fix: tighten edge cases across services (#3158)

This commit is contained in:
Hampus
2026-10-03 13:04:29 +02:00
committed by GitHub
parent a9f7a23c0d
commit 4e6b837ccc
170 changed files with 2028 additions and 421 deletions
+3 -3
View File
@@ -251,7 +251,7 @@ mod tests {
}
#[test]
fn shipped_shell_carries_no_nonce_attribute_or_placeholder() {
fn shipped_shell_has_no_nonce_attribute_or_placeholder() {
assert!(!SHIPPED_APP_SHELL.contains("nonce"));
assert!(!SHIPPED_APP_SHELL.contains("{{CSP_NONCE_PLACEHOLDER}}"));
}
@@ -375,7 +375,7 @@ mod tests {
}
#[test]
fn media_preconnect_carries_no_crossorigin_attribute() {
fn media_preconnect_has_no_crossorigin_attribute() {
assert!(!MEDIA_PRECONNECT_TAG.contains("crossorigin"));
}
@@ -464,7 +464,7 @@ mod tests {
}
#[test]
fn a_configured_endpoint_that_already_carries_a_port_is_left_alone() {
fn a_configured_endpoint_that_already_has_a_port_is_left_alone() {
let discovery = discovery_offering("https://chat.example.test:8443/api");
assert_eq!(
api_public_endpoint(Some("https://chat.example.test:9443/api"), &discovery),
+1 -1
View File
@@ -707,7 +707,7 @@ mod tests {
}
#[test]
fn the_boot_html_api_endpoint_keeps_a_port_it_already_carries() {
fn the_boot_html_api_endpoint_keeps_a_port_it_already_has() {
assert_eq!(
resolve_bootstrap_endpoint_from_pairs(&[
(
+10 -10
View File
@@ -613,7 +613,7 @@ mod tests {
}
#[tokio::test]
async fn a_not_found_carrying_a_long_upstream_lifetime_is_rewritten_to_no_store() {
async fn a_not_found_with_a_long_upstream_lifetime_is_rewritten_to_no_store() {
let response = proxied_asset(
StatusCode::NOT_FOUND,
"public, max-age=31536000, immutable",
@@ -630,7 +630,7 @@ mod tests {
}
#[tokio::test]
async fn a_bad_gateway_carrying_a_long_upstream_lifetime_is_rewritten_to_no_store() {
async fn a_bad_gateway_with_a_long_upstream_lifetime_is_rewritten_to_no_store() {
let response = proxied_asset(
StatusCode::BAD_GATEWAY,
"public, max-age=604800",
@@ -646,7 +646,7 @@ mod tests {
}
#[tokio::test]
async fn a_server_error_carrying_a_long_upstream_lifetime_is_rewritten_to_no_store() {
async fn a_server_error_with_a_long_upstream_lifetime_is_rewritten_to_no_store() {
let response = proxied_asset(
StatusCode::INTERNAL_SERVER_ERROR,
"public, max-age=86400, immutable",
@@ -779,7 +779,7 @@ mod tests {
)
.await;
assert_eq!(cors_origin_of(&first), Some(CORS_ALLOW_ANY_VALUE));
let entity_tag = entity_tag_of(&first).expect("first response carries a validator");
let entity_tag = entity_tag_of(&first).expect("first response has a validator");
let mut conditional = HeaderMap::new();
conditional.insert(
@@ -875,7 +875,7 @@ mod tests {
test_asset_csp(),
)
.await;
let entity_tag = entity_tag_of(&first).expect("first response carries a validator");
let entity_tag = entity_tag_of(&first).expect("first response has a validator");
let mut conditional = HeaderMap::new();
conditional.insert(
@@ -1083,7 +1083,7 @@ mod tests {
}
#[tokio::test]
async fn a_precompressed_variant_carries_its_own_validator() {
async fn a_precompressed_variant_has_its_own_validator() {
let fixture = LocalAssetDir::with_asset("f00dcafe12345678.css", b"body{}")
.and_sibling("f00dcafe12345678.css.br", b"brotli-bytes-are-longer");
@@ -1095,7 +1095,7 @@ mod tests {
test_asset_csp(),
)
.await;
