import { env, exports } from "cloudflare:workers"; import { beforeAll, describe, expect, it } from "vitest"; import { makeAuth } from "@/worker/auth"; import { ISSUER, signInForCookie, testHeaders } from "./helpers"; const SELF = exports.default; const credential = { email: "origin-csrf-tester@example.com", password: "correct-horse-battery-staple", name: "Origin CSRF Tester", }; describe("Origin guard for tessera-owned mutations", () => { let adminCookie: string; beforeAll(async () => { const auth = makeAuth(env, { baseURL: ISSUER, issuer: ISSUER }); await auth.api.signUpEmail({ body: credential, asResponse: false }); await env.DB.prepare("UPDATE users SET role = ? WHERE email = ?").bind("admin", credential.email).run(); adminCookie = await signInForCookie(credential.email, credential.password, "10.73.0.1"); }); describe("POST /api/account/handle", () => { it("403s on missing Origin (before requireUser)", async () => { const res = await SELF.fetch(`${ISSUER}/api/account/handle`, { method: "POST", headers: { "content-type": "application/json" }, body: JSON.stringify({ preferredUsername: "anything" }), }); expect(res.status).toBe(403); const body = (await res.json()) as { error?: string }; expect(body.error).toBe("forbidden_origin"); }); it("403s on foreign Origin even with valid session", async () => { const res = await SELF.fetch(`${ISSUER}/api/account/handle`, { method: "POST", headers: testHeaders({ origin: "https://evil.example.com", cookie: adminCookie }), body: JSON.stringify({ preferredUsername: "anything" }), }); expect(res.status).toBe(403); }); it("passes with matching Origin and a valid session", async () => { const res = await SELF.fetch(`${ISSUER}/api/account/handle`, { method: "POST", headers: testHeaders({ cookie: adminCookie }), body: JSON.stringify({ preferredUsername: "matching-origin" }), }); expect([200, 204]).toContain(res.status); }); it("400s on text/plain JSON body (content-type guard)", async () => { const res = await SELF.fetch(`${ISSUER}/api/account/handle`, { method: "POST", headers: testHeaders({ "content-type": "text/plain", cookie: adminCookie }), body: JSON.stringify({ preferredUsername: "wrong-type" }), }); expect(res.status).toBe(400); const body = (await res.json()) as { error?: string }; expect(body.error).toBe("invalid_content_type"); }); it("accepts application/json; charset=utf-8", async () => { const res = await SELF.fetch(`${ISSUER}/api/account/handle`, { method: "POST", headers: testHeaders({ "content-type": "application/json; charset=utf-8", cookie: adminCookie }), body: JSON.stringify({ preferredUsername: "charset-utf8" }), }); expect([200, 204]).toContain(res.status); }); }); describe("POST /api/admin/clients", () => { it("403s on missing Origin (before requireAdmin)", async () => { const res = await SELF.fetch(`${ISSUER}/api/admin/clients`, { method: "POST", headers: { "content-type": "application/json" }, body: JSON.stringify({ name: "x", redirectUris: ["http://127.0.0.1/cb"] }), }); expect(res.status).toBe(403); }); it("passes GET without Origin (safe method skips the gate)", async () => { const res = await SELF.fetch(`${ISSUER}/api/admin/clients`, { method: "GET", headers: { cookie: adminCookie }, }); expect(res.status).toBe(200); }); }); describe("readOptionalJsonBody empty-body fallback", () => { it("passes admin invites POST with no body and no content-type if body is required", async () => { // handleCreateInvite requires `email`; the handler returns 400 // invalid_body, NOT 400 invalid_content_type, when called with no // body. This proves readOptionalJsonBody's fallback path bypasses // the content-type guard for an empty body. const res = await SELF.fetch(`${ISSUER}/api/admin/invites`, { method: "POST", headers: { origin: ISSUER, cookie: adminCookie, "content-length": "0" }, }); expect(res.status).toBe(400); const body = (await res.json()) as { error?: string }; expect(body.error).toBe("invalid_body"); }); }); describe("POST /api/auth/oauth2/token (excluded from tessera origin guard)", () => { it("foreign Origin reaches Better Auth's catchall (no 403 from tessera)", async () => { // OAuth token endpoint must remain accessible to RPs that originate // from registered redirect URIs. tessera's origin guard must not // intercept this path. Better Auth's own auth.handler applies its // OAuth-specific checks; the response status reflects those, not // a tessera 403. const res = await SELF.fetch(`${ISSUER}/api/auth/oauth2/token`, { method: "POST", headers: { "content-type": "application/x-www-form-urlencoded", origin: "https://rp.example.com", }, body: new URLSearchParams({ grant_type: "authorization_code", code: "no-such-code" }).toString(), }); expect(res.status).not.toBe(403); }); }); });