e2e/security_test.go
48 lines · 1365 bytes
1 symbol in this file
1package e2e
2
3import (
4 "net/http"
5 "strings"
6 "testing"
7)
8
9func TestSecurityHeaders(t *testing.T) {
10 t.Parallel()
11 inst := startInstance(t)
12 aliceKey := inst.newKey(t, "alice")
13 inst.admin(t, "admin", "user", "create", "alice", "--key", aliceKey+".pub")
14 inst.ssh(t, aliceKey, "", "repo", "create", "alice/app")
15
16 resp, err := http.Get(inst.base() + "/")
17 if err != nil {
18 t.Fatal(err)
19 }
20 resp.Body.Close()
21 h := resp.Header
22 csp := h.Get("Content-Security-Policy")
23 for _, want := range []string{"script-src 'none'", "frame-ancestors 'none'", "object-src 'none'"} {
24 if !strings.Contains(csp, want) {
25 t.Errorf("CSP missing %q: %s", want, csp)
26 }
27 }
28 if h.Get("X-Frame-Options") != "DENY" {
29 t.Errorf("X-Frame-Options = %q", h.Get("X-Frame-Options"))
30 }
31 if h.Get("X-Content-Type-Options") != "nosniff" {
32 t.Errorf("nosniff missing")
33 }
34 if h.Get("Referrer-Policy") != "no-referrer" {
35 t.Errorf("Referrer-Policy = %q", h.Get("Referrer-Policy"))
36 }
37 // TLS is off in tests, so HSTS must NOT be set (it would poison
38 // plain-HTTP clients).
39 if h.Get("Strict-Transport-Security") != "" {
40 t.Errorf("HSTS set without TLS")
41 }
42 // Headers are present on repo pages too, not just the root.
43 resp2, _ := http.Get(inst.base() + "/alice/app")
44 resp2.Body.Close()
45 if resp2.Header.Get("Content-Security-Policy") == "" {
46 t.Error("CSP missing on repo page")
47 }
48}