Files
chatballs/apps/backend/hub_platform/http/tests.py
T
AndreyandClaude Opus 4.8 f5bec6bf77 🔒 fix(security): make CORS allowlist env-driven (#7)
- CORS_ALLOWED_ORIGINS read from HUB_CORS_ALLOWED_ORIGINS (comma-separated),
  defaulting to the local dev origins; production sets real domains via env
- document the variable in .env.example
- tests cover allowed/unknown origin and preflight short-circuit

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-23 18:40:04 +03:00

22 lines
1.0 KiB
Python

from django.test import TestCase, override_settings
@override_settings(CORS_ALLOWED_ORIGINS=["http://localhost:5173"])
class LocalCorsMiddlewareTests(TestCase):
def test_allowed_origin_receives_cors_headers(self) -> None:
response = self.client.get("/api/v1/auth/session/", HTTP_ORIGIN="http://localhost:5173")
self.assertEqual(response["Access-Control-Allow-Origin"], "http://localhost:5173")
self.assertEqual(response["Access-Control-Allow-Credentials"], "true")
def test_unknown_origin_gets_no_cors_headers(self) -> None:
response = self.client.get("/api/v1/auth/session/", HTTP_ORIGIN="https://evil.example")
self.assertFalse(response.has_header("Access-Control-Allow-Origin"))
def test_preflight_from_allowed_origin_short_circuits(self) -> None:
response = self.client.options("/api/v1/auth/session/", HTTP_ORIGIN="http://localhost:5173")
self.assertEqual(response.status_code, 204)
self.assertEqual(response["Access-Control-Allow-Origin"], "http://localhost:5173")