diff options
Diffstat (limited to 'internal/web/web_test.go')
| -rw-r--r-- | internal/web/web_test.go | 28 |
1 files changed, 28 insertions, 0 deletions
diff --git a/internal/web/web_test.go b/internal/web/web_test.go index 49915f4..42d3b3a 100644 --- a/internal/web/web_test.go +++ b/internal/web/web_test.go @@ -975,3 +975,31 @@ func TestLoginBodyCapped(t *testing.T) { t.Errorf("got %d, want 400", rec.Code) } } + +// With HTTPS on, links are https, the cookie is Secure and HSTS is sent; with TRUST_PROXY the client is the last X-Forwarded-For hop. +func TestHTTPSAndTrustProxy(t *testing.T) { + cfg := &config.Config{BaseDomain: "example.com", JWTSecret: []byte("x"), HTTPS: true, TrustProxy: true} + if cfg.RootURL() != "https://example.com" || cfg.BlogURL("a") != "https://a.example.com" { + t.Errorf("urls: %s %s", cfg.RootURL(), cfg.BlogURL("a")) + } + s := NewServer(cfg, nil) + rec := httptest.NewRecorder() + req := httptest.NewRequest("GET", "/webadmin", nil) + req.Host = "example.com" + req.AddCookie(&http.Cookie{Name: "session", Value: "garbage"}) // a bad cookie is cleared, with Secure + req.Header.Set("X-Forwarded-For", "203.0.113.9, 10.0.0.2") + s.ServeHTTP(rec, req) + if h := rec.Header().Get("Strict-Transport-Security"); !strings.Contains(h, "includeSubDomains") { + t.Errorf("HSTS = %q", h) + } + if c := rec.Header().Get("Set-Cookie"); !strings.Contains(c, "Secure") || !strings.Contains(c, "Max-Age=0") { + t.Errorf("cleared cookie = %q", c) + } + if ip := s.clientIP(req); ip != "10.0.0.2" { + t.Errorf("clientIP = %q, want the last hop", ip) + } + cfg.TrustProxy = false + if ip := s.clientIP(req); ip != "192.0.2.1" { + t.Errorf("clientIP without TRUST_PROXY = %q, want the peer", ip) + } +} |
