File
Blob: worker/dev/hosts.test.ts
| 1 | import assert from 'node:assert/strict'; |
| 2 | import { test } from 'node:test'; |
| 3 | import { allowedProxyRequest, developmentHosts } from './hosts.ts'; |
| 4 | |
| 5 | test('phone hosts are explicit and shared with the proxy', () => { |
| 6 | const defaults = developmentHosts(); |
| 7 | assert.equal(allowedProxyRequest('192.168.1.20:11880', undefined, undefined, defaults), false); |
| 8 | const hosts = developmentHosts('radio.local,192.168.1.20,radio.local'); |
| 9 | assert.equal(hosts.filter((host) => host === 'radio.local').length, 1); |
| 10 | assert.equal( |
| 11 | allowedProxyRequest('radio.local:11880', 'http://radio.local:11880', 'same-origin', hosts), |
| 12 | true, |
| 13 | ); |
| 14 | assert.equal(allowedProxyRequest('192.168.1.20:11880', undefined, undefined, hosts), true); |
| 15 | assert.equal(allowedProxyRequest('[::1]:11880', undefined, undefined, hosts), true); |
| 16 | }); |
| 17 | |
| 18 | test('cross-origin requests stay blocked for an allowed development host', () => { |
| 19 | const hosts = developmentHosts('radio.local'); |
| 20 | assert.equal( |
| 21 | allowedProxyRequest('radio.local:11880', 'http://untrusted.example', undefined, hosts), |
| 22 | false, |
| 23 | ); |
| 24 | assert.equal(allowedProxyRequest('radio.local:11880', undefined, 'cross-site', hosts), false); |
| 25 | assert.equal(allowedProxyRequest('untrusted.example:11880', undefined, undefined, hosts), false); |
| 26 | }); |
| 27 | |
| 28 | test('development host configuration cannot broaden into URLs or wildcard domains', () => { |
| 29 | for (const host of [ |
| 30 | 'https://radio.local', |
| 31 | 'radio.local:11880', |
| 32 | '.example.com', |
| 33 | '*', |
| 34 | 'user@radio.local', |
| 35 | 'radio.local/path', |
| 36 | 'radio.local?query', |
| 37 | 'radio.local#hash', |
| 38 | ]) { |
| 39 | assert.throws(() => developmentHosts(host)); |
| 40 | } |
| 41 | }); |