Add the four settings the README documented but pixa lacked (closes #61)
check / check (push) Successful in 15s
check / check (push) Successful in 15s
README.md documented access_control_allow_origin, upstream_fetch_timeout, upstream_max_response_size and downstream_timeout, but pixa did not know them, so a config following the README aborted startup. Each is now a setting with its PIXA_ variable, defaulting to the value that was fixed in the code: *, 30s, 50 MiB and 60s. Durations are Go duration strings and must be positive; the size is whole bytes, at most 1 GiB. The origin is * or one http or https origin written exactly as a browser sends it; anything else aborts startup. downstream_timeout sets both the server's write timeout and the per-request timeout. The owner approved the edits to existing tests. Model: opus-5-5
This commit was merged in pull request #142.
This commit is contained in:
@@ -6,6 +6,7 @@ import (
|
||||
"path/filepath"
|
||||
"strings"
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"git.eeqj.de/sneak/smartconfig"
|
||||
)
|
||||
@@ -599,3 +600,244 @@ func TestEnsureStateDirFailsOnUncreatablePath(t *testing.T) {
|
||||
t.Errorf("error %q does not name the offending key state_dir", err.Error())
|
||||
}
|
||||
}
|
||||
|
||||
// TestOmittedOriginTimeoutsAndSizeUseDefaults checks that the CORS
|
||||
// origin, the upstream fetch timeout, the upstream response size limit
|
||||
// and the downstream timeout default to the values pixa used before they
|
||||
// could be configured.
|
||||
func TestOmittedOriginTimeoutsAndSizeUseDefaults(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
c, err := configFromYAML(t, signingKeyLine)
|
||||
if err != nil {
|
||||
t.Fatalf("minimal config should be valid, got error: %v", err)
|
||||
}
|
||||
|
||||
if c.AccessControlAllowOrigin != "*" {
|
||||
t.Errorf("AccessControlAllowOrigin = %q, want *", c.AccessControlAllowOrigin)
|
||||
}
|
||||
|
||||
if c.UpstreamFetchTimeout != 30*time.Second {
|
||||
t.Errorf("UpstreamFetchTimeout = %v, want 30s", c.UpstreamFetchTimeout)
|
||||
}
|
||||
|
||||
if c.UpstreamMaxResponseSize != 50<<20 {
|
||||
t.Errorf("UpstreamMaxResponseSize = %d, want %d (50 MiB)",
|
||||
c.UpstreamMaxResponseSize, 50<<20)
|
||||
}
|
||||
|
||||
if c.DownstreamTimeout != 60*time.Second {
|
||||
t.Errorf("DownstreamTimeout = %v, want 60s", c.DownstreamTimeout)
|
||||
}
|
||||
}
|
||||
|
||||
// TestExplicitOriginTimeoutsAndSizeAreUsed checks that valid values for
|
||||
// the CORS origin, the two timeouts and the response size limit are used
|
||||
// as given. The size is the largest accepted, 1 GiB.
|
||||
func TestExplicitOriginTimeoutsAndSizeAreUsed(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
c, err := configFromYAML(t, signingKeyLine+`
|
||||
access_control_allow_origin: https://app.example.com
|
||||
upstream_fetch_timeout: 10s
|
||||
upstream_max_response_size: 1073741824
|
||||
downstream_timeout: 2m
|
||||
`)
|
||||
if err != nil {
|
||||
t.Fatalf("valid config should load, got error: %v", err)
|
||||
}
|
||||
|
||||
if c.AccessControlAllowOrigin != "https://app.example.com" {
|
||||
t.Errorf("AccessControlAllowOrigin = %q, want https://app.example.com",
|
||||
c.AccessControlAllowOrigin)
|
||||
}
|
||||
|
||||
if c.UpstreamFetchTimeout != 10*time.Second {
|
||||
t.Errorf("UpstreamFetchTimeout = %v, want 10s", c.UpstreamFetchTimeout)
|
||||
}
|
||||
|
||||
if c.UpstreamMaxResponseSize != 1073741824 {
|
||||
t.Errorf("UpstreamMaxResponseSize = %d, want 1073741824",
|
||||
c.UpstreamMaxResponseSize)
|
||||
}
|
||||
|
||||
if c.DownstreamTimeout != 2*time.Minute {
|
||||
t.Errorf("DownstreamTimeout = %v, want 2m", c.DownstreamTimeout)
|
||||
}
|
||||
}
|
||||
|
||||
// TestOriginWithPortOrAnyOriginIsAccepted checks the other accepted forms
|
||||
// of access_control_allow_origin: "*", an origin with a port, and origins
|
||||
// whose host is an IPv4 or IPv6 address.
