Skip to content
File

Blob: worker/tests/runtime/access.test.ts

typescript31 lines
1import { expect, test } from 'vitest';
2import { createHarness } from './harness.ts';
3 
4test('access requires authentication, bounded bodies and a matching origin', async () => {
5 const h = await createHarness();
6 expect((await h.call('/status')).status).toBe(401);
7 expect((await h.call('/device/start', {})).status).toBe(401);
8 expect((await h.call('/login', { password: 'incorrect' })).status).toBe(401);
9 expect((await h.call('/login', ' '.repeat(20001))).status).toBe(413);
10 expect(
11 (
12 await h.call(
13 '/login',
14 { password: 'test-viewer-password' },
15 { Origin: 'https://untrusted.example' },
16 )
17 ).status,
18 ).toBe(403);
19 const cookie = await h.login();
20 expect(
21 cookie.includes('HttpOnly') && cookie.includes('Secure') && cookie.includes('SameSite=Strict'),
22 ).toBeTruthy();
23 expect((await h.call('/status')).status).toBe(200);
24 await h.start();
25 const viewer = await h.viewer();
26 expect(
27 (await h.call(`/viewers/${viewer.id}/claim`, {}, { 'X-Viewer-Token': 'wrong-token' })).status,
28 ).toBe(403);
29 expect((await h.call(`/viewers/${viewer.id}/claim`, {}, viewer.owner)).status).toBe(200);
30});