File
Blob: tests/worker/lib/origins.test.ts
| 1 | import { describe, expect, it } from "vitest"; |
| 2 | |
| 3 | import { getAllowedOrigins, isAllowedOrigin } from "@/worker/lib/origins"; |
| 4 | |
| 5 | function createEnv(value?: string): Pick<Env, "ALLOWED_ORIGINS"> { |
| 6 | return { ALLOWED_ORIGINS: value as Env["ALLOWED_ORIGINS"] }; |
| 7 | } |
| 8 | |
| 9 | describe("worker origins", () => { |
| 10 | it("parses, trims, normalizes, and deduplicates configured origins", () => { |
| 11 | const env = createEnv( |
| 12 | " https://bland.tools , https://bland.tools/ , http://localhost:5173/ , https://staging.bland.tools ", |
| 13 | ); |
| 14 | |
| 15 | expect(getAllowedOrigins(env)).toEqual([ |
| 16 | "https://bland.tools", |
| 17 | "http://localhost:5173", |
| 18 | "https://staging.bland.tools", |
| 19 | ]); |
| 20 | }); |
| 21 | |
| 22 | it("rejects a missing allowlist", () => { |
| 23 | expect(() => getAllowedOrigins(createEnv())).toThrow(/ALLOWED_ORIGINS/); |
| 24 | }); |
| 25 | |
| 26 | it("rejects an empty allowlist", () => { |
| 27 | expect(() => getAllowedOrigins(createEnv(" , "))).toThrow(/ALLOWED_ORIGINS/); |
| 28 | }); |
| 29 | |
| 30 | it("rejects malformed configured origins", () => { |
| 31 | expect(() => getAllowedOrigins(createEnv("not-a-url"))).toThrow(/ALLOWED_ORIGINS/); |
| 32 | }); |
| 33 | |
| 34 | it("rejects non-http origins", () => { |
| 35 | expect(() => getAllowedOrigins(createEnv("ftp://bland.tools"))).toThrow(/ALLOWED_ORIGINS/); |
| 36 | }); |
| 37 | |
| 38 | it("allows configured deployed origins", () => { |
| 39 | const env = createEnv("https://bland.tools,https://staging.bland.tools"); |
| 40 | |
| 41 | expect(isAllowedOrigin("https://bland.tools", env)).toBe(true); |
| 42 | expect(isAllowedOrigin("https://staging.bland.tools", env)).toBe(true); |
| 43 | }); |
| 44 | |
| 45 | it("allows explicitly configured local origins", () => { |
| 46 | const env = createEnv("http://localhost:5173,http://127.0.0.1:5173"); |
| 47 | |
| 48 | expect(isAllowedOrigin("http://localhost:5173", env)).toBe(true); |
| 49 | expect(isAllowedOrigin("http://127.0.0.1:5173", env)).toBe(true); |
| 50 | }); |
| 51 | |
| 52 | it("rejects unlisted local origins", () => { |
| 53 | const env = createEnv("http://localhost:5173"); |
| 54 | |
| 55 | expect(isAllowedOrigin("http://127.0.0.1:5173", env)).toBe(false); |
| 56 | expect(isAllowedOrigin("http://0.0.0.0:5173", env)).toBe(false); |
| 57 | }); |
| 58 | |
| 59 | it("rejects unrelated and malformed request origins", () => { |
| 60 | const env = createEnv("https://bland.tools"); |
| 61 | |
| 62 | expect(isAllowedOrigin("https://example.com", env)).toBe(false); |
| 63 | expect(isAllowedOrigin("not-a-url", env)).toBe(false); |
| 64 | expect(isAllowedOrigin(null, env)).toBe(false); |
| 65 | }); |
| 66 | }); |