Test that neoirc-cli keeps its auth cookie off plain HTTP to other hosts
check / check (push) Waiting to run

The cookie test showed the Secure auth cookie reaching localhost and
127.0.0.1 over plain HTTP, but not that it is still withheld over plain
HTTP from every other host. A new test points the client at
neoirc.example, sends its connections to the test server, and checks
that the cookie does not arrive.

Model: opus-5-5
This commit is contained in:
2026-10-06 16:16:05 +00:00
parent 58d8f5cc94
commit 778b26cc0d
+34
View File
@@ -1,11 +1,13 @@
package neoircapi_test
import (
"context"
"io"
"net"
"net/http"
"net/http/httptest"
"net/url"
"strings"
"testing"
api "sneak.berlin/go/neoirc/internal/cli/api"
@@ -95,3 +97,35 @@ func TestClientKeepsSessionOverPlainHTTPOnLocalhost(t *testing.T) {
})
}
}
func TestClientWithholdsCookieOverPlainHTTPFromOtherHosts(t *testing.T) {
t.Parallel()
server := newSessionServer(t)
// neoirc.example is not loopback. Every connection the client
// opens to it goes to the test server instead.
client := api.NewClient("http://neoirc.example")
client.HTTPClient.Transport = &http.Transport{
DialContext: func(
ctx context.Context, network, _ string,
) (net.Conn, error) {
var dialer net.Dialer
return dialer.DialContext(
ctx, network, server.Listener.Addr().String(),
)
},
}
_, err := client.CreateSession("alice")
if err != nil {
t.Fatalf("create session: %v", err)
}
// The server answers 401 when the auth cookie does not arrive.
_, err = client.GetState()
if err == nil || !strings.Contains(err.Error(), "401") {
t.Fatalf("state: got %v, want 401: cookie sent over plain HTTP", err)
}
}