Files
pure-note/internal/httpapi/nostore_test.go
T
wangairnan 1272d680a8 fix(httpapi): no-store 接线、图片缓存头时序、解压炸弹上限与 RSS 空日期
/api/admin/* 挂 NoStore、/api/me 内联 no-store(P1-3); 图片缓存头移至数据读取成功后,404 不携带 public immutable(P2-9); 上传先 DecodeConfig 限制像素 ≤2^25 再解码(P2-12); 无公开笔记时省略 lastBuildDate(P2-10)。
2026-09-08 17:32:52 +08:00

33 lines
1.1 KiB
Go

package httpapi
import "testing"
// TestNoStoreHeaders 认证与管理端点响应禁缓存(§9.2,评审 round2 P1-3):
// 防登出后 bfcache/历史回退回看管理数据与 CSRF token。
func TestNoStoreHeaders(t *testing.T) {
e := newEnv(t)
// 匿名 /api/me(响应随会话态变化)
resp, _ := e.get(e.client(), "/api/me")
if cc := resp.Header.Get("Cache-Control"); cc != "no-store" {
t.Errorf("匿名 /api/me 期望 Cache-Control: no-store,实际 %q", cc)
}
// 登录后 /api/me(含 csrf_token)与 /api/admin/notes
c := e.loginAdmin()
resp, _ = e.get(c, "/api/me")
if cc := resp.Header.Get("Cache-Control"); cc != "no-store" {
t.Errorf("已认证 /api/me 期望 Cache-Control: no-store,实际 %q", cc)
}
resp, _ = e.get(c, "/api/admin/notes")
if cc := resp.Header.Get("Cache-Control"); cc != "no-store" {
t.Errorf("/api/admin/notes 期望 Cache-Control: no-store,实际 %q", cc)
}
// /api/auth/* 维持 no-store
resp, _ = e.do(c, "POST", "/api/auth/logout", nil, nil)
if cc := resp.Header.Get("Cache-Control"); cc != "no-store" {
t.Errorf("/api/auth/logout 期望 Cache-Control: no-store,实际 %q", cc)
}
}