Skip to content

Tests for CSP and route handlers pulled from Nexus - #3403

Merged
david-crespo merged 5 commits into
gen-api-typescriptfrom
nexus-csp-build-test
Oct 9, 2026
Merged

david-crespo merged 5 commits into
gen-api-typescriptfrom
nexus-csp-build-test

Conversation

@david-crespo

Copy link
Copy Markdown
Collaborator

While doing #3400, I realized I wanted a way to test the CSP from Nexus against our actual production bundle. I decide that because CSP is enforced in the browser, we don't need Nexus for this at all, we just need the CSP string. So all we have to do is use regex to extract that from the pinned Omicron commit, and then we can test the CSP with vite preview and a Playwright test. I was able to confirm the test fails when it's supposed to: on the #3400 branch, if I comment out the step that moves React Router's inline bootstrap scripts into separate files, the app never renders and the test fails with the browser's CSP errors:

Error: expect(received).toEqual(expected) // deep equality
- Array []
+ Array [
+   "Executing inline script violates the following Content Security Policy directive 'default-src 'self''. [...] The action has been blocked.",
+   [3 more of those]
+   "CSP violation: script-src-elem inline",
+   "CSP violation: script-src-elem inline",

Once I had that in place, I thought about what else we might want to test about the contract with Nexus, and I remembered that I have sometimes forgotten to add a new route handler on the Nexus side when we added a new top-level route prefix in the console. So I added a test that similarly extracts the console routes from Nexus and makes sure all the client-side routes are covered by those handlers. That immediately turned up a bug (go to https://oxide.sys.r3.oxide-preview.com/images, click an image, and then refresh — 404), which is fixed in
oxidecomputer/omicron#11467. So the test will fail until that is merged and omicron is bumped.

This is nice and neat because #3402 pulls out the setup.

@vercel

vercel Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
console Ready Ready Preview Oct 9, 2026 7:29pm UTC

Request Review

@david-crespo
david-crespo merged commit 1cd4618 into main Oct 9, 2026
7 checks passed
@david-crespo
david-crespo deleted the nexus-csp-build-test branch October 9, 2026 19:45
david-crespo added a commit that referenced this pull request Oct 9, 2026
Followup to #3403 — there are other security headers besides CSP, we
might as well get em all. We could change the Rust to make these regexes
less gnarly, but it really doesn't matter.

This branch was successfully deployed

1 active deployment
Preview — b72b4d6d Deployed Oct 9, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant