aboutsummaryrefslogtreecommitdiffstats
path: root/internal/web/web_test.go
diff options
context:
space:
mode:
authorgrm <grm@eyesin.space>2026-09-12 12:15:47 +0300
committergrm <grm@eyesin.space>2026-09-12 12:15:47 +0300
commit3073532f723b976a2f54666f779e9a045bacb7f6 (patch)
tree442181bd2b5ac48a2ec5621203f81e64cb1769c5 /internal/web/web_test.go
parentf82c2256d619e92cf0e928deb3b23b735071aaf3 (diff)
downloadblogspace-3073532f723b976a2f54666f779e9a045bacb7f6.tar.gz
blogspace-3073532f723b976a2f54666f779e9a045bacb7f6.tar.bz2
blogspace-3073532f723b976a2f54666f779e9a045bacb7f6.zip
Rename /login to /webadmin and reach it from every blog
The login URL is less guessable, bloggers can type /webadmin on their own blog and get bounced to the root login page (and back to their dashboard after logging in), and the public root blog no longer advertises the admin entry point in its footer. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Sd8UPWrvyYCLj97JexNw3A
Diffstat (limited to 'internal/web/web_test.go')
-rw-r--r--internal/web/web_test.go23
1 files changed, 18 insertions, 5 deletions
diff --git a/internal/web/web_test.go b/internal/web/web_test.go
index dcd766c..6e53bae 100644
--- a/internal/web/web_test.go
+++ b/internal/web/web_test.go
@@ -32,14 +32,14 @@ func TestHostRoutingWithoutDB(t *testing.T) {
t.Errorf("host %q: got %d, want 404", host, rec.Code)
}
}
- // root domain (and www) reach the management mux: /login renders without DB access
+ // root domain (and www) reach the management mux: /webadmin renders without DB access
for _, host := range []string{"example.com", "www.example.com", "example.com:8080"} {
rec := httptest.NewRecorder()
- req := httptest.NewRequest("GET", "/login", nil)
+ req := httptest.NewRequest("GET", "/webadmin", nil)
req.Host = host
s.ServeHTTP(rec, req)
if rec.Code != http.StatusOK || !strings.Contains(rec.Body.String(), "Log in") {
- t.Errorf("host %q /login: got %d", host, rec.Code)
+ t.Errorf("host %q /webadmin: got %d", host, rec.Code)
}
}
}
@@ -48,7 +48,7 @@ func TestHostRoutingWithoutDB(t *testing.T) {
func TestRootRoutePrecedence(t *testing.T) {
cfg := &config.Config{BaseDomain: "example.com", JWTSecret: []byte("x"), MaxUploadBytes: 1 << 20}
s := NewServer(cfg, nil)
- for path, want := range map[string]int{"/login": 200, "/healthz": 200, "/dashboard": 303, "/admin/": 303, "/b/alice/posts": 303, "/account/password": 303} {
+ for path, want := range map[string]int{"/webadmin": 200, "/healthz": 200, "/dashboard": 303, "/admin/": 303, "/b/alice/posts": 303, "/account/password": 303} {
rec := httptest.NewRecorder()
req := httptest.NewRequest("GET", path, nil)
req.Host = "example.com"
@@ -57,7 +57,7 @@ func TestRootRoutePrecedence(t *testing.T) {
t.Errorf("%s: got %d, want %d", path, rec.Code, want)
}
}
- for _, slug := range []string{"login", "admin", "b", "media", "feed.xml"} {
+ for _, slug := range []string{"webadmin", "admin", "b", "media", "feed.xml"} {
if !reservedPageSlugs[slug] {
t.Errorf("page slug %q should be reserved", slug)
}
@@ -91,3 +91,16 @@ func TestAllTemplatesParse(t *testing.T) {
}
}
}
+
+// /webadmin on a blog's own host bounces to the root login page and back to that blog's dashboard.
+func TestSubdomainWebadminRedirect(t *testing.T) {
+ cfg := &config.Config{BaseDomain: "example.com", JWTSecret: []byte("x"), MaxUploadBytes: 1 << 20}
+ s := NewServer(cfg, nil)
+ rec := httptest.NewRecorder()
+ req := httptest.NewRequest("GET", "/webadmin", nil)
+ req.Host = "alice.example.com"
+ s.ServeHTTP(rec, req)
+ if want := "http://example.com/webadmin?next=%2Fb%2Falice%2F"; rec.Code != http.StatusSeeOther || rec.Header().Get("Location") != want {
+ t.Errorf("got %d %q, want 303 %q", rec.Code, rec.Header().Get("Location"), want)
+ }
+}