From 778b26cc0d43b60506c994329afd071933f5f4a9 Mon Sep 17 00:00:00 2001 From: sneak Date: Tue, 6 Oct 2026 16:16:05 +0000 Subject: [PATCH] Test that neoirc-cli keeps its auth cookie off plain HTTP to other hosts The cookie test showed the Secure auth cookie reaching localhost and 127.0.0.1 over plain HTTP, but not that it is still withheld over plain HTTP from every other host. A new test points the client at neoirc.example, sends its connections to the test server, and checks that the cookie does not arrive. Model: opus-5-5 --- internal/cli/api/client_test.go | 34 +++++++++++++++++++++++++++++++++ 1 file changed, 34 insertions(+) diff --git a/internal/cli/api/client_test.go b/internal/cli/api/client_test.go index dbd5e0f..8a42cd1 100644 --- a/internal/cli/api/client_test.go +++ b/internal/cli/api/client_test.go @@ -1,11 +1,13 @@ package neoircapi_test import ( + "context" "io" "net" "net/http" "net/http/httptest" "net/url" + "strings" "testing" api "sneak.berlin/go/neoirc/internal/cli/api" @@ -95,3 +97,35 @@ func TestClientKeepsSessionOverPlainHTTPOnLocalhost(t *testing.T) { }) } } + +func TestClientWithholdsCookieOverPlainHTTPFromOtherHosts(t *testing.T) { + t.Parallel() + + server := newSessionServer(t) + + // neoirc.example is not loopback. Every connection the client + // opens to it goes to the test server instead. + client := api.NewClient("http://neoirc.example") + client.HTTPClient.Transport = &http.Transport{ + DialContext: func( + ctx context.Context, network, _ string, + ) (net.Conn, error) { + var dialer net.Dialer + + return dialer.DialContext( + ctx, network, server.Listener.Addr().String(), + ) + }, + } + + _, err := client.CreateSession("alice") + if err != nil { + t.Fatalf("create session: %v", err) + } + + // The server answers 401 when the auth cookie does not arrive. + _, err = client.GetState() + if err == nil || !strings.Contains(err.Error(), "401") { + t.Fatalf("state: got %v, want 401: cookie sent over plain HTTP", err) + } +}