File
Blob: worker/tests/runtime/access.test.ts
| 1 | import { expect, test } from 'vitest'; |
| 2 | import { createHarness } from './harness.ts'; |
| 3 | |
| 4 | test('access requires authentication, bounded bodies and a matching origin', async () => { |
| 5 | const h = await createHarness(); |
| 6 | expect((await h.call('/status')).status).toBe(401); |
| 7 | expect((await h.call('/device/start', {})).status).toBe(401); |
| 8 | expect((await h.call('/login', { password: 'incorrect' })).status).toBe(401); |
| 9 | expect((await h.call('/login', ' '.repeat(20001))).status).toBe(413); |
| 10 | expect( |
| 11 | ( |
| 12 | await h.call( |
| 13 | '/login', |
| 14 | { password: 'test-viewer-password' }, |
| 15 | { Origin: 'https://untrusted.example' }, |
| 16 | ) |
| 17 | ).status, |
| 18 | ).toBe(403); |
| 19 | const cookie = await h.login(); |
| 20 | expect( |
| 21 | cookie.includes('HttpOnly') && cookie.includes('Secure') && cookie.includes('SameSite=Strict'), |
| 22 | ).toBeTruthy(); |
| 23 | expect((await h.call('/status')).status).toBe(200); |
| 24 | await h.start(); |
| 25 | const viewer = await h.viewer(); |
| 26 | expect( |
| 27 | (await h.call(`/viewers/${viewer.id}/claim`, {}, { 'X-Viewer-Token': 'wrong-token' })).status, |
| 28 | ).toBe(403); |
| 29 | expect((await h.call(`/viewers/${viewer.id}/claim`, {}, viewer.owner)).status).toBe(200); |
| 30 | }); |