1 package org.cacert.gigi;
3 import static org.junit.Assert.*;
5 import java.io.IOException;
6 import java.net.HttpURLConnection;
9 import org.cacert.gigi.testUtils.ManagedTest;
10 import org.junit.Test;
12 public class TestSecurityHeaders extends ManagedTest {
15 public void testSTS() throws IOException {
16 HttpURLConnection uc = (HttpURLConnection) new URL("https://" + getServerName()).openConnection();
17 assertNotNull(uc.getHeaderField("Strict-Transport-Security"));
20 public void testCSP() throws IOException {
21 HttpURLConnection uc = (HttpURLConnection) new URL("https://" + getServerName()).openConnection();
22 assertNotNull(uc.getHeaderField("Content-Security-Policy"));
25 public void testAllowOrigin() throws IOException {
26 HttpURLConnection uc = (HttpURLConnection) new URL("https://" + getServerName()).openConnection();
27 assertNotNull(uc.getHeaderField("Access-Control-Allow-Origin"));