Compare commits
1 Commits
fix/98-sec
...
dea7e441b9
| Author | SHA1 | Date | |
|---|---|---|---|
| dea7e441b9 |
@@ -5,7 +5,7 @@ FROM golang@sha256:f6751d823c26342f9506c03797d2527668d095b0a15f1862cddb4d927a7a4
|
|||||||
RUN apk add --no-cache git make gcc musl-dev binutils-gold
|
RUN apk add --no-cache git make gcc musl-dev binutils-gold
|
||||||
|
|
||||||
# golangci-lint v2.12.2, 2026-08-07
|
# golangci-lint v2.12.2, 2026-08-07
|
||||||
RUN go install github.com/golangci/golangci-lint/v2/cmd/golangci-lint@c0d3ddc9cf3faa61a4e378e879ece580256d76e5
|
RUN go install github.com/golangci/golangci-lint/v2/cmd/golangci-lint@v2.12.2
|
||||||
# goimports v0.42.0
|
# goimports v0.42.0
|
||||||
RUN go install golang.org/x/tools/cmd/goimports@009367f5c17a8d4c45a961a3a509277190a9a6f0
|
RUN go install golang.org/x/tools/cmd/goimports@009367f5c17a8d4c45a961a3a509277190a9a6f0
|
||||||
|
|
||||||
|
|||||||
63
README.md
63
README.md
@@ -17,26 +17,6 @@ without requiring an external database.
|
|||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
## No DNS mocking. Ever.
|
|
||||||
|
|
||||||
**DNS is never mocked in this project — not in tests, not anywhere else.**
|
|
||||||
No mock resolvers, no fake DNS servers, no stubbed lookups.
|
|
||||||
|
|
||||||
dnswatcher's entire purpose is correct behavior against the real DNS.
|
|
||||||
Tests exercise real iterative resolution against live nameservers by
|
|
||||||
design; a test suite that passes against a mock proves nothing about the
|
|
||||||
one thing this program exists to do.
|
|
||||||
|
|
||||||
When live tests are flaky, that is a robustness problem, and it gets
|
|
||||||
fixed with robustness: retries with backoff, querying multiple
|
|
||||||
independent nameservers, longer timeouts — or explicit opt-in gating
|
|
||||||
decided by the project owner. Never with mocks.
|
|
||||||
|
|
||||||
Contributions that introduce mocked, faked, or stubbed DNS will be
|
|
||||||
rejected.
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## Features
|
## Features
|
||||||
|
|
||||||
### DNS Domain Monitoring (Apex Domains)
|
### DNS Domain Monitoring (Apex Domains)
|
||||||
@@ -182,46 +162,6 @@ dnswatcher exposes a lightweight HTTP API for operational visibility:
|
|||||||
| `GET /api/v1/status` | Current monitoring state |
|
| `GET /api/v1/status` | Current monitoring state |
|
||||||
| `GET /metrics` | Prometheus metrics (optional) |
|
| `GET /metrics` | Prometheus metrics (optional) |
|
||||||
|
|
||||||
### Security Headers
|
|
||||||
|
|
||||||
Every response — the dashboard, the static assets under `/s/...`, the
|
|
||||||
healthchecks, the JSON API, and `/metrics` — carries the following
|
|
||||||
headers, set by a global middleware:
|
|
||||||
|
|
||||||
| Header | Value |
|
|
||||||
|-----------------------------|---------------------------------------|
|
|
||||||
| `Strict-Transport-Security` | `max-age=31536000; includeSubDomains` |
|
|
||||||
| `Content-Security-Policy` | see below |
|
|
||||||
| `X-Frame-Options` | `DENY` |
|
|
||||||
| `X-Content-Type-Options` | `nosniff` |
|
|
||||||
| `Referrer-Policy` | `no-referrer` |
|
|
||||||
| `Permissions-Policy` | all unused browser features denied |
|
|
||||||
|
|
||||||
The content security policy is:
|
|
||||||
|
|
||||||
```
|
|
||||||
default-src 'self'; script-src 'none'; style-src 'self'; img-src 'self';
|
|
||||||
font-src 'none'; connect-src 'none'; object-src 'none'; base-uri 'none';
|
|
||||||
form-action 'none'; frame-ancestors 'none'
|
|
||||||
```
|
|
||||||
|
|
||||||
The dashboard ships no JavaScript (the 30-second refresh is a
|
|
||||||
`<meta http-equiv="refresh">`), no inline styles, no inline event
|
|
||||||
handlers, and no images; its only subresource is the embedded stylesheet
|
|
||||||
at `/s/css/tailwind.min.css`, which `style-src 'self'` permits. The
|
|
||||||
policy therefore needs neither `unsafe-inline` nor `unsafe-eval`.
