Pin the body cap's order in every page route group (closes #93)
check / check (push) Successful in 3m28s
check / check (push) Successful in 3m28s
A route test now posts an oversized body with no session or CSRF token to a POST route in each page route group that has one, and requires 413 with no CSRF cookie. Before, only the login form pinned the cap ahead of CSRF; reordering the /hooks or /hook groups failed nothing. The MaxBodySize doc comment says other methods pass uncapped on purpose, the middleware test comment names the helper it describes, and NewRouterForTest says why its hand-built Server is enough. The README already described the cap's position correctly. Model: opus-5-5
This commit is contained in:
@@ -39,6 +39,13 @@ func SentryClientOptionsForTest(
|
||||
// and the HTTP listener. Tests use it so that route-group middleware
|
||||
// registration order is exercised exactly as it ships, rather than
|
||||
// against a hand-rebuilt chain that could drift from routes.go.
|
||||
//
|
||||
// The Server itself is built by hand rather than through New, because
|
||||
// New registers the fx hooks that start the listener. That is enough
|
||||
// only while SetupRoutes reads no fields beyond mw, h, params.Config
|
||||
// and sentryEnabled: a field it starts reading must also be set here
|
||||
// and in the two probe variants below, or these tests run with it
|
||||
// zero.
|
||||
func NewRouterForTest(
|
||||
log *slog.Logger,
|
||||
cfg *config.Config,
|
||||
|
||||
Reference in New Issue
Block a user