package httpapi import "testing" // TestNoStoreHeaders 认证与管理端点响应禁缓存(§9.2,评审 round2 P1-3): // 防登出后 bfcache/历史回退回看管理数据与 CSRF token。 func TestNoStoreHeaders(t *testing.T) { e := newEnv(t) // 匿名 /api/me(响应随会话态变化) resp, _ := e.get(e.client(), "/api/me") if cc := resp.Header.Get("Cache-Control"); cc != "no-store" { t.Errorf("匿名 /api/me 期望 Cache-Control: no-store,实际 %q", cc) } // 登录后 /api/me(含 csrf_token)与 /api/admin/notes c := e.loginAdmin() resp, _ = e.get(c, "/api/me") if cc := resp.Header.Get("Cache-Control"); cc != "no-store" { t.Errorf("已认证 /api/me 期望 Cache-Control: no-store,实际 %q", cc) } resp, _ = e.get(c, "/api/admin/notes") if cc := resp.Header.Get("Cache-Control"); cc != "no-store" { t.Errorf("/api/admin/notes 期望 Cache-Control: no-store,实际 %q", cc) } // /api/auth/* 维持 no-store resp, _ = e.do(c, "POST", "/api/auth/logout", nil, nil) if cc := resp.Header.Get("Cache-Control"); cc != "no-store" { t.Errorf("/api/auth/logout 期望 Cache-Control: no-store,实际 %q", cc) } }