Compare commits
2
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
3ee7acbe32 | ||
|
|
a56f1fe0c8 |
@@ -2698,9 +2698,9 @@ abuse limit later; they are tracked as future work.
|
|||||||
|
|
||||||
#### Authenticated Endpoints
|
#### Authenticated Endpoints
|
||||||
|
|
||||||
A logged-out request to any of these is redirected to `/pages/login`. A
|
A logged-out `GET` of any of these is redirected to `/pages/login` with
|
||||||
`GET` carries its path and query there as `next`, so logging in returns
|
its path and query as `next`, so logging in returns to the page that was
|
||||||
to the page that was asked for.
|
asked for.
|
||||||
|
|
||||||
| Method | Path | Description |
|
| Method | Path | Description |
|
||||||
| ------ | ------------------------ | ----------- |
|
| ------ | ------------------------ | ----------- |
|
||||||
|
|||||||
@@ -539,7 +539,8 @@ func loginPageGet(
|
|||||||
|
|
||||||
// TestLoginPage_CarriesOnlyAPathOnThisSite covers the login page
|
// TestLoginPage_CarriesOnlyAPathOnThisSite covers the login page
|
||||||
// itself: its form carries the requested page only when it is a path
|
// itself: its form carries the requested page only when it is a path
|
||||||
// on this site, and a browser already logged in goes straight there.
|
// on this site, and a browser already logged in goes straight there,
|
||||||
|
// or to "/" when it is not.
|
||||||
func TestLoginPage_CarriesOnlyAPathOnThisSite(t *testing.T) {
|
func TestLoginPage_CarriesOnlyAPathOnThisSite(t *testing.T) {
|
||||||
t.Parallel()
|
t.Parallel()
|
||||||
|
|
||||||
@@ -563,10 +564,21 @@ func TestLoginPage_CarriesOnlyAPathOnThisSite(t *testing.T) {
|
|||||||
)
|
)
|
||||||
|
|
||||||
cookies := authenticatedCookies(t, sess, "test-user-id", "testuser")
|
cookies := authenticatedCookies(t, sess, "test-user-id", "testuser")
|
||||||
w := loginPageGet(h, "/source/abc", cookies)
|
|
||||||
|
|
||||||
assert.Equal(t, http.StatusSeeOther, w.Code)
|
cases := []struct{ next, want string }{
|
||||||
assert.Equal(t, "/source/abc", w.Header().Get("Location"))
|
{"/source/abc", "/source/abc"},
|
||||||
|
{"//evil.example/", "/"},
|
||||||
|
{`/\evil.example/`, "/"},
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, c := range cases {
|
||||||
|
w := loginPageGet(h, c.next, cookies)
|
||||||
|
|
||||||
|
assert.Equal(t, http.StatusSeeOther, w.Code, "next %q", c.next)
|
||||||
|
assert.Equal(
|
||||||
|
t, c.want, w.Header().Get("Location"), "next %q", c.next,
|
||||||
|
)
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// TestLoginPage_HasNoLinkToItself: the navigation bar on the login
|
// TestLoginPage_HasNoLinkToItself: the navigation bar on the login
|
||||||
|
|||||||
@@ -88,6 +88,8 @@ func TestHandleProfile_OwnProfile_OK(t *testing.T) {
|
|||||||
h.HandleProfile().ServeHTTP(w, req)
|
h.HandleProfile().ServeHTTP(w, req)
|
||||||
|
|
||||||
assert.Equal(t, http.StatusOK, w.Code)
|
assert.Equal(t, http.StatusOK, w.Code)
|
||||||
|
assert.Contains(t, w.Body.String(), "Account Information")
|
||||||
|
assert.NotContains(t, w.Body.String(), "Account Type")
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestHandleProfile_OtherProfile_Forbidden(t *testing.T) {
|
func TestHandleProfile_OtherProfile_Forbidden(t *testing.T) {
|
||||||
|
|||||||
@@ -41,10 +41,6 @@
|
|||||||
<dt class="w-32 text-sm font-medium text-gray-500">Username</dt>
|
<dt class="w-32 text-sm font-medium text-gray-500">Username</dt>
|
||||||
<dd class="text-sm text-gray-900">{{.User.Username}}</dd>
|
<dd class="text-sm text-gray-900">{{.User.Username}}</dd>
|
||||||
</div>
|
</div>
|
||||||
<div class="flex">
|
|
||||||
<dt class="w-32 text-sm font-medium text-gray-500">Account Type</dt>
|
|
||||||
<dd class="text-sm text-gray-900">Standard User</dd>
|
|
||||||
</div>
|
|
||||||
</dl>
|
</dl>
|
||||||
</div>
|
</div>
|
||||||
</div>
|
</div>
|
||||||
|
|||||||
Reference in New Issue
Block a user