Skip to content
File

Blob: src/workerd/api/tests/fetch-redirect-test.js

javascript46 lines
1// Copyright (c) 2025 Cloudflare, Inc.
2// Licensed under the Apache 2.0 license found in the LICENSE file or at:
3// https://opensource.org/licenses/Apache-2.0
4import { WorkerEntrypoint } from 'cloudflare:workers';
5import assert from 'node:assert';
6 
7export class Server extends WorkerEntrypoint {
8 async fetch(req) {
9 const endpoint = new URL(req.url).pathname;
10 switch (endpoint) {
11 case '/echo-authorization':
12 return new Response(
13 req.headers.get('authorization') ?? '<not provided>'
14 );
15 
16 case '/redirect-same-origin':
17 return Response.redirect('http://api.example.com/echo-authorization');
18 
19 case '/redirect-cross-origin':
20 return Response.redirect(
21 'http://totallynotahacker.com/echo-authorization'
22 );
23 }
24 }
25}
26 
27export const sameOriginRedirectPreservesAuthorization = {
28 async test(ctrl, env, ctx) {
29 const res = await env.Server.fetch(
30 'http://api.example.com/redirect-same-origin',
31 { headers: { Authorization: 's00persecret' } }
32 );
33 assert.strictEqual(await res.text(), 's00persecret');
34 },
35};
36 
37export const crossOriginRedirectStripsAuthorization = {
38 async test(ctrl, env, ctx) {
39 const res = await env.Server.fetch(
40 'http://api.example.com/redirect-cross-origin',
41 { headers: { Authorization: 's00persecret' } }
42 );
43 assert.strictEqual(await res.text(), '<not provided>');
44 },
45};