2015-10-04 14:58:00 -07:00
|
|
|
package main
|
|
|
|
|
|
|
|
import (
|
|
|
|
"net/http"
|
|
|
|
"net/http/httptest"
|
2015-10-07 03:00:03 -04:00
|
|
|
"os"
|
|
|
|
"path"
|
2015-10-04 14:58:00 -07:00
|
|
|
"testing"
|
|
|
|
|
|
|
|
"github.com/zenazn/goji"
|
|
|
|
)
|
|
|
|
|
|
|
|
var testCSPHeaders = map[string]string{
|
|
|
|
"Content-Security-Policy": "default-src 'none'; style-src 'self';",
|
|
|
|
"X-Frame-Options": "SAMEORIGIN",
|
|
|
|
}
|
|
|
|
|
|
|
|
func TestContentSecurityPolicy(t *testing.T) {
|
2015-10-07 03:00:03 -04:00
|
|
|
Config.siteURL = "http://linx.example.org/"
|
|
|
|
Config.filesDir = path.Join(os.TempDir(), generateBarename())
|
|
|
|
Config.metaDir = Config.filesDir + "_meta"
|
2015-10-08 01:38:50 -04:00
|
|
|
Config.maxSize = 1024 * 1024 * 1024
|
2015-10-07 03:00:03 -04:00
|
|
|
Config.noLogs = true
|
|
|
|
Config.siteName = "linx"
|
|
|
|
Config.contentSecurityPolicy = "default-src 'none'; style-src 'self';"
|
|
|
|
Config.xFrameOptions = "SAMEORIGIN"
|
2015-10-10 11:17:38 -04:00
|
|
|
mux := setup()
|
2015-10-07 03:00:03 -04:00
|
|
|
|
2015-10-04 14:58:00 -07:00
|
|
|
w := httptest.NewRecorder()
|
|
|
|
|
|
|
|
req, err := http.NewRequest("GET", "/", nil)
|
|
|
|
if err != nil {
|
|
|
|
t.Fatal(err)
|
|
|
|
}
|
|
|
|
|
|
|
|
goji.Use(ContentSecurityPolicy(CSPOptions{
|
|
|
|
policy: testCSPHeaders["Content-Security-Policy"],
|
|
|
|
frame: testCSPHeaders["X-Frame-Options"],
|
|
|
|
}))
|
|
|
|
|
2015-10-10 11:17:38 -04:00
|
|
|
mux.ServeHTTP(w, req)
|
2015-10-04 14:58:00 -07:00
|
|
|
|
|
|
|
for k, v := range testCSPHeaders {
|
|
|
|
if w.HeaderMap[k][0] != v {
|
|
|
|
t.Fatalf("%s header did not match expected value set by middleware", k)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|