|
||||
func TestOriginWithPortOrAnyOriginIsAccepted(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
for _, origin := range []string{
|
||||
"*", "http://localhost:3000", "http://192.0.2.1", "http://[2001:db8::1]:8080",
|
||||
} {
|
||||
c, err := configFromYAML(t, signingKeyLine+
|
||||
"access_control_allow_origin: \""+origin+"\"\n")
|
||||
if err != nil {
|
||||
t.Fatalf("origin %q should be accepted, got error: %v", origin, err)
|
||||
}
|
||||
|
||||
if c.AccessControlAllowOrigin != origin {
|
||||
t.Errorf("AccessControlAllowOrigin = %q, want %q",
|
||||
c.AccessControlAllowOrigin, origin)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// invalidTimeoutCases are configs where upstream_fetch_timeout or
|
||||
// downstream_timeout is not a positive Go duration string; each must
|
||||
// abort startup naming the key and the value.
|
||||
func invalidTimeoutCases() []abortCase {
|
||||
return []abortCase{
|
||||
{
|
||||
name: "upstream_fetch_timeout not a duration",
|
||||
yaml: signingKeyLine + "upstream_fetch_timeout: soon\n",
|
||||
wantErrSubstrings: []string{keyUpstreamFetchTimeout, "soon"},
|
||||
},
|
||||
{
|
||||
name: "upstream_fetch_timeout number without a unit",
|
||||
yaml: signingKeyLine + "upstream_fetch_timeout: 45\n",
|
||||
wantErrSubstrings: []string{keyUpstreamFetchTimeout, "45"},
|
||||
},
|
||||
{
|
||||
name: "upstream_fetch_timeout zero",
|
||||
yaml: signingKeyLine + "upstream_fetch_timeout: 0s\n",
|
||||
wantErrSubstrings: []string{keyUpstreamFetchTimeout, "0s"},
|
||||
},
|
||||
{
|
||||
name: "upstream_fetch_timeout negative",
|
||||
yaml: signingKeyLine + "upstream_fetch_timeout: -5s\n",
|
||||
wantErrSubstrings: []string{keyUpstreamFetchTimeout, "-5s"},
|
||||
},
|
||||
{
|
||||
name: "upstream_fetch_timeout null",
|
||||
yaml: signingKeyLine + "upstream_fetch_timeout: null\n",
|
||||
wantErrSubstrings: []string{keyUpstreamFetchTimeout, nullValueText},
|
||||
},
|
||||
{
|
||||
name: "downstream_timeout not a duration",
|
||||
yaml: signingKeyLine + "downstream_timeout: 1 minute\n",
|
||||
wantErrSubstrings: []string{keyDownstreamTimeout, "1 minute"},
|
||||
},
|
||||
{
|
||||
name: "downstream_timeout zero",
|
||||
yaml: signingKeyLine + "downstream_timeout: 0s\n",
|
||||
wantErrSubstrings: []string{keyDownstreamTimeout, "0s"},
|
||||
},
|
||||
{
|
||||
name: "downstream_timeout negative",
|
||||
yaml: signingKeyLine + "downstream_timeout: -1m\n",
|
||||
wantErrSubstrings: []string{keyDownstreamTimeout, "-1m"},
|
||||
},
|
||||
{
|
||||
name: "downstream_timeout null",
|
||||
yaml: signingKeyLine + "downstream_timeout:\n",
|
||||
wantErrSubstrings: []string{keyDownstreamTimeout, nullValueText},
|
||||
},
|
||||
}
|
||||
}
|
||||
|
||||
// invalidSizeAndOriginCases are configs where upstream_max_response_size
|
||||
// is not a whole number of bytes from 1 to 1 GiB, or
|
||||
// access_control_allow_origin is neither "*" nor an origin; each must
|
||||
// abort startup naming the key and the value.
|
||||
func invalidSizeAndOriginCases() []abortCase {
|
||||
badOrigins := []string{
|
||||
"", // empty
|
||||
"example.com", // no scheme
|
||||
"https://example.com/images", // a path
|
||||
"https://example.com/", // a trailing slash
|
||||
// The CORS middleware reads a * inside an origin as a pattern
|
||||
// that lets other sites read responses.
