Vous ne pouvez pas sélectionner plus de 25 sujets Les noms de sujets doivent commencer par une lettre ou un nombre, peuvent contenir des tirets ('-') et peuvent comporter jusqu'à 35 caractères.

157 lignes
6.2KB

  1. [CmdletBinding()]
  2. param(
  3. [Parameter(Mandatory = $true)]
  4. [string]$BaseUrl,
  5. [string]$TestBaseUrl
  6. )
  7. $script:failures = 0
  8. function Report {
  9. param($ok, $label, $detail)
  10. if ($ok) {
  11. Write-Output "PASS: $label"
  12. } else {
  13. Write-Output "FAIL: $label ($detail)"
  14. $script:failures++
  15. }
  16. }
  17. try {
  18. $resp = Invoke-WebRequest -Uri "$BaseUrl/hello" -UseBasicParsing
  19. Report ($resp.StatusCode -eq 200) "GET /hello status 200" "got $($resp.StatusCode)"
  20. Report ($resp.Headers['Content-Type'] -eq 'text/html; charset=utf-8') "GET /hello content-type" "got $($resp.Headers['Content-Type'])"
  21. Report ($resp.Content -eq 'Hello from WSC-MVC!') "GET /hello body" "got '$($resp.Content)'"
  22. } catch {
  23. Report $false "GET /hello request" $_.Exception.Message
  24. }
  25. try {
  26. $postHelloResp = Invoke-WebRequest -Uri "$BaseUrl/hello" -Method Post -UseBasicParsing
  27. Report $false "POST /hello returns 405" "got $($postHelloResp.StatusCode)"
  28. } catch [System.Net.WebException] {
  29. $webResp = $_.Exception.Response
  30. if ($webResp) {
  31. $code = [int]$webResp.StatusCode
  32. Report ($code -eq 405) "POST /hello returns 405" "got $code"
  33. Report ($webResp.Headers['Allow'] -eq 'GET') "POST /hello Allow header" "got '$($webResp.Headers['Allow'])'"
  34. } else {
  35. Report $false "POST /hello returns 405" $_.Exception.Message
  36. }
  37. } catch {
  38. Report $false "POST /hello returns 405" $_.Exception.Message
  39. }
  40. try {
  41. $badPathResp = Invoke-WebRequest -Uri "$BaseUrl/Default.asp?route=/hello/../secret" -UseBasicParsing
  42. Report $false "malformed route returns 400" "got $($badPathResp.StatusCode)"
  43. } catch [System.Net.WebException] {
  44. $webResp = $_.Exception.Response
  45. if ($webResp) {
  46. $code = [int]$webResp.StatusCode
  47. Report ($code -eq 400) "malformed route returns 400" "got $code"
  48. } else {
  49. Report $false "malformed route returns 400" $_.Exception.Message
  50. }
  51. } catch {
  52. Report $false "malformed route returns 400" $_.Exception.Message
  53. }
  54. try {
  55. $rootResp = Invoke-WebRequest -Uri "$BaseUrl/" -UseBasicParsing
  56. Report ($rootResp.StatusCode -eq 200) "GET / status 200" "got $($rootResp.StatusCode)"
  57. Report ($rootResp.Content -eq 'Hello from WSC-MVC!') "GET / maps to /hello" "got '$($rootResp.Content)'"
  58. } catch {
  59. Report $false "GET / request" $_.Exception.Message
  60. }
  61. # /self-test lives on the separate test-app/ site now (see docs/ARCHITECTURE.md
  62. # and tests/run-self-test.sh, which is what actually exercises it) - this
  63. # script tests the production app only. Confirm the diagnostics endpoint is
  64. # genuinely NOT exposed here, since that separation is the point.
  65. try {
  66. $selfTestResp = Invoke-WebRequest -Uri "$BaseUrl/self-test" -UseBasicParsing
  67. Report $false "GET /self-test not exposed on production" "got $($selfTestResp.StatusCode)"
  68. } catch [System.Net.WebException] {
  69. $webResp = $_.Exception.Response
  70. if ($webResp) {
  71. $code = [int]$webResp.StatusCode
  72. Report ($code -eq 404) "GET /self-test not exposed on production" "got $code"
  73. } else {
  74. Report $false "GET /self-test not exposed on production" $_.Exception.Message
  75. }
  76. } catch {
  77. Report $false "GET /self-test not exposed on production" $_.Exception.Message
  78. }
  79. # A caller can request Default.asp directly and supply the internal route
  80. # query string, bypassing URL Rewrite. The per-app route-set argument must
  81. # still prevent production from activating the test controller.
  82. try {
  83. $directSelfTestResp = Invoke-WebRequest -Uri "$BaseUrl/Default.asp?route=/self-test" -UseBasicParsing
  84. Report $false "direct Default.asp cannot cross into test routes" "got $($directSelfTestResp.StatusCode)"
  85. } catch [System.Net.WebException] {
  86. $webResp = $_.Exception.Response
  87. if ($webResp) {
  88. $code = [int]$webResp.StatusCode
  89. Report ($code -eq 404) "direct Default.asp cannot cross into test routes" "got $code"
  90. } else {
  91. Report $false "direct Default.asp cannot cross into test routes" $_.Exception.Message
  92. }
  93. } catch {
  94. Report $false "direct Default.asp cannot cross into test routes" $_.Exception.Message
  95. }
  96. if ($TestBaseUrl) {
  97. try {
  98. $directHelloResp = Invoke-WebRequest -Uri "$TestBaseUrl/Default.asp?route=/hello" -UseBasicParsing
  99. Report $false "test app cannot cross into production routes" "got $($directHelloResp.StatusCode)"
  100. } catch [System.Net.WebException] {
  101. $webResp = $_.Exception.Response
  102. if ($webResp) {
  103. $code = [int]$webResp.StatusCode
  104. Report ($code -eq 404) "test app cannot cross into production routes" "got $code"
  105. } else {
  106. Report $false "test app cannot cross into production routes" $_.Exception.Message
  107. }
  108. } catch {
  109. Report $false "test app cannot cross into production routes" $_.Exception.Message
  110. }
  111. try {
  112. $postSelfTestResp = Invoke-WebRequest -Uri "$TestBaseUrl/self-test" -Method Post -UseBasicParsing
  113. Report ($postSelfTestResp.StatusCode -eq 200) "POST /self-test on test app status 200" "got $($postSelfTestResp.StatusCode)"
  114. Report ($postSelfTestResp.Headers['Content-Type'] -eq 'application/json; charset=utf-8') "POST /self-test content-type" "got $($postSelfTestResp.Headers['Content-Type'])"
  115. } catch {
  116. Report $false "POST /self-test on test app" $_.Exception.Message
  117. }
  118. }
  119. # Framework/ is a sibling of the "public" webroot, not a rule-denied
  120. # subfolder within it - this checks it's genuinely unreachable, not just
  121. # filtered.
  122. try {
  123. $wscResp = Invoke-WebRequest -Uri "$BaseUrl/Framework/Application.wsc" -UseBasicParsing
  124. Report $false "GET /Framework/Application.wsc unreachable" "got $($wscResp.StatusCode)"
  125. } catch [System.Net.WebException] {
  126. $webResp = $_.Exception.Response
  127. if ($webResp) {
  128. $code = [int]$webResp.StatusCode
  129. Report ($code -eq 404) "GET /Framework/Application.wsc unreachable" "got $code"
  130. } else {
  131. Report $false "GET /Framework/Application.wsc unreachable" $_.Exception.Message
  132. }
  133. } catch {
  134. Report $false "GET /Framework/Application.wsc unreachable" $_.Exception.Message
  135. }
  136. Write-Output "---"
  137. if ($script:failures -eq 0) {
  138. Write-Output "RESULT: ALL PASS"
  139. exit 0
  140. } else {
  141. Write-Output "RESULT: $($script:failures) FAILURE(S)"
  142. exit 1
  143. }

Powered by TurnKey Linux.