github.com/google/go-safeweb@v0.0.0-20231219055052-64d8cfc90fbb/examples/sample-application/secure/dispatcher_test.go (about)

     1  // Copyright 2022 Google LLC
     2  //
     3  // Licensed under the Apache License, Version 2.0 (the "License");
     4  // you may not use this file except in compliance with the License.
     5  // You may obtain a copy of the License at
     6  //
     7  //	https://www.apache.org/licenses/LICENSE-2.0
     8  //
     9  // Unless required by applicable law or agreed to in writing, software
    10  // distributed under the License is distributed on an "AS IS" BASIS,
    11  // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
    12  // See the License for the specific language governing permissions and
    13  // limitations under the License.
    14  
    15  package secure
    16  
    17  import (
    18  	"net/http"
    19  	"net/http/httptest"
    20  	"strings"
    21  	"testing"
    22  
    23  	"github.com/google/go-safeweb/examples/sample-application/secure/responses"
    24  	"github.com/google/go-safeweb/safehttp"
    25  	"github.com/google/safehtml"
    26  )
    27  
    28  func TestDispatcherError(t *testing.T) {
    29  	tests := []struct {
    30  		name string
    31  		resp safehttp.ErrorResponse
    32  		want string
    33  	}{
    34  		{
    35  			name: "default dispatcher, plaintext",
    36  			resp: safehttp.StatusForbidden,
    37  			want: http.StatusText(int(safehttp.StatusForbidden)),
    38  		},
    39  		{
    40  			name: "custom dispatcher, safe HTML",
    41  			resp: responses.Error{
    42  				StatusCode: safehttp.StatusNotFound,
    43  				Message:    safehtml.HTMLEscaped("<h1>Escaped</h1"),
    44  			},
    45  			want: "<p>&lt;h1&gt;Escaped&lt;/h1</p>",
    46  		},
    47  	}
    48  	for _, tt := range tests {
    49  		t.Run(tt.name, func(t *testing.T) {
    50  			d := dispatcher{}
    51  			rw := httptest.NewRecorder()
    52  			d.Error(rw, tt.resp)
    53  			if op := rw.Body.String(); !strings.Contains(op, tt.want) {
    54  				t.Errorf("body got: %q, want: %q", op, tt.want)
    55  			}
    56  		})
    57  	}
    58  }