e2e/security_test.go

v1.43.0
gitbay/e2e/security_test.go history · blame · raw

48 lines · 1365 bytes

 1package e2e
 2
 3import (
 4	"net/http"
 5	"strings"
 6	"testing"
 7)
 8
 9func TestSecurityHeaders(t *testing.T) {
10	t.Parallel()
11	inst := startInstance(t)
12	aliceKey := inst.newKey(t, "alice")
13	inst.admin(t, "admin", "user", "create", "alice", "--key", aliceKey+".pub")
14	inst.ssh(t, aliceKey, "", "repo", "create", "alice/app")
15
16	resp, err := http.Get(inst.base() + "/")
17	if err != nil {
18		t.Fatal(err)
19	}
20	resp.Body.Close()
21	h := resp.Header
22	csp := h.Get("Content-Security-Policy")
23	for _, want := range []string{"script-src 'none'", "frame-ancestors 'none'", "object-src 'none'"} {
24		if !strings.Contains(csp, want) {
25			t.Errorf("CSP missing %q: %s", want, csp)
26		}
27	}
28	if h.Get("X-Frame-Options") != "DENY" {
29		t.Errorf("X-Frame-Options = %q", h.Get("X-Frame-Options"))
30	}
31	if h.Get("X-Content-Type-Options") != "nosniff" {
32		t.Errorf("nosniff missing")
33	}
34	if h.Get("Referrer-Policy") != "no-referrer" {
35		t.Errorf("Referrer-Policy = %q", h.Get("Referrer-Policy"))
36	}
37	// TLS is off in tests, so HSTS must NOT be set (it would poison
38	// plain-HTTP clients).
39	if h.Get("Strict-Transport-Security") != "" {
40		t.Errorf("HSTS set without TLS")
41	}
42	// Headers are present on repo pages too, not just the root.
43	resp2, _ := http.Get(inst.base() + "/alice/app")
44	resp2.Body.Close()
45	if resp2.Header.Get("Content-Security-Policy") == "" {
46		t.Error("CSP missing on repo page")
47	}
48}