test: add failing config tests for trusted_proxies
Check that a valid CIDR list lands in TrustedProxies in order, an omitted key trusts no one, and an invalid or null value aborts startup naming the key and value. The list parser is shared with blocked_networks, whose tests exercise the remaining shapes. Model: opus-4-8
This commit is contained in:
@@ -0,0 +1,65 @@
|
|||||||
|
package config
|
||||||
|
|
||||||
|
import (
|
||||||
|
"strings"
|
||||||
|
"testing"
|
||||||
|
)
|
||||||
|
|
||||||
|
// TestTrustedProxiesConfig checks the trusted_proxies key wiring: a valid
|
||||||
|
// CIDR list lands in TrustedProxies in order, and an omitted key trusts no
|
||||||
|
// one. The list parser itself is shared with blocked_networks and is
|
||||||
|
// exercised in depth by that key's tests.
|
||||||
|
func TestTrustedProxiesConfig(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
t.Run("valid list is parsed in order", func(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
c, err := configFromYAML(t,
|
||||||
|
signingKeyLine+`trusted_proxies: ["10.0.0.0/8", "2001:db8::/32"]`+"\n")
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("valid trusted_proxies should load: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
got := make([]string, len(c.TrustedProxies))
|
||||||
|
for i, p := range c.TrustedProxies {
|
||||||
|
got[i] = p.String()
|
||||||
|
}
|
||||||
|
|
||||||
|
if joined := strings.Join(got, ","); joined != "10.0.0.0/8,2001:db8::/32" {
|
||||||
|
t.Errorf("TrustedProxies = %v, want the two ranges in order", got)
|
||||||
|
}
|
||||||
|
})
|
||||||
|
|
||||||
|
t.Run("omitted key trusts no one", func(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
c, err := configFromYAML(t, signingKeyLine)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("minimal config should load: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
if len(c.TrustedProxies) != 0 {
|
||||||
|
t.Errorf("TrustedProxies = %v, want empty", c.TrustedProxies)
|
||||||
|
}
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
// TestTrustedProxiesInvalidAbortsStartup checks that an invalid or null
|
||||||
|
// value aborts startup with an error naming the key and the offending value.
|
||||||
|
func TestTrustedProxiesInvalidAbortsStartup(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
runAbortCases(t, []abortCase{
|
||||||
|
{
|
||||||
|
name: "invalid cidr",
|
||||||
|
yaml: signingKeyLine + `trusted_proxies: ["999.0.0.0/8"]` + "\n",
|
||||||
|
wantErrSubstrings: []string{keyTrustedProxies, "999.0.0.0/8"},
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "null value",
|
||||||
|
yaml: signingKeyLine + "trusted_proxies:\n",
|
||||||
|
wantErrSubstrings: []string{keyTrustedProxies, nullValueText},
|
||||||
|
},
|
||||||
|
})
|
||||||
|
}
|
||||||
Reference in New Issue
Block a user