Repository navigation
Tests for CSP and route handlers pulled from Nexus - #3403
Merged
Merged
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
david-crespo
added this pull request to stack #3404
October 9, 2026 19:15
david-crespo
added a commit
that referenced
this pull request
Oct 9, 2026
Followup to #3403 — there are other security headers besides CSP, we might as well get em all. We could change the Rust to make these regexes less gnarly, but it really doesn't matter.
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
While doing #3400, I realized I wanted a way to test the CSP from Nexus against our actual production bundle. I decide that because CSP is enforced in the browser, we don't need Nexus for this at all, we just need the CSP string. So all we have to do is use regex to extract that from the pinned Omicron commit, and then we can test the CSP with
vite previewand a Playwright test. I was able to confirm the test fails when it's supposed to: on the #3400 branch, if I comment out the step that moves React Router's inline bootstrap scripts into separate files, the app never renders and the test fails with the browser's CSP errors:Once I had that in place, I thought about what else we might want to test about the contract with Nexus, and I remembered that I have sometimes forgotten to add a new route handler on the Nexus side when we added a new top-level route prefix in the console. So I added a test that similarly extracts the console routes from Nexus and makes sure all the client-side routes are covered by those handlers. That immediately turned up a bug (go to https://oxide.sys.r3.oxide-preview.com/images, click an image, and then refresh — 404), which is fixed in
oxidecomputer/omicron#11467. So the test will fail until that is merged and omicron is bumped.
This is nice and neat because #3402 pulls out the setup.