"), content.PerPage)
}
if !strings.Contains(body, `rel="next" href="/posts/page/2/"`) || strings.Contains(body, `rel="prev"`) {
t.Errorf("page one should link next and not prev:\n%s", body)
}
rec = httptest.NewRecorder()
h.ServeHTTP(rec, httptest.NewRequest(http.MethodGet, "/posts/page/2/", nil))
if rec.Code != http.StatusOK {
t.Fatalf("page two = %d, want 200", rec.Code)
}
body = rec.Body.String()
if strings.Count(body, "
"))
}
if !strings.Contains(body, `rel="prev" href="/posts/"`) {
t.Errorf("page two should link back to the bare listing URL:\n%s", body)
}
}
func TestPagePastTheEndIs404(t *testing.T) {
h := listingHandler(t, 3)
rec := httptest.NewRecorder()
h.ServeHTTP(rec, httptest.NewRequest(http.MethodGet, "/posts/page/9/", nil))
if rec.Code != http.StatusNotFound {
t.Errorf("got %d, want 404: an empty page is a URL that means nothing", rec.Code)
}
}
func TestStaticFilesAreServedAndDirectoriesAreNot(t *testing.T) {
fsys := fstest.MapFS{
"content/pages/about.md": {Data: []byte("---\ntitle: About\n---\nx\n")},
"static/style.css": {Data: []byte("body{}")},
"static/img/logo.svg": {Data: []byte("")},
}
bundles, err := content.Scan(fsys)
if err != nil {
t.Fatal(err)
}
r, err := render.New(fsys, content.Settings{}, nil)
if err != nil {
t.Fatal(err)
}
h := Handler(Fixed(content.NewSite(bundles)), r, fsys, nil, content.Settings{})
for path, want := range map[string]int{
"/static/style.css": http.StatusOK,
"/static/img/logo.svg": http.StatusOK,
"/static/": http.StatusNotFound,
"/static/img/": http.StatusNotFound,
"/static/nope.css": http.StatusNotFound,
} {
rec := httptest.NewRecorder()
h.ServeHTTP(rec, httptest.NewRequest(http.MethodGet, path, nil))
if rec.Code != want {
t.Errorf("GET %s = %d, want %d", path, rec.Code, want)
}
}
}
func TestAStaticPathThatEscapesTheRootIs404(t *testing.T) {
// A real directory, not a MapFS: the guard being tested belongs to os.Root (ADR-0031), and the point is
// what the *response* is when it refuses — a miss, never an error page that confirms the path.
dir := t.TempDir()
if err := os.MkdirAll(filepath.Join(dir, "static"), 0o755); err != nil {
t.Fatal(err)
}
if err := os.WriteFile(filepath.Join(dir, "static", "ok.css"), []byte("body{}"), 0o644); err != nil {
t.Fatal(err)
}
outside := filepath.Join(dir, "outside.txt")
if err := os.WriteFile(outside, []byte("secret"), 0o644); err != nil {
t.Fatal(err)
}
if err := os.Symlink(outside, filepath.Join(dir, "static", "escape.txt")); err != nil {
t.Skipf("symlinks unavailable: %v", err)
}
fsys, err := content.OpenSite(dir)
if err != nil {
t.Fatal(err)
}
r, err := render.New(fsys, content.Settings{}, nil)
if err != nil {
t.Fatal(err)
}
h := Handler(Fixed(content.NewSite(nil)), r, fsys, nil, content.Settings{})
for path, want := range map[string]int{
"/static/ok.css": http.StatusOK,
"/static/escape.txt": http.StatusNotFound,
} {
rec := httptest.NewRecorder()
h.ServeHTTP(rec, httptest.NewRequest(http.MethodGet, path, nil))
if rec.Code != want {
t.Errorf("GET %s = %d, want %d", path, rec.Code, want)
}
if strings.Contains(rec.Body.String(), "secret") {
t.Fatalf("GET %s served bytes from outside the root", path)
}
}
}
func seriesHandler(t *testing.T) http.Handler {
t.Helper()
fsys := fstest.MapFS{
"content/comics/the-long-monsoon/_index.md": {Data: []byte("---\ntitle: The Long Monsoon\n---\nA series.\n")},
"content/comics/the-long-monsoon/first-rain.md": {Data: []byte("---\ntitle: First Rain\norder: 10\n---\n")},
"content/comics/the-long-monsoon/the-flood.md": {Data: []byte("---\ntitle: The Flood\norder: 20\n---\n")},
"content/comics/the-long-monsoon/aftermath.md": {Data: []byte("---\ntitle: Aftermath\norder: 30\n---\n")},
"content/pages/about.md": {Data: []byte("---\ntitle: About\n---\nx\n")},
}
bundles, err := content.Scan(fsys)
if err != nil {
t.Fatal(err)
}
r, err := render.New(nil, content.Settings{}, nil)
if err != nil {
t.Fatal(err)
}
return Handler(Fixed(content.NewSite(bundles)), r, nil, nil, content.Settings{})
}
func TestSequenceNavigationLinksNeighbours(t *testing.T) {
h := seriesHandler(t)
rec := httptest.NewRecorder()
