test: add comprehensive test suite (44 tests across 3 packages)

Store tests (21 tests):
- Session: create, validate, delete, delete-all, expiry
- Signup requests: create, duplicate, list pending, approve
  (creates user with must-reset), reject, double-approve/reject
- Existing: user CRUD, auth, fave CRUD, tags, pagination

Middleware tests (9 tests):
- Real IP extraction from trusted/untrusted proxies
- Base path stripping (with prefix, empty prefix)
- Rate limiter (per-IP, exhaustion, different IPs)
- Panic recovery (returns 500)
- Security headers (CSP, X-Frame-Options, etc.)
- RequireLogin redirect
- MustResetPasswordGuard (static path passthrough)

Handler integration tests (14 tests):
- Health endpoint
- Login page rendering, successful login, wrong password
- Fave list requires auth, works when authenticated
- Private fave hidden from other users, visible to owner
- Admin panel requires admin role, works for admin
- Tag search endpoint
- Global Atom feed
- Public profile with display name
- Limited profile hides bio

Also fixes template bugs: profile.html and fave_detail.html used
$.IsOwner which fails inside {{with}} blocks ($ = root PageData,
not .Data map). Fixed with $d variable capture pattern.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
Ole-Morten Duesund 2026-03-29 16:47:32 +02:00
commit 3a3b526a95
6 changed files with 866 additions and 15 deletions

View file

@ -1,5 +1,5 @@
{{define "head"}}
{{with .Data}}{{with .ProfileUser}}
{{with .Data}}{{$d := .}}{{with .ProfileUser}}
{{if eq .ProfileVisibility "public"}}
<meta property="og:title" content="{{.DisplayNameOrUsername}} sine favoritter">
<meta property="og:type" content="profile">
@ -16,6 +16,7 @@
{{define "content"}}
{{with .Data}}
{{$d := .}}
{{with .ProfileUser}}
<section class="profile-header">
{{if .AvatarPath}}
@ -31,14 +32,14 @@
</hgroup>
</section>
{{if not $.IsLimited}}
{{if not $d.IsLimited}}
{{if .Bio}}
<p>{{.Bio}}</p>
{{end}}
<p><small>Medlem siden {{.CreatedAt.Format "02.01.2006"}}</small></p>
{{if $.IsOwner}}
{{if $d.IsOwner}}
<p>
<a href="{{basePath}}/settings" role="button" class="outline">Rediger profil</a>
<a href="{{basePath}}/faves/new" role="button">+ Ny favoritt</a>
@ -46,13 +47,13 @@
{{end}}
<h2>
{{if $.IsOwner}}Favoritter{{else}}Offentlige favoritter{{end}}
<small>({{$.Total}})</small>
{{if $d.IsOwner}}Favoritter{{else}}Offentlige favoritter{{end}}
<small>({{$d.Total}})</small>
</h2>
{{if $.Faves}}
{{if $d.Faves}}
<div class="fave-grid" role="list">
{{range $.Faves}}
{{range $d.Faves}}
<article class="fave-card" role="listitem">
{{if .ImagePath}}
<img src="{{basePath}}/uploads/{{.ImagePath}}"
@ -78,21 +79,21 @@
{{end}}
</div>
{{if gt $.TotalPages 1}}
{{if gt $d.TotalPages 1}}
<nav aria-label="Sidenavigasjon">
<ul>
{{if gt $.Page 1}}
<li><a href="{{basePath}}/u/{{.Username}}?page={{subtract $.Page 1}}">← Forrige</a></li>
{{if gt $d.Page 1}}
<li><a href="{{basePath}}/u/{{.Username}}?page={{subtract $d.Page 1}}">← Forrige</a></li>
{{end}}
<li>Side {{$.Page}} av {{$.TotalPages}}</li>
{{if lt $.Page $.TotalPages}}
<li><a href="{{basePath}}/u/{{.Username}}?page={{add $.Page 1}}">Neste →</a></li>
<li>Side {{$d.Page}} av {{$d.TotalPages}}</li>
{{if lt $d.Page $d.TotalPages}}
<li><a href="{{basePath}}/u/{{.Username}}?page={{add $d.Page 1}}">Neste →</a></li>
{{end}}
</ul>
</nav>
{{end}}
{{else}}
{{if $.IsOwner}}
{{if $d.IsOwner}}
<p>Du har ingen favoritter ennå. <a href="{{basePath}}/faves/new">Legg til din første!</a></p>
{{else}}
<p>Ingen offentlige favoritter ennå.</p>