Files
palette/internal/web/securityheaders_test.go
T
fen 72dbfb1b3c
CI / test (pull_request) Successful in 28s
CI / docker (pull_request) Skipped
Fix invisible select chevron in all presets (#136)
Two compounding causes:
- CSP img-src fell back to default-src (self), blocking the data: URI
  chevron image on all served pages, so no select ever painted it.
- .editor-head select used the background shorthand, wiping the
  background-image set by the later select rule.

Chevron stroke is now a per-preset --chevron token (light stroke for
dark presets, dark for light presets) instead of hardcoded #888.
CSP gains img-src 'self' data: so the data-URI icons can load.
2026-09-09 23:25:15 -05:00

47 lines
1.9 KiB
Go

package web
import (
"net/http"
"net/http/httptest"
"testing"
)
// #59: SecurityHeaders must add the CSP and hardening headers to rendered
// HTML responses only; JSON and /raw responses pass through untouched.
func TestSecurityHeaders(t *testing.T) {
pages := http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
w.Header().Set("Content-Type", "text/html; charset=utf-8")
w.Write([]byte("<html><body>ok</body></html>"))
})
h := SecurityHeaders(pages)
rec := httptest.NewRecorder()
h.ServeHTTP(rec, httptest.NewRequest("GET", "/", nil))
wantCSP := "default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data:; frame-ancestors 'none'"
if got := rec.Header().Get("Content-Security-Policy"); got != wantCSP {
t.Errorf("CSP = %q, want %q", got, wantCSP)
}
if got := rec.Header().Get("Referrer-Policy"); got != "no-referrer" {
t.Errorf("Referrer-Policy = %q, want no-referrer", got)
}
if got := rec.Header().Get("X-Content-Type-Options"); got != "nosniff" {
t.Errorf("X-Content-Type-Options = %q, want nosniff", got)
}
// JSON/raw responses: headers are now set unconditionally BEFORE the handler
// runs. The previous post-handler approach was silently dropped once a page
// handler flushed its template output (headers must be set before WriteHeader).
// CSP/nosniff/referrer on non-HTML bodies is harmless and desirable.
jsonh := SecurityHeaders(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
w.Header().Set("Content-Type", "application/json")
w.Write([]byte(`{"ok":true}`))
}))
rec = httptest.NewRecorder()
jsonh.ServeHTTP(rec, httptest.NewRequest("GET", "/api/x", nil))
if got := rec.Header().Get("Content-Security-Policy"); got != wantCSP {
t.Errorf("CSP missing on JSON response: got %q", got)
}
if got := rec.Header().Get("Referrer-Policy"); got != "no-referrer" {
t.Errorf("Referrer-Policy missing on JSON response: got %q", got)
}
}