From 977be2679031d0ab5b382f2096b8d313f3291a21 Mon Sep 17 00:00:00 2001 From: Bryce Kwon Date: Sun, 6 Sep 2026 20:58:03 -1000 Subject: Refresh the server configs and drop `unsafe-inline` The inline handlers and the auto-submitting selects are gone, so `script-src` no longer needs it, and t0004 now checks that the three configs pin the same policy. --- tests/t0004-docs.sh | 18 ++++++++++++++++-- 1 file changed, 16 insertions(+), 2 deletions(-) (limited to 'tests') diff --git a/tests/t0004-docs.sh b/tests/t0004-docs.sh index 292223f..85a4d8e 100755 --- a/tests/t0004-docs.sh +++ b/tests/t0004-docs.sh @@ -2,8 +2,9 @@ # Checks that the configuration documents stay consistent with each other. # The manual documents every key the reference config sets, the reference -# config sets every key the manual documents, and both settings sections of -# the manual keep their entries sorted. +# config sets every key the manual documents, both settings sections of the +# manual keep their entries sorted, and the three server configs carry one +# identical content security policy. test_description='Check the configuration documents' . ./setup.sh @@ -49,4 +50,17 @@ test_expect_success 'the manual lists its repository settings in order' ' LC_ALL=C sort -c repo-order ' +# The policy is spelled out once per server syntax, so nothing but this check +# keeps the three copies from drifting apart. +test_expect_success 'the server configs agree on one content security policy' ' + for server in apache lighttpd nginx; do + grep "Content-Security-Policy" \ + "$ROOT/custom/servers/$server.conf" | + grep "default-src" | + sed "s/.*\"\(default-src[^\"]*\)\".*/\1/" || return 1 + done >policies && + test_line_count = 3 policies && + test $(sort -u policies | wc -l) -eq 1 +' + test_done -- cgit v2.8.0