|
|
||||||
`frame-ancestors 'none'` is the primary anti-framing control, with
|
|
||||||
`X-Frame-Options: DENY` retained as the legacy fallback.
|
|
||||||
|
|
||||||
HSTS is emitted unconditionally, including over plain HTTP. dnswatcher is
|
|
||||||
expected to run behind a TLS-terminating reverse proxy, and the browser
|
|
||||||
must still be told to enforce HTTPS end to end, so the header is never
|
|
||||||
gated on whether the request itself arrived over TLS.
|
|
||||||
|
|
||||||
`Referrer-Policy: no-referrer` is stricter than the
|
|
||||||
`strict-origin-when-cross-origin` baseline: the dashboard has no
|
|
||||||
cross-origin navigation needs, and its URL may name internal hosts.
|
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
## Architecture
|
## Architecture
|
||||||
@@ -234,8 +174,7 @@ internal/
|
|||||||
globals/globals.go Build-time variables (version)
|
globals/globals.go Build-time variables (version)
|
||||||
logger/logger.go slog structured logging (TTY detection)
|
logger/logger.go slog structured logging (TTY detection)
|
||||||
healthcheck/healthcheck.go Health check service
|
healthcheck/healthcheck.go Health check service
|
||||||
middleware/middleware.go HTTP middleware (logging, CORS, security
|
middleware/middleware.go HTTP middleware (logging, CORS, metrics auth)
|
||||||
headers, metrics auth)
|
|
||||||
handlers/handlers.go HTTP request handlers
|
handlers/handlers.go HTTP request handlers
|
||||||
server/
|
server/
|
||||||
server.go HTTP server lifecycle
|
server.go HTTP server lifecycle
|
||||||
|
|||||||
22
TODO.md
22
TODO.md
@@ -25,24 +25,10 @@ confirm make check still passes.
|
|||||||
|
|
||||||
# Completed Steps
|
# Completed Steps
|
||||||
|
|
||||||
- 2026-08-09: security response headers middleware
|
- 2026-08-07: golangci-lint bumped to v2.12.2 (pins in `Dockerfile` and
|
||||||
(`SecurityHeaders()` in `internal/middleware/middleware.go`)
|
`script/bootstrap`), `.golangci.yml` replaced with the canonical v2
|
||||||
registered globally in `internal/server/routes.go`, so HSTS, CSP,
|
config (settings moved under `linters.settings` so thresholds now
|
||||||
`X-Frame-Options`, `X-Content-Type-Options`, `Referrer-Policy`, and
|
apply); fixed all resulting `goconst`, `dupl`, and `lll` findings
|
||||||
`Permissions-Policy` are set on every response including `/s/...` and
|
|
||||||
`/metrics`; the CSP needs no `unsafe-inline`/`unsafe-eval` because the
|
|
||||||
dashboard ships no JavaScript and no inline styles; HSTS is emitted
|
|
||||||
unconditionally per policy (TLS-terminating proxy in front). Remaining
|
|
||||||
1.0 hardening items — `http.Server` timeouts, request body limits,
|
|
||||||
rate limiting, CORS scoping — are tracked separately
|
|
||||||
- 2026-08-07: golangci-lint bumped to v2.12.2 (commit-pinned installs
|
|
||||||
in `Dockerfile` and `script/bootstrap`); `.golangci.yml` set to the
|
|
||||||
org-standard v2-schema config used across the org's repos
|
|
||||||
(owner-authorized; same file is being landed as canonical via prompts
|
|
||||||
PR #24), with settings under `linters.settings` so the
|
|
||||||
lll/funlen/cyclop/dupl thresholds apply; fixed the resulting
|
|
||||||
`goconst`, `dupl`, and `lll` findings; the informational `gomodguard`
|
|
||||||
deprecation warning under this config is accepted
|
|
||||||
- 2026-07-07 Adopted scripts-to-rule-them-all: `script/` entrypoints,
|
- 2026-07-07 Adopted scripts-to-rule-them-all: `script/` entrypoints,
|
||||||
Makefile shims, README Entrypoints section
|
Makefile shims, README Entrypoints section
|
||||||
- 2026-02-20: iterative DNS resolver implemented; tests made hermetic
|
- 2026-02-20: iterative DNS resolver implemented; tests made hermetic
|
||||||
|
|||||||
@@ -21,60 +21,6 @@ import (
|
|||||||
// corsMaxAge is the maximum age for CORS preflight responses.
