I want to write a unit test to ensure CORS is on and that a particular WebApi method can only be called from a client that reports to be from a certain domain.
I think I'm running into a common gotcha that's described here, whereby it's not seen as a true cross domain request...
The type of unit test would look something like this...
[Fact]
public async Task CheckCors()
{
var httpClient = new HttpClient();
httpClient.BaseAddress = new Uri("http://clientdomain.co.uk/");
httpClient.DefaultRequestHeaders.Accept.Clear();
httpClient.DefaultRequestHeaders.Accept.Add(new MediaTypeWithQualityHeaderValue("application/json"));
var response = await client.GetAsync(new Uri($"http://apidomain.co.uk/api/testcors", UriKind.Absolute));
// Should be forbidden to call the api
response.StatusCode.Should().Be(HttpStatusCode.Forbidden);
}
I may have misunderstood things, but can anyone put me right?