mirror of
https://github.com/priyanshujain/sanderling.git
synced 2026-10-02 19:17:10 +00:00
revert(inspect): drop /html route
Removes htmlPathPattern, serveHTML, and the dispatch block that called it; HTML capture no longer exists on disk.
This commit is contained in:
1 parent
1ec019e632
commit
1a333f2eaa
2 files changed
-64
No files matched your search
@@ -84,7 +84,6 @@ func (s *Server) handleRunsList(responseWriter http.ResponseWriter, request *htt
|
||||
|
||||
var stepPathPattern = regexp.MustCompile(`^([a-zA-Z0-9._-]+)/steps/([^/]+)$`)
|
||||
var screenshotPathPattern = regexp.MustCompile(`^([a-zA-Z0-9._-]+)/screenshots/([a-zA-Z0-9._-]+\.png)$`)
|
||||
var htmlPathPattern = regexp.MustCompile(`^([a-zA-Z0-9._-]+)/html/([a-zA-Z0-9._-]+\.html)$`)
|
||||
var runDetailPathPattern = regexp.MustCompile(`^([a-zA-Z0-9._-]+)/?$`)
|
||||
|
||||
func (s *Server) handleRunsTree(responseWriter http.ResponseWriter, request *http.Request) {
|
||||
@@ -105,10 +104,6 @@ func (s *Server) handleRunsTree(responseWriter http.ResponseWriter, request *htt
|
||||
s.serveScreenshot(responseWriter, request, match[1], match[2])
|
||||
return
|
||||
}
|
||||
if match := htmlPathPattern.FindStringSubmatch(rest); match != nil {
|
||||
s.serveHTML(responseWriter, request, match[1], match[2])
|
||||
return
|
||||
}
|
||||
if match := runDetailPathPattern.FindStringSubmatch(rest); match != nil {
|
||||
s.serveDetail(responseWriter, match[1])
|
||||
return
|
||||
@@ -165,20 +160,6 @@ func (s *Server) serveScreenshot(responseWriter http.ResponseWriter, request *ht
|
||||
http.ServeFile(responseWriter, request, full)
|
||||
}
|
||||
|
||||
func (s *Server) serveHTML(responseWriter http.ResponseWriter, request *http.Request, id, name string) {
|
||||
if !validRunID(id) || strings.Contains(name, "..") {
|
||||
http.Error(responseWriter, "run not found", http.StatusNotFound)
|
||||
return
|
||||
}
|
||||
full := filepath.Join(s.options.RunsDirectory, id, "html", name)
|
||||
if _, err := http.Dir(filepath.Join(s.options.RunsDirectory, id, "html")).Open(name); err != nil {
|
||||
http.NotFound(responseWriter, request)
|
||||
return
|
||||
}
|
||||
responseWriter.Header().Set("Content-Type", "text/html; charset=utf-8")
|
||||
http.ServeFile(responseWriter, request, full)
|
||||
}
|
||||
|
||||
func (s *Server) handleEvents(responseWriter http.ResponseWriter, request *http.Request) {
|
||||
flusher, ok := responseWriter.(http.Flusher)
|
||||
if !ok {
|
||||
|
||||
@@ -171,51 +171,6 @@ func TestScreenshot_ServesWhitelistedPNG(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
func TestServeHTML_Returns200(t *testing.T) {
|
||||
server, root := newFixtureServer(t)
|
||||
htmlDirectory := filepath.Join(root, "run-a", "html")
|
||||
if err := os.MkdirAll(htmlDirectory, 0o755); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
body := []byte("<!doctype html><html><body>hi</body></html>")
|
||||
if err := os.WriteFile(filepath.Join(htmlDirectory, "step-00001.html"), body, 0o644); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
|
||||
recorder := httptest.NewRecorder()
|
||||
request := httptest.NewRequest(http.MethodGet, "/api/runs/run-a/html/step-00001.html", nil)
|
||||
server.Handler().ServeHTTP(recorder, request)
|
||||
if recorder.Code != http.StatusOK {
|
||||
t.Fatalf("status = %d body=%s", recorder.Code, recorder.Body.String())
|
||||
}
|
||||
if recorder.Body.String() != string(body) {
|
||||
t.Errorf("body mismatch")
|
||||
}
|
||||
if !strings.Contains(recorder.Header().Get("Content-Type"), "text/html") {
|
||||
t.Errorf("content-type = %q", recorder.Header().Get("Content-Type"))
|
||||
}
|
||||
}
|
||||
|
||||
func TestServeHTML_RejectsTraversalAndMissing(t *testing.T) {
|
||||
server, _ := newFixtureServer(t)
|
||||
cases := []string{
|
||||
"/api/runs/run-a/html/../meta.json",
|
||||
"/api/runs/run-a/html/..%2Fmeta.json",
|
||||
"/api/runs/run-a/html/missing.html",
|
||||
"/api/runs/run-a/html/step-00001.txt",
|
||||
}
|
||||
for _, path := range cases {
|
||||
t.Run(path, func(t *testing.T) {
|
||||
recorder := httptest.NewRecorder()
|
||||
request := httptest.NewRequest(http.MethodGet, path, nil)
|
||||
server.Handler().ServeHTTP(recorder, request)
|
||||
if recorder.Code == http.StatusOK {
|
||||
t.Errorf("status = %d (should not be 200) body=%s", recorder.Code, recorder.Body.String())
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
func TestScreenshot_RejectsTraversalAndBadNames(t *testing.T) {
|
||||
server, _ := newFixtureServer(t)
|
||||
cases := []string{
|
||||
|
||||
Reference in new issue
Block a user