File
Blob: src/workerd/api/tests/fetch-redirect-test.js
| 1 | // Copyright (c) 2025 Cloudflare, Inc. |
| 2 | // Licensed under the Apache 2.0 license found in the LICENSE file or at: |
| 3 | // https://opensource.org/licenses/Apache-2.0 |
| 4 | import { WorkerEntrypoint } from 'cloudflare:workers'; |
| 5 | import assert from 'node:assert'; |
| 6 | |
| 7 | export class Server extends WorkerEntrypoint { |
| 8 | async fetch(req) { |
| 9 | const endpoint = new URL(req.url).pathname; |
| 10 | switch (endpoint) { |
| 11 | case '/echo-authorization': |
| 12 | return new Response( |
| 13 | req.headers.get('authorization') ?? '<not provided>' |
| 14 | ); |
| 15 | |
| 16 | case '/redirect-same-origin': |
| 17 | return Response.redirect('http://api.example.com/echo-authorization'); |
| 18 | |
| 19 | case '/redirect-cross-origin': |
| 20 | return Response.redirect( |
| 21 | 'http://totallynotahacker.com/echo-authorization' |
| 22 | ); |
| 23 | } |
| 24 | } |
| 25 | } |
| 26 | |
| 27 | export const sameOriginRedirectPreservesAuthorization = { |
| 28 | async test(ctrl, env, ctx) { |
| 29 | const res = await env.Server.fetch( |
| 30 | 'http://api.example.com/redirect-same-origin', |
| 31 | { headers: { Authorization: 's00persecret' } } |
| 32 | ); |
| 33 | assert.strictEqual(await res.text(), 's00persecret'); |
| 34 | }, |
| 35 | }; |
| 36 | |
| 37 | export const crossOriginRedirectStripsAuthorization = { |
| 38 | async test(ctrl, env, ctx) { |
| 39 | const res = await env.Server.fetch( |
| 40 | 'http://api.example.com/redirect-cross-origin', |
| 41 | { headers: { Authorization: 's00persecret' } } |
| 42 | ); |
| 43 | assert.strictEqual(await res.text(), '<not provided>'); |
| 44 | }, |
| 45 | }; |