|
// corsMaxAge is the maximum age for CORS preflight responses.
|
||||||
const corsMaxAge = 300
|
const corsMaxAge = 300
|
||||||
|
|
||||||
// Security response header values applied to every response.
|
|
||||||
//
|
|
||||||
// The CSP is as strict as the dashboard allows: the template ships no
|
|
||||||
// JavaScript, no inline styles, no inline event handlers and no images,
|
|
||||||
// and its only subresource is the embedded stylesheet at
|
|
||||||
// /s/css/tailwind.min.css, which style-src 'self' permits. Neither
|
|
||||||
// unsafe-inline nor unsafe-eval is used. frame-ancestors 'none' is the
|
|
||||||
// primary anti-framing control; X-Frame-Options is the legacy fallback.
|
|
||||||
const (
|
|
||||||
// hstsValue is emitted unconditionally, including over plain HTTP,
|
|
||||||
// because the service runs behind a TLS-terminating proxy and the
|
|
||||||
// browser must still enforce HTTPS end to end.
|
|
||||||
hstsValue = "max-age=31536000; includeSubDomains"
|
|
||||||
|
|
||||||
cspValue = "default-src 'self'; " +
|
|
||||||
"script-src 'none'; " +
|
|
||||||
"style-src 'self'; " +
|
|
||||||
"img-src 'self'; " +
|
|
||||||
"font-src 'none'; " +
|
|
||||||
"connect-src 'none'; " +
|
|
||||||
"object-src 'none'; " +
|
|
||||||
"base-uri 'none'; " +
|
|
||||||
"form-action 'none'; " +
|
|
||||||
"frame-ancestors 'none'"
|
|
||||||
|
|
||||||
frameOptionsValue = "DENY"
|
|
||||||
|
|
||||||
contentTypeOptionsValue = "nosniff"
|
|
||||||
|
|
||||||
// referrerPolicyValue is stricter than the policy minimum of
|
|
||||||
// strict-origin-when-cross-origin: the dashboard has no
|
|
||||||
// cross-origin navigation needs and its URL may name internal
|
|
||||||
// hosts.
|
|
||||||
referrerPolicyValue = "no-referrer"
|
|
||||||
|
|
||||||
permissionsPolicyValue = "accelerometer=(), " +
|
|
||||||
"autoplay=(), " +
|
|
||||||
"camera=(), " +
|
|
||||||
"display-capture=(), " +
|
|
||||||
"encrypted-media=(), " +
|
|
||||||
"fullscreen=(), " +
|
|
||||||
"geolocation=(), " +
|
|
||||||
"gyroscope=(), " +
|
|
||||||
"magnetometer=(), " +
|
|
||||||
"microphone=(), " +
|
|
||||||
"midi=(), " +
|
|
||||||
"payment=(), " +
|
|
||||||
"picture-in-picture=(), " +
|
|
||||||
"publickey-credentials-get=(), " +
|
|
||||||
"screen-wake-lock=(), " +
|
|
||||||
"usb=(), " +
|
|
||||||
"xr-spatial-tracking=()"
|
|
||||||
)
|
|
||||||
|
|
||||||
// Params contains dependencies for Middleware.
|
// Params contains dependencies for Middleware.
|
||||||
type Params struct {
|
type Params struct {
|
||||||
fx.In
|
fx.In
|
||||||
@@ -240,37 +186,6 @@ func (m *Middleware) CORS() func(http.Handler) http.Handler {
|
|||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
// SecurityHeaders returns middleware that sets the security response
|
|
||||||
// headers required for production internet exposure on every response.