|
||||
"https://*",
|
||||
"https://*.example.com",
|
||||
"https://*example.com",
|
||||
"https://a.com,b.com", // two hosts
|
||||
"https://example.com:", // an empty port
|
||||
"https://:8443", // no host
|
||||
"https://example.com:0", // a port below 1
|
||||
"https://example.com:99999", // a port above 65535
|
||||
"https://exämple.com", // a host name that is not ASCII
|
||||
"https://example.com:443", // the default port for https
|
||||
"http://example.com:80", // the default port for http
|
||||
"https://example.com:08080", // a port with a leading zero
|
||||
"https://01.2.3.4", // an IPv4 address with a leading zero
|
||||
"https://10.0.0", // an IPv4 address with three parts
|
||||
"https://192.168.1.256", // an IPv4 address part above 255
|
||||
"https://example.123", // a host name whose last part is a number
|
||||
"https://[0:0:0:0:0:0:0:1]", // an IPv6 address not in its shortest form
|
||||
"file://example.com", // a scheme other than http or https
|
||||
"HTTPS://example.com", // a scheme in upper case
|
||||
"https://Example.com", // a host name in upper case
|
||||
}
|
||||
|
||||
cases := make([]abortCase, 0, len(badOrigins))
|
||||
for _, origin := range badOrigins {
|
||||
cases = append(cases, abortCase{
|
||||
name: "access_control_allow_origin " + origin,
|
||||
yaml: signingKeyLine +
|
||||
"access_control_allow_origin: \"" + origin + "\"\n",
|
||||
wantErrSubstrings: []string{keyAccessControlAllowOrigin, origin},
|
||||
})
|
||||
}
|
||||
|
||||
return append(cases, []abortCase{
|
||||
{
|
||||
name: "access_control_allow_origin null",
|
||||
yaml: signingKeyLine + "access_control_allow_origin: null\n",
|
||||
wantErrSubstrings: []string{keyAccessControlAllowOrigin, nullValueText},
|
||||
},
|
||||
{
|
||||
name: "upstream_max_response_size with a unit",
|
||||
yaml: signingKeyLine + "upstream_max_response_size: 50MB\n",
|
||||
wantErrSubstrings: []string{keyUpstreamMaxResponseSize, "50MB"},
|
||||
},
|
||||
{
|
||||
name: "upstream_max_response_size fractional",
|
||||
yaml: signingKeyLine + "upstream_max_response_size: 1.5\n",
|
||||
wantErrSubstrings: []string{keyUpstreamMaxResponseSize, "1.5"},
|
||||
},
|
||||
{
|
||||
name: "upstream_max_response_size zero",
|
||||
yaml: signingKeyLine + "upstream_max_response_size: 0\n",
|
||||
wantErrSubstrings: []string{keyUpstreamMaxResponseSize, "0"},
|
||||
},
|
||||
{
|
||||
name: "upstream_max_response_size negative",
|
||||
yaml: signingKeyLine + "upstream_max_response_size: -1\n",
|
||||
wantErrSubstrings: []string{keyUpstreamMaxResponseSize, "-1"},
|
||||
},
|
||||
{
|
||||
name: "upstream_max_response_size null",
|
||||
yaml: signingKeyLine + "upstream_max_response_size: null\n",
|
||||
wantErrSubstrings: []string{keyUpstreamMaxResponseSize, nullValueText},
|
||||
},
|
||||
{
|
||||
name: "upstream_max_response_size above 1 GiB",
|
||||
yaml: signingKeyLine + "upstream_max_response_size: 1073741825\n",
|
||||
wantErrSubstrings: []string{keyUpstreamMaxResponseSize, "1073741825"},
|
||||
},
|
||||
{
|
||||
name: "upstream_max_response_size largest 64-bit integer",
|
||||
yaml: signingKeyLine +
|
||||
"upstream_max_response_size: 9223372036854775807\n",
|
||||
wantErrSubstrings: []string{
|
||||
keyUpstreamMaxResponseSize, "9223372036854775807",
|
||||
},
|
||||
},
|
||||
}...)
|
||||
}
|
||||
|
||||
// TestInvalidOriginTimeoutOrSizeAbortsStartup verifies the
|
||||
// no-silent-fallback rule for the CORS origin, the two timeouts and the
|
||||
// response size limit: a value that does not parse or is out of range
|
||||
// aborts startup naming the key and the value.
|
||||
func TestInvalidOriginTimeoutOrSizeAbortsStartup(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
runAbortCases(t, append(invalidTimeoutCases(), invalidSizeAndOriginCases()...))
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user