Skip to content
File

Blob: worker/dev/hosts.test.ts

typescript42 lines
1import assert from 'node:assert/strict';
2import { test } from 'node:test';
3import { allowedProxyRequest, developmentHosts } from './hosts.ts';
4 
5test('phone hosts are explicit and shared with the proxy', () => {
6 const defaults = developmentHosts();
7 assert.equal(allowedProxyRequest('192.168.1.20:11880', undefined, undefined, defaults), false);
8 const hosts = developmentHosts('radio.local,192.168.1.20,radio.local');
9 assert.equal(hosts.filter((host) => host === 'radio.local').length, 1);
10 assert.equal(
11 allowedProxyRequest('radio.local:11880', 'http://radio.local:11880', 'same-origin', hosts),
12 true,
13 );
14 assert.equal(allowedProxyRequest('192.168.1.20:11880', undefined, undefined, hosts), true);
15 assert.equal(allowedProxyRequest('[::1]:11880', undefined, undefined, hosts), true);
16});
17 
18test('cross-origin requests stay blocked for an allowed development host', () => {
19 const hosts = developmentHosts('radio.local');
20 assert.equal(
21 allowedProxyRequest('radio.local:11880', 'http://untrusted.example', undefined, hosts),
22 false,
23 );
24 assert.equal(allowedProxyRequest('radio.local:11880', undefined, 'cross-site', hosts), false);
25 assert.equal(allowedProxyRequest('untrusted.example:11880', undefined, undefined, hosts), false);
26});
27 
28test('development host configuration cannot broaden into URLs or wildcard domains', () => {
29 for (const host of [
30 'https://radio.local',
31 'radio.local:11880',
32 '.example.com',
33 '*',
34 'user@radio.local',
35 'radio.local/path',
36 'radio.local?query',
37 'radio.local#hash',
38 ]) {
39 assert.throws(() => developmentHosts(host));
40 }
41});