From 4d16a1a73c3f9b9fd989d8ade485c1653a7b537d Mon Sep 17 00:00:00 2001 From: fangliquan Date: Mon, 17 Aug 2026 01:10:11 +0800 Subject: [PATCH] test(dashboard-auth): cover empty login route behavior --- .../test_dashboard_auth_middleware.py | 26 +++++++++++++++++++ 1 file changed, 26 insertions(+) diff --git a/tests/hermes_cli/test_dashboard_auth_middleware.py b/tests/hermes_cli/test_dashboard_auth_middleware.py index 3523cfb009..56e5d9c2bb 100644 --- a/tests/hermes_cli/test_dashboard_auth_middleware.py +++ b/tests/hermes_cli/test_dashboard_auth_middleware.py @@ -50,6 +50,32 @@ def gated_app(): # --------------------------------------------------------------------------- +@pytest.mark.parametrize( + "next_value", + [ + "", + "javascript:alert(1)", + "../../etc/passwd", + "canary\r\nSet-Cookie: injected=1", + ], +) +def test_empty_provider_login_page_is_safe_through_real_route( + gated_app, next_value +): + clear_providers() + + response = gated_app.get("/login", params={"next": next_value}) + + assert response.status_code == 200 + assert "text/html" in response.headers["content-type"] + assert "no-store" in response.headers["cache-control"] + assert "Sign-in unavailable" in response.text + assert "username/password provider" in response.text + assert "OAuth provider" in response.text + assert "--insecure" not in response.text + assert next_value not in response.text + + def test_gated_status_is_public(gated_app): """``/api/status`` MUST be public under the OAuth gate.