diff --git a/internal/config/trusted_proxies_internal_test.go b/internal/config/trusted_proxies_internal_test.go index b2593c0..ae61bfd 100644 --- a/internal/config/trusted_proxies_internal_test.go +++ b/internal/config/trusted_proxies_internal_test.go @@ -5,14 +5,15 @@ import ( "testing" ) -// TestTrustedProxiesConfig checks the trusted_proxies key wiring: a valid -// CIDR list lands in TrustedProxies in order, and an omitted key trusts no -// one. The list parser itself is shared with blocked_networks and is -// exercised in depth by that key's tests. +// TestTrustedProxiesConfig checks the trusted_proxies key wiring: an +// explicit CIDR list lands in TrustedProxies in order and replaces the +// default, an omitted key falls back to the RFC 1918 private ranges, and an +// explicitly empty list trusts no one. The list parser itself is shared with +// blocked_networks and is exercised in depth by that key's tests. func TestTrustedProxiesConfig(t *testing.T) { t.Parallel() - t.Run("valid list is parsed in order", func(t *testing.T) { + t.Run("explicit list replaces the default in order", func(t *testing.T) { t.Parallel() c, err := configFromYAML(t, @@ -31,7 +32,7 @@ func TestTrustedProxiesConfig(t *testing.T) { } }) - t.Run("omitted key trusts no one", func(t *testing.T) { + t.Run("omitted key defaults to the RFC 1918 ranges", func(t *testing.T) { t.Parallel() c, err := configFromYAML(t, signingKeyLine) @@ -39,6 +40,25 @@ func TestTrustedProxiesConfig(t *testing.T) { t.Fatalf("minimal config should load: %v", err) } + got := make([]string, len(c.TrustedProxies)) + for i, p := range c.TrustedProxies { + got[i] = p.String() + } + + want := "10.0.0.0/8,172.16.0.0/12,192.168.0.0/16" + if joined := strings.Join(got, ","); joined != want { + t.Errorf("TrustedProxies = %v, want the RFC 1918 ranges %q", got, want) + } + }) + + t.Run("explicitly empty list trusts no one", func(t *testing.T) { + t.Parallel() + + c, err := configFromYAML(t, signingKeyLine+"trusted_proxies: []\n") + if err != nil { + t.Fatalf("empty trusted_proxies should load: %v", err) + } + if len(c.TrustedProxies) != 0 { t.Errorf("TrustedProxies = %v, want empty", c.TrustedProxies) }