A `*.` entry, an entry with a port and one with two leading dots must abort startup for referer_blocklist, and the first two for allowlist_hosts; IPv4 and IPv6 address entries must still load. Model: opus-5-5
This commit is contained in:
@@ -318,6 +318,20 @@ func invalidHostAndCredentialCases() []abortCase {
|
|||||||
keyAllowlistHosts, "example.com/images",
|
keyAllowlistHosts, "example.com/images",
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
|
{
|
||||||
|
name: "allowlist host with wildcard",
|
||||||
|
yaml: signingKeyLine + "allowlist_hosts:\n - \"*.example.com\"\n",
|
||||||
|
wantErrSubstrings: []string{
|
||||||
|
keyAllowlistHosts, "*.example.com",
|
||||||
|
},
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "allowlist host with port",
|
||||||
|
yaml: signingKeyLine + "allowlist_hosts:\n - example.com:8443\n",
|
||||||
|
wantErrSubstrings: []string{
|
||||||
|
keyAllowlistHosts, "example.com:8443",
|
||||||
|
},
|
||||||
|
},
|
||||||
{
|
{
|
||||||
name: "allowlist host with whitespace",
|
name: "allowlist host with whitespace",
|
||||||
yaml: signingKeyLine + "allowlist_hosts:\n - \"exa mple.com\"\n",
|
yaml: signingKeyLine + "allowlist_hosts:\n - \"exa mple.com\"\n",
|
||||||
|
|||||||
@@ -24,6 +24,25 @@ func TestRefererBlocklistParsed(t *testing.T) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// TestRefererBlocklistAcceptsIPAddresses checks that IPv4 and IPv6 addresses,
|
||||||
|
// the IPv6 one written without brackets, are accepted as entries.
|
||||||
|
func TestRefererBlocklistAcceptsIPAddresses(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
c, err := configFromYAML(t, signingKeyLine+`referer_blocklist:
|
||||||
|
- 192.0.2.7
|
||||||
|
- "2001:db8::7"
|
||||||
|
`)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("IP address entries should load, got error: %v", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
want := []string{"192.0.2.7", "2001:db8::7"}
|
||||||
|
if !slices.Equal(c.RefererBlocklist, want) {
|
||||||
|
t.Errorf("RefererBlocklist = %v, want %v", c.RefererBlocklist, want)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
// TestRefererBlocklistOmittedIsEmpty checks that an omitted key blocks no
|
// TestRefererBlocklistOmittedIsEmpty checks that an omitted key blocks no
|
||||||
// referer.
|
// referer.
|
||||||
func TestRefererBlocklistOmittedIsEmpty(t *testing.T) {
|
func TestRefererBlocklistOmittedIsEmpty(t *testing.T) {
|
||||||
@@ -60,6 +79,27 @@ func TestRefererBlocklistInvalidAbortsStartup(t *testing.T) {
|
|||||||
keyRefererBlocklist, "leech.example/page",
|
keyRefererBlocklist, "leech.example/page",
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
|
{
|
||||||
|
name: "wildcard entry",
|
||||||
|
yaml: signingKeyLine + "referer_blocklist:\n - \"*.leech.example\"\n",
|
||||||
|
wantErrSubstrings: []string{
|
||||||
|
keyRefererBlocklist, "*.leech.example",
|
||||||
|
},
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "entry with a port",
|
||||||
|
yaml: signingKeyLine + "referer_blocklist:\n - leech.example:8080\n",
|
||||||
|
wantErrSubstrings: []string{
|
||||||
|
keyRefererBlocklist, "leech.example:8080",
|
||||||
|
},
|
||||||
|
},
|
||||||
|
{
|
||||||
|
name: "two leading dots",
|
||||||
|
yaml: signingKeyLine + "referer_blocklist:\n - ..leech.example\n",
|
||||||
|
wantErrSubstrings: []string{
|
||||||
|
keyRefererBlocklist, "..leech.example",
|
||||||
|
},
|
||||||
|
},
|
||||||
{
|
{
|
||||||
name: "dot only",
|
name: "dot only",
|
||||||
yaml: signingKeyLine + "referer_blocklist:\n - \".\"\n",
|
yaml: signingKeyLine + "referer_blocklist:\n - \".\"\n",
|
||||||
|
|||||||
Reference in New Issue
Block a user