cors fixed

This commit is contained in:
2026-09-24 11:38:46 +05:30
parent 9698de32d5
commit 294fb8ab93
4 changed files with 245 additions and 18 deletions

View File

@@ -271,3 +271,64 @@ func TestNoTokenIsNotAPlatformAccount(t *testing.T) {
t.Fatal("claims were reported present on a request that carried none")
}
}
/* ── The default, after the rollout ────────────────────────────────────── */
func TestEnforcementIsOnByDefault(t *testing.T) {
// It shipped defaulting to off so a live console could adopt tokens without
// its users being locked out. That finished, and the default was measured
// still open: a getorders with no credential returned a real merchant's
// orders to anyone.
t.Setenv("POS_TOKEN_SECRET", webTestSecret)
t.Setenv("WEB_AUTH_REQUIRED", "")
got := call(t, fakeLocations{}, "", "GET", "/live/api/v1/web/orders/tenant/getorders?tenantid=916", "")
if got != fiber.StatusUnauthorized {
t.Fatalf("an untokened request was served with no setting present: %d", got)
}
}
func TestEnforcementCanBeTurnedOffWithoutADeploy(t *testing.T) {
// The escape hatch. Flipping a default that can lock people out has to be
// reversible by one person in one minute.
t.Setenv("POS_TOKEN_SECRET", webTestSecret)
t.Setenv("WEB_AUTH_REQUIRED", "false")
got := call(t, fakeLocations{}, "", "GET", "/live/api/v1/web/orders/tenant/getorders?tenantid=916", "")
if got != fiber.StatusOK {
t.Fatalf("the escape hatch does not work: %d", got)
}
}
func TestOnlyTheWordFalseOpensTheDoor(t *testing.T) {
// A typo must fail closed. "no", "0" and "off" all look like they might
// disable it, and a deployment that meant to disable it and did not is far
// safer than one that meant to enable it and did not.
t.Setenv("POS_TOKEN_SECRET", webTestSecret)
for _, setting := range []string{"no", "0", "off", "FALSE ", "nope"} {
t.Setenv("WEB_AUTH_REQUIRED", setting)
got := call(t, fakeLocations{}, "", "GET", "/live/api/v1/web/orders/tenant/getorders?tenantid=916", "")
if setting == "FALSE " && got != fiber.StatusOK {
t.Fatalf("a trimmed, case-insensitive false was not honoured: %d", got)
}
if setting != "FALSE " && got != fiber.StatusUnauthorized {
t.Fatalf("%q opened the door: %d", setting, got)
}
}
}
func TestSignInStillWorksWithTheNewDefault(t *testing.T) {
// The test that catches a locked-out deployment. Guarding the login route
// means nobody can ever obtain a token.
t.Setenv("POS_TOKEN_SECRET", webTestSecret)
t.Setenv("WEB_AUTH_REQUIRED", "")
for _, path := range []string{
"/live/api/v1/web/users/applogin",
"/live/api/v1/web/tenant/weblogin",
} {
if got := call(t, fakeLocations{}, "", "POST", path, `{"authname":"a@b.c"}`); got != fiber.StatusOK {
t.Fatalf("%s was locked behind a session: %d", path, got)
}
}
}