tests.py 17 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473
  1. import json
  2. import random
  3. from unittest.mock import patch
  4. from django.shortcuts import reverse
  5. from django.test import override_settings
  6. from model_bakery import baker
  7. from rest_framework.test import APITestCase
  8. from environments.models import Environment
  9. from glitchtip import test_utils # pylint: disable=unused-import
  10. from issues.models import EventStatus, Issue
  11. from ..models import Event, LogLevel
  12. from ..test_data.csp import mdn_sample_csp
  13. class EventStoreTestCase(APITestCase):
  14. def setUp(self):
  15. self.project = baker.make("projects.Project")
  16. self.projectkey = self.project.projectkey_set.first()
  17. self.params = f"?sentry_key={self.projectkey.public_key}"
  18. self.url = reverse("event_store", args=[self.project.id]) + self.params
  19. def test_store_api(self):
  20. with open("events/test_data/py_hi_event.json") as json_file:
  21. data = json.load(json_file)
  22. res = self.client.post(self.url, data, format="json")
  23. self.assertEqual(res.status_code, 200)
  24. def test_maintenance_freeze(self):
  25. with open("events/test_data/py_hi_event.json") as json_file:
  26. data = json.load(json_file)
  27. with override_settings(MAINTENANCE_EVENT_FREEZE=True):
  28. res = self.client.post(self.url, data, format="json")
  29. self.assertEqual(res.status_code, 503)
  30. def test_store_duplicate(self):
  31. with open("events/test_data/py_hi_event.json") as json_file:
  32. data = json.load(json_file)
  33. self.client.post(self.url, data, format="json")
  34. res = self.client.post(self.url, data, format="json")
  35. self.assertContains(res, "ID already exist", status_code=403)
  36. def test_store_invalid_key(self):
  37. with open("events/test_data/py_hi_event.json") as json_file:
  38. data = json.load(json_file)
  39. self.client.post(self.url, data, format="json")
  40. res = self.client.post(self.url, data, format="json")
  41. self.assertContains(res, "ID already exist", status_code=403)
  42. def test_store_api_auth_failure(self):
  43. url = "/api/1/store/"
  44. with open("events/test_data/py_hi_event.json") as json_file:
  45. data = json.load(json_file)
  46. params = "?sentry_key=aaa"
  47. url = reverse("event_store", args=[self.project.id]) + params
  48. res = self.client.post(url, data, format="json")
  49. self.assertEqual(res.status_code, 401)
  50. params = "?sentry_key=238df2aac6331578a16c14bcb3db5259"
  51. url = reverse("event_store", args=[self.project.id]) + params
  52. res = self.client.post(url, data, format="json")
  53. self.assertContains(res, "Invalid api key", status_code=401)
  54. url = reverse("event_store", args=[10000]) + self.params
  55. res = self.client.post(url, data, format="json")
  56. self.assertContains(res, "Invalid project_id", status_code=400)
  57. def test_error_event(self):
  58. with open("events/test_data/py_error.json") as json_file:
  59. data = json.load(json_file)
  60. res = self.client.post(self.url, data, format="json")
  61. self.assertEqual(res.status_code, 200)
  62. def test_csp_event(self):
  63. url = reverse("csp_store", args=[self.project.id]) + self.params
  64. data = mdn_sample_csp
  65. res = self.client.post(url, data, format="json")
  66. self.assertEqual(res.status_code, 200)
  67. expected_title = "Blocked 'style' from 'example.com'"
  68. issue = Issue.objects.get(title=expected_title)
  69. event = Event.objects.get()
  70. self.assertEqual(event.data["csp"]["effective_directive"], "style-src")
  71. self.assertTrue(issue)
  72. def test_reopen_resolved_issue(self):
  73. with open("events/test_data/py_hi_event.json") as json_file:
  74. data = json.load(json_file)
  75. self.client.post(self.url, data, format="json")
  76. issue = Issue.objects.all().first()
  77. issue.status = EventStatus.RESOLVED
  78. issue.save()
  79. data["event_id"] = "6600a066e64b4caf8ed7ec5af64ac4ba"
  80. self.client.post(self.url, data, format="json")
  81. issue.refresh_from_db()
  82. self.assertEqual(issue.status, EventStatus.UNRESOLVED)
  83. def test_performance(self):
  84. with open("events/test_data/py_hi_event.json") as json_file:
  85. data = json.load(json_file)
  86. with self.assertNumQueries(15):
  87. res = self.client.post(self.url, data, format="json")
  88. self.assertEqual(res.status_code, 200)
  89. # Second event should have less queries
  90. data["event_id"] = "6600a066e64b4caf8ed7ec5af64ac4bb"
  91. with self.assertNumQueries(8):
  92. res = self.client.post(self.url, data, format="json")
  93. self.assertEqual(res.status_code, 200)
  94. def test_throttle_organization(self):
  95. organization = self.project.organization
  96. organization.is_accepting_events = False
  97. organization.save()
  98. with open("events/test_data/py_hi_event.json") as json_file:
  99. data = json.load(json_file)
  100. res = self.client.post(self.url, data, format="json")
  101. self.assertEqual(res.status_code, 429)
  102. def test_project_first_event(self):
  103. with open("events/test_data/py_error.json") as json_file:
  104. data = json.load(json_file)
  105. self.assertFalse(self.project.first_event)
  106. self.client.post(self.url, data, format="json")
  107. self.project.refresh_from_db()
  108. self.assertTrue(self.project.first_event)
  109. def test_null_character_event(self):
  110. """
  111. Unicode null characters \u0000 are not supported by Postgres JSONB
  112. NUL \x00 characters are not supported by Postgres string types
  113. They should be filtered out
  114. """
  115. with open("events/test_data/py_error.json") as json_file:
  116. data = json.load(json_file)
  117. data["exception"]["values"][0]["stacktrace"]["frames"][0][
  118. "function"
  119. ] = "a\u0000a"
  120. data["exception"]["values"][0]["value"] = "\x00\u0000"
  121. res = self.client.post(self.url, data, format="json")
  122. self.assertEqual(res.status_code, 200)
  123. def test_header_value_array(self):
  124. """
  125. Request Header values are both strings and arrays (sentry-php uses arrays)
  126. """
  127. with open("events/test_data/py_error.json") as json_file:
  128. data = json.load(json_file)
  129. data["request"]["headers"]["Content-Type"] = ["text/plain"]
  130. res = self.client.post(self.url, data, format="json")
  131. self.assertEqual(res.status_code, 200)
  132. event = Event.objects.first()
  133. header = next(
  134. x for x in event.data["request"]["headers"] if x[0] == "Content-Type"
  135. )
  136. self.assertTrue(isinstance(header[1], str))
  137. def test_anonymize_ip(self):
  138. """ip address should get masked because default project settings are to scrub ip address"""
  139. with open("events/test_data/py_hi_event.json") as json_file:
  140. data = json.load(json_file)
  141. test_ip = "123.168.29.14"
  142. res = self.client.post(self.url, data, format="json", REMOTE_ADDR=test_ip)
  143. self.assertEqual(res.status_code, 200)
  144. event = Event.objects.first()
  145. self.assertNotEqual(event.data["user"]["ip_address"], test_ip)
  146. def test_csp_event_anonymize_ip(self):
  147. url = reverse("csp_store", args=[self.project.id]) + self.params
  148. test_ip = "123.168.29.14"
  149. data = mdn_sample_csp
  150. res = self.client.post(url, data, format="json", REMOTE_ADDR=test_ip)
  151. self.assertEqual(res.status_code, 200)
  152. event = Event.objects.first()
  153. self.assertNotEqual(event.data["user"]["ip_address"], test_ip)
  154. def test_store_very_large_data(self):
  155. """
  156. This test is expected to exceed the 1mb limit of a postgres tsvector
  157. """
  158. with open("events/test_data/py_hi_event.json") as json_file:
  159. data = json.load(json_file)
  160. data["platform"] = " ".join([str(random.random()) for _ in range(50000)])
  161. res = self.client.post(self.url, data, format="json")
  162. self.assertEqual(res.status_code, 200)
  163. self.assertEqual(
  164. Issue.objects.first().search_vector,
  165. "",
  166. "No tsvector is expected as it would exceed the Postgres limit",
  167. )
  168. data["event_id"] = "6600a066e64b4caf8ed7ec5af64ac4be"
  169. res = self.client.post(self.url, data, format="json")
  170. self.assertEqual(res.status_code, 200)
  171. @patch("events.views.logger")
  172. def test_invalid_event(self, mock_logger):
  173. with open("events/test_data/py_hi_event.json") as json_file:
  174. data = json.load(json_file)
  175. data["transaction"] = True
  176. res = self.client.post(self.url, data, format="json")
  177. self.assertEqual(res.status_code, 200)
  178. mock_logger.warning.assert_called()
  179. def test_breadcrumbs_object(self):
  180. """Event breadcrumbs may be sent as an array or a object."""
