Skip to content

test: prevent rechallenge tests from opening browsers - #3098

Merged
rinatkhaziev merged 1 commit into
trunkfrom
test/stub-rechallenge-browser
Oct 9, 2026
Merged

rinatkhaziev merged 1 commit into
trunkfrom
test/stub-rechallenge-browser

Conversation

@sjinks

@sjinks sjinks commented Oct 9, 2026 •

Copy link
Copy Markdown
Member

Changes

  • Inject Runner.OpenURL stubs into every Go rechallenge test runner, including GraphQL middleware fixtures, so tests cannot open verification URLs in the default browser.
  • Assert the requested verification URL on successful interactive flows and reject browser calls on non-interactive, unsupported-version, and session-creation failure paths.
  • Keep production behavior unchanged. Node rechallenge tests already mock browser opening.

Validation

  • Full Go unit suite: make test (ambient proxies unset for the command).
  • Go lint: make lint.
  • Rechallenge and GraphQL race tests: go test -race ./internal/rechallenge ./internal/gql -count=10.
  • Existing Node rechallenge flow/link tests: 26 tests passed.
  • git diff --check.

This is the separate test-stubbing follow-up discussed during #3097.

Copilot AI balanced review requested due to automatic review settings October 9, 2026 12:17
@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Scanned Files

None

@sonarqubecloud

sonarqubecloud Bot commented Oct 9, 2026

Copy link
Copy Markdown

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

The test-only changes comprehensively prevent unintended browser launches and correctly validate applicable flow behavior.

0 open findings

What changed in this PR

Prevents Go rechallenge tests from launching real browsers while preserving production behavior.

Changes:

  • Injects browser-opening stubs across rechallenge test runners.
  • Verifies expected URLs and rejects browser calls on invalid flows.
File Description
internal/​rechallenge/​redact_test.go Stubs browser opening in redaction coverage.
internal/​rechallenge/​flow_test.go Stubs and validates interactive browser behavior.
internal/​rechallenge/​flow_noninteractive_test.go Rejects browser calls in non-interactive flows.
internal/​gql/​rechallenge_test.go Stubs browser behavior in GraphQL middleware tests.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@rinatkhaziev
rinatkhaziev merged commit 468c643 into trunk Oct 9, 2026
29 checks passed
@rinatkhaziev
rinatkhaziev deleted the test/stub-rechallenge-browser branch October 9, 2026 18:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants