Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
629e1ca5c1 |
@@ -75,17 +75,6 @@ func serve(
|
||||
return rec
|
||||
}
|
||||
|
||||
// publicPaths returns one path on each public route.
|
||||
func publicPaths() []string {
|
||||
return []string{
|
||||
"/",
|
||||
"/s/css/tailwind.min.css",
|
||||
"/api/v1/status",
|
||||
"/health",
|
||||
"/.well-known/healthcheck",
|
||||
}
|
||||
}
|
||||
|
||||
// TestPublicRoutesAllowAnyOrigin checks that every public route answers
|
||||
// a cross-origin GET with the CORS wildcard.
|
||||
func TestPublicRoutesAllowAnyOrigin(t *testing.T) {
|
||||
@@ -96,7 +85,15 @@ func TestPublicRoutesAllowAnyOrigin(t *testing.T) {
|
||||
|
||||
srv := routedServer(t)
|
||||
|
||||
for _, path := range publicPaths() {
|
||||
paths := []string{
|
||||
"/",
|
||||
"/s/css/tailwind.min.css",
|
||||
"/api/v1/status",
|
||||
"/health",
|
||||
"/.well-known/healthcheck",
|
||||
}
|
||||
|
||||
for _, path := range paths {
|
||||
rec := serve(srv, crossOriginRequest(t, http.MethodGet, path))
|
||||
|
||||
if rec.Code != http.StatusOK {
|
||||
@@ -168,13 +165,10 @@ func TestMetricsHasNoCORS(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
// TestPreflightAllowsOnlyWhatPublicRoutesServe checks what each public
|
||||
// TestPreflightAllowsOnlyWhatPublicRoutesServe checks what a public
|
||||
// route agrees to in a CORS preflight: GET, but not POST, PUT or
|
||||
// DELETE, which no route serves, and not the Authorization or
|
||||
// X-CSRF-Token headers, which no public route reads. It checks every
|
||||
// public route because one added with Get, such as /health, answers a
|
||||
// preflight only while CORS is middleware of a whole router; in a
|
||||
// Group, chi would answer it with 405 and no CORS headers.
|
||||
// X-CSRF-Token headers, which no public route reads.
|
||||
func TestPreflightAllowsOnlyWhatPublicRoutesServe(t *testing.T) {
|
||||
viper.Reset()
|
||||
t.Setenv("DNSWATCHER_TARGETS", "example.com")
|
||||
@@ -197,25 +191,23 @@ func TestPreflightAllowsOnlyWhatPublicRoutesServe(t *testing.T) {
|
||||
{http.MethodGet, "X-CSRF-Token", false},
|
||||
}
|
||||
|
||||
for _, path := range publicPaths() {
|
||||
for _, tt := range tests {
|
||||
rec := serve(srv, preflightRequest(
|
||||
t, path, tt.method, tt.headers,
|
||||
))
|
||||
for _, tt := range tests {
|
||||
rec := serve(srv, preflightRequest(
|
||||
t, "/api/v1/status", tt.method, tt.headers,
|
||||
))
|
||||
|
||||
want := ""
|
||||
if tt.allowed {
|
||||
want = tt.method
|
||||
}
|
||||
want := ""
|
||||
if tt.allowed {
|
||||
want = tt.method
|
||||
}
|
||||
|
||||
got := rec.Header().Get("Access-Control-Allow-Methods")
|
||||
if got != want {
|
||||
t.Errorf(
|
||||
"preflight to %s for %s with headers %q: "+
|
||||
"Access-Control-Allow-Methods = %q, want %q",
|
||||
path, tt.method, tt.headers, got, want,
|
||||
)
|
||||
}
|
||||
got := rec.Header().Get("Access-Control-Allow-Methods")
|
||||
if got != want {
|
||||
t.Errorf(
|
||||
"preflight for %s with headers %q: "+
|
||||
"Access-Control-Allow-Methods = %q, want %q",
|
||||
tt.method, tt.headers, got, want,
|
||||
)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user