Test metrics auth, CORS preflight, login logging and metrics (closes #79)
check / check (push) Failing after 2s
check / check (push) Failing after 2s
New tests only. The basic auth in front of /metrics answers 401 with a challenge without credentials or with a wrong username or password, and lets the configured ones through. A CORS preflight request gets the same Access-Control-Allow-Origin as a GET. A POST / whose form carries the signing key leaves the key out of the log line. The metrics middleware records a request it served, and the router records nothing while no metrics username is set. The pinned basicauth-go already compares the password in constant time with crypto/subtle, so no code changes. Model: opus-5-5
This commit is contained in:
@@ -29,6 +29,16 @@ P2: security: referer blacklist
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-10-04 the metrics basic auth, CORS preflight, request logging and
|
||||
metrics recording have tests (closes #79): the basic auth in front of
|
||||
`/metrics` answers 401 with a challenge without credentials or with a wrong
|
||||
username or password and lets the configured ones through; a preflight
|
||||
request gets `*` for any origin when `access_control_allow_origin` is `*` and
|
||||
no `Access-Control-Allow-Origin` from another origin than the configured
|
||||
one; a `POST /` carrying the signing key leaves no trace of it in the log
|
||||
line; the metrics middleware records a request it served, and the router
|
||||
records nothing while no metrics username is set. Tests only; the basic auth
|
||||
library already compares the password in constant time.
|
||||
- 2026-10-04 routes, encrypted URLs and config file documented (closes #75):
|
||||
"Routes" in `README.md` lists every route with its method, purpose, what it
|
||||
needs and the status codes it answers with, and says `q` and `fit` are part
|
||||
|
||||
Reference in New Issue
Block a user