mirror of
https://github.com/truewhile/MeBox.git
synced 2026-09-28 11:16:37 +08:00
b0fe40142a
* Rebrand MMTL to MeBox across codebase and assets Rename the project display name, Go module path, environment variable prefix (MEBOX_*), Docker image references, and UI branding from MMTL/mmtl to MeBox/mebox. Replace logo assets with the new MeBox icon and keep legacy SQLite migration support for existing mmtl.db deployments. Co-authored-by: truewhile <truewhile@users.noreply.github.com> * Fix logo icons: use cube-only crop without truncated text Previous icon generation cropped too much of the source image, including partial MeBox wordmark text that was cut off in square icon containers. Regenerate logo-64/192/512, favicon, and SVG from cube-only region. Co-authored-by: truewhile <truewhile@users.noreply.github.com> --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: truewhile <truewhile@users.noreply.github.com>
72 lines
2.0 KiB
Go
72 lines
2.0 KiB
Go
package handler
|
|
|
|
import (
|
|
"net/http"
|
|
"net/http/httptest"
|
|
"testing"
|
|
|
|
"github.com/gin-gonic/gin"
|
|
|
|
"github.com/truewhile/MeBox/internal/middleware"
|
|
)
|
|
|
|
func TestSetAccessTokenCookie(t *testing.T) {
|
|
gin.SetMode(gin.TestMode)
|
|
w := httptest.NewRecorder()
|
|
c, _ := gin.CreateTestContext(w)
|
|
c.Request = httptest.NewRequest(http.MethodPost, "https://media.local/api/auth/login", nil)
|
|
|
|
setAccessTokenCookie(c, "access-token", 3600)
|
|
|
|
cookie := findResponseCookie(t, w, middleware.AccessTokenCookieName)
|
|
if cookie.Value != "access-token" {
|
|
t.Fatalf("cookie value = %q", cookie.Value)
|
|
}
|
|
if cookie.Path != middleware.AccessTokenCookiePath {
|
|
t.Fatalf("cookie path = %q, want %q", cookie.Path, middleware.AccessTokenCookiePath)
|
|
}
|
|
if cookie.MaxAge != 3600 {
|
|
t.Fatalf("cookie max age = %d, want 3600", cookie.MaxAge)
|
|
}
|
|
if !cookie.HttpOnly {
|
|
t.Fatal("cookie should be HttpOnly")
|
|
}
|
|
if !cookie.Secure {
|
|
t.Fatal("https request should set Secure cookie")
|
|
}
|
|
if cookie.SameSite != http.SameSiteLaxMode {
|
|
t.Fatalf("cookie SameSite = %v, want Lax", cookie.SameSite)
|
|
}
|
|
}
|
|
|
|
func TestClearAccessTokenCookie(t *testing.T) {
|
|
gin.SetMode(gin.TestMode)
|
|
w := httptest.NewRecorder()
|
|
c, _ := gin.CreateTestContext(w)
|
|
c.Request = httptest.NewRequest(http.MethodPost, "http://127.0.0.1:8080/api/me/logout", nil)
|
|
|
|
clearAccessTokenCookie(c)
|
|
|
|
cookie := findResponseCookie(t, w, middleware.AccessTokenCookieName)
|
|
if cookie.MaxAge >= 0 {
|
|
t.Fatalf("clear cookie max age = %d, want negative", cookie.MaxAge)
|
|
}
|
|
if cookie.Path != middleware.AccessTokenCookiePath {
|
|
t.Fatalf("cookie path = %q, want %q", cookie.Path, middleware.AccessTokenCookiePath)
|
|
}
|
|
if cookie.Secure {
|
|
t.Fatal("plain http request should not set Secure cookie")
|
|
}
|
|
}
|
|
|
|
func findResponseCookie(t *testing.T, w *httptest.ResponseRecorder, name string) *http.Cookie {
|
|
t.Helper()
|
|
for _, cookie := range w.Result().Cookies() {
|
|
if cookie.Name == name {
|
|
return cookie
|
|
}
|
|
}
|
|
t.Fatalf("missing response cookie %q", name)
|
|
return nil
|
|
}
|