feat: allow wildcard web origins for local tunnel testing
This commit is contained in:
1 parent
2a650853ee
commit
e4f4ff42e1
9 files changed
+115
-70
No files matched your search
@@ -6,6 +6,22 @@ import { positionInput, date, amount, businessDate, toBusinessDate } from '../sr
|
||||
import { validateBackup } from '../src/backup';
|
||||
import { RatesService } from '../src/rates';
|
||||
import { Database } from '../src/database';
|
||||
import { allowedOrigin } from '../src/auth';
|
||||
test('development wildcard accepts HTTP origins while exact and production checks stay strict', () => {
|
||||
assert.equal(allowedOrigin('https://tunnel.example', '*'), true);
|
||||
assert.equal(allowedOrigin('http://example.test:8080', '*'), true);
|
||||
for (const origin of [
|
||||
undefined,
|
||||
'null',
|
||||
'file://host',
|
||||
'https://example.test/path',
|
||||
'https://name:secret@example.test',
|
||||
])
|
||||
assert.equal(allowedOrigin(origin, '*'), false);
|
||||
assert.equal(allowedOrigin('https://tunnel.example', '*', true), false);
|
||||
assert.equal(allowedOrigin('https://tunnel.example', 'http://localhost:5173'), false);
|
||||
assert.equal(allowedOrigin('http://localhost:5173', 'http://localhost:5173'), true);
|
||||
});
|
||||
const rev = (amount: string, day: string) => ({
|
||||
id: randomUUID(),
|
||||
amount,
|
||||
|
||||
@@ -6,7 +6,7 @@ import { PrismaClient } from '@prisma/client';
|
||||
import { today } from '../src/validation';
|
||||
import { readBackupZip } from '../src/zip';
|
||||
const base = process.env.TEST_API_URL || 'http://127.0.0.1:3100/api',
|
||||
origin = process.env.WEB_ORIGIN!;
|
||||
origin = process.env.WEB_ORIGIN === '*' ? 'http://localhost:5173' : process.env.WEB_ORIGIN!;
|
||||
test('real MySQL: authentication, isolation, history, backup and atomic failures', async () => {
|
||||
const db = new PrismaClient(),
|
||||
created: { id: string; username: string }[] = [];
|
||||
@@ -53,10 +53,10 @@ test('real MySQL: authentication, isolation, history, backup and atomic failures
|
||||
'Content-Type': 'application/json',
|
||||
Origin: 'https://untrusted.invalid',
|
||||
},
|
||||
body: JSON.stringify({ baseCurrency: 'USD' }),
|
||||
body: JSON.stringify({ showSidebar: true }),
|
||||
})
|
||||
).status,
|
||||
403,
|
||||
process.env.WEB_ORIGIN === '*' ? 200 : 403,
|
||||
);
|
||||
const make = async (
|
||||
kind: string,
|
||||
|
||||
@@ -12,7 +12,7 @@ test('privacy, minute history, backup-gated clear and idle sessions remain user
|
||||
const res = await fetch(base + path, {
|
||||
method,
|
||||
headers: {
|
||||
Origin: process.env.WEB_ORIGIN!,
|
||||
Origin: process.env.WEB_ORIGIN === '*' ? 'http://localhost:5173' : process.env.WEB_ORIGIN!,
|
||||
Cookie: cookie,
|
||||
...(data ? { 'Content-Type': 'application/json' } : {}),
|
||||
},
|
||||
@@ -131,7 +131,11 @@ test('privacy, minute history, backup-gated clear and idle sessions remain user
|
||||
form.append('file', new Blob([content]), 'backup.zip');
|
||||
const res = await fetch(base + '/backup/upload', {
|
||||
method: 'POST',
|
||||
headers: { Origin: process.env.WEB_ORIGIN!, Cookie: cookie },
|
||||
headers: {
|
||||
Origin:
|
||||
process.env.WEB_ORIGIN === '*' ? 'http://localhost:5173' : process.env.WEB_ORIGIN!,
|
||||
Cookie: cookie,
|
||||
},
|
||||
body: form,
|
||||
});
|
||||
return { status: res.status, data: await res.json() };
|
||||
|
||||
Reference in new issue
Block a user