check / check (push) Failing after 2s
New tests only. The basic auth in front of /metrics answers 401 with a challenge without credentials or with a wrong username or password, and lets the configured ones through. A CORS preflight request gets the same Access-Control-Allow-Origin as a GET. A POST / whose form carries the signing key leaves the key out of the log line. The metrics middleware records a request it served, and the router records nothing while no metrics username is set. The pinned basicauth-go already compares the password in constant time with crypto/subtle, so no code changes. Model: opus-5-5
33 lines
1.0 KiB
Go
33 lines
1.0 KiB
Go
package server
|
|
|
|
import (
|
|
"net/http"
|
|
"net/http/httptest"
|
|
"strings"
|
|
"testing"
|
|
|
|
"github.com/prometheus/client_golang/prometheus/promhttp"
|
|
)
|
|
|
|
// TestNoMetricsRecordedWithoutMetricsUsername checks that with no metrics
|
|
// username set the router records nothing about the requests it serves.
|
|
// /metrics is not served then, so the process-wide Prometheus registry is
|
|
// read directly. TestMaintenanceModeKeepsOtherRoutes records into the same
|
|
// registry, but never a GET /robots.txt.
|
|
func TestNoMetricsRecordedWithoutMetricsUsername(t *testing.T) {
|
|
t.Parallel()
|
|
|
|
s := newTestServer(t)
|
|
s.ServeHTTP(httptest.NewRecorder(), httptest.NewRequestWithContext(
|
|
t.Context(), http.MethodGet, "/robots.txt", nil))
|
|
|
|
rec := httptest.NewRecorder()
|
|
promhttp.Handler().ServeHTTP(rec, httptest.NewRequestWithContext(
|
|
t.Context(), http.MethodGet, "/metrics", nil))
|
|
|
|
if strings.Contains(rec.Body.String(), `handler="/robots.txt"`) {
|
|
t.Errorf("with no metrics username GET /robots.txt was recorded:\n%s",
|
|
rec.Body.String())
|
|
}
|
|
}
|