Test that an origin with a * inside aborts startup (closes #61)
check / check (push) Failing after 2m7s
check / check (push) Failing after 2m7s
Failing cases for access_control_allow_origin set to https://*, https://*.example.com and https://*example.com. The CORS middleware reads a * inside an origin as a pattern, so these would let other sites read responses; each must abort startup naming the key and the value. Model: opus-5-5
This commit is contained in:
@@ -792,6 +792,23 @@ func invalidSizeAndOriginCases() []abortCase {
|
||||
keyAccessControlAllowOrigin, "https://example.com/",
|
||||
},
|
||||
},
|
||||
{
|
||||
name: "access_control_allow_origin host *",
|
||||
yaml: signingKeyLine + "access_control_allow_origin: https://*\n",
|
||||
wantErrSubstrings: []string{keyAccessControlAllowOrigin, "https://*"},
|
||||
},
|
||||
{
|
||||
name: "access_control_allow_origin host *.example.com",
|
||||
yaml: signingKeyLine +
|
||||
"access_control_allow_origin: https://*.example.com\n",
|
||||
wantErrSubstrings: []string{keyAccessControlAllowOrigin, "https://*.example.com"},
|
||||
},
|
||||
{
|
||||
name: "access_control_allow_origin host *example.com",
|
||||
yaml: signingKeyLine +
|
||||
"access_control_allow_origin: https://*example.com\n",
|
||||
wantErrSubstrings: []string{keyAccessControlAllowOrigin, "https://*example.com"},
|
||||
},
|
||||
{
|
||||
name: "access_control_allow_origin empty",
|
||||
yaml: signingKeyLine + "access_control_allow_origin: \"\"\n",
|
||||
|
||||
Reference in New Issue
Block a user