Fix disabled vanity field

This commit is contained in:
2026-09-13 09:32:06 +02:00
parent ad611e9652
commit 26186ac738
4 changed files with 80 additions and 7 deletions
+59
View File
@@ -1627,6 +1627,65 @@ func TestUploadPageKeepsTheOneOffTokenField(t *testing.T) {
}
}
// The server reads the multipart body as a stream and stops at the file part,
// so anything the upload depends on has to be in the markup ahead of it. The
// form is laid out to look otherwise, which is exactly why this is pinned: a
// tidy-up that moves the drop zone back up in the markup would silently strip
// the expiry, the custom name and the one-off token from every upload.
func TestUploadFormSendsTheFileLast(t *testing.T) {
h := newHarness(t, nil)
resp := h.get(t, "/", "")
raw, _ := io.ReadAll(resp.Body)
resp.Body.Close()
page := string(raw)
file := strings.Index(page, `name="file"`)
if file < 0 {
t.Fatal("the upload form has no file field")
}
for _, field := range []string{"expiry", "vanity", "token"} {
at := strings.Index(page, `name="`+field+`"`)
if at < 0 {
t.Errorf("the upload form has no %s field", field)
continue
}
if at > file {
t.Errorf("the %s field follows the file part, where the server can no longer read it", field)
}
}
}
// Anonymous visitors may type a custom name: the token that permits it can be
// supplied in the same form, for this upload only. The rule itself is the
// server's to enforce, not the markup's.
func TestCustomNameFieldIsAlwaysUsable(t *testing.T) {
h := newHarness(t, nil)
resp := h.get(t, "/", "")
raw, _ := io.ReadAll(resp.Body)
resp.Body.Close()
form := string(raw)
if i := strings.Index(form, `name="vanity"`); i < 0 {
t.Fatal("the upload form has no custom name field")
} else if j := strings.Index(form[i:], ">"); strings.Contains(form[i:i+j], "disabled") {
t.Error("the custom name field is disabled, so a one-off token cannot be used with it")
}
// Enabled in the page, still refused on the wire without a token.
res := h.formUpload(t, map[string]string{"vanity": "anonymous-pick"}, "f.txt", "hello")
defer res.Body.Close()
if res.StatusCode != http.StatusForbidden {
t.Errorf("anonymous vanity upload = %s, want 403", res.Status)
}
// And accepted when the form carries a token that allows it.
res2 := h.formUpload(t, map[string]string{"vanity": "chosen-name", "token": h.token}, "f.txt", "hello")
defer res2.Body.Close()
if res2.StatusCode != http.StatusCreated {
t.Errorf("one-off token vanity upload = %s, want 201", res2.Status)
}
}
// A chosen passphrase has to work everywhere a generated token does: at the
// login form, on an upload, and as a session.
func TestChosenPassphraseWorksEndToEnd(t *testing.T) {