36 lines
1.3 KiB
PHP
36 lines
1.3 KiB
PHP
<?php
|
|
|
|
namespace App\Tests\Shared;
|
|
|
|
use Symfony\Bundle\FrameworkBundle\Test\WebTestCase;
|
|
|
|
/**
|
|
* The admin SPA (/admin/*) must carry a Content-Security-Policy; other surfaces
|
|
* must not receive the SPA policy (the /api CSP is stricter and set elsewhere).
|
|
*/
|
|
class AdminCspSubscriberTest extends WebTestCase
|
|
{
|
|
public function testAdminResponseCarriesCsp(): void
|
|
{
|
|
$client = static::createClient();
|
|
$client->request('GET', '/admin');
|
|
|
|
$csp = $client->getResponse()->headers->get('Content-Security-Policy');
|
|
self::assertNotNull($csp, 'admin SPA response must set a Content-Security-Policy');
|
|
self::assertStringContainsString("default-src 'self'", $csp);
|
|
self::assertStringContainsString("object-src 'none'", $csp);
|
|
self::assertStringContainsString("frame-ancestors 'none'", $csp);
|
|
}
|
|
|
|
public function testNonAdminResponseDoesNotGetTheAdminCsp(): void
|
|
{
|
|
$client = static::createClient();
|
|
$client->request('GET', '/api/v1/doctors');
|
|
|
|
$csp = (string) $client->getResponse()->headers->get('Content-Security-Policy');
|
|
// The admin policy allows scripts from 'self'; the API policy is default-src 'none'.
|
|
// Either way the admin-specific script-src must not leak onto /api.
|
|
self::assertStringNotContainsString("script-src 'self'", $csp);
|
|
}
|
|
}
|