Test metrics auth, CORS preflight, login logging and metrics (closes #79)
check / check (push) Failing after 2s

New tests only. The basic auth in front of /metrics answers 401 with a
challenge without credentials or with a wrong username or password, and
lets the configured ones through. A CORS preflight request gets the same
Access-Control-Allow-Origin as a GET. A POST / whose form carries the
signing key leaves the key out of the log line. The metrics middleware
records a request it served, and the router records nothing while no
metrics username is set.

The pinned basicauth-go already compares the password in constant time
with crypto/subtle, so no code changes.

Model: opus-5-5
This commit is contained in:
2026-10-04 08:10:43 +00:00
parent 363774c058
commit c4fe5c1d75
3 changed files with 243 additions and 0 deletions
+10
View File
@@ -29,6 +29,16 @@ P2: security: referer blacklist
# Completed Steps
- 2026-10-04 the metrics basic auth, CORS preflight, request logging and
metrics recording have tests (closes #79): the basic auth in front of
`/metrics` answers 401 with a challenge without credentials or with a wrong
username or password and lets the configured ones through; a preflight
request gets `*` for any origin when `access_control_allow_origin` is `*` and
no `Access-Control-Allow-Origin` from another origin than the configured
one; a `POST /` carrying the signing key leaves no trace of it in the log
line; the metrics middleware records a request it served, and the router
records nothing while no metrics username is set. Tests only; the basic auth
library already compares the password in constant time.
- 2026-10-04 routes, encrypted URLs and config file documented (closes #75):
"Routes" in `README.md` lists every route with its method, purpose, what it
needs and the status codes it answers with, and says `q` and `fit` are part