Calling .auth after class is loaded does not apply auth to top-level endpoints
Nobody has claimed this yet.
Assessment
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Newbie friendliness
- 45/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Stale
- Tech stack
- ruby
- Domain
- api, authorization
Research direction
Start with the failing tests in the linked auth-after-load comparison and trace the top-level get endpoint through SomeAPI.http_basic and .auth after the class is loaded. Done means the top-level endpoint passes through the authorization middleware and the regression tests no longer return an unauthorized request as 200.
Written by the indexing model from the issue text.
Description
I've stumbled on an issue where requests to endpoints which are not nested inside resources or namespace blocks don't go through the authorization middleware.
I have added failing tests to demonstrate this: https://github.com/ruby-grape/grape/compare/master...jeromegn:auth-after-load
Concise example:
class SomeAPI < Grape::API
get { "hello" }
end
SomeAPI.http_basic { |u, p| false } # .http_basic calls .auth
GETting this endpoint ^ will return a 200 with "hello" as its body.
- Dominant language
- Ruby
- Stars
- 10k
- Forks
- 1.2k
- Avg merge
- 14h 38m
- Merged PRs (30d)
- 92
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from ruby-grape/grape
-
feature request you can help
Difficulty 2/5 1-3 hours Newbie friendliness 64/100
ruby-grape/grape#2487 · 2 comments · 2 reactions ·
-
chore
Difficulty 2/5 1-3 hours Newbie friendliness 30/100
ruby-grape/grape#2562 · 4 comments ·
-
feature request
Difficulty 5/5 Over a week Newbie friendliness 25/100
ruby-grape/grape#2522 · 3 comments ·
-
bug?
Difficulty 4/5 3-5 days Newbie friendliness 48/100
ruby-grape/grape#2473 · 6 comments · 1 reaction ·
-
chore discuss!
Difficulty 5/5 Over a week Newbie friendliness 25/100
ruby-grape/grape#2446 · 7 comments · 1 reaction ·
All issues in ruby-grape/grape
Similar issues
-
バグ
Difficulty 1/5 Under an hour Newbie friendliness 92/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
voxpupuli/puppet-epel#186 · 1 comment ·
-
external_created_at is no longer used for the message timestamp since the new message UI (v4.4.0) OpenBug Frontend
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
TheOdinProject/curriculum#31402 · 1 comment ·
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 78/100