Re-vendor the canonical files from sneak/prompts at dd4027b (closes #112) #115

Merged
clawbot merged 3 commits from issue-112-revendor-prompts into next 2026-10-06 21:01:47 +02:00
Showing only changes of commit 778b26cc0d - Show all commits
+34
View File
@@ -1,11 +1,13 @@
package neoircapi_test
import (
"context"
"io"
"net"
"net/http"
"net/http/httptest"
"net/url"
"strings"
"testing"
api "sneak.berlin/go/neoirc/internal/cli/api"
@@ -95,3 +97,35 @@ func TestClientKeepsSessionOverPlainHTTPOnLocalhost(t *testing.T) {
})
}
}
func TestClientWithholdsCookieOverPlainHTTPFromOtherHosts(t *testing.T) {
t.Parallel()
server := newSessionServer(t)
// neoirc.example is not loopback. Every connection the client
// opens to it goes to the test server instead.
client := api.NewClient("http://neoirc.example")
client.HTTPClient.Transport = &http.Transport{
DialContext: func(
ctx context.Context, network, _ string,
) (net.Conn, error) {
var dialer net.Dialer
return dialer.DialContext(
ctx, network, server.Listener.Addr().String(),
)
},
}
_, err := client.CreateSession("alice")
if err != nil {
t.Fatalf("create session: %v", err)
}
// The server answers 401 when the auth cookie does not arrive.
_, err = client.GetState()
if err == nil || !strings.Contains(err.Error(), "401") {
t.Fatalf("state: got %v, want 401: cookie sent over plain HTTP", err)
}
}