diff options
Diffstat (limited to 'internal/liturgy/fetch_test.go')
| -rw-r--r-- | internal/liturgy/fetch_test.go | 68 |
1 files changed, 0 insertions, 68 deletions
diff --git a/internal/liturgy/fetch_test.go b/internal/liturgy/fetch_test.go deleted file mode 100644 index c06f0f8..0000000 --- a/internal/liturgy/fetch_test.go +++ /dev/null @@ -1,68 +0,0 @@ -package liturgy - -import ( - "net/http" - "net/http/httptest" - "os" - "path/filepath" - "testing" -) - -func TestLoadCaches(t *testing.T) { - html, _ := os.ReadFile("testdata/2026-06-22.html") - hits := 0 - srv := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { - hits++ - w.Write(html) - })) - defer srv.Close() - t.Setenv("XDG_CACHE_HOME", t.TempDir()) - baseURL = srv.URL + "/liturgia/%s/Ewangelia" // test hook - - secs1, info1, err := Load(Options{Date: "2026-06-22"}) - if err != nil || len(secs1) == 0 { - t.Fatalf("load1: %v", err) - } - if info1.Name == "" { - t.Error("load1: DayInfo.Name empty, want it populated from the freshly-parsed HTML") - } - secs2, info2, _ := Load(Options{Date: "2026-06-22"}) // should hit JSON cache - if hits != 1 { - t.Errorf("server hit %d times, want 1 (cache miss on repeat)", hits) - } - if len(secs2) != len(secs1) { - t.Error("cache returned different section count") - } - // The JSON cache round-trips DayInfo (see cachedDay/loadCache), so a - // cache-hit repeat load must not lose it. - if info2 != info1 { - t.Errorf("cache-hit DayInfo = %+v, want it to match the first load's %+v", info2, info1) - } -} - -// TestLoadRejectsInvalidDate is the liturgy-layer defense-in-depth check for -// the ?date= path-traversal finding: Load must reject a non-YYYY-MM-DD date -// before it ever builds a filesystem path from it, so every caller (web, -// cli, tui) is protected even if a future caller forgets to validate. -// -// The planted "passwd.json" sits one level *above* CacheDir() -- reachable -// only via a "../" date -- so if Load ever built jsonPath from the raw date -// unchecked, loadCache would read it back and return its section instead -// of an error. -func TestLoadRejectsInvalidDate(t *testing.T) { - dir := t.TempDir() - t.Setenv("XDG_CACHE_HOME", dir) - - evilPath := filepath.Join(dir, "passwd.json") - if err := os.WriteFile(evilPath, []byte(`[{"Heading":"SHOULD-NEVER-BE-READ"}]`), 0o644); err != nil { - t.Fatal(err) - } - - secs, _, err := Load(Options{Date: "../passwd"}) - if err == nil { - t.Fatalf("Load(Date=%q) = (%v, nil), want a non-nil error", "../passwd", secs) - } - if secs != nil { - t.Errorf("Load(Date=%q) sections = %v, want nil", "../passwd", secs) - } -} |
