Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 2 additions & 1 deletion mailer.py
Original file line number Diff line number Diff line change
Expand Up @@ -42,7 +42,8 @@ def send_simple_message(self, data: Dict) -> Response:
"""
data['from'] = self.sender
try:
return requests.post(f"{self.api_url}/messages", auth=self.auth, data=data)
return requests.post(f"{self.api_url}/messages", auth=self.auth, data=data,
timeout=(3.05, 10))
except (requests.HTTPError, requests.ConnectionError):
traceback.print_exc()
raise FailedToSendMail
7 changes: 4 additions & 3 deletions mod_auth/controllers.py
Original file line number Diff line number Diff line change
Expand Up @@ -20,6 +20,7 @@
DeactivationForm, LoginForm, ResetForm,
RoleChangeForm, SignupForm)
from mod_auth.models import Role, User
from utility import HTTP_TIMEOUT

mod_auth = Blueprint('auth', __name__)

Expand Down Expand Up @@ -139,7 +140,7 @@ def github_token_validity(token: str):
url = f'https://api.github.com/applications/{github_client_id}/token'
session = requests.Session()
session.auth = (github_client_id, github_client_secret)
response = session.post(url, json={"access_token": token})
response = session.post(url, json={"access_token": token}, timeout=HTTP_TIMEOUT)

return response.status_code == 200

Expand Down Expand Up @@ -182,7 +183,7 @@ def fetch_username_from_token(user=None) -> Any:
session = requests.Session()
session.auth = (user.email, user.github_token)
try:
response = session.get(url, timeout=(3.05, 10))
response = session.get(url, timeout=HTTP_TIMEOUT)
data = response.json()
return data.get('login')
except Exception as e:
Expand All @@ -209,7 +210,7 @@ def github_callback():
'code': request.args['code']
}
headers = {'Accept': 'application/json'}
r = requests.post(url, params=payload, headers=headers)
r = requests.post(url, params=payload, headers=headers, timeout=HTTP_TIMEOUT)
response = r.json()

if 'access_token' in response:
Expand Down
3 changes: 2 additions & 1 deletion mod_upload/controllers.py
Original file line number Diff line number Diff line change
Expand Up @@ -27,6 +27,7 @@
UploadForm)
from mod_upload.models import (FTPCredentials, Platform, QueuedSample, Upload,
UploadLog)
from utility import HTTP_TIMEOUT

mod_upload = Blueprint('upload', __name__)

Expand Down Expand Up @@ -103,7 +104,7 @@ def make_github_issue(title, body=None, labels=None) -> Any:
issue = {'title': title,
'body': body,
'labels': labels}
r = session.post(url, json.dumps(issue))
r = session.post(url, json.dumps(issue), timeout=HTTP_TIMEOUT)

if r.status_code == 201:
g.log.info("new GitHub issue created")
Expand Down
3 changes: 3 additions & 0 deletions tests/test_auth/test_controllers.py
Original file line number Diff line number Diff line change
Expand Up @@ -252,6 +252,7 @@ def test_github_callback_incomplete_get(self, mock_post, mock_g, mock_user_model

self.assertEqual(response.status_code, 302)
mock_post.assert_called_once()
self.assertEqual(mock_post.call_args.kwargs.get('timeout'), (3.05, 10))
mock_user_model.query.filter.assert_called_once()
mock_g.db.commit.assert_not_called()
mock_g.log.error.assert_called_once_with("GitHub didn't return an access token")
Expand Down Expand Up @@ -306,6 +307,8 @@ def test_github_token_validity(self, mock_post):
mock_post.return_value = MockResponse({}, 404)
res = github_token_validity('token')
self.assertEqual(res, False)
mock_post.assert_called_once()
self.assertEqual(mock_post.call_args.kwargs.get('timeout'), (3.05, 10))


class ManageAccount(BaseTestCase):
Expand Down
3 changes: 2 additions & 1 deletion tests/test_mailer.py
Original file line number Diff line number Diff line change
Expand Up @@ -38,4 +38,5 @@ def test_that_send_simple_message_creates_the_appropriate_request(self):

mock_post.assert_called_once_with("%s/messages" % mailer.api_url,
auth=mailer.auth,
data=expected_data)
data=expected_data,
timeout=(3.05, 10))
17 changes: 17 additions & 0 deletions tests/test_upload/test_controllers.py
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,23 @@
from tests.base import BaseTestCase, MockResponse


class TestMakeGithubIssue(BaseTestCase):
"""Test GitHub issue creation HTTP timeout."""

@mock.patch('mod_upload.controllers.g')
@mock.patch('requests.Session.post')
def test_make_github_issue_passes_timeout(self, mock_post, mock_g):
"""make_github_issue must not hang if GitHub never responds."""
mock_post.return_value = MockResponse({'number': 1}, 201)

from mod_upload.controllers import make_github_issue

make_github_issue('title', body='body', labels=['bug'])

mock_post.assert_called_once()
self.assertEqual(mock_post.call_args.kwargs.get('timeout'), (3.05, 10))


class TestControllers(BaseTestCase):
"""Test upload-related cases."""

Expand Down
3 changes: 2 additions & 1 deletion tests/test_utility.py
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,8 @@ def test_get_cached_web_hook_blocks_invalid_response(self, mock_get, mock_critic

cached_web_hook_blocks = get_cached_web_hook_blocks()

mock_get.assert_called_once()
mock_get.assert_called_once_with(
'https://api.github.com/meta', auth=mock.ANY, timeout=(3.05, 10))
mock_critical.assert_called_once_with("Failed to retrieve hook IP's from GitHub! API returned {}")

@mock.patch('flask.g.log')
Expand Down
6 changes: 5 additions & 1 deletion utility.py
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,9 @@

ROOT_DIR = path.dirname(path.abspath(__file__))

# Connect, read. Same tuple already used by fetch_username_from_token.
HTTP_TIMEOUT = (3.05, 10)


def serve_file_download(file_name, file_folder, file_sub_folder='') -> werkzeug.wrappers.response.Response:
"""
Expand Down Expand Up @@ -138,7 +141,8 @@ def get_cached_web_hook_blocks() -> List[str]:
client_id = config.get('GITHUB_CLIENT_ID', '')
client_secret = config.get('GITHUB_CLIENT_KEY', '')
meta_json = requests.get(
'https://api.github.com/meta', auth=(client_id, client_secret)).json()
'https://api.github.com/meta', auth=(client_id, client_secret),
timeout=HTTP_TIMEOUT).json()
try:
cached_web_hook_blocks = meta_json['hooks']
# We successfully fetched the IPs so we reset the clock
Expand Down