CI & Build / Python lint (push) Successful in 2s
CI & Build / Build now, or wait for Android? (push) Successful in 2s
Android / Build, or is the channel already serving this? (push) Successful in 3s
Desktop (Tauri) / Build, or is the channel already serving this? (push) Successful in 2s
CI & Build / TypeScript typecheck (push) Successful in 7s
CI & Build / Python tests (push) Successful in 15s
CI & Build / integration (push) Successful in 45s
CI & Build / Build & push image (push) Skipped
Desktop (Tauri) / Windows installer (cross-compiled) (push) Successful in 4m17s
Desktop (Tauri) / Tauri desktop (Linux) (push) Successful in 7m33s
Desktop (Tauri) / Update manifest (push) Successful in 7s
Android / Kotlin + Rust (APK) (push) Successful in 11m25s
Step 2 of milestone 481. The operator chose a full rename (Scribe note 5071), so this goes past the display strings into the identities: - src/thoughtsync → src/inkwell; every import, the Dockerfile and both compose commands, alembic env, pyproject - THOUGHTSYNC_* → INKWELL_* (database URL, secret key, log level, tag/port/bind) - container data dir /var/thoughtsync → /var/inkwell - image git.fabledsword.com/bvandeusen/inkwell; Postgres user/db default inkwell; CI's integration service follows - the files the image serves are inkwell.*. fetch-clients.sh still fetches the thoughtsync-named release assets, because the lanes that publish them are renamed in steps 3 and 4 - exports are written with app "inkwell" Two deliberate exceptions, both because data rides on them: - compose volumes are now named explicitly and overridable (INKWELL_DB_VOLUME, INKWELL_DATA_VOLUME), so a deployment installed as ThoughtSync points at the volumes and DB identity it already has. .env.example says exactly what to set - import still accepts app "thoughtsync", because exports written before the rename are backups. Tested both ways Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
58 lines
2.2 KiB
Python
58 lines
2.2 KiB
Python
"""Headers every response carries once this is reachable from the internet.
|
|
|
|
Asserted on /api/health because it is the one route that needs no database and no
|
|
session — the headers are set in an after_request hook, so any response proves the
|
|
hook, and this suite has no Postgres.
|
|
"""
|
|
import pytest
|
|
|
|
from inkwell.app import create_app
|
|
|
|
|
|
@pytest.fixture
|
|
def app():
|
|
return create_app()
|
|
|
|
|
|
async def test_content_security_policy_locks_scripts_to_self(app):
|
|
resp = await app.test_client().get("/api/health")
|
|
csp = resp.headers["Content-Security-Policy"]
|
|
assert "script-src 'self'" in csp
|
|
# The two that matter most if anything ever reflects user text into the page.
|
|
assert "object-src 'none'" in csp
|
|
assert "frame-ancestors 'none'" in csp
|
|
# No blanket unsafe-inline for SCRIPT — style is the only place it's conceded.
|
|
assert "script-src 'self' 'unsafe-inline'" not in csp
|
|
|
|
|
|
async def test_link_preview_images_are_still_allowed(app):
|
|
resp = await app.test_client().get("/api/health")
|
|
csp = resp.headers["Content-Security-Policy"]
|
|
# A preview renders the og:image of an arbitrary host; both schemes, because a
|
|
# LAN install is served over http.
|
|
assert "img-src" in csp
|
|
assert "https:" in csp
|
|
assert "http:" in csp
|
|
|
|
|
|
async def test_sniffing_and_referrer_are_pinned(app):
|
|
resp = await app.test_client().get("/api/health")
|
|
assert resp.headers["X-Content-Type-Options"] == "nosniff"
|
|
assert resp.headers["Referrer-Policy"] == "strict-origin-when-cross-origin"
|
|
assert "camera=()" in resp.headers["Permissions-Policy"]
|
|
|
|
|
|
async def test_no_hsts_on_plain_http(app):
|
|
# A plain-HTTP LAN install must not be told to refuse the only scheme it serves.
|
|
resp = await app.test_client().get("/api/health")
|
|
assert "Strict-Transport-Security" not in resp.headers
|
|
|
|
|
|
async def test_hsts_when_a_proxy_terminated_tls(app):
|
|
resp = await app.test_client().get("/api/health", headers={"X-Forwarded-Proto": "https"})
|
|
hsts = resp.headers["Strict-Transport-Security"]
|
|
assert "max-age=" in hsts
|
|
# Scoped to this host: neither of these commits domains the app doesn't own.
|
|
assert "includeSubDomains" not in hsts
|
|
assert "preload" not in hsts
|