Test logging in, logging out, the URL generator and /v1/e/ tokens (closes #77) #191

Merged
clawbot merged 1 commits from issue-77-handler-flow-tests into next 2026-10-04 19:24:40 +02:00
Collaborator

New tests only, in internal/handlers, with the mock fetcher and no network, per the plan on #77.

  • /v1/e/: a valid token serves the image; an expired token answers 410; a token with one character changed, cut short, or made with another signing key answers 400, as README.md says for a token that does not decrypt. The server these run against would serve the photo for any token it accepted.
  • Login: GET / shows the login form; a wrong key shows it again with its error and sets no session cookie; the right key answers 303 to / with a session cookie whose Secure, HttpOnly and SameSite=Strict are checked one by one.
  • GET /logout answers 303 to / with an empty session cookie sent with Max-Age=0.
  • POST /generate with the form's token and cookie but no login session answers 303 to / and makes no URL.
  • Round trip: the URL the generator page shows is served by /v1/e/.

Not visible in the diff:

  • Everywhere these tests look, the code answers as README.md says; no difference is pinned.
  • In the round trip, /v1/e/ runs on separate handlers made with the same signing key, as the generator's test router has no image service.
  • The new file uses formatField and imgcache.FormatJPEG because a third literal "format" or "jpeg" in the package trips the linter's repeated-string check.

Judgement call: the right-key test also checks that GET / with the new cookie shows the generator page, so the cookie is shown to work, not only to carry its attributes.

Model: opus-5-5

New tests only, in `internal/handlers`, with the mock fetcher and no network, per the plan on https://git.eeqj.de/sneak/pixa/issues/77. - `/v1/e/`: a valid token serves the image; an expired token answers 410; a token with one character changed, cut short, or made with another signing key answers 400, as `README.md` says for a token that does not decrypt. The server these run against would serve the photo for any token it accepted. - Login: `GET /` shows the login form; a wrong key shows it again with its error and sets no session cookie; the right key answers 303 to `/` with a session cookie whose `Secure`, `HttpOnly` and `SameSite=Strict` are checked one by one. - `GET /logout` answers 303 to `/` with an empty session cookie sent with `Max-Age=0`. - `POST /generate` with the form's token and cookie but no login session answers 303 to `/` and makes no URL. - Round trip: the URL the generator page shows is served by `/v1/e/`. Not visible in the diff: - Everywhere these tests look, the code answers as `README.md` says; no difference is pinned. - In the round trip, `/v1/e/` runs on separate handlers made with the same signing key, as the generator's test router has no image service. - The new file uses `formatField` and `imgcache.FormatJPEG` because a third literal `"format"` or `"jpeg"` in the package trips the linter's repeated-string check. Judgement call: the right-key test also checks that `GET /` with the new cookie shows the generator page, so the cookie is shown to work, not only to carry its attributes. Model: opus-5-5
clawbot added the needs-review label 2026-10-04 17:28:22 +02:00
clawbot self-assigned this 2026-10-04 17:28:22 +02:00
Author
Collaborator

PASS: head a96d15188821e51f349fe480c1ab50c6df7e4da1, rebased onto next at f8c437b83f642596c211c76b4d25ef10d734ee7d.

Model: opus-5-5

**PASS**: head `a96d15188821e51f349fe480c1ab50c6df7e4da1`, rebased onto `next` at `f8c437b83f642596c211c76b4d25ef10d734ee7d`. Model: opus-5-5
clawbot added 1 commit 2026-10-04 19:09:59 +02:00
New handler tests in internal/handlers, with no network: GET / shows the
login form without a session; a wrong key shows it again with an error and
sets no session cookie; the right key answers 303 with a session cookie
marked Secure, HttpOnly and SameSite=Strict, with which GET / shows the
generator page; GET /logout empties the cookie with Max-Age=0; POST
/generate without a session answers 303 to /; /v1/e/ serves a valid
token's image, answers 410 for an expired token and 400 for one changed,
cut short or made with another signing key; a URL made on the generator
page is served by /v1/e/. No code changes.

Model: opus-5-5
clawbot force-pushed issue-77-handler-flow-tests from a96d151888 to 30ae998114 2026-10-04 19:09:59 +02:00 Compare
clawbot merged commit 233a9c05ad into next 2026-10-04 19:24:40 +02:00
clawbot deleted branch issue-77-handler-flow-tests 2026-10-04 19:24:40 +02:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/pixa#191