Files
websitedev/scripts/test-content-editor-security.js
T
Do Siki bd7287aa58 fix: address code review findings from 2026-08-17
- scope no-cache headers to non-static routes (restore immutable asset caching)
- reset cached rejected MongoDB promise so retries can succeed
- use last X-Forwarded-For entry in Content Editor rate limiter (anti-spoofing)
- remove weak Mongo defaults from compose files (fail loudly on missing env)
- move staging banner text to common.json content
- read APP_PORT from env file in deploy.sh healthcheck
- filter network noise from staging smoke console assertions

Closes MITHOME-48, MITHOME-49, MITHOME-50, MITHOME-51, MITHOME-52, MITHOME-53, MITHOME-54
2026-08-18 12:21:32 +02:00

34 lines
1.6 KiB
JavaScript

#!/usr/bin/env node
const assert = require('assert/strict');
process.env.CMS_USER = 'test-editor';
process.env.CMS_PASS = 'not-a-real-secret';
process.env.CMS_DEPLOY_ENV = 'staging';
const {
hasValidCredentials,
hasValidCsrfToken,
getClientAddress,
securityConfigIsValid,
csrfToken,
} = require('../content-editor');
const authorization = Buffer.from('test-editor:not-a-real-secret').toString('base64');
assert.equal(securityConfigIsValid(), true);
assert.equal(hasValidCredentials({ headers: { authorization: `Basic ${authorization}` } }), true);
assert.equal(hasValidCredentials({ headers: { authorization: 'Basic invalid' } }), false);
assert.equal(hasValidCredentials({ headers: {} }), false);
assert.equal(hasValidCsrfToken({ headers: { 'x-csrf-token': csrfToken } }), true);
assert.equal(hasValidCsrfToken({ headers: { 'x-csrf-token': 'invalid-token' } }), false);
assert.equal(hasValidCsrfToken({ headers: {} }), false);
// X-Forwarded-For: the appended (last) entry is the proxy-observed client address;
// a leading spoofed entry must not become the rate-limit key.
assert.equal(getClientAddress({ headers: { 'x-forwarded-for': '1.2.3.4, 5.6.7.8' }, socket: {} }), '5.6.7.8');
assert.equal(getClientAddress({ headers: { 'x-forwarded-for': 'spoofed, , 9.9.9.9' }, socket: {} }), '9.9.9.9');
assert.equal(getClientAddress({ headers: { 'x-forwarded-for': '5.6.7.8' }, socket: {} }), '5.6.7.8');
assert.equal(getClientAddress({ headers: {}, socket: { remoteAddress: '127.0.0.1' } }), '127.0.0.1');
assert.equal(getClientAddress({ headers: { 'x-forwarded-for': ' ' }, socket: {} }), 'unknown');
console.log('Content Editor security guard test: OK');