check / check (push) Failing after 2s
handlers.Params gets an optional Fetcher, marked optional for fx. When the app provides one, the handlers pass it to the image service, whose Fetcher option already existed for tests, instead of letting it build its own from the config. pixad provides none, so production builds its fetcher from the config exactly as before. A new test builds the handlers in an fx app that provides no fetcher, as pixad does, and checks that an image from an allowlisted localhost is refused with 403 by the fetcher the handlers built. Model: opus-5-5
50 lines
1.3 KiB
Go
50 lines
1.3 KiB
Go
package handlers
|
|
|
|
import (
|
|
"net/http"
|
|
"path/filepath"
|
|
"testing"
|
|
|
|
"github.com/go-chi/chi/v5"
|
|
"go.uber.org/fx"
|
|
"go.uber.org/fx/fxtest"
|
|
|
|
"sneak.berlin/go/pixa/internal/config"
|
|
"sneak.berlin/go/pixa/internal/database"
|
|
"sneak.berlin/go/pixa/internal/globals"
|
|
"sneak.berlin/go/pixa/internal/healthcheck"
|
|
"sneak.berlin/go/pixa/internal/logger"
|
|
)
|
|
|
|
// TestHandlersBuildTheirOwnFetcherWhenNoneIsProvided builds the handlers as
|
|
// pixad does, in an fx app that provides no fetcher, and requests an image
|
|
// from localhost, which is on the allowlist. The fetcher the handlers build
|
|
// from the config refuses localhost, so the answer is 403.
|
|
func TestHandlersBuildTheirOwnFetcherWhenNoneIsProvided(t *testing.T) {
|
|
t.Parallel()
|
|
|
|
stateDir := t.TempDir()
|
|
cfg := &config.Config{
|
|
SigningKey: testSigningKey,
|
|
StateDir: stateDir,
|
|
DBURL: "file:" + filepath.Join(stateDir, "state.sqlite3"),
|
|
AllowlistHosts: []string{"localhost"},
|
|
}
|
|
|
|
var h *Handlers
|
|
|
|
app := fxtest.New(t,
|
|
fx.Supply(cfg),
|
|
fx.Provide(globals.New, logger.New, database.New, healthcheck.New, New),
|
|
fx.Populate(&h),
|
|
)
|
|
app.RequireStart()
|
|
t.Cleanup(app.RequireStop)
|
|
|
|
r := chi.NewRouter()
|
|
r.Get("/v1/image/*", h.HandleImage())
|
|
|
|
rec := sendGet(t, r, photoURL("localhost"))
|
|
checkErrorBody(t, rec, http.StatusForbidden, "forbidden")
|
|
}
|