h.ServeHTTP(rec, httptest.NewRequest(http.MethodGet, "/comics/the-long-monsoon/the-flood/", nil))
if rec.Code != http.StatusOK {
t.Fatalf("got %d, want 200", rec.Code)
}
body := rec.Body.String()
for _, want := range []string{
`rel="prev" href="/comics/the-long-monsoon/first-rain/"`,
`rel="next" href="/comics/the-long-monsoon/aftermath/"`,
`href="/comics/the-long-monsoon/">The Long Monsoon 2 of 3`,
} {
if !strings.Contains(body, want) {
t.Errorf("missing %q — prev is the *earlier* chapter:\n%s", want, body)
}
}
nav := body[strings.Index(body, `")], "the-flood") {
t.Error("the nav should link its neighbours and the series, never the chapter it is on")
}
}
func TestSequenceEndsHaveNoNeighbourBeyondThem(t *testing.T) {
h := seriesHandler(t)
for path, absent := range map[string]string{
"/comics/the-long-monsoon/first-rain/": `rel="prev"`,
"/comics/the-long-monsoon/aftermath/": `rel="next"`,
} {
rec := httptest.NewRecorder()
h.ServeHTTP(rec, httptest.NewRequest(http.MethodGet, path, nil))
if rec.Code != http.StatusOK {
t.Fatalf("GET %s = %d, want 200", path, rec.Code)
}
if strings.Contains(rec.Body.String(), absent) {
t.Errorf("GET %s should not carry %s at the end of a series", path, absent)
}
}
}
func TestSeriesLandingPageListsChaptersInOrder(t *testing.T) {
h := seriesHandler(t)
rec := httptest.NewRecorder()
h.ServeHTTP(rec, httptest.NewRequest(http.MethodGet, "/comics/the-long-monsoon/", nil))
if rec.Code != http.StatusOK {
t.Fatalf("got %d, want 200", rec.Code)
}
body := rec.Body.String()
if !strings.Contains(body, "A series.") {
t.Error("the landing page is still a bundle and renders its own body")
}
first, second, third := strings.Index(body, "First Rain"), strings.Index(body, "The Flood"), strings.Index(body, "Aftermath")
if first < 0 || second < first || third < second {
t.Errorf("the archive must read in sequence order, not newest first:\n%s", body)
}
if strings.Contains(body, `rel="prev"`) || strings.Contains(body, `rel="next"`) {
t.Error("a landing page holds no position of its own, so it has no neighbours")
}
}
func TestPagesOutsideASeriesGetNoSequence(t *testing.T) {
h := seriesHandler(t)
rec := httptest.NewRecorder()
h.ServeHTTP(rec, httptest.NewRequest(http.MethodGet, "/pages/about/", nil))
if rec.Code != http.StatusOK {
t.Fatalf("got %d, want 200", rec.Code)
}
if body := rec.Body.String(); strings.Contains(body, "sequence") {
t.Errorf("an unrelated page must render no sequence nav:\n%s", body)
}
}
func tagHandler(t *testing.T) http.Handler {
t.Helper()
fsys := fstest.MapFS{
"content/posts/essay.md": {Data: []byte("---\ntitle: Essay\ndate: 2026-01-03\ntags: [Monsoon]\n---\n")},
"content/comics/rain.md": {Data: []byte("---\ntitle: Rain\ndate: 2026-01-02\ntags: [monsoon]\n---\n")},
"content/posts/other.md": {Data: []byte("---\ntitle: Other\ndate: 2026-01-01\ntags: [prose]\n---\n")},
}
bundles, err := content.Scan(fsys)
if err != nil {
t.Fatal(err)
}
r, err := render.New(nil, content.Settings{}, nil)
if err != nil {
t.Fatal(err)
}
return Handler(Fixed(content.NewSite(bundles)), r, nil, nil, content.Settings{})
}
func TestGlobalTagListingSpansSectionsGroupedByOne(t *testing.T) {
h := tagHandler(t)
rec := httptest.NewRecorder()
h.ServeHTTP(rec, httptest.NewRequest(http.MethodGet, "/tags/monsoon/", nil))
if rec.Code != http.StatusOK {
t.Fatalf("got %d, want 200", rec.Code)
}
body := rec.Body.String()
for _, want := range []string{"
posts
", "
comics
", "Essay", "Rain"} {
if !strings.Contains(body, want) {
t.Errorf("missing %q — a tag spans sections and groups by one:\n%s", want, body)
}
}
if strings.Contains(body, "Other") {
t.Error("a different tag leaked in")
}
}
func TestSectionNarrowedTagListing(t *testing.T) {
h := tagHandler(t)
rec := httptest.NewRecorder()
h.ServeHTTP(rec, httptest.NewRequest(http.MethodGet, "/comics/tags/monsoon/", nil))
if rec.Code != http.StatusOK {
t.Fatalf("got %d, want 200", rec.Code)
}
body := rec.Body.String()
if !strings.Contains(body, "Rain") || strings.Contains(body, "Essay") {
t.Errorf("narrowing to comics should drop the posts entry:\n%s", body)
}
}