test(10-05): cover every Phase 10 Go change with branch-level tests
- bouncer TestPhase10CookieGuard: cookie read without Bearer, Bearer wins, empty cookie, frontend audience and blacklisted jti rejected - boardwalk TestPhase10BoardwalkServing: HEAD, query strings, encoded traversal, index by name, nested prefix, MIME fallback, constructor errors - cabana TestPhase10Coverage: mounted unsafe routes vs the CSRF walk, option and filter edges, read-only labels, relation message defaults, bundle fallback locale, cookie refresh of an expired token in the refresh window - phrasebook override precedence, new locale, Bundle merge order, Forms shapes - surf prefix collision for deeper paths and the default /backend prefix - swagger2openapi TestUnionRewrite and converter branch tests - framework tests no longer name the application (acme fixtures instead)
This commit is contained in:
@@ -14,11 +14,11 @@ import (
|
||||
|
||||
func TestCORSLaravelGlobMatchesNestedPaths(t *testing.T) {
|
||||
re := compileLaravelGlob("api/*")
|
||||
if re == nil || !re.MatchString("api/v1/fonoteka/genres") {
|
||||
t.Fatal("api/* must match api/v1/fonoteka/genres (Laravel Str::is, not Go path.Match)")
|
||||
if re == nil || !re.MatchString("api/v1/acme/genres") {
|
||||
t.Fatal("api/* must match api/v1/acme/genres (Laravel Str::is, not Go path.Match)")
|
||||
}
|
||||
if re.MatchString("_fonoteka/api/v1/genres") {
|
||||
t.Fatal("api/* must not match _fonoteka/api/v1/genres")
|
||||
if re.MatchString("_acme/api/v1/genres") {
|
||||
t.Fatal("api/* must not match _acme/api/v1/genres")
|
||||
}
|
||||
mcp := compileLaravelGlob("oauth/mcp/*")
|
||||
if mcp == nil || !mcp.MatchString("oauth/mcp/token") {
|
||||
@@ -34,22 +34,22 @@ func TestCORSPathScopedHeaders(t *testing.T) {
|
||||
AllowedHeaders: []string{"*"},
|
||||
}
|
||||
mux := http.NewServeMux()
|
||||
mux.HandleFunc("GET /api/v1/fonoteka/genres", func(w http.ResponseWriter, r *http.Request) {
|
||||
mux.HandleFunc("GET /api/v1/acme/genres", func(w http.ResponseWriter, r *http.Request) {
|
||||
w.WriteHeader(http.StatusOK)
|
||||
})
|
||||
mux.HandleFunc("GET /_fonoteka/api/v1/genres", func(w http.ResponseWriter, r *http.Request) {
|
||||
mux.HandleFunc("GET /_acme/api/v1/genres", func(w http.ResponseWriter, r *http.Request) {
|
||||
w.WriteHeader(http.StatusOK)
|
||||
})
|
||||
h := pathScopedCORS(cfg, mux)
|
||||
|
||||
rec := httptest.NewRecorder()
|
||||
h.ServeHTTP(rec, httptest.NewRequest(http.MethodGet, "/api/v1/fonoteka/genres", nil))
|
||||
h.ServeHTTP(rec, httptest.NewRequest(http.MethodGet, "/api/v1/acme/genres", nil))
|
||||
if rec.Header().Get("Access-Control-Allow-Origin") != "*" {
|
||||
t.Fatalf("token group ACAO = %q", rec.Header().Get("Access-Control-Allow-Origin"))
|
||||
}
|
||||
|
||||
rec = httptest.NewRecorder()
|
||||
h.ServeHTTP(rec, httptest.NewRequest(http.MethodGet, "/_fonoteka/api/v1/genres", nil))
|
||||
h.ServeHTTP(rec, httptest.NewRequest(http.MethodGet, "/_acme/api/v1/genres", nil))
|
||||
if got := rec.Header().Get("Access-Control-Allow-Origin"); got != "" {
|
||||
t.Fatalf("JWT group ACAO = %q, want empty", got)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user