File
Blob: chord/local_stats_handler_test.go
| 1 | package chord |
| 2 | |
| 3 | import ( |
| 4 | "net/http" |
| 5 | "net/http/httptest" |
| 6 | "testing" |
| 7 | |
| 8 | "github.com/stretchr/testify/require" |
| 9 | ) |
| 10 | |
| 11 | func TestStatsHTMLTreatsStoredKeysAsText(t *testing.T) { |
| 12 | as := require.New(t) |
| 13 | node := NewLocalNode(devConfig(t, as)) |
| 14 | as.NoError(node.Create()) |
| 15 | defer node.Leave() |
| 16 | waitRing(as, node) |
| 17 | key := "<script>alert(1)</script>" |
| 18 | as.NoError(node.kv.Put(t.Context(), []byte(key), []byte("value"))) |
| 19 | handler := ChordStatsHandler(node, []*LocalNode{node}) |
| 20 | |
| 21 | htmlResponse := httptest.NewRecorder() |
| 22 | handler.ServeHTTP(htmlResponse, httptest.NewRequest(http.MethodGet, "/stats.html", nil)) |
| 23 | as.Equal(http.StatusOK, htmlResponse.Code) |
| 24 | as.Contains(htmlResponse.Body.String(), "<script>") |
| 25 | as.NotContains(htmlResponse.Body.String(), key) |
| 26 | as.Contains(htmlResponse.Body.String(), "</pre></body></html>") |
| 27 | |
| 28 | textResponse := httptest.NewRecorder() |
| 29 | handler.ServeHTTP(textResponse, httptest.NewRequest(http.MethodGet, "/stats.txt", nil)) |
| 30 | as.Equal(http.StatusOK, textResponse.Code) |
| 31 | as.Contains(textResponse.Body.String(), key) |
| 32 | } |