|
|
||||||
//
|
|
||||||
// The headers are set before the request reaches the next handler so
|
|
||||||
// that they are present on every response, including panics recovered
|
|
||||||
// by chi's Recoverer and timeouts produced by chi's Timeout.
|
|
||||||
func (m *Middleware) SecurityHeaders() func(http.Handler) http.Handler {
|
|
||||||
return func(next http.Handler) http.Handler {
|
|
||||||
return http.HandlerFunc(func(
|
|
||||||
writer http.ResponseWriter,
|
|
||||||
request *http.Request,
|
|
||||||
) {
|
|
||||||
header := writer.Header()
|
|
||||||
header.Set("Strict-Transport-Security", hstsValue)
|
|
||||||
header.Set("Content-Security-Policy", cspValue)
|
|
||||||
header.Set("X-Frame-Options", frameOptionsValue)
|
|
||||||
header.Set(
|
|
||||||
"X-Content-Type-Options",
|
|
||||||
contentTypeOptionsValue,
|
|
||||||
)
|
|
||||||
header.Set("Referrer-Policy", referrerPolicyValue)
|
|
||||||
header.Set(
|
|
||||||
"Permissions-Policy",
|
|
||||||
permissionsPolicyValue,
|
|
||||||
)
|
|
||||||
|
|
||||||
next.ServeHTTP(writer, request)
|
|
||||||
})
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// MetricsAuth returns basic auth middleware for /metrics.
|
// MetricsAuth returns basic auth middleware for /metrics.
|
||||||
func (m *Middleware) MetricsAuth() func(http.Handler) http.Handler {
|
func (m *Middleware) MetricsAuth() func(http.Handler) http.Handler {
|
||||||
if m.params.Config.MetricsUsername == "" {
|
if m.params.Config.MetricsUsername == "" {
|
||||||
|
|||||||
@@ -1,333 +0,0 @@
|
|||||||
package middleware_test
|
|
||||||
|
|
||||||
import (
|
|
||||||
"net/http"
|
|
||||||
"net/http/httptest"
|
|
||||||
"strings"
|
|
||||||
"testing"
|
|
||||||
|
|
||||||
"github.com/go-chi/chi/v5"
|
|
||||||
|
|
||||||
"sneak.berlin/go/dnswatcher/internal/config"
|
|
||||||
"sneak.berlin/go/dnswatcher/internal/globals"
|
|
||||||
"sneak.berlin/go/dnswatcher/internal/handlers"
|
|
||||||
"sneak.berlin/go/dnswatcher/internal/logger"
|
|
||||||
"sneak.berlin/go/dnswatcher/internal/middleware"
|
|
||||||
"sneak.berlin/go/dnswatcher/internal/notify"
|
|
||||||
"sneak.berlin/go/dnswatcher/internal/state"
|
|
||||||
)
|
|
||||||
|
|
||||||
// Expected security header values, spelled out literally so that any
|
|
||||||
// change to the middleware has to be made deliberately here as well.
|
|
||||||
const (
|
|
||||||
wantHSTS = "max-age=31536000; includeSubDomains"
|
|
||||||
|
|
||||||
wantCSP = "default-src 'self'; " +
|
|
||||||
"script-src 'none'; " +
|
|
||||||
"style-src 'self'; " +
|
|
||||||
"img-src 'self'; " +
|
|
||||||
"font-src 'none'; " +
|
|
||||||
"connect-src 'none'; " +
|
|
||||||
"object-src 'none'; " +
|
|
||||||
"base-uri 'none'; " +
|
|
||||||
"form-action 'none'; " +
|
|
||||||
"frame-ancestors 'none'"
|
|
||||||
|
|
||||||
wantFrameOptions = "DENY"
|
|
||||||
|
|
||||||
wantContentTypeOptions = "nosniff"
|
|
||||||
|
|
||||||
wantReferrerPolicy = "no-referrer"
|
|
||||||
|
|
||||||
wantPermissionsPolicy = "accelerometer=(), " +
|
|
||||||
"autoplay=(), " +
|
|
||||||
"camera=(), " +
|
|
||||||
"display-capture=(), " +
|
|
||||||
"encrypted-media=(), " +
|
|
||||||
"fullscreen=(), " +
|
|
||||||
"geolocation=(), " +
|
|
||||||
"gyroscope=(), " +
|
|
||||||
"magnetometer=(), " +
|
|
||||||
"microphone=(), " +
|
|
||||||
"midi=(), " +
|
|
||||||
"payment=(), " +
|
|
||||||
"picture-in-picture=(), " +
|
|
||||||
"publickey-credentials-get=(), " +
|
|
||||||
"screen-wake-lock=(), " +
|
|
||||||
"usb=(), " +
|
|
||||||
"xr-spatial-tracking=()"
|
|
||||||
)
|
|
||||||
|
|
||||||
// stylesheetPath is the only subresource the dashboard loads.
|
|
||||||
const stylesheetPath = "/s/css/tailwind.min.css"
|
|
||||||
|
|
||||||
// newTestLogger builds a logger for direct component construction.
|
|
||||||
func newTestLogger(t *testing.T) *logger.Logger {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
glob, err := globals.New(nil)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("globals.New: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
log, err := logger.New(nil, logger.Params{Globals: glob})
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("logger.New: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
return log
|
|
||||||
}
|
|
||||||
|
|
||||||
// newTestMiddleware builds a Middleware without an fx application.
|
|
||||||
func newTestMiddleware(t *testing.T) *middleware.Middleware {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
glob, err := globals.New(nil)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("globals.New: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
mw, err := middleware.New(nil, middleware.Params{
|
|
||||||
Logger: newTestLogger(t),
|
|
||||||
Globals: glob,
|
|
||||||
Config: &config.Config{},
|
|
||||||
})
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("middleware.New: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
return mw
|
|
||||||
}
|
|
||||||
|
|
||||||
// serveWithSecurityHeaders runs a GET through SecurityHeaders and
|
|
||||||
// returns the recorded response.
|
|
||||||
func serveWithSecurityHeaders(
|
|
||||||
t *testing.T,
|
|
||||||
target string,
|
|
||||||
handler http.Handler,
|
|
||||||
) *httptest.ResponseRecorder {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
mw := newTestMiddleware(t)
|
|
||||||
rec := httptest.NewRecorder()
|
|
||||||
req := httptest.NewRequestWithContext(
|
|
||||||
t.Context(), http.MethodGet, target, nil,
|
|
||||||
)
|
|
||||||
|
|
||||||
mw.SecurityHeaders()(handler).ServeHTTP(rec, req)
|
|
||||||
|
|
||||||
return rec
|
|
||||||
}
|
|
||||||
|
|
||||||
// okHandler writes a trivial 200 response.
|
|
||||||
func okHandler() http.Handler {
|
|
||||||
return http.HandlerFunc(func(
|
|
||||||
writer http.ResponseWriter,
|
|
||||||
_ *http.Request,
|
|
||||||
) {
|
|
||||||
writer.WriteHeader(http.StatusOK)
|
|
||||||
})
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestSecurityHeaders(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
tests := []struct {
|
|
||||||
name string
|
|
||||||
header string
|
|
||||||
want string
|
|
||||||
}{
|
|
||||||
{
|
|
||||||
"hsts",
|
|
||||||
"Strict-Transport-Security",
|
|
||||||
wantHSTS,
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"csp",
|
|
||||||
"Content-Security-Policy",
|
|
||||||
wantCSP,
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"frame options",
|
|
||||||
"X-Frame-Options",
|
|
||||||
wantFrameOptions,
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"content type options",
|
|
||||||
"X-Content-Type-Options",
|
|
||||||
wantContentTypeOptions,
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"referrer policy",
|
|
||||||
"Referrer-Policy",
|
|
||||||
wantReferrerPolicy,
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"permissions policy",
|
|
||||||
"Permissions-Policy",
|
|
||||||
wantPermissionsPolicy,
|
|
||||||
},
|
|
||||||
}
|
|
||||||
|
|
||||||
for _, tt := range tests {
|
|
||||||
t.Run(tt.name, func(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
rec := serveWithSecurityHeaders(t, "/", okHandler())
|
|
||||||
|
|
||||||
got := rec.Header().Get(tt.header)
|
|
||||||
if got != tt.want {
|
|
||||||
t.Errorf(
|
|
||||||
"%s = %q, want %q",
|
|
||||||
tt.header, got, tt.want,
|
|
||||||
)
|
|
||||||
}
|
|
||||||
})
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestSecurityHeadersCSPDirectives guards the properties the repo
|
|
||||||
// policy requires of the content security policy itself.
