|
- [CmdletBinding()]
- param(
- [Parameter(Mandatory = $true)]
- [string]$BaseUrl,
- [string]$TestBaseUrl
- )
-
- $script:failures = 0
-
- function Report {
- param($ok, $label, $detail)
- if ($ok) {
- Write-Output "PASS: $label"
- } else {
- Write-Output "FAIL: $label ($detail)"
- $script:failures++
- }
- }
-
- try {
- $resp = Invoke-WebRequest -Uri "$BaseUrl/hello" -UseBasicParsing
- Report ($resp.StatusCode -eq 200) "GET /hello status 200" "got $($resp.StatusCode)"
- Report ($resp.Headers['Content-Type'] -eq 'text/html; charset=utf-8') "GET /hello content-type" "got $($resp.Headers['Content-Type'])"
- Report ($resp.Content -eq 'Hello from WSC-MVC!') "GET /hello body" "got '$($resp.Content)'"
- } catch {
- Report $false "GET /hello request" $_.Exception.Message
- }
-
- try {
- $postHelloResp = Invoke-WebRequest -Uri "$BaseUrl/hello" -Method Post -UseBasicParsing
- Report $false "POST /hello returns 405" "got $($postHelloResp.StatusCode)"
- } catch [System.Net.WebException] {
- $webResp = $_.Exception.Response
- if ($webResp) {
- $code = [int]$webResp.StatusCode
- Report ($code -eq 405) "POST /hello returns 405" "got $code"
- Report ($webResp.Headers['Allow'] -eq 'GET') "POST /hello Allow header" "got '$($webResp.Headers['Allow'])'"
- } else {
- Report $false "POST /hello returns 405" $_.Exception.Message
- }
- } catch {
- Report $false "POST /hello returns 405" $_.Exception.Message
- }
-
- try {
- $badPathResp = Invoke-WebRequest -Uri "$BaseUrl/Default.asp?route=/hello/../secret" -UseBasicParsing
- Report $false "malformed route returns 400" "got $($badPathResp.StatusCode)"
- } catch [System.Net.WebException] {
- $webResp = $_.Exception.Response
- if ($webResp) {
- $code = [int]$webResp.StatusCode
- Report ($code -eq 400) "malformed route returns 400" "got $code"
- } else {
- Report $false "malformed route returns 400" $_.Exception.Message
- }
- } catch {
- Report $false "malformed route returns 400" $_.Exception.Message
- }
-
- try {
- $rootResp = Invoke-WebRequest -Uri "$BaseUrl/" -UseBasicParsing
- Report ($rootResp.StatusCode -eq 200) "GET / status 200" "got $($rootResp.StatusCode)"
- Report ($rootResp.Content -eq 'Hello from WSC-MVC!') "GET / maps to /hello" "got '$($rootResp.Content)'"
- } catch {
- Report $false "GET / request" $_.Exception.Message
- }
-
- # /self-test lives on the separate test-app/ site now (see docs/ARCHITECTURE.md
- # and tests/run-self-test.sh, which is what actually exercises it) - this
- # script tests the production app only. Confirm the diagnostics endpoint is
- # genuinely NOT exposed here, since that separation is the point.
- try {
- $selfTestResp = Invoke-WebRequest -Uri "$BaseUrl/self-test" -UseBasicParsing
- Report $false "GET /self-test not exposed on production" "got $($selfTestResp.StatusCode)"
- } catch [System.Net.WebException] {
- $webResp = $_.Exception.Response
- if ($webResp) {
- $code = [int]$webResp.StatusCode
- Report ($code -eq 404) "GET /self-test not exposed on production" "got $code"
- } else {
- Report $false "GET /self-test not exposed on production" $_.Exception.Message
- }
- } catch {
- Report $false "GET /self-test not exposed on production" $_.Exception.Message
- }
-
- # A caller can request Default.asp directly and supply the internal route
- # query string, bypassing URL Rewrite. The per-app route-set argument must
- # still prevent production from activating the test controller.
- try {
- $directSelfTestResp = Invoke-WebRequest -Uri "$BaseUrl/Default.asp?route=/self-test" -UseBasicParsing
- Report $false "direct Default.asp cannot cross into test routes" "got $($directSelfTestResp.StatusCode)"
- } catch [System.Net.WebException] {
- $webResp = $_.Exception.Response
- if ($webResp) {
- $code = [int]$webResp.StatusCode
- Report ($code -eq 404) "direct Default.asp cannot cross into test routes" "got $code"
- } else {
- Report $false "direct Default.asp cannot cross into test routes" $_.Exception.Message
- }
- } catch {
- Report $false "direct Default.asp cannot cross into test routes" $_.Exception.Message
- }
-
- if ($TestBaseUrl) {
- try {
- $directHelloResp = Invoke-WebRequest -Uri "$TestBaseUrl/Default.asp?route=/hello" -UseBasicParsing
- Report $false "test app cannot cross into production routes" "got $($directHelloResp.StatusCode)"
- } catch [System.Net.WebException] {
- $webResp = $_.Exception.Response
- if ($webResp) {
- $code = [int]$webResp.StatusCode
- Report ($code -eq 404) "test app cannot cross into production routes" "got $code"
- } else {
- Report $false "test app cannot cross into production routes" $_.Exception.Message
- }
- } catch {
- Report $false "test app cannot cross into production routes" $_.Exception.Message
- }
-
- try {
- $postSelfTestResp = Invoke-WebRequest -Uri "$TestBaseUrl/self-test" -Method Post -UseBasicParsing
- Report ($postSelfTestResp.StatusCode -eq 200) "POST /self-test on test app status 200" "got $($postSelfTestResp.StatusCode)"
- Report ($postSelfTestResp.Headers['Content-Type'] -eq 'application/json; charset=utf-8') "POST /self-test content-type" "got $($postSelfTestResp.Headers['Content-Type'])"
- } catch {
- Report $false "POST /self-test on test app" $_.Exception.Message
- }
-
- }
-
- # Framework/ is a sibling of the "public" webroot, not a rule-denied
- # subfolder within it - this checks it's genuinely unreachable, not just
- # filtered.
- try {
- $wscResp = Invoke-WebRequest -Uri "$BaseUrl/Framework/Application.wsc" -UseBasicParsing
- Report $false "GET /Framework/Application.wsc unreachable" "got $($wscResp.StatusCode)"
- } catch [System.Net.WebException] {
- $webResp = $_.Exception.Response
- if ($webResp) {
- $code = [int]$webResp.StatusCode
- Report ($code -eq 404) "GET /Framework/Application.wsc unreachable" "got $code"
- } else {
- Report $false "GET /Framework/Application.wsc unreachable" $_.Exception.Message
- }
- } catch {
- Report $false "GET /Framework/Application.wsc unreachable" $_.Exception.Message
- }
-
- Write-Output "---"
- if ($script:failures -eq 0) {
- Write-Output "RESULT: ALL PASS"
- exit 0
- } else {
- Write-Output "RESULT: $($script:failures) FAILURE(S)"
- exit 1
- }
|