mirror of
https://github.com/truewhile/MeBox.git
synced 2026-10-04 12:36:37 +08:00
41 lines
1.2 KiB
Go
41 lines
1.2 KiB
Go
package handler
|
|
|
|
import (
|
|
"net/http"
|
|
"net/http/httptest"
|
|
"strings"
|
|
"testing"
|
|
)
|
|
|
|
// 段评打开接口的 HTTP 层契约:路由存在、参数校验生效、内网地址被拒。
|
|
//
|
|
// 正常路径(真的去抓评论页)依赖外部站点,放在服务层解析单测里覆盖;
|
|
// 这里只钉住契约与安全边界,避免把测试绑到网络。
|
|
func TestReaderOpenCommentRejectsBadURL(t *testing.T) {
|
|
container := newReaderHandlerContainer(t)
|
|
router := registerReaderRoutesForTest(container)
|
|
|
|
post := func(body string) int {
|
|
w := httptest.NewRecorder()
|
|
req := httptest.NewRequest(http.MethodPost, "/api/reader/comments/open", strings.NewReader(body))
|
|
req.Header.Set("Content-Type", "application/json")
|
|
router.ServeHTTP(w, req)
|
|
return w.Code
|
|
}
|
|
|
|
cases := []struct {
|
|
name string
|
|
body string
|
|
}{
|
|
{"缺少 url", `{"book_id":"x"}`},
|
|
{"非 http 协议", `{"book_id":"x","url":"javascript:alert(1)"}`},
|
|
{"回环地址", `{"book_id":"x","url":"http://127.0.0.1/c"}`},
|
|
{"内网地址", `{"book_id":"x","url":"http://192.168.1.1/c"}`},
|
|
}
|
|
for _, c := range cases {
|
|
if code := post(c.body); code != http.StatusBadRequest {
|
|
t.Fatalf("%s:应 400,得到 %d", c.name, code)
|
|
}
|
|
}
|
|
}
|