[CmdletBinding()] param( [Parameter(Mandatory = $true)] [string]$BaseUrl, [string]$TestBaseUrl ) $script:failures = 0 function Report { param($ok, $label, $detail) if ($ok) { Write-Output "PASS: $label" } else { Write-Output "FAIL: $label ($detail)" $script:failures++ } } try { $resp = Invoke-WebRequest -Uri "$BaseUrl/hello" -UseBasicParsing Report ($resp.StatusCode -eq 200) "GET /hello status 200" "got $($resp.StatusCode)" Report ($resp.Headers['Content-Type'] -eq 'text/html; charset=utf-8') "GET /hello content-type" "got $($resp.Headers['Content-Type'])" Report ($resp.Content -eq 'Hello from WSC-MVC!') "GET /hello body" "got '$($resp.Content)'" } catch { Report $false "GET /hello request" $_.Exception.Message } try { $rootResp = Invoke-WebRequest -Uri "$BaseUrl/" -UseBasicParsing Report ($rootResp.StatusCode -eq 200) "GET / status 200" "got $($rootResp.StatusCode)" Report ($rootResp.Content -eq 'Hello from WSC-MVC!') "GET / maps to /hello" "got '$($rootResp.Content)'" } catch { Report $false "GET / request" $_.Exception.Message } # /self-test lives on the separate test-app/ site now (see docs/ARCHITECTURE.md # and tests/run-self-test.sh, which is what actually exercises it) - this # script tests the production app only. Confirm the diagnostics endpoint is # genuinely NOT exposed here, since that separation is the point. try { $selfTestResp = Invoke-WebRequest -Uri "$BaseUrl/self-test" -UseBasicParsing Report $false "GET /self-test not exposed on production" "got $($selfTestResp.StatusCode)" } catch [System.Net.WebException] { $webResp = $_.Exception.Response if ($webResp) { $code = [int]$webResp.StatusCode Report ($code -eq 404) "GET /self-test not exposed on production" "got $code" } else { Report $false "GET /self-test not exposed on production" $_.Exception.Message } } catch { Report $false "GET /self-test not exposed on production" $_.Exception.Message } # A caller can request Default.asp directly and supply the internal route # query string, bypassing URL Rewrite. The per-app route-set argument must # still prevent production from activating the test controller. try { $directSelfTestResp = Invoke-WebRequest -Uri "$BaseUrl/Default.asp?route=/self-test" -UseBasicParsing Report $false "direct Default.asp cannot cross into test routes" "got $($directSelfTestResp.StatusCode)" } catch [System.Net.WebException] { $webResp = $_.Exception.Response if ($webResp) { $code = [int]$webResp.StatusCode Report ($code -eq 404) "direct Default.asp cannot cross into test routes" "got $code" } else { Report $false "direct Default.asp cannot cross into test routes" $_.Exception.Message } } catch { Report $false "direct Default.asp cannot cross into test routes" $_.Exception.Message } if ($TestBaseUrl) { try { $directHelloResp = Invoke-WebRequest -Uri "$TestBaseUrl/Default.asp?route=/hello" -UseBasicParsing Report $false "test app cannot cross into production routes" "got $($directHelloResp.StatusCode)" } catch [System.Net.WebException] { $webResp = $_.Exception.Response if ($webResp) { $code = [int]$webResp.StatusCode Report ($code -eq 404) "test app cannot cross into production routes" "got $code" } else { Report $false "test app cannot cross into production routes" $_.Exception.Message } } catch { Report $false "test app cannot cross into production routes" $_.Exception.Message } } # Framework/ is a sibling of the "public" webroot, not a rule-denied # subfolder within it - this checks it's genuinely unreachable, not just # filtered. try { $wscResp = Invoke-WebRequest -Uri "$BaseUrl/Framework/Application.wsc" -UseBasicParsing Report $false "GET /Framework/Application.wsc unreachable" "got $($wscResp.StatusCode)" } catch [System.Net.WebException] { $webResp = $_.Exception.Response if ($webResp) { $code = [int]$webResp.StatusCode Report ($code -eq 404) "GET /Framework/Application.wsc unreachable" "got $code" } else { Report $false "GET /Framework/Application.wsc unreachable" $_.Exception.Message } } catch { Report $false "GET /Framework/Application.wsc unreachable" $_.Exception.Message } Write-Output "---" if ($script:failures -eq 0) { Write-Output "RESULT: ALL PASS" exit 0 } else { Write-Output "RESULT: $($script:failures) FAILURE(S)" exit 1 }