Files
Jungfraujoch/tests/BrokerHttpAuthTest.cpp
leonarski_f 84228bf8be
Build Packages / Create release (push) Successful in 24s
Build Packages / build:viewer:macos-arm64:nocuda (push) Successful in 3m29s
Build Packages / build:rugnux:macos-arm64:nocuda (push) Successful in 2m43s
Build Packages / build:rugnux:linux-aarch64:cuda (push) Successful in 8m27s
Build Packages / build:rugnux:linux-x86_64:cuda (push) Successful in 9m53s
Build Packages / build:viewer:linux-x86_64:nocuda (push) Successful in 9m58s
Build Packages / build:viewer:linux-x86_64:cuda (push) Successful in 11m22s
Build Packages / build:jfjoch:rocky8:nocuda (push) Successful in 13m39s
Build Packages / build:viewer:windows-x86_64:nocuda (push) Successful in 18m37s
Build Packages / build:jfjoch:rocky9:nocuda (push) Successful in 16m32s
Build Packages / build:viewer:windows-x86_64:cuda (push) Successful in 24m11s
Build Packages / HDF5 consumer tests (DIALS, XDS) (push) Successful in 25m30s
Build Packages / build:jfjoch:ubuntu2404:nocuda (push) Successful in 19m3s
Build Packages / build:jfjoch:ubuntu2204:nocuda (push) Successful in 20m23s
Build Packages / build:jfjoch:rocky8:cuda-sls9 (push) Successful in 19m41s
Build Packages / Generate python client (push) Successful in 50s
Build Packages / Build documentation (push) Successful in 1m16s
Build Packages / build:jfjoch:rocky9:cuda-sls9 (push) Successful in 21m0s
Build Packages / build:jfjoch:rocky8:cuda (push) Successful in 18m38s
Build Packages / build:rugnux:windows-x86_64:cuda (push) Successful in 14m33s
Build Packages / build:jfjoch:rocky9:cuda (push) Successful in 17m55s
Build Packages / build:jfjoch:ubuntu2204:cuda (push) Successful in 20m50s
Build Packages / build:jfjoch:ubuntu2404:cuda (push) Successful in 18m38s
Build Packages / Unit tests (push) Successful in 1h46m14s
v1.0.0-rc.173 (#83)
* jfjoch_broker: Optional per-dataset authentication - statistics, images and plots can require a bearer token, which jfjoch_viewer supports.
* jfjoch_viewer: Dark mode and a theme-matched colour scheme, a magnifier panel, and simpler contrast and background controls.
* Rugnux: Multiple performance improvements on GPU and CPU (CPU-only processing up to 40% faster, faster image decoding on ARM), with unchanged results.
* Rugnux: `--model` rigid-body refinement runs on the GPU, and the model-validation check is faster and more reliable.
* Rugnux: Improved scaling and merging - error model, outlier rejection, absorption correction and French-Wilson amplitudes now agree more closely with XDS and ctruncate.
* Rugnux: Improved integration - radial background on powder and ice rings, crowded rotation data keep their reflections, and CPU-only builds integrate large unit cells as GPU builds do.
* Rugnux: More robust detector geometry - measured beam centre, X-ray bandwidth and goniometer rate, and geometry refinement accepted only on significant evidence.
* Rugnux: Merged files are written in the standard setting, or in the setting of a reference MTZ, structure-factor mmCIF or model, with its free-R flags.
* Rugnux: Richer report - ice and powder rings, further lattices, superstructure candidates and mosaicity, with warnings worded as prompts to check.
* Rugnux: Clear error messages when a data set needs more GPU or host memory than is available.

Reviewed-on: #83
Co-authored-by: Filip Leonarski <filip.leonarski@psi.ch>
2026-09-29 15:57:32 +02:00

