Test metrics auth, CORS preflight, login logging and metrics (closes #79)
check / check (push) Failing after 2s
check / check (push) Failing after 2s
New tests only. The basic auth in front of /metrics answers 401 with a challenge without credentials or with a wrong username or password, and lets the configured ones through. A CORS preflight request gets the same Access-Control-Allow-Origin as a GET. A POST / whose form carries the signing key leaves the key out of the log line. The metrics middleware records a request it served, and the router records nothing while no metrics username is set. The pinned basicauth-go already compares the password in constant time with crypto/subtle, so no code changes. Model: opus-5-5
This commit is contained in:
@@ -0,0 +1,32 @@
|
||||
package server
|
||||
|
||||
import (
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
"strings"
|
||||
"testing"
|
||||
|
||||
"github.com/prometheus/client_golang/prometheus/promhttp"
|
||||
)
|
||||
|
||||
// TestNoMetricsRecordedWithoutMetricsUsername checks that with no metrics
|
||||
// username set the router records nothing about the requests it serves.
|
||||
// /metrics is not served then, so the process-wide Prometheus registry is
|
||||
// read directly. TestMaintenanceModeKeepsOtherRoutes records into the same
|
||||
// registry, but never a GET /robots.txt.
|
||||
func TestNoMetricsRecordedWithoutMetricsUsername(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
s := newTestServer(t)
|
||||
s.ServeHTTP(httptest.NewRecorder(), httptest.NewRequestWithContext(
|
||||
t.Context(), http.MethodGet, "/robots.txt", nil))
|
||||
|
||||
rec := httptest.NewRecorder()
|
||||
promhttp.Handler().ServeHTTP(rec, httptest.NewRequestWithContext(
|
||||
t.Context(), http.MethodGet, "/metrics", nil))
|
||||
|
||||
if strings.Contains(rec.Body.String(), `handler="/robots.txt"`) {
|
||||
t.Errorf("with no metrics username GET /robots.txt was recorded:\n%s",
|
||||
rec.Body.String())
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user