giteabot backport / giteabot (push) Canceled after 0s
giteabot / giteabot (push) Canceled after 0s
release-nightly / nightly-binary (push) Canceled after 0s
release-nightly / nightly-container (push) Canceled after 0s
cache-seeder / gobuild (push) Canceled after 0s
cache-seeder / lint (bindata, lint-backend) (push) Canceled after 0s
release-nightly-snapcraft / build-and-publish (push) Canceled after 0s
Includes direct password setup links in registration emails. Assisted-by: Codex:GPT-5
30 lines
873 B
Go
30 lines
873 B
Go
// Copyright 2026 The Gitea Authors. All rights reserved.
|
|
// SPDX-License-Identifier: MIT
|
|
|
|
package setting
|
|
|
|
import (
|
|
"testing"
|
|
|
|
"github.com/stretchr/testify/assert"
|
|
)
|
|
|
|
func TestLoadSecurityFrom(t *testing.T) {
|
|
assert.Equal(t, "SAMEORIGIN", Security.XFrameOptions)
|
|
assert.Equal(t, "nosniff", Security.XContentTypeOptions)
|
|
assert.Equal(t, "external", Security.AllowedHostList)
|
|
|
|
cfg, err := NewConfigProviderFromData(`[security]
|
|
X_FRAME_OPTIONS = DENY
|
|
X_CONTENT_TYPE_OPTIONS = unset
|
|
ALLOWED_HOST_LIST = foo
|
|
CONTENT_SECURITY_POLICY_GENERAL = "script-src *; foo"
|
|
`)
|
|
assert.NoError(t, err)
|
|
loadSecurityFrom(cfg)
|
|
assert.Equal(t, "DENY", Security.XFrameOptions)
|
|
assert.Equal(t, "unset", Security.XContentTypeOptions)
|
|
assert.Equal(t, "foo", Security.AllowedHostList)
|
|
assert.Equal(t, `"script-src *`, Security.ContentSecurityPolicyGeneral) // holy shit ini package bug
|
|
}
|