Test that an origin with a * inside aborts startup (closes #61)

Failing cases for access_control_allow_origin set to https://*,
https://*.example.com and https://*example.com. The CORS middleware
reads a * inside an origin as a pattern, so these would let other sites
read responses; each must abort startup naming the key and the value.

Model: opus-5-5
This commit is contained in:
2026-09-29 00:19:07 +00:00
parent 2cd328d2da
commit 7a969bb225
@@ -792,6 +792,23 @@ func invalidSizeAndOriginCases() []abortCase {
keyAccessControlAllowOrigin, "https://example.com/", keyAccessControlAllowOrigin, "https://example.com/",
}, },
}, },
{
name: "access_control_allow_origin host *",
yaml: signingKeyLine + "access_control_allow_origin: https://*\n",
wantErrSubstrings: []string{keyAccessControlAllowOrigin, "https://*"},
},
{
name: "access_control_allow_origin host *.example.com",
yaml: signingKeyLine +
"access_control_allow_origin: https://*.example.com\n",
wantErrSubstrings: []string{keyAccessControlAllowOrigin, "https://*.example.com"},
},
{
name: "access_control_allow_origin host *example.com",
yaml: signingKeyLine +
"access_control_allow_origin: https://*example.com\n",
wantErrSubstrings: []string{keyAccessControlAllowOrigin, "https://*example.com"},
},
{ {
name: "access_control_allow_origin empty", name: "access_control_allow_origin empty",
yaml: signingKeyLine + "access_control_allow_origin: \"\"\n", yaml: signingKeyLine + "access_control_allow_origin: \"\"\n",