diff --git a/packages/kit/test/apps/basics/src/routes/endpoint-input/sha256/+server.js b/packages/kit/test/apps/basics/src/routes/endpoint-input/sha256/+server.js deleted file mode 100644 index 95db0f5808c7..000000000000 --- a/packages/kit/test/apps/basics/src/routes/endpoint-input/sha256/+server.js +++ /dev/null @@ -1,20 +0,0 @@ -import { createHash } from 'node:crypto'; - -/** @type {import('./$types').RequestHandler} */ -export async function PUT({ request }) { - const hash = createHash('sha256'); - const reader = request.body?.getReader(); - - if (!reader) { - return new Response('no body', { status: 400 }); - } - - for (;;) { - const { done, value } = await reader.read(); - if (done) break; - hash.update(value); - await new Promise((r) => setTimeout(r, 10)); - } - - return new Response(hash.digest('base64url')); -} diff --git a/packages/kit/test/apps/basics/unit-test/server.spec.js b/packages/kit/test/apps/basics/unit-test/server.spec.js index 246935153895..9d63c38278d4 100644 --- a/packages/kit/test/apps/basics/unit-test/server.spec.js +++ b/packages/kit/test/apps/basics/unit-test/server.spec.js @@ -193,121 +193,16 @@ describe.skipIf(dev)('CSRF', () => { } }); - test('Allows requests from same origin', async () => { - const res = await get('/csrf', { - method: 'POST', - headers: { 'content-type': 'application/x-www-form-urlencoded', origin } - }); - expect(res.status).toBe(200); - expect(await res.text()).toBe('ok'); - }); - test('Allows requests from allowed origins', async () => { - // Test with trusted.example.com which is in trustedOrigins - const res1 = await get('/csrf', { + const res = await get('/csrf', { method: 'POST', headers: { 'content-type': 'application/x-www-form-urlencoded', origin: 'https://trusted.example.com' } }); - expect(res1.status).toBe(200); - expect(await res1.text()).toBe('ok'); - - // Test with payment-gateway.test which is also in trustedOrigins - const res2 = await get('/csrf', { - method: 'POST', - headers: { - 'content-type': 'application/x-www-form-urlencoded', - origin: 'https://payment-gateway.test' - } - }); - expect(res2.status).toBe(200); - expect(await res2.text()).toBe('ok'); - }); - - test('Blocks requests from non-allowed origins', async () => { - // Test with origin not in trustedOrigins list - const res1 = await get('/csrf', { - method: 'POST', - headers: { - 'content-type': 'application/x-www-form-urlencoded', - origin: 'https://malicious-site.com' - } - }); - expect(res1.status).toBe(403); - expect(await res1.text()).toBe('Cross-site POST form submissions are forbidden'); - - // Test with similar but not exact origin - const res2 = await get('/csrf', { - method: 'POST', - headers: { - 'content-type': 'application/x-www-form-urlencoded', - origin: 'https://trusted.example.com.evil.com' - } - }); - expect(res2.status).toBe(403); - expect(await res2.text()).toBe('Cross-site POST form submissions are forbidden'); - - // Test subdomain attack (should be blocked) - const res3 = await get('/csrf', { - method: 'POST', - headers: { - 'content-type': 'application/x-www-form-urlencoded', - origin: 'https://evil.trusted.example.com' - } - }); - expect(res3.status).toBe(403); - expect(await res3.text()).toBe('Cross-site POST form submissions are forbidden'); - }); - - test('Allows GET requests regardless of origin', async () => { - const res = await get('/csrf', { - method: 'GET', - headers: { - 'content-type': 'application/x-www-form-urlencoded', - origin: 'https://any-origin.com' - } - }); expect(res.status).toBe(200); - }); - - test('Allows non-form content types regardless of origin', async () => { - const res = await get('/csrf', { - method: 'POST', - headers: { - 'content-type': 'application/json', - origin: 'https://any-origin.com' - } - }); - expect(res.status).toBe(200); - }); - - test('Allows all protected HTTP methods from allowed origins', async () => { - const methods = ['POST', 'PUT', 'PATCH', 'DELETE']; - for (const method of methods) { - const res = await get('/csrf', { - method, - headers: { - 'content-type': 'application/x-www-form-urlencoded', - origin: 'https://trusted.example.com' - } - }); - expect(res.status, `Method ${method} should be allowed from trusted origin`).toBe(200); - expect(await res.text(), `Method ${method} should return ok`).toBe('ok'); - } - }); - - test('Handles undefined origin correctly', async () => { - // Some requests may have null origin (e.g., from certain mobile apps) - const res = await get('/csrf', { - method: 'POST', - headers: { - 'content-type': 'application/x-www-form-urlencoded' - } - }); - expect(res.status).toBe(403); - expect(await res.text()).toBe('Cross-site POST form submissions are forbidden'); + expect(await res.text()).toBe('ok'); }); }); @@ -459,17 +354,6 @@ describe('Endpoints', () => { expect(response.headers.get('digest')).toEqual(`sha-256=${digest}`); }); - test('request body can be read slow', async () => { - const data = randomBytes(1024 * 256); - const digest = createHash('sha256').update(data).digest('base64url'); - const response = await get('/endpoint-input/sha256', { - method: 'PUT', - headers: { 'content-type': 'application/octet-stream' }, - body: data - }); - expect(await response.text()).toEqual(digest); - }); - test('OPTIONS handler', async () => { const url = '/endpoint-output';