Add failing tests for host entries that can never match
check / check (push) Failing after 1s

A `*.` entry, an entry with a port and one with two leading dots must
abort startup for referer_blocklist, and the first two for
allowlist_hosts; IPv4 and IPv6 address entries must still load.

Model: opus-5-5
This commit is contained in:
2026-10-04 19:01:23 +00:00
parent 8f66a795ad
commit a31dbcb70a
2 changed files with 54 additions and 0 deletions
@@ -318,6 +318,20 @@ func invalidHostAndCredentialCases() []abortCase {
keyAllowlistHosts, "example.com/images", keyAllowlistHosts, "example.com/images",
}, },
}, },
{
name: "allowlist host with wildcard",
yaml: signingKeyLine + "allowlist_hosts:\n - \"*.example.com\"\n",
wantErrSubstrings: []string{
keyAllowlistHosts, "*.example.com",
},
},
{
name: "allowlist host with port",
yaml: signingKeyLine + "allowlist_hosts:\n - example.com:8443\n",
wantErrSubstrings: []string{
keyAllowlistHosts, "example.com:8443",
},
},
{ {
name: "allowlist host with whitespace", name: "allowlist host with whitespace",
yaml: signingKeyLine + "allowlist_hosts:\n - \"exa mple.com\"\n", yaml: signingKeyLine + "allowlist_hosts:\n - \"exa mple.com\"\n",
@@ -24,6 +24,25 @@ func TestRefererBlocklistParsed(t *testing.T) {
} }
} }
// TestRefererBlocklistAcceptsIPAddresses checks that IPv4 and IPv6 addresses,
// the IPv6 one written without brackets, are accepted as entries.
func TestRefererBlocklistAcceptsIPAddresses(t *testing.T) {
t.Parallel()
c, err := configFromYAML(t, signingKeyLine+`referer_blocklist:
- 192.0.2.7
- "2001:db8::7"
`)
if err != nil {
t.Fatalf("IP address entries should load, got error: %v", err)
}
want := []string{"192.0.2.7", "2001:db8::7"}
if !slices.Equal(c.RefererBlocklist, want) {
t.Errorf("RefererBlocklist = %v, want %v", c.RefererBlocklist, want)
}
}
// TestRefererBlocklistOmittedIsEmpty checks that an omitted key blocks no // TestRefererBlocklistOmittedIsEmpty checks that an omitted key blocks no
// referer. // referer.
func TestRefererBlocklistOmittedIsEmpty(t *testing.T) { func TestRefererBlocklistOmittedIsEmpty(t *testing.T) {
@@ -60,6 +79,27 @@ func TestRefererBlocklistInvalidAbortsStartup(t *testing.T) {
keyRefererBlocklist, "leech.example/page", keyRefererBlocklist, "leech.example/page",
}, },
}, },
{
name: "wildcard entry",
yaml: signingKeyLine + "referer_blocklist:\n - \"*.leech.example\"\n",
wantErrSubstrings: []string{
keyRefererBlocklist, "*.leech.example",
},
},
{
name: "entry with a port",
yaml: signingKeyLine + "referer_blocklist:\n - leech.example:8080\n",
wantErrSubstrings: []string{
keyRefererBlocklist, "leech.example:8080",
},
},
{
name: "two leading dots",
yaml: signingKeyLine + "referer_blocklist:\n - ..leech.example\n",
wantErrSubstrings: []string{
keyRefererBlocklist, "..leech.example",
},
},
{ {
name: "dot only", name: "dot only",
yaml: signingKeyLine + "referer_blocklist:\n - \".\"\n", yaml: signingKeyLine + "referer_blocklist:\n - \".\"\n",