Test metrics auth, CORS preflight, login logging and metrics (closes #79)
check / check (push) Failing after 2s

New tests only. The basic auth in front of /metrics answers 401 with a
challenge without credentials or with a wrong username or password, and
lets the configured ones through. A CORS preflight request gets the same
Access-Control-Allow-Origin as a GET. A POST / whose form carries the
signing key leaves the key out of the log line. The metrics middleware
records a request it served, and the router records nothing while no
metrics username is set.

The pinned basicauth-go already compares the password in constant time
with crypto/subtle, so no code changes.

Model: opus-5-5
This commit is contained in:
2026-10-04 08:10:43 +00:00
parent 363774c058
commit c4fe5c1d75
3 changed files with 243 additions and 0 deletions
+32
View File
@@ -0,0 +1,32 @@
package server
import (
"net/http"
"net/http/httptest"
"strings"
"testing"
"github.com/prometheus/client_golang/prometheus/promhttp"
)
// TestNoMetricsRecordedWithoutMetricsUsername checks that with no metrics
// username set the router records nothing about the requests it serves.
// /metrics is not served then, so the process-wide Prometheus registry is
// read directly. TestMaintenanceModeKeepsOtherRoutes records into the same
// registry, but never a GET /robots.txt.
func TestNoMetricsRecordedWithoutMetricsUsername(t *testing.T) {
t.Parallel()
s := newTestServer(t)
s.ServeHTTP(httptest.NewRecorder(), httptest.NewRequestWithContext(
t.Context(), http.MethodGet, "/robots.txt", nil))
rec := httptest.NewRecorder()
promhttp.Handler().ServeHTTP(rec, httptest.NewRequestWithContext(
t.Context(), http.MethodGet, "/metrics", nil))
if strings.Contains(rec.Body.String(), `handler="/robots.txt"`) {
t.Errorf("with no metrics username GET /robots.txt was recorded:\n%s",
rec.Body.String())
}
}