Correct release-blocking README and startup-warning inaccuracies (closes #151)
All checks were successful
check / check (push) Successful in 3m0s
All checks were successful
check / check (push) Successful in 3m0s
Publishing this README would have shipped false statements about the product. Corrects the eight items on the issue plus everything a full sweep turned up: the Slack circuit-breaker scope, a nonexistent WAL, the wrong config key for slack targets, six undocumented routes, the conditional /metrics registration, wrong retention bands, wrong shutdown mechanism, and a Quick Start that led a new contributor into a red build. The lockout warning now fires whenever TRUSTED_PROXIES is empty rather than only in production, since the variable it was gated on defaults to dev. Rate-limit keying, the limits and the TRUSTED_PROXIES default are untouched — those belong to #150. What /s/* actually serves was settled empirically rather than by reading: all five of GET/HEAD/POST/PUT/DELETE return 200, pinned by TestStaticServesEveryMethod. Restricting it is filed separately. Independently reviewed after three prior rounds. The reviewer re-derived all fifteen claim-table rows against the code, including every row a previous revision had marked "correct, left alone" and got wrong, and found zero false; then verified every route method-by-method, all twelve environment variables, all nine entity tables, and the package tree against git ls-files. The Quick Start was confirmed by running it in a fresh clone.
This commit was merged in pull request #156.
This commit is contained in:
@@ -24,6 +24,7 @@ import (
|
||||
"sneak.berlin/go/webhooker/internal/middleware"
|
||||
"sneak.berlin/go/webhooker/internal/server"
|
||||
"sneak.berlin/go/webhooker/internal/session"
|
||||
"sneak.berlin/go/webhooker/static"
|
||||
)
|
||||
|
||||
// csrfCookieName is the cookie gorilla/csrf issues when it runs. Its
|
||||
@@ -246,6 +247,56 @@ func (e *testEnv) storedHash(t *testing.T, username string) string {
|
||||
return user.Password
|
||||
}
|
||||
|
||||
// --- /s static group ---
|
||||
|
||||
// TestStaticServesEveryMethod pins what the static mount actually
|
||||
// answers. chi's Mount registers the handler for all methods and
|
||||
// http.FileServer only special-cases HEAD (by suppressing the body),
|
||||
// so a POST or a DELETE to an asset is served the file rather than
|
||||
// refused. The README documents this; the test is what keeps the two
|
||||
// from drifting.
|
||||
func TestStaticServesEveryMethod(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
env := newTestEnv(t)
|
||||
|
||||
body, err := static.Static.ReadFile("js/app.js")
|
||||
require.NoError(t, err)
|
||||
require.NotEmpty(t, body)
|
||||
|
||||
for _, method := range []string{
|
||||
http.MethodGet,
|
||||
http.MethodHead,
|
||||
http.MethodPost,
|
||||
http.MethodPut,
|
||||
http.MethodDelete,
|
||||
} {
|
||||
t.Run(method, func(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
req := httptest.NewRequestWithContext(
|
||||
context.Background(), method,
|
||||
"/s/js/app.js", nil,
|
||||
)
|
||||
w := httptest.NewRecorder()
|
||||
env.router.ServeHTTP(w, req)
|
||||
|
||||
assert.Equal(t, http.StatusOK, w.Code,
|
||||
"static mount answers every method")
|
||||
|
||||
if method == http.MethodHead {
|
||||
assert.Empty(t, w.Body.Bytes(),
|
||||
"HEAD must not carry a body")
|
||||
|
||||
return
|
||||
}
|
||||
|
||||
assert.Equal(t, body, w.Body.Bytes(),
|
||||
"the asset itself is returned")
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
// --- /pages group ---
|
||||
|
||||
// TestPagesLogin_OversizeBody_RejectedBeforeCSRF proves the cap runs
|
||||
|
||||
Reference in New Issue
Block a user