|
@@ -10,6 +10,7 @@ import json
|
|
|
import sys
|
|
import sys
|
|
|
import time
|
|
import time
|
|
|
import urllib.error
|
|
import urllib.error
|
|
|
|
|
+import urllib.parse
|
|
|
import urllib.request
|
|
import urllib.request
|
|
|
|
|
|
|
|
BASE = "http://localhost:8090/api/v1"
|
|
BASE = "http://localhost:8090/api/v1"
|
|
@@ -63,7 +64,18 @@ def run_http_case(case, token, workflow_id):
|
|
|
url = BASE.replace("/api/v1", "") + spec["path"].replace("{workflowId}", workflow_id)
|
|
url = BASE.replace("/api/v1", "") + spec["path"].replace("{workflowId}", workflow_id)
|
|
|
method = spec.get("method", "POST")
|
|
method = spec.get("method", "POST")
|
|
|
multipart = spec.get("multipart")
|
|
multipart = spec.get("multipart")
|
|
|
- if multipart:
|
|
|
|
|
|
|
+ form_body = spec.get("formBody")
|
|
|
|
|
+ if form_body is not None:
|
|
|
|
|
+ # application/x-www-form-urlencoded, not JSON - cpp-httplib only
|
|
|
|
|
+ # fills req.params (what handleWebhook's password check reads via
|
|
|
|
|
+ # req.has_param) from a urlencoded body. A JSON body never reaches
|
|
|
|
|
+ # that check, and multipart puts non-file parts in req.files instead
|
|
|
|
|
+ # of req.params, so neither can exercise the password gate's
|
|
|
|
|
+ # success path - only this can.
|
|
|
|
|
+ payload = urllib.parse.urlencode(form_body).encode()
|
|
|
|
|
+ req = urllib.request.Request(url, data=payload, method="POST")
|
|
|
|
|
+ req.add_header("Content-Type", "application/x-www-form-urlencoded")
|
|
|
|
|
+ elif multipart:
|
|
|
boundary = "----smartboticverify"
|
|
boundary = "----smartboticverify"
|
|
|
parts = []
|
|
parts = []
|
|
|
for name, value in multipart.get("fields", {}).items():
|
|
for name, value in multipart.get("fields", {}).items():
|