Pin the body cap's order in every page route group (closes #93)
check / check (push) Successful in 3m28s

A route test now posts an oversized body with no session or CSRF
token to a POST route in each page route group that has one, and
requires 413 with no CSRF cookie. Before, only the login form pinned
the cap ahead of CSRF; reordering the /hooks or /hook groups failed
nothing.

The MaxBodySize doc comment says other methods pass uncapped on
purpose, the middleware test comment names the helper it describes,
and NewRouterForTest says why its hand-built Server is enough. The
README already described the cap's position correctly.

Model: opus-5-5
This commit is contained in:
2026-10-02 14:54:59 +00:00
parent 0ccb01cada
commit f76a175091
4 changed files with 55 additions and 5 deletions
+6 -4
View File
@@ -730,10 +730,8 @@ func TestNoCache_SetsHeaders(t *testing.T) {
const testBodyLimit int64 = 64
// maxBodySizeHandler wraps a sentinel handler in MaxBodySize with
// testBodyLimit. The sentinel records whether it ran and how much of
// the body it managed to read, so tests can distinguish "never
// reached" from "reached but truncated".
// maxBodySizeResult is what runMaxBodySize's sentinel handler saw,
// together with the response.
type maxBodySizeResult struct {
called bool
read int
@@ -741,6 +739,10 @@ type maxBodySizeResult struct {
response *httptest.ResponseRecorder
}
// runMaxBodySize wraps a sentinel handler in MaxBodySize with
// testBodyLimit and serves req through it. The sentinel records
// whether it ran and how much of the body it managed to read, so
// tests can distinguish "never reached" from "reached but truncated".
func runMaxBodySize(
t *testing.T,
req *http.Request,