fix: keep opted-in HTTP assets on HTTP
TallyNote release / linux-x64 (push) Successful in 6m7s

This commit is contained in:
Qiufeng
2026-09-02 15:11:48 +08:00
parent 1925676fc9
commit c518890fc3
3 changed files with 53 additions and 4 deletions
+42
View File
@@ -87,6 +87,48 @@ describe("TallyNote API", () => {
expect(missing.json().error.requestId).toBeTruthy();
});
it("显式允许的公网 HTTP 不会把静态资源升级到 HTTPS", async () => {
const publicHttpConfig = {
...config,
publicOrigin: "http://192.0.2.10:3999",
isLocalOrigin: false,
allowInsecureHttp: true,
cookieSecure: false,
};
const publicHttpApp = await buildApp(database, publicHttpConfig);
try {
const response = await publicHttpApp.inject({ method: "GET", url: "/health" });
expect(response.statusCode).toBe(200);
expect(response.headers["content-security-policy"]).not.toContain("upgrade-insecure-requests");
expect(response.headers["strict-transport-security"]).toBeUndefined();
expect(response.headers["cross-origin-opener-policy"]).toBeUndefined();
expect(response.headers["origin-agent-cluster"]).toBeUndefined();
} finally {
await publicHttpApp.close();
}
});
it("HTTPS 仍保留传输安全响应头", async () => {
const secureConfig = {
...config,
publicOrigin: "https://example.test:3999",
isLocalOrigin: false,
allowInsecureHttp: false,
cookieSecure: true,
};
const secureApp = await buildApp(database, secureConfig);
try {
const response = await secureApp.inject({ method: "GET", url: "/health" });
expect(response.statusCode).toBe(200);
expect(response.headers["content-security-policy"]).toContain("upgrade-insecure-requests");
expect(response.headers["strict-transport-security"]).toContain("max-age=");
expect(response.headers["cross-origin-opener-policy"]).toBe("same-origin");
expect(response.headers["origin-agent-cluster"]).toBe("?1");
} finally {
await secureApp.close();
}
});
it("拒绝没有 Origin 的写请求", async () => {
const response = await app.inject({ method: "POST", url: "/api/auth/login", payload: { username: "x", password: "x" } });
expect(response.statusCode).toBe(403);