fix: bootstrap admin CSRF tokens
This commit is contained in:
1 parent
a57c73055f
commit
b3245a18ea
8 files changed
+270
-45
No files matched your search
@@ -0,0 +1,51 @@
|
||||
import { NextRequest } from "next/server";
|
||||
import { beforeEach, describe, expect, it, vi } from "vitest";
|
||||
|
||||
const mocks = vi.hoisted(() => ({
|
||||
setCsrfCookie: vi.fn(),
|
||||
}));
|
||||
|
||||
vi.mock("@/lib/api-handler", () => ({
|
||||
withAdmin:
|
||||
(_options: unknown, handler: (...args: never[]) => unknown) =>
|
||||
(...args: never[]) =>
|
||||
handler(...args),
|
||||
}));
|
||||
|
||||
vi.mock("@/lib/foundation/security", () => ({
|
||||
setCsrfCookie: mocks.setCsrfCookie,
|
||||
}));
|
||||
|
||||
import { GET } from "./route";
|
||||
|
||||
describe("admin CSRF bootstrap route", () => {
|
||||
beforeEach(() => {
|
||||
mocks.setCsrfCookie.mockReset();
|
||||
});
|
||||
|
||||
it("returns the token written by the route handler without caching", async () => {
|
||||
const token = "a".repeat(64);
|
||||
mocks.setCsrfCookie.mockResolvedValue(token);
|
||||
|
||||
const response = await GET(
|
||||
new NextRequest("http://localhost/api/admin/csrf"),
|
||||
);
|
||||
|
||||
expect(response.status).toBe(200);
|
||||
expect(response.headers.get("cache-control")).toBe("no-store");
|
||||
expect(await response.json()).toEqual({ ok: true, token });
|
||||
});
|
||||
|
||||
it("fails closed when the cookie cannot be written", async () => {
|
||||
mocks.setCsrfCookie.mockResolvedValue("");
|
||||
|
||||
const response = await GET(
|
||||
new NextRequest("http://localhost/api/admin/csrf"),
|
||||
);
|
||||
|
||||
expect(response.status).toBe(500);
|
||||
expect(await response.json()).toEqual({
|
||||
error: "Unable to initialize CSRF token",
|
||||
});
|
||||
});
|
||||
});
|
||||
Reference in new issue
Block a user