tablo-core 0.3.0

The core toolkit types for Tablo, a server-rendered admin toolkit on Topcoat and Toasty.
Documentation
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
796
797
798
799
800
801
802
803
804
805
806
807
808
809
810
811
812
813
814
815
816
817
818
819
820
821
822
823
824
825
826
827
828
829
830
831
832
833
834
835
836
837
838
839
840
841
842
843
844
845
846
847
848
849
850
851
852
853
854
855
856
857
858
859
860
861
862
863
864
865
866
867
868
869
870
871
872
873
874
875
876
877
878
879
880
881
882
883
884
885
886
887
888
889
890
891
892
893
894
895
896
897
898
899
900
901
902
903
904
905
906
907
908
909
910
911
912
913
914
915
916
917
918
919
920
921
922
923
924
925
926
927
928
929
930
931
932
933
934
//! The upload seam end to end.

use std::{
    path::PathBuf,
    sync::{Arc, Mutex},
};

use http::header::{
    CONTENT_DISPOSITION, IF_MODIFIED_SINCE, LAST_MODIFIED, LOCATION, X_CONTENT_TYPE_OPTIONS,
};
use tablo_core::{
    Ability, Auth, DeclarationErrorKind, Field, Panel, Resource, ResourceDef, Schema, Table,
    TextColumn, Uploader, lens,
};
use toasty::Db;
use topcoat::{
    context::Cx,
    router::{Body, Router, response::Response},
};
use uuid::Uuid;

use crate::common::{
    body_bytes, body_string, csp, field_error, get, memory_db, mount, multipart_body, new_csrf,
    panel, post, post_multipart, refusal,
};

/// A document with one required and one optional upload.
#[derive(Debug, Clone, toasty::Model)]
struct Doc {
    #[key]
    #[auto]
    id: Uuid,
    title: String,
    /// Required by the form's default (the lens is a non-nullable `String`).
    cover: String,
    /// Declared `.optional()`: the app allows a record to lose its file.
    attachment: String,
}

/// What an uploader was handed: sanitized filename and bytes.
type Seen = Arc<Mutex<Vec<(String, Vec<u8>)>>>;

/// An uploader that records what it was handed and answers a deterministic path.
#[derive(Clone, Default)]
struct RecordingUploader {
    seen: Seen,
}

impl RecordingUploader {
    fn seen(&self) -> Vec<(String, Vec<u8>)> {
        self.seen.lock().expect("uploader lock").clone()
    }
}

impl Uploader for RecordingUploader {
    async fn store(&self, filename: &str, bytes: &[u8]) -> Result<String, String> {
        self.seen
            .lock()
            .expect("uploader lock")
            .push((filename.to_string(), bytes.to_vec()));
        Ok(format!("/uploads/{filename}"))
    }
}

/// An uploader that always refuses, for the inline-error path.
struct FailingUploader;

impl Uploader for FailingUploader {
    async fn store(&self, _filename: &str, _bytes: &[u8]) -> Result<String, String> {
        Err("this deployment has no room left".to_string())
    }
}

struct DocResource;

impl Resource for DocResource {
    type Model = Doc;
    type Form = DocForm;

    fn declare() -> ResourceDef<Self> {
        ResourceDef::new()
            // Every policy hook defaults to deny.
            .policy(|_cx: &Cx, ability: Ability<'_, Doc>| {
                matches!(
                    ability,
                    Ability::ViewAny | Ability::View(_) | Ability::Create | Ability::Update(_)
                )
            })
            .table(Table::new(TextColumn::new(lens!(Doc.title))).paginate(25))
            .form(Schema::new((
                Field::text(Doc::fields().title()),
                Field::file(Doc::fields().cover()).label("Cover"),
                Field::file(Doc::fields().attachment())
                    .label("Attachment")
                    .optional(),
            )))
    }
}
#[derive(tablo_core::RecordForm)]
#[form(model = Doc)]
struct DocForm {
    title: String,
    cover: String,
    attachment: String,
}
async fn seeded_db() -> Db {
    memory_db(toasty::models!(Doc)).await
}

/// The same DB with the shipped auth models registered.
async fn auth_seeded_db() -> Db {
    memory_db(toasty::models!(
        Doc,
        tablo_core::auth::AdminUser,
        tablo_core::auth::AuthSession
    ))
    .await
}

/// A panel over `Doc`, optionally with an uploader.
fn router(db: Db, uploader: Option<impl Uploader>) -> Router {
    let panel = panel();
    let panel = match uploader {
        Some(uploader) => panel.uploads(uploader),
        None => panel,
    };
    mount(db, panel.resource::<DocResource>()).expect("panel builds")
}

/// A directory of this test's own.
fn temp_dir(tag: &str) -> PathBuf {
    let dir = std::env::temp_dir().join(format!("tablo-uploads-{tag}-{}", Uuid::new_v4()));
    std::fs::create_dir_all(&dir).expect("create temp dir");
    dir
}

/// A GET that revalidates.
async fn get_if_modified_since(router: &Router, uri: &str, since: &str) -> Response<Body> {
    let request = http::Request::builder()
        .uri(uri)
        .header(IF_MODIFIED_SINCE, since)
        .body(Body::empty())
        .expect("request builds");
    router.handle(request).await
}

/// The exact directive a served file carries.
const SERVED_FILE_POLICY: &str = "default-src 'none'; img-src 'self'; media-src 'self'; \
     style-src 'unsafe-inline'; sandbox; frame-ancestors 'self'";

async fn seed_doc(db: &Db, title: &str, cover: &str, attachment: &str) -> Doc {
    let mut db = db.clone();
    toasty::create!(Doc {
        title: title.to_string(),
        cover: cover.to_string(),
        attachment: attachment.to_string(),
    })
    .exec(&mut db)
    .await
    .expect("seed doc")
}

async fn docs(db: &Db) -> Vec<Doc> {
    let mut db = db.clone();
    Doc::all().exec(&mut db).await.expect("query docs")
}

#[tokio::test]
async fn an_installed_uploader_stores_the_bytes_and_the_path_reaches_the_record() {
    let db = seeded_db().await;
    let uploader = RecordingUploader::default();
    let router = router(db.clone(), Some(uploader.clone()));
    let csrf = new_csrf();
    let body = multipart_body(
        "B",
        &[
            ("title", None, "Notes"),
            ("cover", Some("cover.png"), "PNG-BYTES"),
            ("attachment", Some("spec.pdf"), "PDF-BYTES"),
            ("csrf_token", None, &csrf),
        ],
    );

    let response = post_multipart(&router, "/admin/docs/create", &csrf, "B", body).await;
    assert_eq!(response.status(), 303, "a valid create redirects");

    // The record stores what the uploader returned.
    let created = docs(&db).await;
    assert_eq!(created.len(), 1);
    assert_eq!(created[0].cover, "/uploads/cover.png");
    assert_eq!(created[0].attachment, "/uploads/spec.pdf");

    // The uploader saw the bytes under sanitized names.
    let mut seen = uploader.seen();
    seen.sort();
    assert_eq!(
        seen,
        vec![
            ("cover.png".to_string(), b"PNG-BYTES".to_vec()),
            ("spec.pdf".to_string(), b"PDF-BYTES".to_vec()),
        ],
        "the uploader receives each file part's sanitized name and content"
    );
}

#[tokio::test]
async fn without_an_uploader_the_sanitized_basename_is_still_stored() {
    let db = seeded_db().await;
    let router = router(db.clone(), None::<RecordingUploader>);
    let csrf = new_csrf();
    let body = multipart_body(
        "B",
        &[
            ("title", None, "Notes"),
            // A path-carrying client name is sanitized to its basename.
            ("cover", Some("../../etc/cover.png"), "PNG-BYTES"),
            ("csrf_token", None, &csrf),
        ],
    );

    let response = post_multipart(&router, "/admin/docs/create", &csrf, "B", body).await;
    assert_eq!(response.status(), 303);

    let created = docs(&db).await;
    assert_eq!(created[0].cover, "cover.png");
    assert_eq!(created[0].attachment, "");
}

#[tokio::test]
async fn a_refused_upload_is_an_inline_field_error_and_writes_nothing() {
    let db = seeded_db().await;
    let router = router(db.clone(), Some(FailingUploader));
    let csrf = new_csrf();
    let body = multipart_body(
        "B",
        &[
            ("title", None, "Notes"),
            ("cover", Some("cover.png"), "PNG-BYTES"),
            ("csrf_token", None, &csrf),
        ],
    );

    let response = post_multipart(&router, "/admin/docs/create", &csrf, "B", body).await;
    assert_eq!(response.status(), 200, "the form re-renders");
    let html = body_string(response).await;
    assert_eq!(
        field_error(&html, "cover").as_deref(),
        Some("Cover could not be uploaded: this deployment has no room left"),
        "the uploader's reason must reach the field's inline error: {html}"
    );
    assert!(
        !html.contains("Cover is required"),
        "'required' would restate the symptom and hide the reason: {html}"
    );
    assert!(
        !html.contains("data-file-current"),
        "a create must not present the refused filename as a stored file: {html}"
    );
    assert!(
        docs(&db).await.is_empty(),
        "a refused upload must not create the record"
    );
}

#[tokio::test]
async fn an_untouched_file_input_keeps_the_stored_path_and_a_chosen_one_replaces_it() {
    let db = seeded_db().await;
    let uploader = RecordingUploader::default();
    let router = router(db.clone(), Some(uploader.clone()));
    let doc = seed_doc(&db, "Original", "cover.png", "spec.pdf").await;

    // A browser submits every file input.
    let csrf = new_csrf();
    let body = multipart_body(
        "B",
        &[
            ("title", None, "Renamed"),
            ("cover", Some(""), ""),
            ("attachment", Some(""), ""),
            ("csrf_token", None, &csrf),
        ],
    );
    let response = post_multipart(
        &router,
        &format!("/admin/docs/{}/edit", doc.id),
        &csrf,
        "B",
        body,
    )
    .await;
    assert_eq!(response.status(), 303, "an untouched upload saves");
    let updated = docs(&db).await;
    assert_eq!(updated[0].title, "Renamed");
    assert_eq!(updated[0].cover, "cover.png", "the stored path is kept");
    assert_eq!(updated[0].attachment, "spec.pdf");
    assert!(
        uploader.seen().is_empty(),
        "an untouched file input must not reach the uploader"
    );

    // Choosing a file replaces the stored one: the new path is what is stored.
    let csrf = new_csrf();
    let body = multipart_body(
        "B",
        &[
            ("title", None, "Renamed"),
            ("cover", Some("new.png"), "NEW-BYTES"),
            ("attachment", Some(""), ""),
            ("csrf_token", None, &csrf),
        ],
    );
    let response = post_multipart(
        &router,
        &format!("/admin/docs/{}/edit", doc.id),
        &csrf,
        "B",
        body,
    )
    .await;
    assert_eq!(response.status(), 303);
    assert_eq!(docs(&db).await[0].cover, "/uploads/new.png");
}

/// A url-encoded pair under a declared file field's name is dropped before validation.
#[tokio::test]
async fn a_text_value_for_a_file_upload_is_not_stored_on_create() {
    let db = seeded_db().await;
    let router = router(db.clone(), Some(RecordingUploader::default()));
    let csrf = new_csrf();
    let body = format!("title=Notes&cover=javascript%3Aalert%281%29&csrf_token={csrf}");

    let response = post(
        &router,
        "/admin/docs/create",
        &csrf,
        "application/x-www-form-urlencoded".to_string(),
        body,
    )
    .await;
    assert_eq!(
        response.status(),
        200,
        "the form re-renders with the required error"
    );
    let html = body_string(response).await;
    assert_eq!(
        field_error(&html, "cover").as_deref(),
        Some("Cover is required"),
        "the typed value leaves the required field empty: {html}"
    );
    assert!(
        !html.contains("javascript"),
        "the typed value must not survive into the re-rendered form: {html}"
    );
    assert!(
        docs(&db).await.is_empty(),
        "a client-typed upload value must not create the record"
    );
}

/// A multipart text part under a declared file field's name is dropped too.
#[tokio::test]
async fn a_text_value_for_a_file_upload_keeps_the_stored_file_on_edit() {
    let db = seeded_db().await;
    let router = router(db.clone(), Some(RecordingUploader::default()));
    let doc = seed_doc(&db, "Original", "/uploads/old.png", "spec.pdf").await;
    let csrf = new_csrf();
    let body = multipart_body(
        "B",
        &[
            ("title", None, "Renamed"),
            ("cover", None, "javascript:alert(1)"),
            ("csrf_token", None, &csrf),
        ],
    );

    let response = post_multipart(
        &router,
        &format!("/admin/docs/{}/edit", doc.id),
        &csrf,
        "B",
        body,
    )
    .await;
    assert_eq!(
        response.status(),
        303,
        "the edit saves with the stored file kept"
    );
    let updated = docs(&db).await;
    assert_eq!(
        updated[0].title, "Renamed",
        "the rest of the edit still applies"
    );
    assert_eq!(
        updated[0].cover, "/uploads/old.png",
        "a client-typed value must not replace the stored file"
    );
}

/// Duplicate part names are last-write-wins.
#[tokio::test]
async fn a_text_part_after_a_file_part_does_not_forge_a_value_on_create() {
    let db = seeded_db().await;
    let router = router(db.clone(), None::<RecordingUploader>);
    let csrf = new_csrf();
    let body = multipart_body(
        "B",
        &[
            ("title", None, "Notes"),
            ("cover", Some("cover.png"), "PNG-BYTES"),
            ("cover", None, "javascript:alert(1)"),
            ("csrf_token", None, &csrf),
        ],
    );

    let response = post_multipart(&router, "/admin/docs/create", &csrf, "B", body).await;
    assert_eq!(
        response.status(),
        200,
        "the form re-renders with the required error"
    );
    let html = body_string(response).await;
    assert_eq!(
        field_error(&html, "cover").as_deref(),
        Some("Cover is required"),
        "the later text part leaves the field empty: {html}"
    );
    assert!(
        !html.contains("javascript"),
        "the typed value must not survive into the re-rendered form: {html}"
    );
    assert!(
        docs(&db).await.is_empty(),
        "the typed value must not create the record"
    );
}

/// The same duplicate-name bypass on edit, with an uploader installed.
#[tokio::test]
async fn a_text_part_after_a_file_part_keeps_the_stored_file_on_edit() {
    let db = seeded_db().await;
    let uploader = RecordingUploader::default();
    let router = router(db.clone(), Some(uploader.clone()));
    let doc = seed_doc(&db, "Original", "/uploads/old.png", "spec.pdf").await;
    let csrf = new_csrf();
    let body = multipart_body(
        "B",
        &[
            ("title", None, "Renamed"),
            ("cover", Some("new.png"), "NEW-BYTES"),
            ("cover", None, "javascript:alert(1)"),
            ("csrf_token", None, &csrf),
        ],
    );

    let response = post_multipart(
        &router,
        &format!("/admin/docs/{}/edit", doc.id),
        &csrf,
        "B",
        body,
    )
    .await;
    assert_eq!(response.status(), 303, "the edit saves");
    let updated = docs(&db).await;
    assert_eq!(
        updated[0].title, "Renamed",
        "the rest of the edit still applies"
    );
    assert_eq!(
        updated[0].cover, "/uploads/old.png",
        "the stored file must survive the duplicate name"
    );
    assert!(
        uploader.seen().is_empty(),
        "the discarded file part must not reach the uploader"
    );
}

/// The duplicate-name bypass on edit with no uploader.
#[tokio::test]
async fn a_text_part_after_a_file_part_keeps_the_stored_file_without_an_uploader() {
    let db = seeded_db().await;
    let router = router(db.clone(), None::<RecordingUploader>);
    let doc = seed_doc(&db, "Original", "/uploads/old.png", "spec.pdf").await;
    let csrf = new_csrf();
    let body = multipart_body(
        "B",
        &[
            ("title", None, "Renamed"),
            ("cover", Some("new.png"), "NEW-BYTES"),
            ("cover", None, "javascript:alert(1)"),
            ("csrf_token", None, &csrf),
        ],
    );

    let response = post_multipart(
        &router,
        &format!("/admin/docs/{}/edit", doc.id),
        &csrf,
        "B",
        body,
    )
    .await;
    assert_eq!(response.status(), 303, "the edit saves");
    assert_eq!(
        docs(&db).await[0].cover,
        "/uploads/old.png",
        "the stored file must survive the duplicate name"
    );
}

/// The last part wins in the other order too.
#[tokio::test]
async fn a_file_part_after_a_text_part_wins_on_create() {
    let db = seeded_db().await;
    let router = router(db.clone(), Some(RecordingUploader::default()));
    let csrf = new_csrf();
    let body = multipart_body(
        "B",
        &[
            ("title", None, "Notes"),
            ("cover", None, "javascript:alert(1)"),
            ("cover", Some("cover.png"), "PNG-BYTES"),
            ("csrf_token", None, &csrf),
        ],
    );

    let response = post_multipart(&router, "/admin/docs/create", &csrf, "B", body).await;
    assert_eq!(response.status(), 303, "the last part is a file and wins");
    let created = docs(&db).await;
    assert_eq!(
        created[0].cover, "/uploads/cover.png",
        "the file part's value is what the record stores"
    );
}

