Some checks failed
Test examples / Test Examples (20) (push) Has been cancelled
Test examples / Test Examples (22) (push) Has been cancelled
Lock Threads / action (push) Has been cancelled
Trigger Release / start (push) Has been cancelled
Stale issue handler / stale (push) Has been cancelled
Update Font Data / create-pull-request (push) Has been cancelled
build-and-deploy / deploy-target (push) Has been cancelled
build-and-deploy / build (push) Has been cancelled
build-and-deploy / stable - aarch64-unknown-linux-musl - node@16 (push) Has been cancelled
build-and-deploy / stable - x86_64-unknown-linux-musl - node@16 (push) Has been cancelled
build-and-deploy / stable - aarch64-unknown-linux-gnu - node@16 (push) Has been cancelled
build-and-deploy / stable - x86_64-unknown-linux-gnu - node@16 (push) Has been cancelled
build-and-deploy / stable - aarch64-pc-windows-msvc - node@16 (push) Has been cancelled
build-and-deploy / stable - x86_64-pc-windows-msvc - node@16 (push) Has been cancelled
build-and-deploy / stable - aarch64-apple-darwin - node@16 (push) Has been cancelled
build-and-deploy / stable - x86_64-apple-darwin - node@16 (push) Has been cancelled
build-and-deploy / build-wasm (nodejs) (push) Has been cancelled
build-and-deploy / build-wasm (web) (push) Has been cancelled
build-and-deploy / Deploy preview tarball (push) Has been cancelled
build-and-deploy / Potentially publish release (push) Has been cancelled
build-and-deploy / publish-turbopack-npm-packages (push) Has been cancelled
build-and-deploy / Deploy examples (push) Has been cancelled
build-and-deploy / thank you, build (push) Has been cancelled
build-and-deploy / Upload Turbopack Bytesize metrics to Datadog (push) Has been cancelled
Rspack Next.js development integration tests / Rspack integration tests (push) Has been cancelled
Rspack Next.js production integration tests / Rspack integration tests (push) Has been cancelled
Turbopack Next.js development integration tests / Next.js integration tests (push) Has been cancelled
Turbopack Next.js production integration tests / Next.js integration tests (push) Has been cancelled
Update Rspack test manifest / Update and upload Rspack development test manifest (push) Has been cancelled
Update Rspack test manifest / Update and upload Rspack production test manifest (push) Has been cancelled
Upload bundler test manifests to areweturboyet.com / Upload test results (push) Has been cancelled
Update React / create-pull-request (push) Has been cancelled
test-e2e-project-reset-cron / reset-test-project (push) Has been cancelled
Notify about the top 15 issues/PRs/feature requests (most reacted) in the last 90 days / run (push) Has been cancelled
83 lines
2.6 KiB
TypeScript
83 lines
2.6 KiB
TypeScript
import { join } from 'path'
|
|
import webdriver from 'next-webdriver'
|
|
import { createNext, FileRef } from 'e2e-utils'
|
|
import { NextInstance } from 'e2e-utils'
|
|
import { fetchViaHTTP, renderViaHTTP } from 'next-test-utils'
|
|
|
|
describe.each([[''], ['/docs']])(
|
|
'misc basic dev tests, basePath: %p',
|
|
(basePath: string) => {
|
|
let next: NextInstance
|
|
|
|
beforeAll(async () => {
|
|
next = await createNext({
|
|
files: {
|
|
pages: new FileRef(join(__dirname, 'misc/pages')),
|
|
public: new FileRef(join(__dirname, 'misc/public')),
|
|
},
|
|
nextConfig: {
|
|
basePath,
|
|
},
|
|
})
|
|
})
|
|
afterAll(() => next.destroy())
|
|
|
|
it('should set process.env.NODE_ENV in development', async () => {
|
|
const browser = await webdriver(next.url, basePath + '/process-env')
|
|
const nodeEnv = await browser.elementByCss('#node-env').text()
|
|
expect(nodeEnv).toBe('development')
|
|
await browser.close()
|
|
})
|
|
|
|
it('should allow access to public files', async () => {
|
|
const data = await renderViaHTTP(next.url, basePath + '/data/data.txt')
|
|
expect(data).toBe('data')
|
|
|
|
const legacy = await renderViaHTTP(
|
|
next.url,
|
|
basePath + '/static/legacy.txt'
|
|
)
|
|
expect(legacy).toMatch(`new static folder`)
|
|
})
|
|
|
|
describe('With Security Related Issues', () => {
|
|
it('should not allow accessing files outside .next/static and .next/server directory', async () => {
|
|
const pathsToCheck = [
|
|
basePath + '/_next/static/../BUILD_ID',
|
|
basePath + '/_next/static/../routes-manifest.json',
|
|
]
|
|
for (const path of pathsToCheck) {
|
|
const res = await fetchViaHTTP(next.url, path)
|
|
const text = await res.text()
|
|
try {
|
|
expect(res.status).toBe(404)
|
|
expect(text).toMatch(/This page could not be found/)
|
|
} catch (err) {
|
|
throw new Error(`Path ${path} accessible from the browser`)
|
|
}
|
|
}
|
|
})
|
|
|
|
it('should handle encoded / value for trailing slash correctly', async () => {
|
|
const res = await fetchViaHTTP(
|
|
next.url,
|
|
basePath + '/%2fexample.com/',
|
|
undefined,
|
|
{
|
|
redirect: 'manual',
|
|
}
|
|
)
|
|
|
|
const { pathname, hostname } = new URL(
|
|
res.headers.get('location') || ''
|
|
)
|
|
expect(res.status).toBe(308)
|
|
expect(pathname).toBe(basePath + '/%2fexample.com')
|
|
expect(hostname).not.toBe('example.com')
|
|
const text = await res.text()
|
|
expect(text).toEqual(basePath + '/%2fexample.com')
|
|
})
|
|
})
|
|
}
|
|
)
|