handler_test.go
⎇
Raw
1package handler
2
3import (
4 "net/http/httptest"
5 "net/url"
6 "strings"
7 "testing"
8
9 "vidarchive/internal/models"
10)
11
12func TestApplyPresetFormClearsDependentCommentSettings(t *testing.T) {
13 tests := []struct {
14 name string
15 writeInfo string
16 writeComments string
17 wantCleared bool
18 }{
19 {"info JSON disabled", "", "1", true},
20 {"comments disabled", "1", "", true},
21 {"both enabled", "1", "1", false},
22 }
23
24 for _, tc := range tests {
25 t.Run(tc.name, func(t *testing.T) {
26 form := url.Values{
27 "name": {"Preset"},
28 "format_mode": {"default"},
29 "write_info_json": {tc.writeInfo},
30 "write_comments": {tc.writeComments},
31 "comment_sort": {"top"},
32 "max_comments": {"25"},
33 "comment_extractor_args": {"youtube:player_client=web"},
34 }
35 r := httptest.NewRequest("POST", "/settings/presets", strings.NewReader(form.Encode()))
36 r.Header.Set("Content-Type", "application/x-www-form-urlencoded")
37 preset := &models.Preset{}
38 if err := applyPresetForm(preset, r); err != nil {
39 t.Fatalf("applyPresetForm: %v", err)
40 }
41 if tc.wantCleared {
42 if preset.WriteComments || preset.CommentSort != "" || preset.MaxComments != 0 || preset.CommentExtractorArgs != "" {
43 t.Fatalf("dependent settings were not cleared: %+v", preset)
44 }
45 return
46 }
47 if !preset.WriteComments || preset.CommentSort != "top" || preset.MaxComments != 25 || preset.CommentExtractorArgs == "" {
48 t.Fatalf("comment settings not retained: %+v", preset)
49 }
50 })
51 }
52}
53
54// The Referer header is attacker-controlled, so the theme form must never
55// redirect to the host it names — only back to a path on this site.
56func TestLocalRefererKeepsPathOnly(t *testing.T) {
57 tests := []struct {
58 referer string
59 want string
60 }{
61 {"", "/"},
62 {"https://evil.example/phish", "/phish"},
63 {"//evil.example/phish", "/phish"},
64 {"https://vidarchive.local/library?path=music", "/library?path=music"},
65 {"/queue?sort=status", "/queue?sort=status"},
66 {"not a url", "/"},
67 }
68
69 for _, tc := range tests {
70 r := httptest.NewRequest("POST", "/theme", nil)
71 if tc.referer != "" {
72 r.Header.Set("Referer", tc.referer)
73 }
74 if got := localReferer(r); got != tc.want {
75 t.Errorf("localReferer(%q) = %q, want %q", tc.referer, got, tc.want)
76 }
77 }
78}
79