Pin the body cap's order in every page route group (closes #93)
check / check (push) Successful in 3m12s
check / check (push) Successful in 3m12s
A route test now posts an oversized body with no session or CSRF token to each page route group, /settings included, and requires 413 with no CSRF cookie. Before, only the login form pinned the cap ahead of CSRF; reordering the /settings, /hooks or /hook groups failed nothing. The MaxBodySize doc comment says other methods pass uncapped on purpose, and the middleware test comment names the helper it describes. The three router helpers in the server tests build the Server through New, on a lifecycle that is never started, instead of setting its fields by hand. The README already described the cap's position correctly. Model: opus-5-5
This commit is contained in:
@@ -136,7 +136,7 @@ func newTestEnvWithConfig(
|
||||
t.Cleanup(app.RequireStop)
|
||||
|
||||
return &testEnv{
|
||||
router: server.NewRouterForTest(log.Get(), cfg, mw, hnd),
|
||||
router: server.NewRouterForTest(t, log, cfg, mw, hnd),
|
||||
sess: sess,
|
||||
db: db,
|
||||
dbMgr: dbMgr,
|
||||
@@ -531,6 +531,48 @@ func TestStaticServesOnlyGetAndHead(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
// --- every page route group ---
|
||||
|
||||
// TestPageRouteGroups_OversizeBody_RejectedBeforeCSRF pins the body
|
||||
// cap ahead of CSRF and RequireAuth in every page route group. The
|
||||
// requests carry no session and no CSRF token, so if either ran first
|
||||
// the answer would be a 403 or a redirect to the login page rather
|
||||
// than 413, and CSRF would issue its cookie (see
|
||||
// TestPagesLogin_UnderLimit_NoToken_CSRFRejects). /settings has no
|
||||
// POST route, but its group's middleware runs before the method is
|
||||
// matched, so a POST there still reaches CSRF's form parsing if the
|
||||
// cap moves after it. The user and webhook in the paths need not
|
||||
// exist: nothing after the cap runs.
|
||||
func TestPageRouteGroups_OversizeBody_RejectedBeforeCSRF(
|
||||
t *testing.T,
|
||||
) {
|
||||
t.Parallel()
|
||||
|
||||
env := newTestEnv(t)
|
||||
|
||||
form := url.Values{}
|
||||
form.Set("name", oversizeValue())
|
||||
|
||||
for _, path := range []string{
|
||||
"/pages/login",
|
||||
"/user/nobody/password",
|
||||
"/settings/",
|
||||
"/hooks/new",
|
||||
"/hook/nonexistent/edit",
|
||||
} {
|
||||
w := env.post(path, form, nil)
|
||||
|
||||
assert.Equal(
|
||||
t, http.StatusRequestEntityTooLarge, w.Code, path,
|
||||
)
|
||||
assert.False(
|
||||
t, csrfCookieSet(w),
|
||||
"CSRF middleware must not run for an oversized body to %s",
|
||||
path,
|
||||
)
|
||||
}
|
||||
}
|
||||
|
||||
// --- /pages group ---
|
||||
|
||||
// TestPagesLogin_OversizeBody_RejectedBeforeCSRF proves the cap runs
|
||||
@@ -1610,7 +1652,7 @@ func TestTwoMetricsRoutersInOneProcess(t *testing.T) {
|
||||
)
|
||||
third := &testEnv{
|
||||
router: server.NewRouterForTest(
|
||||
first.log.Get(), first.cfg, first.mw, first.hnd,
|
||||
t, first.log, first.cfg, first.mw, first.hnd,
|
||||
),
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user