Files
webhooker/internal/server/static_assets_test.go
clawbot b8272e158c
All checks were successful
check / check (push) Successful in 3m29s
Fetch Alpine.js at build time under a verified hash (closes #145)
static/js/alpine.min.js was a committed minified bundle: unreviewable,
referenced by no hash, and forbidden by REPO_POLICIES.md on both counts.

It is now fetched by script/fetch-assets from a pinned npm registry
tarball, with the tarball sha256 and the extracted file's sha256 both
hardcoded and checked before anything is installed. The hash of every
installed asset lives in static/vendor.sha256, and static/vendor_test.go
re-hashes the bytes go:embed actually put in the binary against that
manifest, so the pin is enforced on what ships rather than merely
recorded. .gitignore keeps the artifact out of the repo and
.dockerignore keeps a host copy out of the build context, so the image
can only get it by fetching and verifying it.

Alpine 3.14.9 is byte-identical to the blob that was committed
(3ed1eed252488921df65e363d6715deb04d7f92aaedb9e52199fdf73cb1e0ad3), so
the served asset does not change; internal/server/static_assets_test.go
fetches every /s/ script base.html loads through the real router to
prove the page still gets it.
2026-08-17 20:57:52 +00:00

51 lines
1.3 KiB
Go

package server_test
import (
"net/http"
"regexp"
"testing"
"github.com/stretchr/testify/assert"
"github.com/stretchr/testify/require"
"sneak.berlin/go/webhooker/templates"
)
// TestBaseTemplateScriptsAreServed walks every /s/ script the base
// template loads on each page and fetches it through the real router.
// Alpine.js is fetched at build time rather than committed, so nothing
// in the repo guarantees it is present: this is the check that the page
// still gets the JavaScript it asks for.
func TestBaseTemplateScriptsAreServed(t *testing.T) {
t.Parallel()
// scriptSrc matches the src of every <script> tag pointing at the
// /s/ static mount.
scriptSrc := regexp.MustCompile(`<script[^>]+src="(/s/[^"]+)"`)
base, err := templates.Templates.ReadFile("base.html")
require.NoError(t, err)
matches := scriptSrc.FindAllStringSubmatch(string(base), -1)
require.NotEmpty(t, matches, "base.html should load scripts from /s/")
env := newTestEnv(t)
for _, m := range matches {
src := m[1]
t.Run(src, func(t *testing.T) {
t.Parallel()
w := env.get(src, nil)
require.Equalf(
t, http.StatusOK, w.Code,
"base.html loads %s but the server does not serve it", src,
)
assert.NotEmptyf(
t, w.Body.Bytes(), "%s is served but empty", src,
)
})
}
}