Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
24 changes: 12 additions & 12 deletions frontend/src/__tests__/app/signin/route.test.ts
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,8 @@ jest.mock('@/utils/amplify-utils');
jest.mock('@/utils/csrf-utils');
jest.mock('next/headers');

const baseUrl = 'https://test';

test('returns redirect', async () => {
jest.mocked(getSessionId).mockResolvedValue('session-id');
jest.mocked(generateSessionCsrfToken).mockResolvedValue('csrf');
Expand All @@ -23,40 +25,40 @@ test('returns redirect', async () => {
});
jest.mocked(cookies).mockResolvedValue(cookiesMock);

const request = new NextRequest('https://test?redirect=/redirect-url');
const request = new NextRequest(`${baseUrl}?redirect=/redirect-url`);
const response = await GET(request);

expect(cookieSetMock).toHaveBeenCalledWith('csrf_token', 'csrf', {
sameSite: 'strict',
secure: true,
});
expect(response.status).toEqual(307);
expect(response.headers.get('Location')).toEqual('/redirect-url');
expect(response.headers.get('Location')).toEqual(`${baseUrl}/redirect-url`);
});

test('returns redirect - sanitizes redirect path', async () => {
jest.mocked(getSessionId).mockResolvedValue('session-id');
jest.mocked(generateSessionCsrfToken).mockResolvedValue('csrf');
jest.mocked(cookies).mockResolvedValue(mockDeep<ReadonlyRequestCookies>());

const request = new NextRequest('https://test?redirect=redirect-url'); // no leading slash in redirect search param value
const request = new NextRequest(`${baseUrl}?redirect=redirect-url`);
const response = await GET(request);

expect(response.status).toEqual(307);
expect(response.headers.get('Location')).toEqual('/redirect-url');
expect(response.headers.get('Location')).toEqual(`${baseUrl}/redirect-url`);
});

test('returns redirect to /templates/message-templates if no redirect given', async () => {
jest.mocked(getSessionId).mockResolvedValue('session-id');
jest.mocked(generateSessionCsrfToken).mockResolvedValue('csrf');
jest.mocked(cookies).mockResolvedValue(mockDeep<ReadonlyRequestCookies>({}));

const request = new NextRequest('https://test');
const request = new NextRequest(baseUrl);
const response = await GET(request);

expect(response.status).toEqual(307);
expect(response.headers.get('Location')).toEqual(
'/templates/message-templates'
`${baseUrl}/templates/message-templates`
);
});

Expand All @@ -65,27 +67,25 @@ test('returns redirect to /auth if no session detected', async () => {
const cookiesMock = mockDeep<ReadonlyRequestCookies>();
jest.mocked(cookies).mockResolvedValue(cookiesMock);

const request = new NextRequest('https://test');
const request = new NextRequest(baseUrl);
const response = await GET(request);

expect(cookiesMock.delete).toHaveBeenCalledWith('csrf_token');

expect(response.status).toEqual(307);
expect(response.headers.get('Location')).toEqual('/auth');
expect(response.headers.get('Location')).toEqual(`${baseUrl}/auth`);
});

test('retains redirect search param on /auth redirect', async () => {
jest.mocked(getSessionId).mockResolvedValue('');
const cookiesMock = mockDeep<ReadonlyRequestCookies>();
jest.mocked(cookies).mockResolvedValue(cookiesMock);

const request = new NextRequest('https://test?redirect=/redirect-path');
const request = new NextRequest(`${baseUrl}?redirect=/redirect-path`);
const response = await GET(request);

expect(cookiesMock.delete).toHaveBeenCalledWith('csrf_token');

expect(response.status).toEqual(307);
expect(response.headers.get('Location')).toEqual(
'/auth?redirect=%2Fredirect-path'
`${baseUrl}/auth?redirect=%2Fredirect-path`
);
});
10 changes: 4 additions & 6 deletions frontend/src/app/signin/route.ts
Original file line number Diff line number Diff line change
Expand Up @@ -34,10 +34,8 @@ export const GET = async (request: NextRequest) => {
}
}

return NextResponse.json(null, {
status: 307,
headers: {
Location: redirectPath,
},
});
return NextResponse.redirect(
new URL(redirectPath, request.nextUrl.origin),
307
);
};