|
1 | 1 | const test = require('tape');
|
2 | 2 | const sirv = require('../packages/sirv');
|
| 3 | +const { Writable } = require('stream'); |
| 4 | + |
| 5 | +function runMiddleware(fn, req) { |
| 6 | + const out = { |
| 7 | + headers: {}, |
| 8 | + statusCode: -1, |
| 9 | + } |
| 10 | + return new Promise((resolve, reject) => { |
| 11 | + const res = new Writable({ |
| 12 | + write() {} |
| 13 | + }); |
| 14 | + Object.defineProperty(res, 'statusCode', { |
| 15 | + set(value) { |
| 16 | + out.statusCode = value; |
| 17 | + } |
| 18 | + }) |
| 19 | + res.on('error', reject) |
| 20 | + res.on('finish', resolve); |
| 21 | + res.writeHead = (code, headers) => { |
| 22 | + out.statusCode = code; |
| 23 | + Object.assign(out.headers, headers); |
| 24 | + } |
| 25 | + fn(req, res); |
| 26 | + }).then(() => out); |
| 27 | +} |
3 | 28 |
|
4 | 29 | test('exports', t => {
|
5 | 30 | t.is(typeof sirv, 'function', 'exports a function');
|
6 | 31 | t.end();
|
7 | 32 | });
|
| 33 | + |
| 34 | +test('prevents directory traversal attacks', t => { |
| 35 | + const request = { |
| 36 | + headers: {}, |
| 37 | + path: encodeURIComponent('../package.json'), |
| 38 | + }; |
| 39 | + |
| 40 | + t.plan(1) |
| 41 | + runMiddleware( |
| 42 | + sirv(__dirname), |
| 43 | + request |
| 44 | + ) |
| 45 | + .then(response => { |
| 46 | + t.is(response.statusCode, 404); |
| 47 | + t.end(); |
| 48 | + }) |
| 49 | + .catch(err => { |
| 50 | + t.fail(err.message) |
| 51 | + }); |
| 52 | +}); |
| 53 | + |
| 54 | +test('prevents directory traversal attacks in dev mode', t => { |
| 55 | + const request = { |
| 56 | + headers: {}, |
| 57 | + path: encodeURIComponent('../package.json'), |
| 58 | + }; |
| 59 | + |
| 60 | + t.plan(1) |
| 61 | + runMiddleware( |
| 62 | + sirv(__dirname, { dev: true }), |
| 63 | + request |
| 64 | + ) |
| 65 | + .then(response => { |
| 66 | + t.is(response.statusCode, 404); |
| 67 | + t.end(); |
| 68 | + }) |
| 69 | + .catch(err => { |
| 70 | + t.fail(err.message) |
| 71 | + }); |
| 72 | +}); |
0 commit comments