Resolve real client IP behind trusted proxies (closes #94) #127
@@ -0,0 +1,65 @@
|
||||
package config
|
||||
|
||||
import (
|
||||
"strings"
|
||||
"testing"
|
||||
)
|
||||
|
||||
// TestTrustedProxiesConfig checks the trusted_proxies key wiring: a valid
|
||||
// CIDR list lands in TrustedProxies in order, and an omitted key trusts no
|
||||
// one. The list parser itself is shared with blocked_networks and is
|
||||
// exercised in depth by that key's tests.
|
||||
func TestTrustedProxiesConfig(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
t.Run("valid list is parsed in order", func(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
c, err := configFromYAML(t,
|
||||
signingKeyLine+`trusted_proxies: ["10.0.0.0/8", "2001:db8::/32"]`+"\n")
|
||||
if err != nil {
|
||||
t.Fatalf("valid trusted_proxies should load: %v", err)
|
||||
}
|
||||
|
||||
got := make([]string, len(c.TrustedProxies))
|
||||
for i, p := range c.TrustedProxies {
|
||||
got[i] = p.String()
|
||||
}
|
||||
|
||||
if joined := strings.Join(got, ","); joined != "10.0.0.0/8,2001:db8::/32" {
|
||||
t.Errorf("TrustedProxies = %v, want the two ranges in order", got)
|
||||
}
|
||||
})
|
||||
|
||||
t.Run("omitted key trusts no one", func(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
c, err := configFromYAML(t, signingKeyLine)
|
||||
if err != nil {
|
||||
t.Fatalf("minimal config should load: %v", err)
|
||||
}
|
||||
|
||||
if len(c.TrustedProxies) != 0 {
|
||||
t.Errorf("TrustedProxies = %v, want empty", c.TrustedProxies)
|
||||
}
|
||||
})
|
||||
}
|
||||
|
||||
// TestTrustedProxiesInvalidAbortsStartup checks that an invalid or null
|
||||
// value aborts startup with an error naming the key and the offending value.
|
||||
func TestTrustedProxiesInvalidAbortsStartup(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
runAbortCases(t, []abortCase{
|
||||
{
|
||||
name: "invalid cidr",
|
||||
yaml: signingKeyLine + `trusted_proxies: ["999.0.0.0/8"]` + "\n",
|
||||
wantErrSubstrings: []string{keyTrustedProxies, "999.0.0.0/8"},
|
||||
},
|
||||
{
|
||||
name: "null value",
|
||||
yaml: signingKeyLine + "trusted_proxies:\n",
|
||||
wantErrSubstrings: []string{keyTrustedProxies, nullValueText},
|
||||
},
|
||||
})
|
||||
}
|
||||
Reference in New Issue
Block a user