From a8f7e4639b79718b06b958bb3c06c82e97bfe31b Mon Sep 17 00:00:00 2001 From: Bryce Kwon Date: Thu, 1 Oct 2026 20:13:25 -1000 Subject: Mark a page behind an auth filter private Only the login page carried a Cache-Control, so a page an auth filter had let a visitor see could be kept by a cache shared with the next visitor. The page also varies on the cookie that got them in. --- tests/t0303-robustness.sh | 22 ++++++++++++++++++++++ 1 file changed, 22 insertions(+) (limited to 'tests') diff --git a/tests/t0303-robustness.sh b/tests/t0303-robustness.sh index fd1c02e..8dff969 100755 --- a/tests/t0303-robustness.sh +++ b/tests/t0303-robustness.sh @@ -545,6 +545,28 @@ test_expect_success 'a client that disconnects ends the request quietly' ' ! grep "die()" err ' +# A page an auth filter let a visitor see is theirs alone, so a cache +# shared with other visitors has to be told, while a site without a filter +# keeps its pages free of any such header. +test_expect_success 'pages behind an auth filter are marked private' ' + cat >letin.sh <<-\EOF && + #!/bin/sh + exit 1 + EOF + chmod +x letin.sh && + { + echo "auth-filter=exec:$PWD/letin.sh" && + cat robrc + } >letinrc && + CGIT_CONFIG="$PWD/letinrc" QUERY_STRING="url=rob/log/" cgit >tmp && + grep "^Status: 200" tmp && + grep "^Cache-Control: private$" tmp && + grep "^Vary: Cookie$" tmp && + robq "url=rob/log/" >tmp && + ! grep "^Cache-Control" tmp && + ! grep "^Vary" tmp +' + # The about page redirects to its trailing-slash form so relative links # resolve, and the branch asked for has to survive that hop, as does the # hop back to the summary of a repository without a readme. -- cgit v2.8.0