Expect a Content-Security-Policy without unsafe-inline
The security headers test now expects script-src and style-src to allow only 'self', and checks that the policy carries no 'unsafe-inline' at all. It fails until the login and generator pages stop needing inline script and style. Model: opus-5-5
This commit is contained in:
@@ -325,6 +325,13 @@ func TestSecurityHeaders_PolicyHeaders(t *testing.T) {
|
|||||||
|
|
||||||
handler.ServeHTTP(rec, req)
|
handler.ServeHTTP(rec, req)
|
||||||
|
|
||||||
|
// The login and generator pages load their script and stylesheet from
|
||||||
|
// /static, so the policy allows no inline script or style.
|
||||||
|
csp := rec.Header().Get("Content-Security-Policy")
|
||||||
|
if strings.Contains(csp, "unsafe-inline") {
|
||||||
|
t.Errorf("Content-Security-Policy allows unsafe-inline: %q", csp)
|
||||||
|
}
|
||||||
|
|
||||||
tests := []struct {
|
tests := []struct {
|
||||||
header string
|
header string
|
||||||
want string
|
want string
|
||||||
@@ -333,8 +340,8 @@ func TestSecurityHeaders_PolicyHeaders(t *testing.T) {
|
|||||||
{
|
{
|
||||||
"Content-Security-Policy",
|
"Content-Security-Policy",
|
||||||
"default-src 'self'; " +
|
"default-src 'self'; " +
|
||||||
"script-src 'self' 'unsafe-inline'; " +
|
"script-src 'self'; " +
|
||||||
"style-src 'self' 'unsafe-inline'; " +
|
"style-src 'self'; " +
|
||||||
"object-src 'none'; " +
|
"object-src 'none'; " +
|
||||||
"base-uri 'self'; " +
|
"base-uri 'self'; " +
|
||||||
"form-action 'self'; " +
|
"form-action 'self'; " +
|
||||||
|
|||||||
Reference in New Issue
Block a user