X-Git-Url: https://git.arvados.org/arvados.git/blobdiff_plain/ce2d2f5807822534756e52ac04bc272dd572d13d..aaa45b09de0e9437743fce53d7c0bf8165074b5e:/services/api/config/routes.rb diff --git a/services/api/config/routes.rb b/services/api/config/routes.rb index d5ef141ef3..f89d2c16a8 100644 --- a/services/api/config/routes.rb +++ b/services/api/config/routes.rb @@ -3,31 +3,52 @@ Server::Application.routes.draw do # See http://guides.rubyonrails.org/routing.html + # OPTIONS requests are not allowed at routes that use cookies. + ['/auth/*a', '/login', '/logout'].each do |nono| + match nono, :to => 'user_sessions#cross_origin_forbidden', :via => 'OPTIONS' + end + # OPTIONS at discovery and API paths get an empty response with CORS headers. + match '/discovery/v1/*a', :to => 'static#empty', :via => 'OPTIONS' + match '/arvados/v1/*a', :to => 'static#empty', :via => 'OPTIONS' + namespace :arvados do namespace :v1 do resources :api_client_authorizations do post 'create_system_auth', on: :collection + get 'current', on: :collection end resources :api_clients resources :authorized_keys resources :collections do get 'provenance', on: :member get 'used_by', on: :member + post 'trash', on: :member end resources :groups do + get 'contents', on: :collection get 'contents', on: :member end resources :humans resources :job_tasks + resources :containers do + get 'auth', on: :member + post 'lock', on: :member + post 'unlock', on: :member + get 'current', on: :collection + end + resources :container_requests resources :jobs do get 'queue', on: :collection - get 'log_tail_follow', on: :member + get 'queue_size', on: :collection post 'cancel', on: :member + post 'lock', on: :member end resources :keep_disks do post 'ping', on: :collection end - resources :keep_services + resources :keep_services do + get 'accessible', on: :collection + end resources :links resources :logs resources :nodes do @@ -35,6 +56,7 @@ Server::Application.routes.draw do end resources :pipeline_instances resources :pipeline_templates + resources :workflows resources :repositories do get 'get_all_permissions', on: :collection end @@ -47,7 +69,6 @@ Server::Application.routes.draw do resources :users do get 'current', on: :collection get 'system', on: :collection - get 'event_stream', on: :member post 'activate', on: :member post 'setup', on: :collection post 'unsetup', on: :member @@ -56,12 +77,19 @@ Server::Application.routes.draw do get 'logins', on: :member get 'get_all_logins', on: :collection end + get '/permissions/:uuid', :to => 'links#get_permissions' end end + if Rails.env == 'test' + post '/database/reset', to: 'database#reset' + end + # omniauth match '/auth/:provider/callback', :to => 'user_sessions#create' match '/auth/failure', :to => 'user_sessions#failure' + # not handled by omniauth provider -> 403 with no CORS headers. + get '/auth/*a', :to => 'user_sessions#cross_origin_forbidden' # Custom logout match '/login', :to => 'user_sessions#login'