|
22 | 22 | * - the `x-share-password` header is accepted on both public routes, the |
23 | 23 | * `?password=` query parameter still is, and a wrong password is refused |
24 | 24 | * through either form; |
25 | | - * - no log line carries the presented password. |
| 25 | + * - no log line carries the presented password; |
| 26 | + * - both public routes answer `Cache-Control: no-store` and |
| 27 | + * `Vary: X-Share-Password` on every outcome, and the authenticated routes |
| 28 | + * do not; |
| 29 | + * - the pure-JS scrypt the WebContainer path uses and `node:crypto`'s produce |
| 30 | + * interchangeable hashes. |
26 | 31 | */ |
27 | 32 |
|
28 | 33 | import { describe, it, expect, afterEach, vi } from 'vitest'; |
@@ -98,15 +103,15 @@ async function drive( |
98 | 103 | headers?: Record<string, string>; |
99 | 104 | body?: unknown; |
100 | 105 | } = {}, |
101 | | -): Promise<{ status: number; body: any }> { |
| 106 | +): Promise<{ status: number; body: any; headers: Record<string, string | string[]> }> { |
102 | 107 | const handler = http.routes.get(key); |
103 | 108 | if (!handler) throw new Error(`no handler for ${key}`); |
104 | | - const captured = { status: 200, body: undefined as any }; |
| 109 | + const captured = { status: 200, body: undefined as any, headers: {} as Record<string, string | string[]> }; |
105 | 110 | const res: IHttpResponse = { |
106 | 111 | json: vi.fn((data: any) => { captured.body = data; }) as any, |
107 | 112 | send: vi.fn() as any, |
108 | 113 | status: vi.fn((code: number) => { captured.status = code; return res; }) as any, |
109 | | - header: vi.fn(() => res) as any, |
| 114 | + header: vi.fn((name: string, value: string | string[]) => { captured.headers[name] = value; return res; }) as any, |
110 | 115 | }; |
111 | 116 | const req: IHttpRequest = { |
112 | 117 | params: opts.params ?? {}, |
@@ -472,3 +477,41 @@ describe('[#21839] how the password travels in', () => { |
472 | 477 | expect(loggedText(logger)).not.toContain('wrong one 21839'); |
473 | 478 | }); |
474 | 479 | }); |
| 480 | + |
| 481 | +describe('[#21839] the public routes are never cached', () => { |
| 482 | + function expectNoStore(res: { headers: Record<string, string | string[]> }, label: string) { |
| 483 | + expect(res.headers['Cache-Control'], label).toBe('no-store'); |
| 484 | + expect(res.headers.Vary, label).toBe('X-Share-Password'); |
| 485 | + } |
| 486 | + |
| 487 | + it.each(['resolve', 'messages'] as const)('/%s sends no-store + Vary on success and on every refusal', async (route) => { |
| 488 | + const booted = await boot(); |
| 489 | + const link = await booted.service.createLink( |
| 490 | + { object: 'ai_conversations', recordId: 'conv_1', password: PASSWORD }, |
| 491 | + CREATOR, |
| 492 | + ); |
| 493 | + const key = `GET ${B}/:token/${route}`; |
| 494 | + const ok = await drive(booted.http, key, { params: { token: link.token }, headers: { 'x-share-password': PASSWORD } }); |
| 495 | + expect(ok.status).toBe(200); |
| 496 | + expectNoStore(ok, 'success'); |
| 497 | + |
| 498 | + const bare = await drive(booted.http, key, { params: { token: link.token } }); |
| 499 | + expect(bare.status).not.toBe(200); |
| 500 | + expectNoStore(bare, 'no password'); |
| 501 | + |
| 502 | + const wrong = await drive(booted.http, key, { params: { token: link.token }, query: { password: 'nope 21839' } }); |
| 503 | + expect(wrong.status).not.toBe(200); |
| 504 | + expectNoStore(wrong, 'wrong password'); |
| 505 | + |
| 506 | + const unknown = await drive(booted.http, key, { params: { token: 'no-such-token-21839' } }); |
| 507 | + expect(unknown.status).toBe(404); |
| 508 | + expectNoStore(unknown, 'unknown token'); |
| 509 | + }); |
| 510 | + |
| 511 | + it('the authenticated list route is not given the public headers', async () => { |
| 512 | + const { http } = await boot(); |
| 513 | + const res = await drive(http, `GET ${B}`); |
| 514 | + expect(res.headers['Cache-Control']).toBeUndefined(); |
| 515 | + expect(res.headers.Vary).toBeUndefined(); |
| 516 | + }); |
| 517 | +}); |
0 commit comments