diff options
context:
space:
mode:
Diffstat (limited to 'tests')
-rwxr-xr-xtests/t0303-robustness.sh22
1 file changed, 22 insertions, 0 deletions
diff --git a/tests/t0303-robustness.sh b/tests/t0303-robustness.sh
index fd1c02e..8dff969 100755
--- a/tests/t0303-robustness.sh
+++ b/tests/t0303-robustness.sh
@@ -545,6 +545,28 @@ test_expect_success 'a client that disconnects ends the request quietly' '
! grep "die()" err
'
+# A page an auth filter let a visitor see is theirs alone, so a cache
+# shared with other visitors has to be told, while a site without a filter
+# keeps its pages free of any such header.
+test_expect_success 'pages behind an auth filter are marked private' '
+ cat >letin.sh <<-\EOF &&
+ #!/bin/sh
+ exit 1
+ EOF
+ chmod +x letin.sh &&
+ {
+ echo "auth-filter=exec:$PWD/letin.sh" &&
+ cat robrc
+ } >letinrc &&
+ CGIT_CONFIG="$PWD/letinrc" QUERY_STRING="url=rob/log/" cgit >tmp &&
+ grep "^Status: 200" tmp &&
+ grep "^Cache-Control: private$" tmp &&
+ grep "^Vary: Cookie$" tmp &&
+ robq "url=rob/log/" >tmp &&
+ ! grep "^Cache-Control" tmp &&
+ ! grep "^Vary" tmp
+'
+
# The about page redirects to its trailing-slash form so relative links
# resolve, and the branch asked for has to survive that hop, as does the
# hop back to the summary of a repository without a readme.