From 37372cd6fe377d5469e0f3a40ef7c52d8e3f6f58 Mon Sep 17 00:00:00 2001 From: clawbot <35+clawbot@noreply.example.org> Date: Mon, 28 Sep 2026 20:24:12 +0000 Subject: [PATCH] Test that origins a browser does not send abort startup (closes #61) Adds the review's examples to invalidSizeAndOriginCases: a scheme's default port, a port with a leading zero, hosts a browser reads as an IPv4 address or refuses, an IPv6 address not in its shortest form, plus a scheme other than http or https and a host name in upper case. Model: opus-5-5 --- internal/config/config_validation_internal_test.go | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/internal/config/config_validation_internal_test.go b/internal/config/config_validation_internal_test.go index fdcd17b..c275e38 100644 --- a/internal/config/config_validation_internal_test.go +++ b/internal/config/config_validation_internal_test.go @@ -762,6 +762,16 @@ func invalidSizeAndOriginCases() []abortCase { "https://example.com:0", // a port below 1 "https://example.com:99999", // a port above 65535 "https://exämple.com", // a host name that is not ASCII + "https://example.com:443", // the default port for https + "http://example.com:80", // the default port for http + "https://example.com:08080", // a port with a leading zero + "https://01.2.3.4", // an IPv4 address with a leading zero + "https://10.0.0", // an IPv4 address with three parts + "https://192.168.1.256", // an IPv4 address part above 255 + "https://example.123", // a host name whose last part is a number + "https://[0:0:0:0:0:0:0:1]", // an IPv6 address not in its shortest form + "file://example.com", // a scheme other than http or https + "https://Example.com", // a host name in upper case } cases := make([]abortCase, 0, len(badOrigins))