Make web tests database-free and finish review hardening.

Introduce a Store interface with Postgres and in-memory backends, cover mutations/CSRF/session rotation without Postgres, bound avatar decode dimensions, add truncate/prepareAvatar unit tests, and run go test -race in CI.
This commit is contained in:
2026-08-22 07:36:13 -07:00
parent afd2476f3c
commit f4cec32afb
12 changed files with 945 additions and 223 deletions
+8 -7
View File
@@ -43,7 +43,7 @@ func (s *Server) handleLogin(w http.ResponseWriter, r *http.Request) {
username := strings.TrimSpace(r.PostFormValue("username"))
password := r.PostFormValue("password")
next := safeNext(r.PostFormValue("next"))
u, err := store.UserByUsername(r.Context(), s.db, username)
u, err := s.store.UserByUsername(r.Context(), username)
if err != nil || bcrypt.CompareHashAndPassword([]byte(u.PasswordHash), []byte(password)) != nil {
w.WriteHeader(http.StatusUnauthorized)
s.exec(w, "login", authPage{
@@ -94,7 +94,7 @@ func (s *Server) handleRegister(w http.ResponseWriter, r *http.Request) {
}
role := store.RoleUser
if s.cfg.AdminUsername != "" && store.NormalizeUsername(username) == store.NormalizeUsername(s.cfg.AdminUsername) {
n, err := store.CountAdmins(r.Context(), s.db)
n, err := s.store.CountAdmins(r.Context())
if err != nil {
http.Error(w, "could not create account", http.StatusInternalServerError)
return
@@ -103,11 +103,12 @@ func (s *Server) handleRegister(w http.ResponseWriter, r *http.Request) {
role = store.RoleAdmin
}
}
u := store.NewUser(s.db)
u.Username = username
u.PasswordHash = string(hash)
u.Role = role
if err := u.Create(r.Context()); err != nil {
u := &store.User{
Username: username,
PasswordHash: string(hash),
Role: role,
}
if err := s.store.CreateUser(r.Context(), u); err != nil {
p.Error = "That username is taken."
s.exec(w, "register", p)
return