Release the response before tearing the test server down (#2212)
TestRest_securityHeaders and TestRest_frameAncestors both start a server, read one response, and then call teardown() partway through the test to start a second server with different options. The first response body is only closed by a defer, which does not run until the test returns. httptest.Server.Close waits on connections still in use, so it blocks on a body that will not be closed until after it returns. The tests deadlock and the whole rest/api package dies on the timeout rather than on an assertion. CI pins go 1.25, where the responses are small enough that the connection goes back to the pool on its own and nothing hangs. On go 1.27 both tests hang, which is how this surfaced. Close the body and the client's idle connections before teardown() in both.
This commit is contained in:
@@ -271,11 +271,14 @@ func TestRest_securityHeaders(t *testing.T) {
|
||||
client := http.Client{}
|
||||
resp, err := client.Get(ts.URL + "/web/index.html")
|
||||
require.NoError(t, err)
|
||||
defer resp.Body.Close()
|
||||
assert.Equal(t, http.StatusOK, resp.StatusCode)
|
||||
assert.Contains(t, resp.Header.Get("Content-Security-Policy"), "img-src *;")
|
||||
assert.Equal(t, "nosniff", resp.Header.Get("X-Content-Type-Options"))
|
||||
assert.Equal(t, "strict-origin-when-cross-origin", resp.Header.Get("Referrer-Policy"))
|
||||
// httptest.Server.Close waits on connections still in use, and a deferred close does not run
|
||||
// until the test ends, so the body has to be released before the server is torn down here
|
||||
require.NoError(t, resp.Body.Close())
|
||||
client.CloseIdleConnections()
|
||||
teardown()
|
||||
|
||||
// check CSP with proxy enabled
|
||||
|
||||
@@ -573,9 +573,12 @@ func TestRest_frameAncestors(t *testing.T) {
|
||||
client := http.Client{}
|
||||
resp, err := client.Get(ts.URL + "/web/index.html")
|
||||
require.NoError(t, err)
|
||||
defer resp.Body.Close()
|
||||
assert.Equal(t, http.StatusOK, resp.StatusCode)
|
||||
assert.Contains(t, resp.Header.Get("Content-Security-Policy"), "frame-ancestors 'self' https://example.com;")
|
||||
// httptest.Server.Close waits on connections still in use, and a deferred close does not run
|
||||
// until the test ends, so the body has to be released before the server is torn down here
|
||||
require.NoError(t, resp.Body.Close())
|
||||
client.CloseIdleConnections()
|
||||
teardown()
|
||||
|
||||
// test case without frame-ancestors
|
||||
|
||||
Reference in New Issue
Block a user