forked from electerious/Ackee
-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathserverWithAutoCors.js
60 lines (45 loc) · 1.89 KB
/
serverWithAutoCors.js
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
'use strict'
const test = require('ava')
const listen = require('test-listen')
const fetch = require('node-fetch')
const mockedEnv = require('mocked-env')
const server = require('../src/server')
const Domain = require('../src/models/Domain')
const { connectToDatabase, disconnectFromDatabase } = require('./resolvers/_utils')
const base = listen(server)
test.before(connectToDatabase)
test.after.always(disconnectFromDatabase)
test.beforeEach(async (t) => {
t.context.domain1 = await Domain.create({ title: 'fqdn.example.com' })
t.context.domain2 = await Domain.create({ title: 'not-an-fqdn' })
})
test.afterEach.always(async (t) => {
await Domain.findOneAndDelete({ id: t.context.domain1.id })
await Domain.findOneAndDelete({ id: t.context.domain2.id })
})
test('return cors headers for domain with fully qualifed domain name', async (t) => {
const url = new URL('/api', await base)
const origin = 'fqdn.example.com'
const restore = mockedEnv({
ACKEE_AUTO_ORIGIN: 'true',
})
const { headers } = await fetch(url.href, { headers: { Host: origin } })
t.is(headers.get('Access-Control-Allow-Origin'), origin)
t.is(headers.get('Access-Control-Allow-Methods'), 'GET, POST, PATCH, OPTIONS')
t.is(headers.get('Access-Control-Allow-Headers'), 'Content-Type, Authorization, Time-Zone')
t.is(headers.get('Access-Control-Allow-Credentials'), 'true')
restore()
})
test('do not return cors headers for domain that is not a fully qualified domain name', async (t) => {
const url = new URL('/api', await base)
const origin = 'not-an-fqdn'
const restore = mockedEnv({
ACKEE_AUTO_ORIGIN: 'true',
})
const { headers } = await fetch(url.href, { headers: { Host: origin } })
t.is(headers.get('Access-Control-Allow-Origin'), null)
t.is(headers.get('Access-Control-Allow-Methods'), null)
t.is(headers.get('Access-Control-Allow-Headers'), null)
t.is(headers.get('Access-Control-Allow-Credentials'), null)
restore()
})