Repository navigation
Expand file tree
/
Copy pathstatic_test.go
More file actions
61 lines (58 loc) · 1.85 KB
/
Copy pathstatic_test.go
File metadata and controls
61 lines (58 loc) · 1.85 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
package main
import (
"regexp"
"strings"
"testing"
)
// Every write from the console must carry a JSON content type. The server
// requires it — that requirement is the CSRF defence, since a JSON content type
// forces a CORS preflight we never answer — and a page that omits it gets a 415
// which looks, from the user's side, like a rejected password.
//
// That is not hypothetical: login.html shipped without the header and every
// sign-in failed with "wrong username or password". The API tests all passed,
// because they set the header themselves. This test reads the pages instead.
func TestConsolePagesSendJSONContentType(t *testing.T) {
// Matches a fetch() call up to its closing brace, non-greedily.
call := regexp.MustCompile(`(?s)fetch\(.{0,600}?\}\s*\)`)
method := regexp.MustCompile(`method\s*:\s*['"](\w+)['"]`)
pages, err := staticFS.ReadDir("static")
if err != nil {
t.Fatal(err)
}
checked := 0
for _, p := range pages {
if !strings.HasSuffix(p.Name(), ".html") {
continue
}
b, err := staticFS.ReadFile("static/" + p.Name())
if err != nil {
t.Fatal(err)
}
for _, c := range call.FindAllString(string(b), -1) {
m := method.FindStringSubmatch(c)
if m == nil {
continue // a plain GET
}
switch strings.ToUpper(m[1]) {
case "POST", "PUT", "PATCH", "DELETE":
default:
continue
}
// A body-less call (logout) never reaches the decoder, so the header
// is only required when something is actually sent.
if !strings.Contains(c, "body") {
continue
}
checked++
if !strings.Contains(c, "Content-Type") {
t.Errorf("%s: a %s fetch with a body does not set Content-Type:\n%s",
p.Name(), m[1], c)
}
}
}
if checked == 0 {
t.Fatal("found no write requests to check — the matcher has stopped working")
}
t.Logf("checked %d write requests across the console pages", checked)
}