131 lines
6.2 KiB
C++

// SPDX-FileCopyrightText: 2026 Filip Leonarski, Paul Scherrer Institute <filip.leonarski@psi.ch>
// SPDX-License-Identifier: GPL-3.0-only
#include <catch2/catch_all.hpp>
#include <httplib.h>
#include <nlohmann/json.hpp>
#include <chrono>
#include <thread>
#include "../broker/JFJochBrokerHttp.h"
// The tokens given to /start guard the endpoints that expose the dataset, and nothing else, for as
// long as that dataset is the current one. Runs the real HTTP layer against a broker with no
// receiver: /start is then accepted and finishes at once with nothing to acquire.
TEST_CASE("JFJochBrokerHttp_BearerTokens", "[broker]") {
DiffractionExperiment experiment;
SpotFindingSettings spot_finding;
JFJochBrokerHttp broker(experiment, spot_finding);
broker.AddDetectorSetup(DetJF4M());
httplib::Server server;
broker.attach(server);
const int port = server.bind_to_any_port("127.0.0.1");
REQUIRE(port > 0);
// Stopped and joined however the test ends, so a failed REQUIRE does not abort on a joinable thread.
struct ServerThread {
httplib::Server &server;
std::thread thread;
explicit ServerThread(httplib::Server &s) : server(s), thread([&s] { s.listen_after_bind(); }) {}
~ServerThread() { server.stop(); thread.join(); }
} server_thread(server);
server.wait_until_ready();
httplib::Client client("127.0.0.1", port);
const httplib::Headers good{{"Authorization", "Bearer secret-1"}};
const httplib::Headers other{{"Authorization", "Bearer secret-2"}};
const httplib::Headers wrong{{"Authorization", "Bearer nope"}};
auto start = [&](const nlohmann::json &extra) {
nlohmann::json body = {{"beam_x_pxl", 1000}, {"beam_y_pxl", 1000},
{"detector_distance_mm", 100}, {"incident_energy_keV", 12.4},
{"images_per_trigger", 1}, {"ntrigger", 1},
{"file_prefix", "protected_run"}};
body.update(extra);
auto res = client.Post("/start", body.dump(), "application/json");
REQUIRE(res);
REQUIRE(res->status == 200);
// With no receiver the measurement thread idles for 30 s before the run ends; wait it out.
for (int i = 0; i < 120; i++) {
auto status = client.Get("/status");
REQUIRE(status);
if (nlohmann::json::parse(status->body).at("state") == "Idle")
return;
std::this_thread::sleep_for(std::chrono::milliseconds(500));
}
FAIL("broker did not return to Idle after the start");
};
REQUIRE(client.Post("/initialize")->status == 200);
// Nothing started yet: open, whatever the header says.
REQUIRE(client.Get("/statistics/data_collection")->status == 200);
REQUIRE(client.Get("/statistics/data_collection", wrong)->status == 200);
REQUIRE(client.Get("/statistics")->status == 200);
start({{"tokens", {"secret-1", "secret-2"}}});
SECTION("protected endpoints refuse without a token and say nothing about the dataset") {
for (const char *path: {"/statistics/data_collection", "/result/scan", "/image_buffer/start.cbor",
"/image_buffer/image.cbor?id=0", "/image_buffer/image.tiff?id=0",
"/image_buffer/image.jpeg?id=0", "/preview/plot?type=bkg_estimate",
"/preview/plot.bin?type=bkg_estimate"}) {
INFO(path);
auto res = client.Get(path);
REQUIRE(res);
REQUIRE(res->status == 401);
REQUIRE(res->get_header_value("WWW-Authenticate") == "Bearer");
REQUIRE(res->body.find("protected_run") == std::string::npos);
REQUIRE(client.Get(path, wrong)->status == 401);
}
}
SECTION("either token opens them") {
auto res = client.Get("/statistics/data_collection", good);
REQUIRE(res->status == 200);
REQUIRE(res->body.find("protected_run") != std::string::npos);
REQUIRE(client.Get("/statistics/data_collection", other)->status == 200);
REQUIRE(client.Get("/preview/plot?type=bkg_estimate", good)->status == 200);
}
SECTION("the aggregate statistics drop the measurement block instead of refusing") {
auto res = client.Get("/statistics");
REQUIRE(res->status == 200);
REQUIRE_FALSE(nlohmann::json::parse(res->body).contains("measurement"));
REQUIRE(res->body.find("protected_run") == std::string::npos);
auto with_token = client.Get("/statistics", good);
REQUIRE(with_token->status == 200);
REQUIRE(nlohmann::json::parse(with_token->body).contains("measurement"));
}
SECTION("the control plane and the broker status stay open") {
REQUIRE(client.Get("/status")->status == 200);
REQUIRE(client.Get("/image_buffer/status")->status == 200);
REQUIRE(client.Get("/config/detector")->status == 200);
}
SECTION("a refused start keeps the current tokens, an accepted one replaces them") {
// Not idle: /start is refused, the dataset stays protected by its own tokens.
REQUIRE(client.Post("/deactivate")->status == 200);
nlohmann::json body = {{"beam_x_pxl", 1000}, {"beam_y_pxl", 1000},
{"detector_distance_mm", 100}, {"incident_energy_keV", 12.4}};
REQUIRE(client.Post("/start", body.dump(), "application/json")->status == 500);
REQUIRE(client.Post("/initialize")->status == 200);
REQUIRE(client.Get("/statistics/data_collection")->status == 401);
REQUIRE(client.Get("/statistics/data_collection", good)->status == 200);
// The next start without tokens lifts the protection.
start(nlohmann::json::object());
REQUIRE(client.Get("/statistics/data_collection")->status == 200);
REQUIRE(client.Get("/statistics/data_collection", wrong)->status == 200);
// And with new tokens, the old ones no longer open it.
start({{"tokens", {"secret-3"}}});
const httplib::Headers newer{{"Authorization", "Bearer secret-3"}};
REQUIRE(client.Get("/statistics/data_collection", good)->status == 401);
REQUIRE(client.Get("/statistics/data_collection", newer)->status == 200);
}
}