e2e/security_test.go

v1.22.0
gitbay/e2e/security_test.go history · blame · raw

47 lines · 1351 bytes

 1package e2e
 2
 3import (
 4	"net/http"
 5	"strings"
 6	"testing"
 7)
 8
 9func TestSecurityHeaders(t *testing.T) {
10	inst := startInstance(t)
11	aliceKey := inst.newKey(t, "alice")
12	inst.admin(t, "admin", "user", "create", "alice", "--key", aliceKey+".pub")
13	inst.ssh(t, aliceKey, "", "repo", "create", "alice/app")
14
15	resp, err := http.Get(inst.base() + "/")
16	if err != nil {
17		t.Fatal(err)
18	}
19	resp.Body.Close()
20	h := resp.Header
21	csp := h.Get("Content-Security-Policy")
22	for _, want := range []string{"script-src 'none'", "frame-ancestors 'none'", "object-src 'none'"} {
23		if !strings.Contains(csp, want) {
24			t.Errorf("CSP missing %q: %s", want, csp)
25		}
26	}
27	if h.Get("X-Frame-Options") != "DENY" {
28		t.Errorf("X-Frame-Options = %q", h.Get("X-Frame-Options"))
29	}
30	if h.Get("X-Content-Type-Options") != "nosniff" {
31		t.Errorf("nosniff missing")
32	}
33	if h.Get("Referrer-Policy") != "no-referrer" {
34		t.Errorf("Referrer-Policy = %q", h.Get("Referrer-Policy"))
35	}
36	// TLS is off in tests, so HSTS must NOT be set (it would poison
37	// plain-HTTP clients).
38	if h.Get("Strict-Transport-Security") != "" {
39		t.Errorf("HSTS set without TLS")
40	}
41	// Headers are present on repo pages too, not just the root.
42	resp2, _ := http.Get(inst.base() + "/alice/app")
43	resp2.Body.Close()
44	if resp2.Header.Get("Content-Security-Policy") == "" {
45		t.Error("CSP missing on repo page")
46	}
47}