summaryrefslogtreecommitdiff
path: root/cgithub/src/app.test.ts
diff options
context:
space:
mode:
authorJoe Mou <dev@mou.fo>2026-08-12 01:27:25 -0400
committerJoe Mou <dev@mou.fo>2026-08-12 01:28:04 -0400
commit679a2b71c3e73dc1b8cf11806b3f3df49018b535 (patch)
treeabd5824f7834c595867893634016a4e050c30067 /cgithub/src/app.test.ts
parent21310d0366c0f21e73c1f4f78d38370edfb59445 (diff)
Use an HTTP redirect for same-origin requests
The meta refresh page renders as a broken image when the request came from an <img> on one of our own pages. Such requests are already past the redirect-loop hazard the refresh works around, so send them a real redirect instead.
Diffstat (limited to 'cgithub/src/app.test.ts')
-rw-r--r--cgithub/src/app.test.ts20
1 files changed, 20 insertions, 0 deletions
diff --git a/cgithub/src/app.test.ts b/cgithub/src/app.test.ts
index 5474f8d..59ed352 100644
--- a/cgithub/src/app.test.ts
+++ b/cgithub/src/app.test.ts
@@ -110,6 +110,26 @@ describe("redirects to GitHub", () => {
assert.doesNotMatch(body, /<script/);
});
+ // Same-origin requests are mostly subresources, which render an HTML page as
+ // a broken image rather than following its refresh.
+ it("should redirect over HTTP when the referer is one of our own pages", async () => {
+ const res = await app.request("http://cgithub.example/a/b/c?x=1", {
+ headers: { Referer: "http://cgithub.example/a/b" },
+ });
+
+ assert.strictEqual(res.status, 302);
+ assert.strictEqual(res.headers.get("location"), "https://github.com/a/b/c?x=1");
+ });
+
+ it("should use a meta refresh when the referer is another site", async () => {
+ const res = await app.request("http://cgithub.example/a/b/c?x=1", {
+ headers: { Referer: "https://github.example/a/b" },
+ });
+
+ assert.strictEqual(res.status, 200);
+ assert.strictEqual(res.headers.get("location"), null);
+ });
+
it("should redirect unhandled search types", async () => {
const res = await app.request(
"http://cgithub.example/actions/deploy-pages/search?q=x&type=code",