|
|
||||||
func TestSecurityHeadersCSPDirectives(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
rec := serveWithSecurityHeaders(t, "/", okHandler())
|
|
||||||
csp := rec.Header().Get("Content-Security-Policy")
|
|
||||||
|
|
||||||
forbidden := []string{"unsafe-inline", "unsafe-eval"}
|
|
||||||
for _, directive := range forbidden {
|
|
||||||
if strings.Contains(csp, directive) {
|
|
||||||
t.Errorf("CSP must not contain %q: %q", directive, csp)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
required := []string{
|
|
||||||
"default-src 'self'",
|
|
||||||
"script-src 'none'",
|
|
||||||
"style-src 'self'",
|
|
||||||
"frame-ancestors 'none'",
|
|
||||||
}
|
|
||||||
for _, directive := range required {
|
|
||||||
if !strings.Contains(csp, directive) {
|
|
||||||
t.Errorf("CSP must contain %q: %q", directive, csp)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestSecurityHeadersOnErrorResponse verifies the headers are emitted
|
|
||||||
// even when the wrapped handler fails, since they are set before the
|
|
||||||
// handler runs.
|
|
||||||
func TestSecurityHeadersOnErrorResponse(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
failing := http.HandlerFunc(func(
|
|
||||||
writer http.ResponseWriter,
|
|
||||||
_ *http.Request,
|
|
||||||
) {
|
|
||||||
http.Error(
|
|
||||||
writer,
|
|
||||||
"boom",
|
|
||||||
http.StatusInternalServerError,
|
|
||||||
)
|
|
||||||
})
|
|
||||||
|
|
||||||
rec := serveWithSecurityHeaders(t, "/api/v1/status", failing)
|
|
||||||
|
|
||||||
if rec.Code != http.StatusInternalServerError {
|
|
||||||
t.Fatalf("status = %d, want 500", rec.Code)
|
|
||||||
}
|
|
||||||
|
|
||||||
if got := rec.Header().Get(
|
|
||||||
"X-Content-Type-Options",
|
|
||||||
); got != wantContentTypeOptions {
|
|
||||||
t.Errorf(
|
|
||||||
"X-Content-Type-Options = %q, want %q",
|
|
||||||
got, wantContentTypeOptions,
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
if got := rec.Header().Get(
|
|
||||||
"Strict-Transport-Security",
|
|
||||||
); got != wantHSTS {
|
|
||||||
t.Errorf(
|
|
||||||
"Strict-Transport-Security = %q, want %q",
|
|
||||||
got, wantHSTS,
|
|
||||||
)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// newTestHandlers builds real Handlers with empty monitoring state.
|
|
||||||
func newTestHandlers(t *testing.T) *handlers.Handlers {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
glob, err := globals.New(nil)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("globals.New: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
log := newTestLogger(t)
|
|
||||||
|
|
||||||
notifier, err := notify.New(nil, notify.Params{
|
|
||||||
Logger: log,
|
|
||||||
Config: &config.Config{},
|
|
||||||
})
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("notify.New: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
hnd, err := handlers.New(nil, handlers.Params{
|
|
||||||
Logger: log,
|
|
||||||
Globals: glob,
|
|
||||||
State: state.NewForTest(),
|
|
||||||
Notify: notifier,
|
|
||||||
})
|
|
||||||
if err != nil {
|
|
||||||
t.Fatalf("handlers.New: %v", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
return hnd
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestDashboardRendersWithSecurityHeaders renders the real dashboard
|
|
||||||
// through the middleware and checks that the policy still permits the
|
|
||||||
// one stylesheet the page loads.