/// A later file part whose name sanitizes to empty discards the staged bytes.
#[tokio::test]
async fn a_rejected_filename_after_a_file_part_discards_the_staged_bytes() {
    let db = seeded_db().await;
    let uploader = RecordingUploader::default();
    let router = router(db.clone(), Some(uploader.clone()));
    let csrf = new_csrf();
    let body = multipart_body(
        "B",
        &[
            ("title", None, "Notes"),
            ("cover", Some("first.png"), "FIRST-BYTES"),
            ("cover", Some(".."), "SECOND-BYTES"),
            ("csrf_token", None, &csrf),
        ],
    );

    let response = post_multipart(&router, "/admin/docs/create", &csrf, "B", body).await;
    assert_eq!(
        response.status(),
        200,
        "a rejected name leaves the required field empty"
    );
    assert!(
        uploader.seen().is_empty(),
        "the discarded file part must not reach the uploader"
    );
    assert!(
        docs(&db).await.is_empty(),
        "a rejected name must not create the record"
    );
}

#[tokio::test]
async fn clearing_an_optional_upload_empties_the_stored_path() {
    let db = seeded_db().await;
    let router = router(db.clone(), Some(RecordingUploader::default()));
    let doc = seed_doc(&db, "Original", "cover.png", "spec.pdf").await;

    let csrf = new_csrf();
    let body = multipart_body(
        "B",
        &[
            ("title", None, "Original"),
            ("cover", Some(""), ""),
            ("attachment", Some(""), ""),
            // The framework's own control posts this.
            ("clear_attachment", None, "1"),
            ("csrf_token", None, &csrf),
        ],
    );
    let response = post_multipart(
        &router,
        &format!("/admin/docs/{}/edit", doc.id),
        &csrf,
        "B",
        body,
    )
    .await;
    assert_eq!(response.status(), 303, "clearing an optional upload saves");

    let updated = docs(&db).await;
    assert_eq!(updated[0].attachment, "", "the cleared field is emptied");
    assert_eq!(updated[0].cover, "cover.png", "the untouched one is kept");
}

#[tokio::test]
async fn clearing_a_required_upload_is_refused_inline() {
    let db = seeded_db().await;
    let router = router(db.clone(), Some(RecordingUploader::default()));
    let doc = seed_doc(&db, "Original", "cover.png", "spec.pdf").await;

    let csrf = new_csrf();
    let body = multipart_body(
        "B",
        &[
            ("title", None, "Original"),
            ("cover", Some(""), ""),
            ("attachment", Some(""), ""),
            ("clear_cover", None, "1"),
            ("csrf_token", None, &csrf),
        ],
    );
    let response = post_multipart(
        &router,
        &format!("/admin/docs/{}/edit", doc.id),
        &csrf,
        "B",
        body,
    )
    .await;
    assert_eq!(response.status(), 200, "the form re-renders with the error");
    let html = body_string(response).await;
    assert_eq!(
        field_error(&html, "cover").as_deref(),
        Some("Cover is required"),
        "a required upload refuses the clear inline: {html}"
    );
    assert_eq!(
        docs(&db).await[0].cover,
        "cover.png",
        "the refused clear writes nothing"
    );
}

#[tokio::test]
async fn a_refused_edit_upload_keeps_showing_the_stored_file() {
    let db = seeded_db().await;
    let router = router(db.clone(), Some(FailingUploader));
    let doc = seed_doc(&db, "Notes", "/uploads/old.png", "spec.pdf").await;

    let csrf = new_csrf();
    let body = multipart_body(
        "B",
        &[
            ("title", None, "Renamed"),
            ("cover", Some("new.png"), "NEW-BYTES"),
            ("attachment", Some(""), ""),
            ("csrf_token", None, &csrf),
        ],
    );
    let response = post_multipart(
        &router,
        &format!("/admin/docs/{}/edit", doc.id),
        &csrf,
        "B",
        body,
    )
    .await;
    assert_eq!(response.status(), 200, "the form re-renders");
    let html = body_string(response).await;
    assert_eq!(
        field_error(&html, "cover").as_deref(),
        Some("Cover could not be uploaded: this deployment has no room left"),
        "the reason must reach the field: {html}"
    );
    assert!(
        html.contains("data-file-current=\"/uploads/old.png\""),
        "the stored file is still there and must still be shown: {html}"
    );
    assert_eq!(
        docs(&db).await[0].cover,
        "/uploads/old.png",
        "a refused upload writes nothing"
    );
}

