Call vanity vanity again
This commit is contained in:
@@ -722,7 +722,7 @@ func TestLoginStoresTheToken(t *testing.T) {
|
||||
t.Error("'stay logged in' did not persist the cookie")
|
||||
}
|
||||
|
||||
// The session alone is now enough to claim a custom name.
|
||||
// The session alone is now enough to claim a vanity name.
|
||||
req, _ := http.NewRequest("POST", h.ts.URL+"/upload", strings.NewReader("two"))
|
||||
req.Header.Set("Accept", "application/json")
|
||||
req.Header.Set("Vanity", "session-upload")
|
||||
@@ -1733,7 +1733,7 @@ func TestUploadPageKeepsTheOneOffTokenField(t *testing.T) {
|
||||
// so anything the upload depends on has to be in the markup ahead of it. The
|
||||
// form is laid out to look otherwise, which is exactly why this is pinned: a
|
||||
// tidy-up that moves the drop zone back up in the markup would silently strip
|
||||
// the expiry, the custom name and the one-off token from every upload.
|
||||
// the expiry, the vanity name and the one-off token from every upload.
|
||||
func TestUploadFormSendsTheFileLast(t *testing.T) {
|
||||
h := newHarness(t, nil)
|
||||
resp := h.get(t, "/", "")
|
||||
@@ -1757,10 +1757,10 @@ func TestUploadFormSendsTheFileLast(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
// Anonymous visitors may type a custom name: the token that permits it can be
|
||||
// Anonymous visitors may type a vanity name: the token that permits it can be
|
||||
// supplied in the same form, for this upload only. The rule itself is the
|
||||
// server's to enforce, not the markup's.
|
||||
func TestCustomNameFieldIsAlwaysUsable(t *testing.T) {
|
||||
func TestVanityFieldIsAlwaysUsable(t *testing.T) {
|
||||
h := newHarness(t, nil)
|
||||
resp := h.get(t, "/", "")
|
||||
raw, _ := io.ReadAll(resp.Body)
|
||||
@@ -1768,9 +1768,9 @@ func TestCustomNameFieldIsAlwaysUsable(t *testing.T) {
|
||||
|
||||
form := string(raw)
|
||||
if i := strings.Index(form, `name="vanity"`); i < 0 {
|
||||
t.Fatal("the upload form has no custom name field")
|
||||
t.Fatal("the upload form has no vanity name field")
|
||||
} else if j := strings.Index(form[i:], ">"); strings.Contains(form[i:i+j], "disabled") {
|
||||
t.Error("the custom name field is disabled, so a one-off token cannot be used with it")
|
||||
t.Error("the vanity name field is disabled, so a one-off token cannot be used with it")
|
||||
}
|
||||
|
||||
// Enabled in the page, still refused on the wire without a token.
|
||||
|
||||
@@ -196,7 +196,7 @@ func (s *Server) storeUpload(w http.ResponseWriter, r *http.Request, req uploadR
|
||||
return
|
||||
}
|
||||
if req.vanity != "" && !lim.AllowVanity {
|
||||
s.fail(w, r, http.StatusForbidden, "Custom names require a token.")
|
||||
s.fail(w, r, http.StatusForbidden, "Vanity names require a token.")
|
||||
return
|
||||
}
|
||||
expires, err := resolveExpiry(req.expiry, lim, now)
|
||||
@@ -220,7 +220,7 @@ func (s *Server) storeUpload(w http.ResponseWriter, r *http.Request, req uploadR
|
||||
return
|
||||
case errors.Is(err, store.ErrBadID):
|
||||
s.fail(w, r, http.StatusBadRequest,
|
||||
"A custom name must be 2-64 characters of letters, digits, dot, dash or underscore.")
|
||||
"A vanity name must be 2-64 characters of letters, digits, dot, dash or underscore.")
|
||||
return
|
||||
case err != nil:
|
||||
s.log.Error("reserving object", "err", err)
|
||||
|
||||
Reference in New Issue
Block a user