Welcome to mirror list, hosted at ThFree Co, Russian Federation.

collector_app_attack_spec.rb « product_analytics « requests « spec - gitlab.com/gitlab-org/gitlab-foss.git - Unnamed repository; edit this file 'description' to name the repository.
summaryrefslogtreecommitdiff
blob: 6f86e39c295fdd694bf2af25f9eb856dd0fb926e (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
# frozen_string_literal: true

require 'spec_helper'

RSpec.describe 'ProductAnalytics::CollectorApp throttle' do
  include RackAttackSpecHelpers

  include_context 'rack attack cache store'

  let(:project1) { create(:project) }
  let(:project2) { create(:project) }

  before do
    allow(ProductAnalyticsEvent).to receive(:create).and_return(true)
  end

  context 'per application id' do
    let(:params) do
      {
        aid: project1.id,
        eid: SecureRandom.uuid
      }
    end

    it 'throttles the endpoint' do
      # Allow requests under the rate limit.
      100.times do
        expect_ok { get '/-/collector/i', params: params }
      end

      # Ensure its not related to ip address
      random_next_ip

      # Reject request over the limit
      expect_rejection { get '/-/collector/i', params: params }

      # But allows request for different aid
      expect_ok { get '/-/collector/i', params: params.merge(aid: project2.id) }
    end
  end
end