Test that neoirc-cli keeps its auth cookie off plain HTTP to other hosts
check / check (push) Waiting to run
check / check (push) Waiting to run
The cookie test showed the Secure auth cookie reaching localhost and 127.0.0.1 over plain HTTP, but not that it is still withheld over plain HTTP from every other host. A new test points the client at neoirc.example, sends its connections to the test server, and checks that the cookie does not arrive. Model: opus-5-5
This commit is contained in:
@@ -1,11 +1,13 @@
|
|||||||
package neoircapi_test
|
package neoircapi_test
|
||||||
|
|
||||||
import (
|
import (
|
||||||
|
"context"
|
||||||
"io"
|
"io"
|
||||||
"net"
|
"net"
|
||||||
"net/http"
|
"net/http"
|
||||||
"net/http/httptest"
|
"net/http/httptest"
|
||||||
"net/url"
|
"net/url"
|
||||||
|
"strings"
|
||||||
"testing"
|
"testing"
|
||||||
|
|
||||||
api "sneak.berlin/go/neoirc/internal/cli/api"
|
api "sneak.berlin/go/neoirc/internal/cli/api"
|
||||||
@@ -95,3 +97,35 @@ func TestClientKeepsSessionOverPlainHTTPOnLocalhost(t *testing.T) {
|
|||||||
})
|
})
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func TestClientWithholdsCookieOverPlainHTTPFromOtherHosts(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
server := newSessionServer(t)
|
||||||
|
|
||||||
|
// neoirc.example is not loopback. Every connection the client
|
||||||
|
// opens to it goes to the test server instead.
|
||||||
|
client := api.NewClient("http://neoirc.example")
|
||||||
|
client.HTTPClient.Transport = &http.Transport{
|
||||||
|
DialContext: func(
|
||||||
|
ctx context.Context, network, _ string,
|
||||||
|
) (net.Conn, error) {
|
||||||
|
var dialer net.Dialer
|
||||||
|
|
||||||
|
return dialer.DialContext(
|
||||||
|
ctx, network, server.Listener.Addr().String(),
|
||||||
|
)
|
||||||
|
},
|
||||||
|
}
|
||||||
|
|
||||||
|
_, err := client.CreateSession("alice")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("create session: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
// The server answers 401 when the auth cookie does not arrive.
|
||||||
|
_, err = client.GetState()
|
||||||
|
if err == nil || !strings.Contains(err.Error(), "401") {
|
||||||
|
t.Fatalf("state: got %v, want 401: cookie sent over plain HTTP", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user