fix(csr): send csrf token with component rpc
Quality / quality (ubuntu-latest) (push) Failing after 10m42s
Quality / quality (windows-latest) (push) Canceled after 0s

This commit is contained in:
2026-08-12 18:15:15 +05:30
parent 1719059fa0
commit 9637a47ec7
2 changed files with 30 additions and 2 deletions
+27
View File
@@ -801,6 +801,33 @@ test("an unbound native-named output does not re-enter its DOM handler", () => {
expect(outputs).toBe(1);
});
test("component server calls send the CSRF cookie in the RPC header", async () => {
const win = mount(
`<div data-scope="" data-wrn-component="Home">` +
`<button data-on-click="server.handleClick()">go</button>` +
`</div>`,
);
Object.defineProperty(win.document, "cookie", {
configurable: true,
value: "wire-csrf=rpc%20token",
});
let request: RequestInit | undefined;
const globals = globalThis as Record<string, unknown>;
const originalFetch = globals.fetch;
globals.fetch = async (_input: RequestInfo | URL, init?: RequestInit) => {
request = init;
return Response.json({ ok: true });
};
try {
(win.document.querySelector("button") as unknown as HTMLElement).click();
await new Promise((resolve) => setTimeout(resolve, 0));
} finally {
globals.fetch = originalFetch;
}
expect(new Headers(request?.headers).get("x-csrf-token")).toBe("rpc token");
});
test("development runtime warns when a component binding names a missing function", () => {
const win = new Window() as unknown as Window & Record<string, unknown>;
win.document.body.innerHTML =