mirror of
https://github.com/go-gitea/gitea.git
synced 2026-09-06 04:53:22 +09:00
77 lines
2.8 KiB
Go
77 lines
2.8 KiB
Go
// Copyright 2023 The Gitea Authors. All rights reserved.
|
|
// SPDX-License-Identifier: MIT
|
|
|
|
package context
|
|
|
|
import (
|
|
"net/http"
|
|
"net/http/httptest"
|
|
"net/url"
|
|
"strings"
|
|
"testing"
|
|
|
|
"gitea.dev/modules/reqctx"
|
|
"gitea.dev/modules/setting"
|
|
"gitea.dev/modules/test"
|
|
|
|
"github.com/stretchr/testify/assert"
|
|
)
|
|
|
|
func TestRemoveSessionCookieHeader(t *testing.T) {
|
|
w := httptest.NewRecorder()
|
|
w.Header().Add("Set-Cookie", (&http.Cookie{Name: setting.SessionConfig.CookieName, Value: "foo"}).String())
|
|
w.Header().Add("Set-Cookie", (&http.Cookie{Name: "other", Value: "bar"}).String())
|
|
assert.Len(t, w.Header().Values("Set-Cookie"), 2)
|
|
removeSessionCookieHeader(w)
|
|
assert.Len(t, w.Header().Values("Set-Cookie"), 1)
|
|
assert.Contains(t, "other=bar", w.Header().Get("Set-Cookie"))
|
|
}
|
|
|
|
func TestRedirectToCurrentSite(t *testing.T) {
|
|
setting.IsInTesting = true
|
|
defer test.MockVariableValue(&setting.AppURL, "http://localhost:3000/sub/")()
|
|
defer test.MockVariableValue(&setting.AppSubURL, "/sub")()
|
|
cases := []struct {
|
|
location string
|
|
want string
|
|
}{
|
|
{"/", "/sub/"},
|
|
{"http://localhost:3000/sub?k=v", "http://localhost:3000/sub?k=v"},
|
|
{"http://other", "/sub/"},
|
|
}
|
|
for _, c := range cases {
|
|
t.Run(c.location, func(t *testing.T) {
|
|
req := &http.Request{URL: &url.URL{Path: "/"}}
|
|
resp := httptest.NewRecorder()
|
|
base := NewBaseContextForTest(t, resp, req)
|
|
ctx := NewWebContext(base, nil, nil)
|
|
ctx.RedirectToCurrentSite(c.location)
|
|
redirect := test.RedirectURL(resp)
|
|
assert.Equal(t, c.want, redirect)
|
|
})
|
|
}
|
|
}
|
|
|
|
func TestAppFullLink(t *testing.T) {
|
|
setting.IsInTesting = true
|
|
defer test.MockVariableValue(&setting.AppURL, "https://gitea.example.com/sub/")()
|
|
defer test.MockVariableValue(&setting.AppSubURL, "/sub")()
|
|
defer test.MockVariableValue(&setting.PublicURLDetection, setting.PublicURLNever)()
|
|
|
|
req := httptest.NewRequest(http.MethodGet, "https://gitea.example.com/sub/", nil)
|
|
tmplCtx := NewTemplateContext(reqctx.NewRequestContextForTest(t), req)
|
|
|
|
assert.Equal(t, "https://gitea.example.com/sub", string(tmplCtx.AppFullLink()))
|
|
assert.Equal(t, "https://gitea.example.com/sub/user/repo", string(tmplCtx.AppFullLink("user/repo")))
|
|
assert.Equal(t, "https://gitea.example.com/sub/user/repo", string(tmplCtx.AppFullLink("/user/repo")))
|
|
}
|
|
|
|
func TestHeadMetaContentSecurityPolicy(t *testing.T) {
|
|
tmplCtx := NewTemplateContext(reqctx.NewRequestContextForTest(t), nil)
|
|
nonce := tmplCtx.CspScriptNonce()
|
|
assert.Equal(t, `<meta http-equiv="Content-Security-Policy" content="default-src * data: blob:;script-src * 'nonce-`+nonce+`';style-src * 'unsafe-inline';">`, string(tmplCtx.HeadMetaContentSecurityPolicy()))
|
|
assert.False(t, strings.ContainsAny(WebContentSecurityPolicy(nonce), `"<>&`))
|
|
defer test.MockVariableValue(&setting.Security.ContentSecurityPolicyGeneral, "unset")()
|
|
assert.Empty(t, tmplCtx.HeadMetaContentSecurityPolicy())
|
|
}
|