Skip to content
File

Blob: tests/worker/lib/origins.test.ts

typescript67 lines
1import { describe, expect, it } from "vitest";
2 
3import { getAllowedOrigins, isAllowedOrigin } from "@/worker/lib/origins";
4 
5function createEnv(value?: string): Pick<Env, "ALLOWED_ORIGINS"> {
6 return { ALLOWED_ORIGINS: value as Env["ALLOWED_ORIGINS"] };
7}
8 
9describe("worker origins", () => {
10 it("parses, trims, normalizes, and deduplicates configured origins", () => {
11 const env = createEnv(
12 " https://bland.tools , https://bland.tools/ , http://localhost:5173/ , https://staging.bland.tools ",
13 );
14 
15 expect(getAllowedOrigins(env)).toEqual([
16 "https://bland.tools",
17 "http://localhost:5173",
18 "https://staging.bland.tools",
19 ]);
20 });
21 
22 it("rejects a missing allowlist", () => {
23 expect(() => getAllowedOrigins(createEnv())).toThrow(/ALLOWED_ORIGINS/);
24 });
25 
26 it("rejects an empty allowlist", () => {
27 expect(() => getAllowedOrigins(createEnv(" , "))).toThrow(/ALLOWED_ORIGINS/);
28 });
29 
30 it("rejects malformed configured origins", () => {
31 expect(() => getAllowedOrigins(createEnv("not-a-url"))).toThrow(/ALLOWED_ORIGINS/);
32 });
33 
34 it("rejects non-http origins", () => {
35 expect(() => getAllowedOrigins(createEnv("ftp://bland.tools"))).toThrow(/ALLOWED_ORIGINS/);
36 });
37 
38 it("allows configured deployed origins", () => {
39 const env = createEnv("https://bland.tools,https://staging.bland.tools");
40 
41 expect(isAllowedOrigin("https://bland.tools", env)).toBe(true);
42 expect(isAllowedOrigin("https://staging.bland.tools", env)).toBe(true);
43 });
44 
45 it("allows explicitly configured local origins", () => {
46 const env = createEnv("http://localhost:5173,http://127.0.0.1:5173");
47 
48 expect(isAllowedOrigin("http://localhost:5173", env)).toBe(true);
49 expect(isAllowedOrigin("http://127.0.0.1:5173", env)).toBe(true);
50 });
51 
52 it("rejects unlisted local origins", () => {
53 const env = createEnv("http://localhost:5173");
54 
55 expect(isAllowedOrigin("http://127.0.0.1:5173", env)).toBe(false);
56 expect(isAllowedOrigin("http://0.0.0.0:5173", env)).toBe(false);
57 });
58 
59 it("rejects unrelated and malformed request origins", () => {
60 const env = createEnv("https://bland.tools");
61 
62 expect(isAllowedOrigin("https://example.com", env)).toBe(false);
63 expect(isAllowedOrigin("not-a-url", env)).toBe(false);
64 expect(isAllowedOrigin(null, env)).toBe(false);
65 });
66});