mirror of
https://github.com/vercel/next.js.git
synced 2026-09-20 02:25:18 +08:00
6ba71046b0
Node.js ships with a built-in `fetch` now so `node-fetch` is no longer necessary. Mostly motivated by tracing Node.js deprecation warnings which originated from `node-fetch` by calling the deprecated `url.parse`. Call sites keep working through a compatibility type on `fetchViaHTTP` that translates node-fetch-only options: Instead of `agent` we pass to `http(s)` directly, `timeout` becomes `AbortSignal.timeout`, and Node.js readable streams are accepted as bodies with `duplex: 'half'` set automatically. The `abort-controller` polyfill is dropped since its signal type predates the current AbortSignal and undici would not honor it. `node-fetch` stays installed because `scripts/generate-release-log.mjs`, `scripts/reset-project.mjs`, and `scripts/update-google-fonts.js` still import it (follow-up material). Fixture apps will be migrated separately.
77 lines
2.4 KiB
TypeScript
77 lines
2.4 KiB
TypeScript
import { join } from 'path'
|
|
import { FileRef, nextTestSetup } from 'e2e-utils'
|
|
import { fetchViaHTTP, renderViaHTTP } from 'next-test-utils'
|
|
|
|
describe.each([[''], ['/docs']])(
|
|
'misc basic dev tests, basePath: %p',
|
|
(basePath: string) => {
|
|
const { next } = nextTestSetup({
|
|
files: {
|
|
pages: new FileRef(join(__dirname, 'misc/pages')),
|
|
public: new FileRef(join(__dirname, 'misc/public')),
|
|
},
|
|
nextConfig: {
|
|
basePath,
|
|
},
|
|
})
|
|
|
|
it('should set process.env.NODE_ENV in development', async () => {
|
|
const browser = await next.browser(basePath + '/process-env')
|
|
const nodeEnv = await browser.elementByCss('#node-env').text()
|
|
expect(nodeEnv).toBe('development')
|
|
await browser.close()
|
|
})
|
|
|
|
it('should allow access to public files', async () => {
|
|
const data = await renderViaHTTP(next.url, basePath + '/data/data.txt')
|
|
expect(data).toBe('data')
|
|
|
|
const legacy = await renderViaHTTP(
|
|
next.url,
|
|
basePath + '/static/legacy.txt'
|
|
)
|
|
expect(legacy).toMatch(`new static folder`)
|
|
})
|
|
|
|
describe('With Security Related Issues', () => {
|
|
it('should not allow accessing files outside .next/static and .next/server directory', async () => {
|
|
const pathsToCheck = [
|
|
basePath + '/_next/static/../BUILD_ID',
|
|
basePath + '/_next/static/../routes-manifest.json',
|
|
]
|
|
for (const path of pathsToCheck) {
|
|
const res = await fetchViaHTTP(next.url, path)
|
|
const text = await res.text()
|
|
try {
|
|
expect(res.status).toBe(404)
|
|
expect(text).toMatch(/This page could not be found/)
|
|
} catch (err) {
|
|
throw new Error(`Path ${path} accessible from the browser`)
|
|
}
|
|
}
|
|
})
|
|
|
|
it('should handle encoded / value for trailing slash correctly', async () => {
|
|
const res = await fetchViaHTTP(
|
|
next.url,
|
|
basePath + '/%2fexample.com/',
|
|
undefined,
|
|
{
|
|
redirect: 'manual',
|
|
}
|
|
)
|
|
|
|
const { pathname, hostname } = new URL(
|
|
res.headers.get('location') || '',
|
|
res.url
|
|
)
|
|
expect(res.status).toBe(308)
|
|
expect(pathname).toBe(basePath + '/%2fexample.com')
|
|
expect(hostname).not.toBe('example.com')
|
|
const text = await res.text()
|
|
expect(text).toEqual(basePath + '/%2fexample.com')
|
|
})
|
|
})
|
|
}
|
|
)
|