From f94a534facb34e6b5ddba904e1044c04d814cd05 Mon Sep 17 00:00:00 2001 From: Mark Paluch Date: Wed, 8 Mar 2017 11:04:39 +0100 Subject: [PATCH] DATAREST-1019 - Consider base URI when resolving cross-origin configuration on repositories. We now consider the base URI when resolving CORS configuration from repository interfaces. The base URI is now stripped from the request. Previously the base URI was not stripped from the request and was used to determine an exported resource. --- .../webmvc/RepositoryRestHandlerMapping.java | 2 +- ...RepositoryRestHandlerMappingUnitTests.java | 42 +++++++++++++++++++ 2 files changed, 43 insertions(+), 1 deletion(-) diff --git a/spring-data-rest-webmvc/src/main/java/org/springframework/data/rest/webmvc/RepositoryRestHandlerMapping.java b/spring-data-rest-webmvc/src/main/java/org/springframework/data/rest/webmvc/RepositoryRestHandlerMapping.java index cd831fabf..8d3f9c0ea 100644 --- a/spring-data-rest-webmvc/src/main/java/org/springframework/data/rest/webmvc/RepositoryRestHandlerMapping.java +++ b/spring-data-rest-webmvc/src/main/java/org/springframework/data/rest/webmvc/RepositoryRestHandlerMapping.java @@ -214,7 +214,7 @@ public class RepositoryRestHandlerMapping extends BasePathAwareHandlerMapping { CorsConfiguration corsConfiguration = super.getCorsConfiguration(handler, request); return repositories.filter(it -> StringUtils.hasText(repositoryLookupPath))// - .flatMap(it -> corsConfigurationAccessor.findCorsConfiguration(lookupPath)) + .flatMap(it -> corsConfigurationAccessor.findCorsConfiguration(repositoryLookupPath)) .map(it -> it.combine(corsConfiguration))// .orElse(corsConfiguration); } diff --git a/spring-data-rest-webmvc/src/test/java/org/springframework/data/rest/webmvc/RepositoryRestHandlerMappingUnitTests.java b/spring-data-rest-webmvc/src/test/java/org/springframework/data/rest/webmvc/RepositoryRestHandlerMappingUnitTests.java index 547cf02bb..cb597c479 100755 --- a/spring-data-rest-webmvc/src/test/java/org/springframework/data/rest/webmvc/RepositoryRestHandlerMappingUnitTests.java +++ b/spring-data-rest-webmvc/src/test/java/org/springframework/data/rest/webmvc/RepositoryRestHandlerMappingUnitTests.java @@ -19,6 +19,7 @@ import static org.assertj.core.api.Assertions.*; import static org.mockito.Mockito.*; import java.lang.reflect.Method; +import java.util.Collections; import org.junit.Before; import org.junit.Test; @@ -27,11 +28,13 @@ import org.mockito.Mock; import org.mockito.junit.MockitoJUnitRunner; import org.springframework.data.domain.Sort; import org.springframework.data.repository.support.Repositories; +import org.springframework.data.rest.core.Path; import org.springframework.data.rest.core.config.EnumTranslationConfiguration; import org.springframework.data.rest.core.config.MetadataConfiguration; import org.springframework.data.rest.core.config.ProjectionDefinitionConfiguration; import org.springframework.data.rest.core.config.RepositoryRestConfiguration; import org.springframework.data.rest.core.mapping.ResourceMappings; +import org.springframework.data.rest.core.mapping.ResourceMetadata; import org.springframework.data.rest.webmvc.config.RepositoryRestMvcConfiguration; import org.springframework.data.rest.webmvc.support.DefaultedPageable; import org.springframework.mock.web.MockHttpServletRequest; @@ -44,6 +47,7 @@ import org.springframework.web.method.HandlerMethod; * * @author Oliver Gierke * @author Greg Turnquist + * @author Mark Paluch */ @RunWith(MockitoJUnitRunner.Silent.class) public class RepositoryRestHandlerMappingUnitTests { @@ -57,6 +61,7 @@ public class RepositoryRestHandlerMappingUnitTests { } @Mock ResourceMappings mappings; + @Mock ResourceMetadata resourceMetadata; @Mock Repositories repositories; RepositoryRestConfiguration configuration; @@ -210,6 +215,43 @@ public class RepositoryRestHandlerMappingUnitTests { assertThat(handlerMapping.getHandler(mockRequest)).isNull(); } + @Test // DATAREST-1019 + public void resolvesCorsConfigurationFromRequestUri() { + + String uri = "/people"; + + when(mappings.exportsTopLevelResourceFor("/people")).thenReturn(true); + when(mappings.iterator()).thenReturn(Collections.singleton(resourceMetadata).iterator()); + when(resourceMetadata.getPath()).thenReturn(new Path("/people")); + + mockRequest = new MockHttpServletRequest("GET", uri); + mockRequest.setServletPath(uri); + + handlerMapping.getCorsConfiguration(uri, mockRequest); + + verify(mappings).exportsTopLevelResourceFor("/people"); + } + + @Test // DATAREST-1019 + public void stripsBaseUriForCorsConfigurationResolution() { + + String baseUri = "/foo"; + String uri = baseUri.concat("/people"); + + configuration.setBasePath(baseUri); + + when(mappings.exportsTopLevelResourceFor("/people")).thenReturn(true); + when(mappings.iterator()).thenReturn(Collections.singleton(resourceMetadata).iterator()); + when(resourceMetadata.getPath()).thenReturn(new Path("/people")); + + mockRequest = new MockHttpServletRequest("GET", uri); + mockRequest.setServletPath(uri); + + handlerMapping.getCorsConfiguration(uri, mockRequest); + + verify(mappings).exportsTopLevelResourceFor("/people"); + } + @Test // DATAREST-994 public void twoArgumentConstructorDoesNotThrowException() { new RepositoryRestHandlerMapping(mappings, configuration);