|
- [CmdletBinding()]
- param(
- [Parameter(Mandatory = $true)]
- [string]$BaseUrl,
- [string]$TestBaseUrl
- )
-
- $script:failures = 0
-
- function Report {
- param($ok, $label, $detail)
- if ($ok) {
- Write-Output "PASS: $label"
- } else {
- Write-Output "FAIL: $label ($detail)"
- $script:failures++
- }
- }
-
- try {
- $resp = Invoke-WebRequest -Uri "$BaseUrl/hello" -UseBasicParsing
- Report ($resp.StatusCode -eq 200) "GET /hello status 200" "got $($resp.StatusCode)"
- Report ($resp.Headers['Content-Type'] -eq 'text/html; charset=utf-8') "GET /hello content-type" "got $($resp.Headers['Content-Type'])"
- Report ($resp.Content -eq 'Hello from WSC-MVC!') "GET /hello body" "got '$($resp.Content)'"
- } catch {
- Report $false "GET /hello request" $_.Exception.Message
- }
-
- # /self-test lives on the separate test-app/ site now (see docs/ARCHITECTURE.md
- # and tests/run-self-test.sh, which is what actually exercises it) - this
- # script tests the production app only. Confirm the diagnostics endpoint is
- # genuinely NOT exposed here, since that separation is the point.
- try {
- $selfTestResp = Invoke-WebRequest -Uri "$BaseUrl/self-test" -UseBasicParsing
- Report $false "GET /self-test not exposed on production" "got $($selfTestResp.StatusCode)"
- } catch [System.Net.WebException] {
- $webResp = $_.Exception.Response
- if ($webResp) {
- $code = [int]$webResp.StatusCode
- Report ($code -eq 404) "GET /self-test not exposed on production" "got $code"
- } else {
- Report $false "GET /self-test not exposed on production" $_.Exception.Message
- }
- } catch {
- Report $false "GET /self-test not exposed on production" $_.Exception.Message
- }
-
- # A caller can request Default.asp directly and supply the internal route
- # query string, bypassing URL Rewrite. The per-app route-set argument must
- # still prevent production from activating the test controller.
- try {
- $directSelfTestResp = Invoke-WebRequest -Uri "$BaseUrl/Default.asp?route=/self-test" -UseBasicParsing
- Report $false "direct Default.asp cannot cross into test routes" "got $($directSelfTestResp.StatusCode)"
- } catch [System.Net.WebException] {
- $webResp = $_.Exception.Response
- if ($webResp) {
- $code = [int]$webResp.StatusCode
- Report ($code -eq 404) "direct Default.asp cannot cross into test routes" "got $code"
- } else {
- Report $false "direct Default.asp cannot cross into test routes" $_.Exception.Message
- }
- } catch {
- Report $false "direct Default.asp cannot cross into test routes" $_.Exception.Message
- }
-
- if ($TestBaseUrl) {
- try {
- $directHelloResp = Invoke-WebRequest -Uri "$TestBaseUrl/Default.asp?route=/hello" -UseBasicParsing
- Report $false "test app cannot cross into production routes" "got $($directHelloResp.StatusCode)"
- } catch [System.Net.WebException] {
- $webResp = $_.Exception.Response
- if ($webResp) {
- $code = [int]$webResp.StatusCode
- Report ($code -eq 404) "test app cannot cross into production routes" "got $code"
- } else {
- Report $false "test app cannot cross into production routes" $_.Exception.Message
- }
- } catch {
- Report $false "test app cannot cross into production routes" $_.Exception.Message
- }
- }
-
- # Framework/ is a sibling of the "public" webroot, not a rule-denied
- # subfolder within it - this checks it's genuinely unreachable, not just
- # filtered.
- try {
- $wscResp = Invoke-WebRequest -Uri "$BaseUrl/Framework/Application.wsc" -UseBasicParsing
- Report $false "GET /Framework/Application.wsc unreachable" "got $($wscResp.StatusCode)"
- } catch [System.Net.WebException] {
- $webResp = $_.Exception.Response
- if ($webResp) {
- $code = [int]$webResp.StatusCode
- Report ($code -eq 404) "GET /Framework/Application.wsc unreachable" "got $code"
- } else {
- Report $false "GET /Framework/Application.wsc unreachable" $_.Exception.Message
- }
- } catch {
- Report $false "GET /Framework/Application.wsc unreachable" $_.Exception.Message
- }
-
- Write-Output "---"
- if ($script:failures -eq 0) {
- Write-Output "RESULT: ALL PASS"
- exit 0
- } else {
- Write-Output "RESULT: $($script:failures) FAILURE(S)"
- exit 1
- }
|