Browse Source

feat(core): rename strategies based on security perspective

pull/3453/head
Arman Ozak 7 years ago
parent
commit
2b50598a91
  1. 12
      npm/ng-packs/packages/core/src/lib/strategies/content-security.strategy.ts
  2. 18
      npm/ng-packs/packages/core/src/lib/tests/content-security.strategy.spec.ts

12
npm/ng-packs/packages/core/src/lib/strategies/content-security.strategy.ts

@ -4,7 +4,7 @@ export abstract class ContentSecurityStrategy {
abstract applyCSP(element: HTMLScriptElement | HTMLStyleElement): void; abstract applyCSP(element: HTMLScriptElement | HTMLStyleElement): void;
} }
export class StrictContentSecurityStrategy extends ContentSecurityStrategy { export class LooseContentSecurityStrategy extends ContentSecurityStrategy {
constructor(nonce: string) { constructor(nonce: string) {
super(nonce); super(nonce);
} }
@ -14,7 +14,7 @@ export class StrictContentSecurityStrategy extends ContentSecurityStrategy {
} }
} }
export class LooseContentSecurityStrategy extends ContentSecurityStrategy { export class StrictContentSecurityStrategy extends ContentSecurityStrategy {
constructor() { constructor() {
super(); super();
} }
@ -23,10 +23,10 @@ export class LooseContentSecurityStrategy extends ContentSecurityStrategy {
} }
export const CONTENT_SECURITY_STRATEGY = { export const CONTENT_SECURITY_STRATEGY = {
Loose() { Loose(nonce: string) {
return new LooseContentSecurityStrategy(); return new LooseContentSecurityStrategy(nonce);
}, },
Strict(nonce: string) { Strict() {
return new StrictContentSecurityStrategy(nonce); return new StrictContentSecurityStrategy();
}, },
}; };

18
npm/ng-packs/packages/core/src/lib/tests/content-security.strategy.spec.ts

@ -7,25 +7,25 @@ import { uuid } from '../utils';
describe('LooseContentSecurityStrategy', () => { describe('LooseContentSecurityStrategy', () => {
describe('#applyCSP', () => { describe('#applyCSP', () => {
it('should not set nonce attribute', () => { it('should set nonce attribute', () => {
const strategy = new LooseContentSecurityStrategy(); const nonce = uuid();
const strategy = new LooseContentSecurityStrategy(nonce);
const element = document.createElement('link'); const element = document.createElement('link');
strategy.applyCSP(element); strategy.applyCSP(element);
expect(element.getAttribute('nonce')).toBeNull(); expect(element.getAttribute('nonce')).toBe(nonce);
}); });
}); });
}); });
describe('StrictContentSecurityStrategy', () => { describe('StrictContentSecurityStrategy', () => {
describe('#applyCSP', () => { describe('#applyCSP', () => {
it('should set nonce attribute', () => { it('should not set nonce attribute', () => {
const nonce = uuid(); const strategy = new StrictContentSecurityStrategy();
const strategy = new StrictContentSecurityStrategy(nonce);
const element = document.createElement('link'); const element = document.createElement('link');
strategy.applyCSP(element); strategy.applyCSP(element);
expect(element.getAttribute('nonce')).toBe(nonce); expect(element.getAttribute('nonce')).toBeNull();
}); });
}); });
}); });
@ -33,8 +33,8 @@ describe('StrictContentSecurityStrategy', () => {
describe('CONTENT_SECURITY_STRATEGY', () => { describe('CONTENT_SECURITY_STRATEGY', () => {
test.each` test.each`
name | Strategy | nonce name | Strategy | nonce
${'Loose'} | ${LooseContentSecurityStrategy} | ${undefined} ${'Loose'} | ${LooseContentSecurityStrategy} | ${uuid()}
${'Strict'} | ${StrictContentSecurityStrategy} | ${uuid()} ${'Strict'} | ${StrictContentSecurityStrategy} | ${undefined}
`('should successfully map $name to $Strategy.name', ({ name, Strategy, nonce }) => { `('should successfully map $name to $Strategy.name', ({ name, Strategy, nonce }) => {
expect(CONTENT_SECURITY_STRATEGY[name](nonce)).toEqual(new Strategy(nonce)); expect(CONTENT_SECURITY_STRATEGY[name](nonce)).toEqual(new Strategy(nonce));
}); });

Loading…
Cancel
Save