Pin the body cap's order in every page route group (closes #93)
check / check (push) Successful in 3m12s

A route test now posts an oversized body with no session or CSRF
token to each page route group, /settings included, and requires 413
with no CSRF cookie. Before, only the login form pinned the cap ahead
of CSRF; reordering the /settings, /hooks or /hook groups failed
nothing.

The MaxBodySize doc comment says other methods pass uncapped on
purpose, and the middleware test comment names the helper it
describes. The three router helpers in the server tests build the
Server through New, on a lifecycle that is never started, instead of
setting its fields by hand. The README already described the cap's
position correctly.

Model: opus-5-5
This commit is contained in:
2026-10-02 15:29:03 +00:00
parent 385fbc1a6a
commit 091d17c5ae
7 changed files with 107 additions and 39 deletions
+6 -4
View File
@@ -730,10 +730,8 @@ func TestNoCache_SetsHeaders(t *testing.T) {
const testBodyLimit int64 = 64
// maxBodySizeHandler wraps a sentinel handler in MaxBodySize with
// testBodyLimit. The sentinel records whether it ran and how much of
// the body it managed to read, so tests can distinguish "never
// reached" from "reached but truncated".
// maxBodySizeResult is what runMaxBodySize's sentinel handler saw,
// together with the response.
type maxBodySizeResult struct {
called bool
read int
@@ -741,6 +739,10 @@ type maxBodySizeResult struct {
response *httptest.ResponseRecorder
}
// runMaxBodySize wraps a sentinel handler in MaxBodySize with
// testBodyLimit and serves req through it. The sentinel records
// whether it ran and how much of the body it managed to read, so
// tests can distinguish "never reached" from "reached but truncated".
func runMaxBodySize(
t *testing.T,
req *http.Request,