mirror of
https://github.com/0rangebananaspy/authelia.git
synced 2024-09-14 22:47:21 +07:00
6b78240d39
From this commit on, api endpoints reply with a 401 error code and non api endpoints redirect to /error/40X. This commit also fixes missing restrictions on /loggedin (the "already logged in page). This was not a security issue, though. The change also makes error pages automatically redirect the user after few seconds based on the referrer or the default_redirection_url if provided in the configuration. Warning: The old /verify endpoint of the REST API has moved to /api/verify. You will need to update your nginx configuration to take this change into account.
61 lines
1.8 KiB
TypeScript
61 lines
1.8 KiB
TypeScript
import Sinon = require("sinon");
|
|
import Express = require("express");
|
|
import Assert = require("assert");
|
|
import Get403 from "../../../../src/lib/routes/error/403/get";
|
|
import { ServerVariables } from "../../../../src/lib/ServerVariables";
|
|
import { ServerVariablesMockBuilder, ServerVariablesMock }
|
|
from "../../../mocks/ServerVariablesMockBuilder";
|
|
|
|
describe("Server error 403", function () {
|
|
let vars: ServerVariables;
|
|
let mocks: ServerVariablesMock;
|
|
let req: any;
|
|
let res: any;
|
|
let renderSpy: Sinon.SinonSpy;
|
|
|
|
beforeEach(function () {
|
|
const s = ServerVariablesMockBuilder.build();
|
|
vars = s.variables;
|
|
mocks = s.mocks;
|
|
|
|
renderSpy = Sinon.spy();
|
|
req = {
|
|
headers: {}
|
|
};
|
|
res = {
|
|
render: renderSpy
|
|
};
|
|
});
|
|
|
|
it("should set redirection url to the default redirection url", function () {
|
|
vars.config.default_redirection_url = "http://default-redirection";
|
|
return Get403(vars)(req, res as any)
|
|
.then(function () {
|
|
Assert(renderSpy.calledOnce);
|
|
Assert(renderSpy.calledWithExactly("errors/403", {
|
|
redirection_url: "http://default-redirection"
|
|
}));
|
|
});
|
|
});
|
|
|
|
it("should set redirection url to the referer", function () {
|
|
req.headers["referer"] = "http://redirection";
|
|
return Get403(vars)(req, res as any)
|
|
.then(function () {
|
|
Assert(renderSpy.calledOnce);
|
|
Assert(renderSpy.calledWithExactly("errors/403", {
|
|
redirection_url: "http://redirection"
|
|
}));
|
|
});
|
|
});
|
|
|
|
it("should render without redirecting the user", function () {
|
|
return Get403(vars)(req, res as any)
|
|
.then(function () {
|
|
Assert(renderSpy.calledOnce);
|
|
Assert(renderSpy.calledWithExactly("errors/403", {
|
|
redirection_url: undefined
|
|
}));
|
|
});
|
|
});
|
|
}); |