feat: allow wildcard web origins for local tunnel testing

This commit is contained in:
陈煜 committed 2026-10-01 17:58:28 +08:00
1 parent 2a650853ee
commit e4f4ff42e1
9 files changed
+115 -70

No files matched your search

+16
View File
@@ -6,6 +6,22 @@ import { positionInput, date, amount, businessDate, toBusinessDate } from '../sr
import { validateBackup } from '../src/backup';
import { RatesService } from '../src/rates';
import { Database } from '../src/database';
import { allowedOrigin } from '../src/auth';
test('development wildcard accepts HTTP origins while exact and production checks stay strict', () => {
assert.equal(allowedOrigin('https://tunnel.example', '*'), true);
assert.equal(allowedOrigin('http://example.test:8080', '*'), true);
for (const origin of [
undefined,
'null',
'file://host',
'https://example.test/path',
'https://name:secret@example.test',
])
assert.equal(allowedOrigin(origin, '*'), false);
assert.equal(allowedOrigin('https://tunnel.example', '*', true), false);
assert.equal(allowedOrigin('https://tunnel.example', 'http://localhost:5173'), false);
assert.equal(allowedOrigin('http://localhost:5173', 'http://localhost:5173'), true);
});
const rev = (amount: string, day: string) => ({
id: randomUUID(),
amount,
+3 -3
View File
@@ -6,7 +6,7 @@ import { PrismaClient } from '@prisma/client';
import { today } from '../src/validation';
import { readBackupZip } from '../src/zip';
const base = process.env.TEST_API_URL || 'http://127.0.0.1:3100/api',
origin = process.env.WEB_ORIGIN!;
origin = process.env.WEB_ORIGIN === '*' ? 'http://localhost:5173' : process.env.WEB_ORIGIN!;
test('real MySQL: authentication, isolation, history, backup and atomic failures', async () => {
const db = new PrismaClient(),
created: { id: string; username: string }[] = [];
@@ -53,10 +53,10 @@ test('real MySQL: authentication, isolation, history, backup and atomic failures
'Content-Type': 'application/json',
Origin: 'https://untrusted.invalid',
},
body: JSON.stringify({ baseCurrency: 'USD' }),
body: JSON.stringify({ showSidebar: true }),
})
).status,
403,
process.env.WEB_ORIGIN === '*' ? 200 : 403,
);
const make = async (
kind: string,
+6 -2
View File
@@ -12,7 +12,7 @@ test('privacy, minute history, backup-gated clear and idle sessions remain user
const res = await fetch(base + path, {
method,
headers: {
Origin: process.env.WEB_ORIGIN!,
Origin: process.env.WEB_ORIGIN === '*' ? 'http://localhost:5173' : process.env.WEB_ORIGIN!,
Cookie: cookie,
...(data ? { 'Content-Type': 'application/json' } : {}),
},
@@ -131,7 +131,11 @@ test('privacy, minute history, backup-gated clear and idle sessions remain user
form.append('file', new Blob([content]), 'backup.zip');
const res = await fetch(base + '/backup/upload', {
method: 'POST',
headers: { Origin: process.env.WEB_ORIGIN!, Cookie: cookie },
headers: {
Origin:
process.env.WEB_ORIGIN === '*' ? 'http://localhost:5173' : process.env.WEB_ORIGIN!,
Cookie: cookie,
},
body: form,
});
return { status: res.status, data: await res.json() };