#[tokio::test]
async fn an_over_cap_body_still_413s_with_an_uploader_installed() {
    let db = seeded_db().await;
    let router = router(db.clone(), Some(RecordingUploader::default()));
    let csrf = new_csrf();
    let huge = "a".repeat(11 * 1024 * 1024);
    let body = multipart_body(
        "B",
        &[
            ("title", None, "Too big"),
            ("cover", Some("huge.png"), &huge),
            ("csrf_token", None, &csrf),
        ],
    );

    let response = post_multipart(&router, "/admin/docs/create", &csrf, "B", body).await;
    assert_eq!(
        response.status(),
        413,
        "an over-cap upload must 413 whether or not the bytes are buffered"
    );
    assert!(
        docs(&db).await.is_empty(),
        "an over-cap body must not create the record"
    );
}

#[tokio::test]
async fn the_edit_form_links_the_stored_files() {
    let db = seeded_db().await;
    let router = router(db.clone(), Some(RecordingUploader::default()));
    let doc = seed_doc(&db, "Notes", "/uploads/photo.png", "/files/spec.pdf").await;

    let response = get(&router, &format!("/admin/docs/{}/edit", doc.id)).await;
    assert!(response.status().is_success());
    let html = body_string(response).await;
    assert!(
        !html.contains("src=\"/uploads/photo.png\""),
        "no stored path is rendered as an image: {html}"
    );
    assert!(
        html.contains("href=\"/uploads/photo.png\""),
        "a stored image path is a link to the file: {html}"
    );
    assert!(
        html.contains("href=\"/files/spec.pdf\""),
        "a stored non-image path is a link to the file: {html}"
    );
    // Both stored values offer the clear control, labelled with what it does.
    assert!(html.contains("name=\"clear_cover\""), "{html}");
    assert!(html.contains("name=\"clear_attachment\""), "{html}");
    assert!(html.contains("Remove the current file"), "{html}");
}

#[tokio::test]
async fn a_create_form_offers_no_stored_value_and_no_clear_control() {
    let db = seeded_db().await;
    let router = router(db.clone(), Some(RecordingUploader::default()));

    let response = get(&router, "/admin/docs/create").await;
    assert!(response.status().is_success());
    let html = body_string(response).await;
    assert!(!html.contains("<img"), "{html}");
    assert!(!html.contains("data-file-current"), "{html}");
    assert!(!html.contains("name=\"clear_"), "{html}");
    assert!(
        html.contains("enctype=\"multipart/form-data\""),
        "a form with a file input posts multipart: {html}"
    );
}

#[tokio::test]
async fn serve_dir_serves_the_upload_directory_through_the_panel() {
    let db = seeded_db().await;
    let dir = temp_dir("serve");
    std::fs::write(dir.join("cat.png"), b"PNG-FILE").expect("write upload");

    let router = mount(
        db,
        Panel::new("admin")
            .auth(Auth::disabled())
            .serve_dir("/uploads/{*file}", dir.clone())
            .resource::<DocResource>(),
    )
    .expect("panel builds");

    let response = get(&router, "/uploads/cat.png").await;
    assert_eq!(response.status(), 200, "the stored path is fetchable");
    assert_eq!(body_bytes(response).await, b"PNG-FILE");

    // The directory route's own rules hold through the panel.
    let escaped = get(&router, "/uploads/%2e%2e/Cargo.toml").await;
    assert_eq!(
        escaped.status(),
        404,
        "a path out of the served directory is not served"
    );
    let missing = get(&router, "/uploads/absent.png").await;
    assert_eq!(missing.status(), 404);
}

#[tokio::test]
async fn a_served_directory_is_reachable_without_a_session() {
    let db = auth_seeded_db().await;
    let dir = temp_dir("serve-anonymous");
    std::fs::write(dir.join("cat.png"), b"PNG-FILE").expect("write upload");

    let router = mount(
        db,
        Panel::new("admin")
            // No `.auth(..)` call.
            .serve_dir("/uploads/{*file}", dir.clone())
            .resource::<DocResource>(),
    )
    .expect("panel builds");

