e2e/security_test.go
47 lines · 1351 bytes
1package e2e
2
3import (
4 "net/http"
5 "strings"
6 "testing"
7)
8
9func TestSecurityHeaders(t *testing.T) {
10 inst := startInstance(t)
11 aliceKey := inst.newKey(t, "alice")
12 inst.admin(t, "admin", "user", "create", "alice", "--key", aliceKey+".pub")
13 inst.ssh(t, aliceKey, "", "repo", "create", "alice/app")
14
15 resp, err := http.Get(inst.base() + "/")
16 if err != nil {
17 t.Fatal(err)
18 }
19 resp.Body.Close()
20 h := resp.Header
21 csp := h.Get("Content-Security-Policy")
22 for _, want := range []string{"script-src 'none'", "frame-ancestors 'none'", "object-src 'none'"} {
23 if !strings.Contains(csp, want) {
24 t.Errorf("CSP missing %q: %s", want, csp)
25 }
26 }
27 if h.Get("X-Frame-Options") != "DENY" {
28 t.Errorf("X-Frame-Options = %q", h.Get("X-Frame-Options"))
29 }
30 if h.Get("X-Content-Type-Options") != "nosniff" {
31 t.Errorf("nosniff missing")
32 }
33 if h.Get("Referrer-Policy") != "no-referrer" {
34 t.Errorf("Referrer-Policy = %q", h.Get("Referrer-Policy"))
35 }
36 // TLS is off in tests, so HSTS must NOT be set (it would poison
37 // plain-HTTP clients).
38 if h.Get("Strict-Transport-Security") != "" {
39 t.Errorf("HSTS set without TLS")
40 }
41 // Headers are present on repo pages too, not just the root.
42 resp2, _ := http.Get(inst.base() + "/alice/app")
43 resp2.Body.Close()
44 if resp2.Header.Get("Content-Security-Policy") == "" {
45 t.Error("CSP missing on repo page")
46 }
47}