import { expect, test, type Page } from "@playwright/test"; const ORIGIN = "http://127.0.0.1:4173"; async function localOnly(page: Page) { const external: string[] = []; await page.route("**/*", async (route) => { const url = new URL(route.request().url()); if (url.origin !== ORIGIN) { external.push(url.href); await route.abort(); } else await route.continue(); }); return external; } test("runs from a nested path without external requests", async ({ page }) => { const errors: string[] = []; page.on("pageerror", (error) => errors.push(error.message)); page.on("console", (message) => { if (message.type() === "error") errors.push(message.text()); }); const external = await localOnly(page); await page.goto("/deep/nested/network/"); await expect( page.getByRole("heading", { name: "Network Tools" }), ).toBeVisible(); expect(external).toEqual([]); expect(errors).toEqual([]); }); test("calculates a subnet and sanitises a credential-bearing URL", async ({ page, }) => { const external = await localOnly(page); await page.goto("/deep/nested/network/"); await expect( page.getByText("Network", { exact: true }).locator("..").locator("dd"), ).toHaveText("192.168.10.0"); await expect( page.getByText("Last address", { exact: true }).locator("..").locator("dd"), ).toHaveText("192.168.10.255"); await page.getByRole("button", { name: "URL" }).click(); await page .getByLabel("URL or reference") .fill("https://alice:secret@example.test/a?q=one&q=two"); await expect( page.getByText("https://alice@example.test/a?q=one&q=two", { exact: true }), ).toBeVisible(); await expect(page.getByText(/password; it was removed/u)).toBeVisible(); await expect(page.getByText("secret", { exact: false })).toHaveCount(0); expect(external).toEqual([]); }); test("plans VLSM and inspects a zone and deployed CSP without lookups", async ({ page, }) => { const external = await localOnly(page); await page.goto("/deep/nested/network/"); await page.getByRole("button", { name: "VLSM planner" }).click(); await expect(page.getByText("10.20.0.0/23", { exact: true })).toBeVisible(); await expect(page.getByText("10.20.2.0/25", { exact: true })).toBeVisible(); await page.getByRole("button", { name: "Zone file" }).click(); await expect( page.getByText("Validated records").locator("..").locator("dd"), ).toHaveText("6"); await expect( page.locator("pre").filter({ hasText: "192.0.2.80" }), ).toBeVisible(); await page.getByRole("button", { name: "HTTP & CSP" }).click(); await page .getByLabel("Response headers") .fill( "Content-Security-Policy: default-src 'self'; script-src 'unsafe-eval'\nSet-Cookie: session=x; SameSite=None", ); await expect(page.getByText(/permits 'unsafe-eval'/u)).toBeVisible(); await expect(page.getByText(/SameSite=None without Secure/u)).toBeVisible(); expect(external).toEqual([]); }); test("serves the release identity and hardened headers", async ({ request, }) => { const index = await request.get("/deep/nested/network/"); expect(index.ok()).toBe(true); expect(index.headers()["content-security-policy"]).toContain( "default-src 'self'", ); expect(await index.text()).not.toMatch(/\b(?:src|href)=["']\//u); const manifest = await request.get("/deep/nested/network/toolbox-app.json"); await expect(manifest.json()).resolves.toMatchObject({ id: "de.add-ideas.network-tools", version: "0.2.0", entry: "./", }); });