let brotli_tag = entity_tag_of(&brotli).expect("the brotli variant carries a validator");
let brotli_tag = entity_tag_of(&brotli).expect("the brotli variant has a validator");
let identity = serve_local_asset(
&budgets(),
@@ -1105,7 +1105,7 @@ mod tests {
test_asset_csp(),
)
.await;
let identity_tag = entity_tag_of(&identity).expect("the raw file carries a validator");
let identity_tag = entity_tag_of(&identity).expect("the raw file has a validator");
assert_ne!(
brotli_tag, identity_tag,
@@ -1305,7 +1305,7 @@ mod tests {
assert_eq!(
body_bytes(response).await,
b"already brotli, and long enough to clear the thirty-two byte floor",
"re-encoding upstream bytes that already carry an encoding breaks every browser"
"re-encoding upstream bytes that already have an encoding breaks every browser"
);
}
@@ -1536,7 +1536,7 @@ mod tests {
assert_eq!(
body.as_ref(),
b"console.log(1)",
"a response served past the read slot count carried the wrong bytes"
"a response served past the read slot count had the wrong bytes"
);
}
}
+6 -6
View File
@@ -687,7 +687,7 @@ mod tests {
const SHELL_WITH_AN_INLINE_SCRIPT: &str = r#"<!doctype html><html><head><title>Fluxer</title><script>inline()</script><script src="/assets/app.js"></script></head><body></body></html>"#;
#[test]
fn the_rendered_document_always_carries_the_bootstrap() {
fn the_rendered_document_always_includes_the_bootstrap() {
let rendered = render_spa_document(
SHELL_WITH_AN_INLINE_SCRIPT,
"<script>booted</script>",
@@ -732,7 +732,7 @@ mod tests {
<link rel="icon" type="image/png" sizes="32x32" href="{{STATIC_CDN_ENDPOINT}}/web/favicon-32x32.png"><link rel="apple-touch-icon" sizes="180x180" href="{{STATIC_CDN_ENDPOINT}}/web/apple-touch-icon.png"><script>inline()</script><script src="/assets/app.js"></script></head><body></body></html>"#;
#[test]
fn the_static_cdn_argument_resolves_every_hole_the_shell_carries() {
fn the_static_cdn_argument_resolves_every_hole_the_shell_has() {
let rendered = render_spa_document(
SHELL_WITH_ENDPOINT_HOLES,
"<script>booted</script>",
@@ -1069,13 +1069,13 @@ mod tests {
let tag = &tag[..tag.find('>').unwrap()];
assert!(
tag.is_empty() || tag.contains(" src="),
"the served document carries a script tag the test cannot classify: <script{tag}>"
"the served document has a script tag the test cannot classify: <script{tag}>"
);
}
let inline = bare_inline_scripts_in(document);
assert!(
!inline.is_empty(),
"the served document carries no inline script at all"
"the served document has no inline script at all"
);
let mut expected: Vec<String> = inline.iter().map(|script| sha256_source(script)).collect();
expected.sort();
@@ -1084,7 +1084,7 @@ mod tests {
granted.sort();
assert_eq!(
granted, expected,
"the policy must grant exactly the inline scripts the document carries"
"the policy must grant exactly the inline scripts the document contains"
);
assert!(!document.contains("nonce"));
assert!(!policy.contains("nonce"));
@@ -1437,7 +1437,7 @@ mod tests {
}
#[tokio::test]
async fn the_shipped_shell_runs_every_inline_script_it_carries_under_its_policy() {
async fn the_shipped_shell_runs_every_inline_script_it_contains_under_its_policy() {
let state = spa_state_serving(ReleaseChannel::Stable, Some(SHIPPED_APP_SHELL)).await;
let response = serve_spa_index(&state, &HeaderMap::new()).await;