|
|
||||||
func TestDashboardRendersWithSecurityHeaders(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
mw := newTestMiddleware(t)
|
|
||||||
hnd := newTestHandlers(t)
|
|
||||||
|
|
||||||
router := chi.NewRouter()
|
|
||||||
router.Use(mw.SecurityHeaders())
|
|
||||||
router.Get("/", hnd.HandleDashboard())
|
|
||||||
|
|
||||||
rec := httptest.NewRecorder()
|
|
||||||
req := httptest.NewRequestWithContext(
|
|
||||||
t.Context(), http.MethodGet, "/", nil,
|
|
||||||
)
|
|
||||||
|
|
||||||
router.ServeHTTP(rec, req)
|
|
||||||
|
|
||||||
if rec.Code != http.StatusOK {
|
|
||||||
t.Fatalf("status = %d, want 200", rec.Code)
|
|
||||||
}
|
|
||||||
|
|
||||||
body := rec.Body.String()
|
|
||||||
if !strings.Contains(body, stylesheetPath) {
|
|
||||||
t.Errorf("dashboard does not reference %q", stylesheetPath)
|
|
||||||
}
|
|
||||||
|
|
||||||
if !strings.Contains(body, "dnswatcher") {
|
|
||||||
t.Errorf("dashboard body looks empty: %d bytes", len(body))
|
|
||||||
}
|
|
||||||
|
|
||||||
csp := rec.Header().Get("Content-Security-Policy")
|
|
||||||
if csp != wantCSP {
|
|
||||||
t.Errorf("CSP = %q, want %q", csp, wantCSP)
|
|
||||||
}
|
|
||||||
|
|
||||||
// The stylesheet is same-origin, so style-src 'self' allows it.
|
|
||||||
if !strings.Contains(csp, "style-src 'self'") {
|
|
||||||
t.Errorf("CSP would block %q: %q", stylesheetPath, csp)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -21,7 +21,6 @@ func (s *Server) SetupRoutes() {
|
|||||||
// Global middleware
|
// Global middleware
|
||||||
s.router.Use(chimw.Recoverer)
|
s.router.Use(chimw.Recoverer)
|
||||||
s.router.Use(chimw.RequestID)
|
s.router.Use(chimw.RequestID)
|
||||||
s.router.Use(s.mw.SecurityHeaders())
|
|
||||||
s.router.Use(s.mw.Logging())
|
s.router.Use(s.mw.Logging())
|
||||||
s.router.Use(s.mw.CORS())
|
s.router.Use(s.mw.CORS())
|
||||||
s.router.Use(chimw.Timeout(requestTimeout))
|
s.router.Use(chimw.Timeout(requestTimeout))
|
||||||
|
|||||||
@@ -4,14 +4,14 @@
|
|||||||
# installed tools are skipped. Base tooling comes from nix, apt, brew,
|
# installed tools are skipped. Base tooling comes from nix, apt, brew,
|
||||||
# or apk (detected in that order); assumes nothing is present.
|
# or apk (detected in that order); assumes nothing is present.
|
||||||
# golangci-lint and goimports are installed via `go install` at the same
|
# golangci-lint and goimports are installed via `go install` at the same
|
||||||
# pinned commits the Dockerfile uses (never "latest").
|
# pinned refs the Dockerfile uses (never "latest").
|
||||||
set -eu
|
set -eu
|
||||||
|
|
||||||
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||||
|
|
||||||
# Pinned versions, 2026-08-07 (same pins as the Dockerfile)
|
# Pinned versions, 2026-08-07 (same pins as the Dockerfile)
|
||||||
# golangci-lint v2.12.2
|
# golangci-lint v2.12.2
|
||||||
GOLANGCI_LINT_REF="github.com/golangci/golangci-lint/v2/cmd/golangci-lint@c0d3ddc9cf3faa61a4e378e879ece580256d76e5"
|
GOLANGCI_LINT_REF="github.com/golangci/golangci-lint/v2/cmd/golangci-lint@v2.12.2"
|
||||||
# goimports v0.42.0
|
# goimports v0.42.0
|
||||||
GOIMPORTS_REF="golang.org/x/tools/cmd/goimports@009367f5c17a8d4c45a961a3a509277190a9a6f0"
|
GOIMPORTS_REF="golang.org/x/tools/cmd/goimports@009367f5c17a8d4c45a961a3a509277190a9a6f0"
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user