20 lines
564 B
Go
20 lines
564 B
Go
package spaserver
|
|||
|
|
|
||
|
|
import (
|
||
|
|
"net/http"
|
||
|
|
"net/http/httptest"
|
||
|
|
"testing"
|
||
|
|
)
|
||
|
|
|
||
|
|
// securityHeaders must stamp nosniff on every response, regardless of the route.
|
||
|
|
func TestSecurityHeaders_Nosniff(t *testing.T) {
|
||
|
|
h := securityHeaders(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) {
|
||
|
|
w.WriteHeader(http.StatusOK)
|
||
|
|
}))
|
||
|
|
rec := httptest.NewRecorder()
|
||
|
|
h.ServeHTTP(rec, httptest.NewRequest(http.MethodGet, "/", nil))
|
||
|
|
if got := rec.Header().Get("X-Content-Type-Options"); got != "nosniff" {
|
||
|
|
t.Fatalf("X-Content-Type-Options = %q, want nosniff", got)
|
||
|
|
}
|
||
|
|
}
|