  181. with open("events/test_data/py_hi_event.json") as json_file:
  182. data = json.load(json_file)
  183. data["breadcrumbs"] = {
  184. "values": [
  185. {
  186. "timestamp": "2020-01-20T20:00:00.000Z",
  187. "message": "Something",
  188. "category": "log",
  189. "data": {"foo": "bar"},
  190. },
  191. ]
  192. }
  193. res = self.client.post(self.url, data, format="json")
  194. self.assertEqual(res.status_code, 200)
  195. self.assertTrue(Issue.objects.exists())
  196. def test_event_release(self):
  197. with open("events/test_data/py_hi_event.json") as json_file:
  198. data = json.load(json_file)
  199. self.client.post(self.url, data, format="json")
  200. event = Event.objects.first()
  201. event_json = event.event_json()
  202. self.assertTrue(event.release)
  203. self.assertEqual(event_json.get("release"), event.release.version)
  204. self.assertIn(
  205. event.release.version,
  206. dict(event_json.get("tags")).values(),
  207. )
  208. def test_client_tags(self):
  209. with open("events/test_data/py_hi_event.json") as json_file:
  210. data = json.load(json_file)
  211. data["tags"] = {"test_tag": "the value"}
  212. self.client.post(self.url, data, format="json")
  213. event = Event.objects.first()
  214. event_json = event.event_json()
  215. self.assertIn(
  216. "the value",
  217. tuple(event_json.get("tags"))[1],
  218. )
  219. def test_client_tags_invalid(self):
  220. """Invalid tags should not be saved. But should not error."""
  221. with open("events/test_data/py_hi_event.json") as json_file:
  222. data = json.load(json_file)
  223. data["tags"] = {
  224. "value": "valid value",
  225. "my invalid tag key": {"oh": "this is invalid"},
  226. }
  227. res = self.client.post(self.url, data, format="json")
  228. event = Event.objects.first()
  229. self.assertEqual(res.status_code, 200)
  230. self.assertTrue(event)
  231. event_json = event.event_json()
  232. tags = tuple(event_json.get("tags"))
  233. self.assertIn(
  234. "valid value",
  235. tags[0],
  236. )
  237. for tag in tags:
  238. self.assertNotIn("this is invalid", tag)
  239. self.assertEqual(len(event_json.get("errors")), 1)
  240. def test_malformed_exception_value(self):
  241. """Malformed exception values aren't 100% supported, but should stored anyway"""
  242. with open("events/test_data/py_error.json") as json_file:
  243. data = json.load(json_file)
  244. data["exception"]["values"][0]["value"] = {"why is this": "any object?"}
  245. res = self.client.post(self.url, data, format="json")
  246. self.assertEqual(res.status_code, 200)
  247. def test_no_sdk(self):
  248. data = {
  249. "exception": [
  250. {
  251. "type": "Plug.Parsers.ParseError",
  252. "value": "malformed request",
  253. "module": None,
  254. }
  255. ],
  256. "culprit": "Plug.Parsers.JSON.decode",
  257. "extra": {},
  258. "event_id": "11111111111111111111111111111111",
  259. "breadcrumbs": [],
  260. "level": "error",
  261. "modules": {
  262. "cowboy": "2.8.0",
  263. },
  264. "fingerprint": ["{{ default }}"],
  265. "message": "(Plug.Parsers.ParseError) malformed",
  266. }
  267. res = self.client.post(self.url, data, format="json")
  268. self.assertEqual(res.status_code, 200)
  269. self.assertTrue(Event.objects.exists())
  270. def test_invalid_level(self):
  271. data = {
  272. "exception": [
  273. {
  274. "type": "a",
  275. "value": "a",
  276. "module": None,
  277. }
  278. ],
  279. "culprit": "a",
  280. "extra": {},
  281. "event_id": "11111111111111111111111111111111",
  282. "breadcrumbs": [],
  283. "level": "haha",
  284. "message": "a",
  285. }
  286. res = self.client.post(self.url, data, format="json")
  287. self.assertEqual(res.status_code, 200)
  288. self.assertTrue(Event.objects.filter(level=LogLevel.ERROR).exists())
