbn-xsrf', 'xxx')
.set(X_ELASTIC_INTERNAL_ORIGIN_REQUEST, 'kibana')
.send({
id: 'api-test-space',
name: 'api test space',
disabledFeatures: [],
color: '#aaBB78',
})
.expect(200, {
id: 'api-test-space',
name: 'api test space',
disabledFeatures: [],
color: '#aaBB78',
});
});
it('should allow a space to be created with an avatar image', async () => {
await supertest
.post('/api/spaces/space')
.set('kbn-xsrf', 'xxx')
.set(X_ELASTIC_INTERNAL_ORIGIN_REQUEST, 'kibana')
.send({
id: 'api-test-space2',
name: 'Space with image',
disabledFeatures: [],
color: '#cafeba',
imageUrl:
'',
})
.expect(200, {
id: 'api-test-space2',
name: 'Space with image',
disabledFeatures: [],
color: '#cafeba',
imageUrl:
'',
});
});
it('creating a space with an invalid image fails', async () => {
await supertest
.post('/api/spaces/space')
.set('kbn-xsrf', 'xxx')
.set(X_ELASTIC_INTERNAL_ORIGIN_REQUEST, 'kibana')
.send({
id: 'api-test-space3',
name: 'Space with invalid image',
disabledFeatures: [],
color: '#cafeba',
imageUrl: 'invalidImage',
})
.expect(400, {
error: 'Bad Request',
message: "[request body.imageUrl]: must start with 'data:image'",
statusCode: 400,
});
});
});
}