feat: per-file Cache-Control, navigation-scoped SPA fallback, nosniff, non-root image; v1.7.0
- Cache-Control per file: no-cache for index.html + service workers, immutable 1y for content-hashed assets, 1h for the rest (Vite/CRA/Angular). Closes the stale-release trap at the HTTP layer that the v1.6.0 image fix closed at the container layer. - SPA fallback scoped to navigation: a missing asset (path w/ extension) or a non-HTML Accept now returns 404 instead of index.html (no more HTML-as-JS 'Unexpected token <'). - X-Content-Type-Options: nosniff on every response. - Image runs as a non-root 'spa' user. - README: caching table, fallback contract, and the Angular dist/<project>/browser/ note.
This commit is contained in:
@@ -0,0 +1,19 @@
|
||||
package spaserver
|
||||
|
||||
import (
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
"testing"
|
||||
)
|
||||
|
||||
// securityHeaders must stamp nosniff on every response, regardless of the route.
|
||||
func TestSecurityHeaders_Nosniff(t *testing.T) {
|
||||
h := securityHeaders(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) {
|
||||
w.WriteHeader(http.StatusOK)
|
||||
}))
|
||||
rec := httptest.NewRecorder()
|
||||
h.ServeHTTP(rec, httptest.NewRequest(http.MethodGet, "/", nil))
|
||||
if got := rec.Header().Get("X-Content-Type-Options"); got != "nosniff" {
|
||||
t.Fatalf("X-Content-Type-Options = %q, want nosniff", got)
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user