mirror of
https://github.com/ZHANGTIANYAO1/teamspeak-music-bot.git
synced 2026-10-06 06:52:49 +08:00
feat(auth): add csrfOriginCheck middleware
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
1 parent
17c11f0512
commit
d1c9e14bf0
2 files changed
+93
No files matched your search
@@ -0,0 +1,58 @@
|
||||
import { describe, it, expect, beforeEach } from "vitest";
|
||||
import express from "express";
|
||||
import request from "supertest";
|
||||
import { csrfOriginCheck } from "./csrf.js";
|
||||
|
||||
describe("csrfOriginCheck middleware", () => {
|
||||
let app: express.Express;
|
||||
|
||||
beforeEach(() => {
|
||||
app = express();
|
||||
app.use(csrfOriginCheck);
|
||||
app.get("/", (_req, res) => res.json({ ok: true }));
|
||||
app.post("/", (_req, res) => res.json({ ok: true }));
|
||||
});
|
||||
|
||||
it("allows safe methods (GET/HEAD/OPTIONS) without Origin", async () => {
|
||||
const res = await request(app).get("/");
|
||||
expect(res.status).toBe(200);
|
||||
});
|
||||
|
||||
it("rejects POST without Origin or Referer", async () => {
|
||||
const res = await request(app).post("/");
|
||||
expect(res.status).toBe(403);
|
||||
expect(res.body).toEqual({ error: "bad origin" });
|
||||
});
|
||||
|
||||
it("accepts POST when Origin host matches request host", async () => {
|
||||
const res = await request(app)
|
||||
.post("/")
|
||||
.set("Host", "example.com")
|
||||
.set("Origin", "https://example.com");
|
||||
expect(res.status).toBe(200);
|
||||
});
|
||||
|
||||
it("rejects POST when Origin host does not match request host", async () => {
|
||||
const res = await request(app)
|
||||
.post("/")
|
||||
.set("Host", "example.com")
|
||||
.set("Origin", "https://evil.com");
|
||||
expect(res.status).toBe(403);
|
||||
});
|
||||
|
||||
it("accepts POST when Referer host matches and Origin is absent", async () => {
|
||||
const res = await request(app)
|
||||
.post("/")
|
||||
.set("Host", "example.com")
|
||||
.set("Referer", "https://example.com/some/path");
|
||||
expect(res.status).toBe(200);
|
||||
});
|
||||
|
||||
it("rejects POST when Referer host does not match", async () => {
|
||||
const res = await request(app)
|
||||
.post("/")
|
||||
.set("Host", "example.com")
|
||||
.set("Referer", "https://evil.com/some/path");
|
||||
expect(res.status).toBe(403);
|
||||
});
|
||||
});
|
||||
Reference in new issue
Block a user