fix(test): avoid unhandled header injection rejection
This commit is contained in:
1 parent
c0374eeb34
commit
c036fab353
1 file changed
+4
-8
@@ -180,18 +180,14 @@ describe('Security Features', () => {
|
|||||||
}, 20000);
|
}, 20000);
|
||||||
|
|
||||||
it('should handle header injection attempts', async () => {
|
it('should handle header injection attempts', async () => {
|
||||||
// Headers with CRLF injection should be rejected by the runtime
|
// Malformed headers should be rejected before the request is dispatched.
|
||||||
try {
|
expect(() => {
|
||||||
await SELF.fetch('https://example.com/gh/test/repo', {
|
new Request('https://example.com/gh/test/repo', {
|
||||||
headers: {
|
headers: {
|
||||||
'X-Test': 'value\r\nX-Injected: malicious'
|
'X-Test': 'value\r\nX-Injected: malicious'
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
// If it doesn't throw, it should not be a server error
|
}).toThrow(/[Ii]nvalid|[Hh]eader/);
|
||||||
} catch (error) {
|
|
||||||
// Expected to throw TypeError for invalid header value
|
|
||||||
expect(/** @type {Error} */ (error).message).toMatch(/[Ii]nvalid|[Hh]eader/);
|
|
||||||
}
|
|
||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|||||||
Reference in new issue
Block a user