39 lines
1.6 KiB
PHP
39 lines
1.6 KiB
PHP
<?php
|
|
|
|
namespace App\Tests\Shared;
|
|
|
|
use Symfony\Bundle\FrameworkBundle\Test\WebTestCase;
|
|
|
|
/**
|
|
* The admin SPA (/admin/*) must carry a Content-Security-Policy; other surfaces
|
|
* must not receive the SPA policy (the /api CSP is stricter and set elsewhere).
|
|
*/
|
|
class AdminCspSubscriberTest extends WebTestCase
|
|
{
|
|
public function testAdminResponseCarriesCsp(): void
|
|
{
|
|
$client = static::createClient();
|
|
$client->request('GET', '/admin');
|
|
|
|
$csp = $client->getResponse()->headers->get('Content-Security-Policy');
|
|
self::assertNotNull($csp, 'admin SPA response must set a Content-Security-Policy');
|
|
self::assertStringContainsString("default-src 'self'", $csp);
|
|
self::assertStringContainsString("object-src 'none'", $csp);
|
|
self::assertStringContainsString("frame-ancestors 'none'", $csp);
|
|
// ALTCHA solves its proof-of-work inside blob: Web Workers; without this
|
|
// directive the login captcha errors out (worker-src falls back to script-src).
|
|
self::assertStringContainsString("worker-src 'self' blob:", $csp);
|
|
}
|
|
|
|
public function testNonAdminResponseDoesNotGetTheAdminCsp(): void
|
|
{
|
|
$client = static::createClient();
|
|
$client->request('GET', '/api/v1/doctors');
|
|
|
|
$csp = (string) $client->getResponse()->headers->get('Content-Security-Policy');
|
|
// The admin policy allows scripts from 'self'; the API policy is default-src 'none'.
|
|
// Either way the admin-specific script-src must not leak onto /api.
|
|
self::assertStringNotContainsString("script-src 'self'", $csp);
|
|
}
|
|
}
|