Merge pull request #1364 from ecordell/error-json-fixes

Fix error-related issues
This commit is contained in:
Evan Cordell 2016-04-13 13:32:00 -04:00
commit 09064853ac
4 changed files with 42 additions and 27 deletions

View file

@ -39,9 +39,9 @@ api.decorators = [csrf_protect,
@crossdomain(origin='*', headers=['Authorization', 'Content-Type'])
def handle_api_error(error):
response = Response(json.dumps(error.to_dict()), error.status_code, mimetype='application/problem+json')
if error.status_code is 401:
if error.status_code == 401:
response.headers['WWW-Authenticate'] = ('Bearer error="%s" error_description="%s"' %
(error.error_type, error.error_description))
(error.error_type.value, error.error_description))
return response
def resource(*urls, **kwargs):

View file

@ -197,6 +197,14 @@ def swagger_route_data(include_internal=False, compact=False):
'title': {
'type': 'string',
'description': 'Unique error code to identify the type of error.'
},
'error_message': {
'type': 'string',
'description': 'Deprecated; alias for detail'
},
'error_type': {
'type': 'string',
'description': 'Deprecated; alias for detail'
}
},
'required': [
@ -224,7 +232,7 @@ def swagger_route_data(include_internal=False, compact=False):
},
}
for status, body in responses.items():
for _, body in responses.items():
body['schema'] = {'$ref': '#/definitions/ApiError'}
if method_name == 'DELETE':

View file

@ -67,7 +67,9 @@ class ApiException(Exception):
if self.error_description is not None:
rv['detail'] = self.error_description
rv['error_message'] = self.error_description # TODO: deprecate
rv['error_type'] = self.error_type.value # TODO: deprecate
rv['title'] = self.error_type.value
rv['type'] = url_for('error', error_type=self.error_type.value, _external=True)
rv['status'] = self.status_code

View file

@ -103,6 +103,11 @@ class TestAuth(ApiTestCase):
self.conduct_basic_auth('$oauthtoken', 'foobar')
self.verify_no_identity()
def test_oauth_invalid_http_response(self):
rv = self.app.get(api.url_for(User), headers={'Authorization': 'Bearer bad_token'})
assert 'WWW-Authenticate' in rv.headers
self.assertEquals(401, rv.status_code)
def test_oauth_valid_user(self):
user = model.user.get_user(ADMIN_ACCESS_USER)
self.create_oauth(user)