  289. def test_null_release(self):
  290. data = {
  291. "exception": [
  292. {
  293. "type": "a",
  294. "value": "a",
  295. "module": None,
  296. }
  297. ],
  298. "culprit": "a",
  299. "extra": {},
  300. "event_id": "11111111111111111111111111111111",
  301. "breadcrumbs": [],
  302. "level": "haha",
  303. "message": "",
  304. "release": None,
  305. "environment": None,
  306. "request": {"env": {"FOO": None}},
  307. }
  308. res = self.client.post(self.url, data, format="json")
  309. self.assertEqual(res.status_code, 200)
  310. self.assertTrue(Event.objects.filter().exists())
  311. def test_formatted_message(self):
  312. data = {
  313. "exception": [
  314. {
  315. "type": "a",
  316. "value": "a",
  317. "module": None,
  318. }
  319. ],
  320. "event_id": "11111111111111111111111111111111",
  321. "message": {"formatted": "Hello"},
  322. }
  323. res = self.client.post(self.url, data, format="json")
  324. self.assertTrue(Event.objects.filter(data__message="Hello").exists())
  325. def test_invalid_message(self):
  326. # It's actually accepted as is. Considered to be message: ""
  327. data = {
  328. "exception": [
  329. {
  330. "type": "a",
  331. "value": "a",
  332. "module": None,
  333. }
  334. ],
  335. "event_id": "11111111111111111111111111111111",
  336. "message": {},
  337. }
  338. res = self.client.post(self.url, data, format="json")
  339. self.assertTrue(Event.objects.filter(data__message="").exists())
  340. def test_null_message(self):
  341. data = {
  342. "exception": [{}],
  343. "event_id": "11111111111111111111111111111111",
  344. "message": None,
  345. }
  346. res = self.client.post(self.url, data, format="json")
  347. self.assertTrue(Event.objects.filter(data__message=None).exists())
  348. def test_long_environment(self):
  349. data = {
  350. "exception": [
  351. {
  352. "type": "a",
  353. "value": "a",
  354. "module": None,
  355. }
  356. ],
  357. "event_id": "11111111111111111111111111111111",
  358. "environment": "a" * 257,
  359. }
  360. res = self.client.post(self.url, data, format="json")
  361. self.assertTrue(Event.objects.filter().exists())
  362. def test_invalid_environment(self):
  363. data = {
  364. "exception": [
  365. {
  366. "type": "a",
  367. "value": "a",
  368. "module": None,
  369. }
  370. ],
  371. "event_id": "11111111111111111111111111111111",
  372. "environment": "a/a",
  373. }
  374. res = self.client.post(self.url, data, format="json")
  375. self.assertTrue(Event.objects.filter().exists())
  376. self.assertFalse(Environment.objects.exists())
  377. def test_query_string_formats(self):
  378. data = {
  379. "event_id": "11111111111111111111111111111111",
  380. "exception": [
  381. {
  382. "type": "a",
  383. "value": "a",
  384. "module": None,
  385. }
  386. ],
  387. "request": {
  388. "method": "GET",
  389. "query_string": {"search": "foo"},
  390. },
  391. }
  392. self.client.post(self.url, data, format="json")
  393. data = {
  394. "event_id": "11111111111111111111111111111112",
  395. "exception": [
  396. {
  397. "type": "a",
  398. "value": "a",
  399. "module": None,
  400. }
  401. ],
  402. "request": {
  403. "query_string": "search=foo",
  404. },
  405. }
  406. self.client.post(self.url, data, format="json")
  407. data = {
  408. "event_id": "11111111111111111111111111111113",
  409. "exception": [
  410. {
  411. "type": "a",
  412. "value": "a",
  413. "module": None,
  414. }
  415. ],
  416. "request": {"query_string": [["search", "foo"]]},
  417. }
  418. self.client.post(self.url, data, format="json")
  419. self.assertEqual(
  420. Event.objects.filter(
  421. data__request__query_string=[["search", "foo"]]
  422. ).count(),
  423. 3,
  424. )