Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
37bf7f4fbd |
@@ -75,6 +75,17 @@ func serve(
|
|||||||
return rec
|
return rec
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// publicPaths returns one path on each public route.
|
||||||
|
func publicPaths() []string {
|
||||||
|
return []string{
|
||||||
|
"/",
|
||||||
|
"/s/css/tailwind.min.css",
|
||||||
|
"/api/v1/status",
|
||||||
|
"/health",
|
||||||
|
"/.well-known/healthcheck",
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
// TestPublicRoutesAllowAnyOrigin checks that every public route answers
|
// TestPublicRoutesAllowAnyOrigin checks that every public route answers
|
||||||
// a cross-origin GET with the CORS wildcard.
|
// a cross-origin GET with the CORS wildcard.
|
||||||
func TestPublicRoutesAllowAnyOrigin(t *testing.T) {
|
func TestPublicRoutesAllowAnyOrigin(t *testing.T) {
|
||||||
@@ -85,15 +96,7 @@ func TestPublicRoutesAllowAnyOrigin(t *testing.T) {
|
|||||||
|
|
||||||
srv := routedServer(t)
|
srv := routedServer(t)
|
||||||
|
|
||||||
paths := []string{
|
for _, path := range publicPaths() {
|
||||||
"/",
|
|
||||||
"/s/css/tailwind.min.css",
|
|
||||||
"/api/v1/status",
|
|
||||||
"/health",
|
|
||||||
"/.well-known/healthcheck",
|
|
||||||
}
|
|
||||||
|
|
||||||
for _, path := range paths {
|
|
||||||
rec := serve(srv, crossOriginRequest(t, http.MethodGet, path))
|
rec := serve(srv, crossOriginRequest(t, http.MethodGet, path))
|
||||||
|
|
||||||
if rec.Code != http.StatusOK {
|
if rec.Code != http.StatusOK {
|
||||||
@@ -165,10 +168,13 @@ func TestMetricsHasNoCORS(t *testing.T) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// TestPreflightAllowsOnlyWhatPublicRoutesServe checks what a public
|
// TestPreflightAllowsOnlyWhatPublicRoutesServe checks what each public
|
||||||
// route agrees to in a CORS preflight: GET, but not POST, PUT or
|
// route agrees to in a CORS preflight: GET, but not POST, PUT or
|
||||||
// DELETE, which no route serves, and not the Authorization or
|
// DELETE, which no route serves, and not the Authorization or
|
||||||
// X-CSRF-Token headers, which no public route reads.
|
// X-CSRF-Token headers, which no public route reads. It checks every
|
||||||
|
// public route because one added with Get, such as /health, answers a
|
||||||
|
// preflight only while CORS is middleware of a whole router; in a
|
||||||
|
// Group, chi would answer it with 405 and no CORS headers.
|
||||||
func TestPreflightAllowsOnlyWhatPublicRoutesServe(t *testing.T) {
|
func TestPreflightAllowsOnlyWhatPublicRoutesServe(t *testing.T) {
|
||||||
viper.Reset()
|
viper.Reset()
|
||||||
t.Setenv("DNSWATCHER_TARGETS", "example.com")
|
t.Setenv("DNSWATCHER_TARGETS", "example.com")
|
||||||
@@ -191,23 +197,25 @@ func TestPreflightAllowsOnlyWhatPublicRoutesServe(t *testing.T) {
|
|||||||
{http.MethodGet, "X-CSRF-Token", false},
|
{http.MethodGet, "X-CSRF-Token", false},
|
||||||
}
|
}
|
||||||
|
|
||||||
for _, tt := range tests {
|
for _, path := range publicPaths() {
|
||||||
rec := serve(srv, preflightRequest(
|
for _, tt := range tests {
|
||||||
t, "/api/v1/status", tt.method, tt.headers,
|
rec := serve(srv, preflightRequest(
|
||||||
))
|
t, path, tt.method, tt.headers,
|
||||||
|
))
|
||||||
|
|
||||||
want := ""
|
want := ""
|
||||||
if tt.allowed {
|
if tt.allowed {
|
||||||
want = tt.method
|
want = tt.method
|
||||||
}
|
}
|
||||||
|
|
||||||
got := rec.Header().Get("Access-Control-Allow-Methods")
|
got := rec.Header().Get("Access-Control-Allow-Methods")
|
||||||
if got != want {
|
if got != want {
|
||||||
t.Errorf(
|
t.Errorf(
|
||||||
"preflight for %s with headers %q: "+
|
"preflight to %s for %s with headers %q: "+
|
||||||
"Access-Control-Allow-Methods = %q, want %q",
|
"Access-Control-Allow-Methods = %q, want %q",
|
||||||
tt.method, tt.headers, got, want,
|
path, tt.method, tt.headers, got, want,
|
||||||
)
|
)
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user