package config import ( "strings" "testing" ) // TestTrustedProxiesConfig checks the trusted_proxies key wiring: a valid // CIDR list lands in TrustedProxies in order, and an omitted key trusts no // one. The list parser itself is shared with blocked_networks and is // exercised in depth by that key's tests. func TestTrustedProxiesConfig(t *testing.T) { t.Parallel() t.Run("valid list is parsed in order", func(t *testing.T) { t.Parallel() c, err := configFromYAML(t, signingKeyLine+`trusted_proxies: ["10.0.0.0/8", "2001:db8::/32"]`+"\n") if err != nil { t.Fatalf("valid trusted_proxies should load: %v", err) } got := make([]string, len(c.TrustedProxies)) for i, p := range c.TrustedProxies { got[i] = p.String() } if joined := strings.Join(got, ","); joined != "10.0.0.0/8,2001:db8::/32" { t.Errorf("TrustedProxies = %v, want the two ranges in order", got) } }) t.Run("omitted key trusts no one", func(t *testing.T) { t.Parallel() c, err := configFromYAML(t, signingKeyLine) if err != nil { t.Fatalf("minimal config should load: %v", err) } if len(c.TrustedProxies) != 0 { t.Errorf("TrustedProxies = %v, want empty", c.TrustedProxies) } }) } // TestTrustedProxiesInvalidAbortsStartup checks that an invalid or null // value aborts startup with an error naming the key and the offending value. func TestTrustedProxiesInvalidAbortsStartup(t *testing.T) { t.Parallel() runAbortCases(t, []abortCase{ { name: "invalid cidr", yaml: signingKeyLine + `trusted_proxies: ["999.0.0.0/8"]` + "\n", wantErrSubstrings: []string{keyTrustedProxies, "999.0.0.0/8"}, }, { name: "null value", yaml: signingKeyLine + "trusted_proxies:\n", wantErrSubstrings: []string{keyTrustedProxies, nullValueText}, }, }) }