Files
clinicpro/tests/Shared/AdminCspSubscriberTest.php
T

39 lines
1.6 KiB
PHP

<?php
namespace App\Tests\Shared;
use Symfony\Bundle\FrameworkBundle\Test\WebTestCase;
/**
* The admin SPA (/admin/*) must carry a Content-Security-Policy; other surfaces
* must not receive the SPA policy (the /api CSP is stricter and set elsewhere).
*/
class AdminCspSubscriberTest extends WebTestCase
{
public function testAdminResponseCarriesCsp(): void
{
$client = static::createClient();
$client->request('GET', '/admin');
$csp = $client->getResponse()->headers->get('Content-Security-Policy');
self::assertNotNull($csp, 'admin SPA response must set a Content-Security-Policy');
self::assertStringContainsString("default-src 'self'", $csp);
self::assertStringContainsString("object-src 'none'", $csp);
self::assertStringContainsString("frame-ancestors 'none'", $csp);
// ALTCHA solves its proof-of-work inside blob: Web Workers; without this
// directive the login captcha errors out (worker-src falls back to script-src).
self::assertStringContainsString("worker-src 'self' blob:", $csp);
}
public function testNonAdminResponseDoesNotGetTheAdminCsp(): void
{
$client = static::createClient();
$client->request('GET', '/api/v1/doctors');
$csp = (string) $client->getResponse()->headers->get('Content-Security-Policy');
// The admin policy allows scripts from 'self'; the API policy is default-src 'none'.
// Either way the admin-specific script-src must not leak onto /api.
self::assertStringNotContainsString("script-src 'self'", $csp);
}
}