mirror of
https://github.com/dartdavros/chatballs.git
synced 2026-10-10 11:25:00 +03:00
- CORS_ALLOWED_ORIGINS read from HUB_CORS_ALLOWED_ORIGINS (comma-separated), defaulting to the local dev origins; production sets real domains via env - document the variable in .env.example - tests cover allowed/unknown origin and preflight short-circuit Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
22 lines
1.0 KiB
Python
22 lines
1.0 KiB
Python
from django.test import TestCase, override_settings
|
|
|
|
|
|
@override_settings(CORS_ALLOWED_ORIGINS=["http://localhost:5173"])
|
|
class LocalCorsMiddlewareTests(TestCase):
|
|
def test_allowed_origin_receives_cors_headers(self) -> None:
|
|
response = self.client.get("/api/v1/auth/session/", HTTP_ORIGIN="http://localhost:5173")
|
|
|
|
self.assertEqual(response["Access-Control-Allow-Origin"], "http://localhost:5173")
|
|
self.assertEqual(response["Access-Control-Allow-Credentials"], "true")
|
|
|
|
def test_unknown_origin_gets_no_cors_headers(self) -> None:
|
|
response = self.client.get("/api/v1/auth/session/", HTTP_ORIGIN="https://evil.example")
|
|
|
|
self.assertFalse(response.has_header("Access-Control-Allow-Origin"))
|
|
|
|
def test_preflight_from_allowed_origin_short_circuits(self) -> None:
|
|
response = self.client.options("/api/v1/auth/session/", HTTP_ORIGIN="http://localhost:5173")
|
|
|
|
self.assertEqual(response.status_code, 204)
|
|
self.assertEqual(response["Access-Control-Allow-Origin"], "http://localhost:5173")
|