Skip to content

test: cover csrf rejection, stored episodes and since filtering - #83

Merged
cbrgm merged 2 commits into
mainfrom
test/close-mutation-gaps
Oct 6, 2026
Merged

cbrgm merged 2 commits into
mainfrom
test/close-mutation-gaps

Conversation

@cbrgm

@cbrgm cbrgm commented Oct 6, 2026 •

Copy link
Copy Markdown
Owner

What

Tests for the four gaps the mutation check on #82 found, no production code changes.

  • csrf_test.go: protected POST with missing / wrong / other-session token -> 403 and nothing changes. Valid form and header token still pass.
  • TestHandleUploadEpisodes: uploaded action actually lands in the store
  • TestHandleGetEpisodes_Since, TestHandleGetSubscriptionChanges_Since: since filters by modification time, incl. removals

Why

Follow-up from #82. Seeded these bugs into production code, the whole suite stayed green on main:

  • validCSRFToken always true
  • uploaded episodes never stored
  • since ignored for episodes
  • since ignored for subscription changes

The old tests only checked status codes, e.g. "supports since query parameter" asserted 200 and nothing else. Against the mock nothing more was possible, it ignored since and always returned empty changes. With the real store from #82 it is.

CSRF is the important one, its a security check nobody tested.

Testing

Same mutations against this branch:

mutation                               result
csrf check always passes               caught
uploaded episodes not stored           caught
subscription changes ignore since      caught
episodes ignore since                  caught
$ go test -count=1 ./...
ok  	github.com/cbrgm/gopodder/cmd/gopodder	0.399s
ok  	github.com/cbrgm/gopodder/gopodder	20.191s
$ go test -count=1 -shuffle=on ./gopodder/
ok  	github.com/cbrgm/gopodder/gopodder	19.705s
$ go vet ./... && make lint
0 issues.

cbrgm added 2 commits October 6, 2026 23:48
Nothing sent a bad token to a protected route, validCSRFToken could
return true unconditionally and the suite stayed green. Covers form
and header token, and a token minted for another session.
The episode and subscription change tests only checked status codes
and response shape, written against a mock that ignored since. Upload
now checks the action is stored, both pull endpoints check that since
filters by modification time.
@cbrgm
cbrgm merged commit 3b6c501 into main Oct 6, 2026
11 checks passed
@cbrgm
cbrgm deleted the test/close-mutation-gaps branch October 6, 2026 21:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant