From 5d0b5f864e4476d4747bcee91356795802f244b3 Mon Sep 17 00:00:00 2001 From: clawbot Date: Fri, 7 Aug 2026 18:44:01 +0200 Subject: [PATCH] docs: record manual test pass of auth and encrypted URL flows (closes #49) (#50) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit closes #49 Records the P0 manual test pass in `TODO.md` per its Workflow section (checked-off results into Completed Steps; cache size management and eviction promoted to Next Step). `TODO.md` is the only changed file — no production code changes, as the issue requires. ## Test setup `pixad` built from `main` at `6573b9d` via `make build`, run on port 18099 with a throwaway local config (temp state dir, known `signing_key`, `allowlist_hosts` including `s3.sneak.cloud`), driven with curl using explicit cookie replay (session cookies are `Secure`/`HttpOnly`/`SameSite=Strict`). ## Results — all six checks PASS 1. **Login form**: GET `/` → HTTP 200, `Pixa - Login` page with `name="key"` password form. 2. **Wrong key error**: POST `/` with `key=wrong-key` → HTTP 200 login page containing "Invalid signing key". 3. **Generator form**: POST `/` with the correct signing key → HTTP 303 to `/` with `Set-Cookie: pixa_session=...; HttpOnly; Secure; SameSite=Strict`; GET `/` with that cookie → `Pixa - URL Generator` with the `/generate` form and logout link. 4. **Encrypted URL serves image**: POST `/generate` (ttl=3600) produced a `/v1/e//img.jpeg` URL → HTTP 200, `Content-Type: image/jpeg`, 800x600 baseline JPEG, 61706 bytes. 5. **Expired URL → 410**: a ttl=1 URL fetched after 3 s → HTTP 410 Gone with `{"error":"URL has expired","status":410,...}`. 6. **Logout**: GET `/logout` → HTTP 303 to `/` with `Set-Cookie: pixa_session=; Max-Age=0`; subsequent GET `/` → login form again. Additionally, all nine checks in `scripts/manual-test.sh` passed against the same server instance. ## Verification `make check` green on the branch head (all tests, golangci-lint 0 issues, fmt-check clean) — the first fully green `make check` on a `main`-derived branch under the current linter, confirming the #47/#48 fix on merged `main`. Note for review: the test execution was performed this session; the adversarial re-review (independently re-running the six flows) is still pending and should happen before merge. Co-authored-by: sneak Reviewed-on: https://git.eeqj.de/sneak/pixa/pulls/50 Co-authored-by: clawbot Co-committed-by: clawbot --- TODO.md | 32 +++++++++++++++++++++++++------- 1 file changed, 25 insertions(+), 7 deletions(-) diff --git a/TODO.md b/TODO.md index 29359f7..334fae9 100644 --- a/TODO.md +++ b/TODO.md @@ -19,14 +19,34 @@ on main. # Next Step -P0: manual test pass of the auth and encrypted URL flows, then commit -the checked-off results to TODO.md: visit / and see the login form; -wrong key shows an error; correct signing key shows the generator form; -a generated encrypted URL serves the image; an expired URL (short TTL) -returns 410; logout redirects back to login +P0: implement cache size management and eviction so the disk cannot +fill up # Completed Steps +- 2026-08-07 manual test pass of the auth and encrypted URL flows + against a locally built and running `pixad` (built from `main` at + `6573b9d`, port 18099, local throwaway config); all six checks + passed, plus all nine tests in `scripts/manual-test.sh` (closes #49): + - [x] visit `/` and see the login form: HTTP 200, `Pixa - Login` + page with `name="key"` password form + - [x] wrong key shows an error: POST `/` with `key=wrong-key` + returned HTTP 200 login page containing "Invalid signing key" + - [x] correct signing key shows the generator form: POST `/` + returned HTTP 303 to `/` with + `Set-Cookie: pixa_session=...; HttpOnly; Secure; SameSite=Strict`; + GET `/` with that cookie rendered `Pixa - URL Generator` with the + `/generate` form and logout link + - [x] a generated encrypted URL serves the image: POST `/generate` + (ttl=3600) produced a `/v1/e//img.jpeg` URL that returned + HTTP 200, `Content-Type: image/jpeg`, an 800x600 baseline JPEG of + 61706 bytes + - [x] an expired URL (short TTL) returns 410: a ttl=1 URL fetched + after 3 s returned HTTP 410 Gone with + `{"error":"URL has expired","status":410,...}` + - [x] logout redirects back to login: GET `/logout` returned HTTP + 303 to `/` with `Set-Cookie: pixa_session=; Max-Age=0`; + subsequent GET `/` rendered the login form again - 2026-08-07 fix the two remaining gosec findings (G124 in internal/session): session cookies now always carry Secure/HttpOnly/SameSite=Strict on both the set and clear paths; @@ -53,8 +73,6 @@ returns 410; logout redirects back to login # Future Steps -- P0: implement cache size management and eviction so the disk cannot - fill up - P0: validate configuration on startup, fail fast on bad config - P1: implement blocked networks configuration to extend SSRF protection