mirror of
https://github.com/warmbly/warmbly.git
synced 2026-10-08 08:02:13 +00:00
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
33 lines
1.0 KiB
Go
33 lines
1.0 KiB
Go
package middleware
|
|
|
|
import (
|
|
"net/http"
|
|
"net/http/httptest"
|
|
"testing"
|
|
|
|
"github.com/gin-gonic/gin"
|
|
"github.com/warmbly/warmbly/internal/config"
|
|
)
|
|
|
|
func TestDashboardOriginMiddleware(t *testing.T) {
|
|
t.Setenv("APP_URL", "https://app.warmbly.com")
|
|
t.Setenv("APP_ORIGIN", "")
|
|
t.Setenv("CORS_ALLOW_ORIGINS", "https://tac-security-assessment.warmbly.com")
|
|
r := gin.New()
|
|
r.Use(DashboardOriginMiddleware())
|
|
r.GET("/", func(c *gin.Context) { c.String(http.StatusOK, config.DashboardBaseURL(c.Request.Context())) })
|
|
for _, tt := range []struct{ origin, want string }{
|
|
{"https://tac-security-assessment.warmbly.com", "https://tac-security-assessment.warmbly.com"},
|
|
{"https://evil.example.com", "https://app.warmbly.com"},
|
|
{"", "https://app.warmbly.com"},
|
|
} {
|
|
req := httptest.NewRequest(http.MethodGet, "/", nil)
|
|
req.Header.Set("Origin", tt.origin)
|
|
w := httptest.NewRecorder()
|
|
r.ServeHTTP(w, req)
|
|
if w.Body.String() != tt.want {
|
|
t.Errorf("request origin %q returned %q", tt.origin, w.Body.String())
|
|
}
|
|
}
|
|
}
|