All checks were successful
check / check (push) Successful in 3m29s
static/js/alpine.min.js was a committed minified bundle: unreviewable, referenced by no hash, and forbidden by REPO_POLICIES.md on both counts. It is now fetched by script/fetch-assets from a pinned npm registry tarball, with the tarball sha256 and the extracted file's sha256 both hardcoded and checked before anything is installed. The hash of every installed asset lives in static/vendor.sha256, and static/vendor_test.go re-hashes the bytes go:embed actually put in the binary against that manifest, so the pin is enforced on what ships rather than merely recorded. .gitignore keeps the artifact out of the repo and .dockerignore keeps a host copy out of the build context, so the image can only get it by fetching and verifying it. Alpine 3.14.9 is byte-identical to the blob that was committed (3ed1eed252488921df65e363d6715deb04d7f92aaedb9e52199fdf73cb1e0ad3), so the served asset does not change; internal/server/static_assets_test.go fetches every /s/ script base.html loads through the real router to prove the page still gets it.
51 lines
1.3 KiB
Go
51 lines
1.3 KiB
Go
package server_test
|
|
|
|
import (
|
|
"net/http"
|
|
"regexp"
|
|
"testing"
|
|
|
|
"github.com/stretchr/testify/assert"
|
|
"github.com/stretchr/testify/require"
|
|
|
|
"sneak.berlin/go/webhooker/templates"
|
|
)
|
|
|
|
// TestBaseTemplateScriptsAreServed walks every /s/ script the base
|
|
// template loads on each page and fetches it through the real router.
|
|
// Alpine.js is fetched at build time rather than committed, so nothing
|
|
// in the repo guarantees it is present: this is the check that the page
|
|
// still gets the JavaScript it asks for.
|
|
func TestBaseTemplateScriptsAreServed(t *testing.T) {
|
|
t.Parallel()
|
|
|
|
// scriptSrc matches the src of every <script> tag pointing at the
|
|
// /s/ static mount.
|
|
scriptSrc := regexp.MustCompile(`<script[^>]+src="(/s/[^"]+)"`)
|
|
|
|
base, err := templates.Templates.ReadFile("base.html")
|
|
require.NoError(t, err)
|
|
|
|
matches := scriptSrc.FindAllStringSubmatch(string(base), -1)
|
|
require.NotEmpty(t, matches, "base.html should load scripts from /s/")
|
|
|
|
env := newTestEnv(t)
|
|
|
|
for _, m := range matches {
|
|
src := m[1]
|
|
t.Run(src, func(t *testing.T) {
|
|
t.Parallel()
|
|
|
|
w := env.get(src, nil)
|
|
|
|
require.Equalf(
|
|
t, http.StatusOK, w.Code,
|
|
"base.html loads %s but the server does not serve it", src,
|
|
)
|
|
assert.NotEmptyf(
|
|
t, w.Body.Bytes(), "%s is served but empty", src,
|
|
)
|
|
})
|
|
}
|
|
}
|