fix(httpapi): no-store 接线、图片缓存头时序、解压炸弹上限与 RSS 空日期
/api/admin/* 挂 NoStore、/api/me 内联 no-store(P1-3); 图片缓存头移至数据读取成功后,404 不携带 public immutable(P2-9); 上传先 DecodeConfig 限制像素 ≤2^25 再解码(P2-12); 无公开笔记时省略 lastBuildDate(P2-10)。
This commit is contained in:
@@ -0,0 +1,32 @@
|
||||
package httpapi
|
||||
|
||||
import "testing"
|
||||
|
||||
// TestNoStoreHeaders 认证与管理端点响应禁缓存(§9.2,评审 round2 P1-3):
|
||||
// 防登出后 bfcache/历史回退回看管理数据与 CSRF token。
|
||||
func TestNoStoreHeaders(t *testing.T) {
|
||||
e := newEnv(t)
|
||||
|
||||
// 匿名 /api/me(响应随会话态变化)
|
||||
resp, _ := e.get(e.client(), "/api/me")
|
||||
if cc := resp.Header.Get("Cache-Control"); cc != "no-store" {
|
||||
t.Errorf("匿名 /api/me 期望 Cache-Control: no-store,实际 %q", cc)
|
||||
}
|
||||
|
||||
// 登录后 /api/me(含 csrf_token)与 /api/admin/notes
|
||||
c := e.loginAdmin()
|
||||
resp, _ = e.get(c, "/api/me")
|
||||
if cc := resp.Header.Get("Cache-Control"); cc != "no-store" {
|
||||
t.Errorf("已认证 /api/me 期望 Cache-Control: no-store,实际 %q", cc)
|
||||
}
|
||||
resp, _ = e.get(c, "/api/admin/notes")
|
||||
if cc := resp.Header.Get("Cache-Control"); cc != "no-store" {
|
||||
t.Errorf("/api/admin/notes 期望 Cache-Control: no-store,实际 %q", cc)
|
||||
}
|
||||
|
||||
// /api/auth/* 维持 no-store
|
||||
resp, _ = e.do(c, "POST", "/api/auth/logout", nil, nil)
|
||||
if cc := resp.Header.Get("Cache-Control"); cc != "no-store" {
|
||||
t.Errorf("/api/auth/logout 期望 Cache-Control: no-store,实际 %q", cc)
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user