    // The gate is live.
    let page = get(&router, "/admin/docs").await;
    assert_eq!(
        page.status(),
        307,
        "the panel must still gate anonymous page requests"
    );
    assert_eq!(
        page.headers().get(LOCATION).unwrap().to_str().unwrap(),
        "/admin/login?next=%2Fadmin%2Fdocs",
        "the anonymous panel page must be sent to login"
    );

    // The served directory is not behind that gate: no cookie, no session.
    let response = get(&router, "/uploads/cat.png").await;
    assert_eq!(
        response.status(),
        200,
        "a served file needs no session (ADR-0017)"
    );
    assert_eq!(body_bytes(response).await, b"PNG-FILE");
}

#[tokio::test]
async fn served_active_content_is_inert() {
    let db = seeded_db().await;
    let dir = temp_dir("serve-inert");
    std::fs::write(dir.join("cat.png"), b"PNG-FILE").expect("write upload");
    std::fs::write(
        dir.join("evil.svg"),
        br#"<svg xmlns="http://www.w3.org/2000/svg"/>"#,
    )
    .expect("write upload");
    std::fs::write(dir.join("evil.html"), b"<p>x</p>").expect("write upload");

    let router = mount(
        db,
        Panel::new("admin")
            .auth(Auth::disabled())
            .serve_dir("/uploads/{*file}", dir.clone())
            .resource::<DocResource>(),
    )
    .expect("panel builds");

    let png = get(&router, "/uploads/cat.png").await;
    assert_eq!(png.status(), 200);
    assert_eq!(
        png.headers().get(X_CONTENT_TYPE_OPTIONS).unwrap(),
        "nosniff",
        "a served file is never sniffed"
    );
    assert_eq!(
        csp(&png),
        SERVED_FILE_POLICY,
        "a served file carries the fixed sandboxing policy"
    );
    assert!(
        png.headers().get(CONTENT_DISPOSITION).is_none(),
        "a raster image opens inline"
    );

    // A revalidated file is still hardened, and the missing `Content-Type` of a
    // 304 must not turn an inline image into a download.
    let last_modified = png
        .headers()
        .get(LAST_MODIFIED)
        .expect("a served file is dated")
        .to_str()
        .unwrap()
        .to_string();
    let revalidated = get_if_modified_since(&router, "/uploads/cat.png", &last_modified).await;
    assert_eq!(revalidated.status(), 304, "the file did not change");
    assert_eq!(
        revalidated.headers().get(X_CONTENT_TYPE_OPTIONS).unwrap(),
        "nosniff"
    );
    assert_eq!(csp(&revalidated), SERVED_FILE_POLICY);
    assert!(
        revalidated.headers().get(CONTENT_DISPOSITION).is_none(),
        "a 304 has nothing to download"
    );

    for path in ["/uploads/evil.svg", "/uploads/evil.html"] {
        let response = get(&router, path).await;
        assert_eq!(response.status(), 200, "{path} is served");
        assert_eq!(
            response.headers().get(X_CONTENT_TYPE_OPTIONS).unwrap(),
            "nosniff",
            "{path} is never sniffed"
        );
        assert_eq!(
            csp(&response),
            SERVED_FILE_POLICY,
            "{path} carries the fixed sandboxing policy"
        );
        let disposition = response
            .headers()
            .get(CONTENT_DISPOSITION)
            .unwrap_or_else(|| panic!("{path} must download"))
            .to_str()
            .unwrap();
        assert!(
            disposition.starts_with("attachment"),
            "{path} must download, got {disposition}"
        );
    }

    // The layer is scoped to the served path.
    let page = get(&router, "/admin/docs").await;
    assert_eq!(page.status(), 200);
    assert_eq!(
        csp(&page),
        "frame-ancestors 'self'",
        "a panel page keeps its own policy"
    );
}

#[tokio::test]
async fn a_serve_dir_path_without_a_catch_all_fails_the_build() {
    let db = seeded_db().await;
    let errors = refusal(mount(
        db,
        Panel::new("admin")
            .serve_dir("/uploads", temp_dir("bad-path"))
            .resource::<DocResource>(),
    ));
    assert_eq!(
        errors[0].kind,
        DeclarationErrorKind::ServeDirWithoutCatchAll {
            path: "/uploads".to_string(),
        }
    );
}