| 1 | package serve |
| 2 | |
| 3 | import ( |
| 4 | "bytes" |
| 5 | "encoding/json" |
| 6 | "net/http" |
| 7 | "net/http/httptest" |
| 8 | "testing" |
| 9 | ) |
| 10 | |
| 11 | // An HTTP client may start a migration but not choose the directory it reads: |
| 12 | // that is a host path only a local frontend names. |
| 13 | func TestSubmitRefusesAnExplicitMigrationSource(t *testing.T) { |
| 14 | for input, allowed := range map[string]bool{ |
| 15 | `/migrate --from "C:\Users\someone\Old"`: false, |
| 16 | "/migration /etc": false, |
| 17 | "/migrate": true, |
| 18 | "please /migrate --from x": true, |
| 19 | } { |
| 20 | body, err := json.Marshal(map[string]string{"input": input}) |
| 21 | if err != nil { |
| 22 | t.Fatal(err) |
| 23 | } |
| 24 | w := httptest.NewRecorder() |
| 25 | r := httptest.NewRequest(http.MethodPost, "/submit", bytes.NewReader(body)) |
| 26 | _, _, ok := decodeSubmitRequest(w, r) |
| 27 | if ok != allowed { |
| 28 | t.Fatalf("%q: accepted=%v, want %v (status %d)", input, ok, allowed, w.Code) |
| 29 | } |
| 30 | if !allowed && w.Code != http.StatusForbidden { |
| 31 | t.Fatalf("%q: status %d, want 403", input, w.Code) |
| 32 | } |
| 33 | } |
| 34 | } |
| 35 |