All checks were successful
Check / check (push) Successful in 4s
Bumps golangci-lint from v2.10.1 to v2.12.2 everywhere it is pinned and installs the canonical `.golangci.yml`, then fixes every finding the new linter surfaces so `make check` is green. ## Version pins - `Dockerfile` lint stage: `golangci/golangci-lint:v2.12.2` (Debian-based), tag plus digest pin - `script/bootstrap`: `GOLANGCI_LINT_VERSION=2.12.2` with updated `linux-amd64`/`linux-arm64` release-archive sha256 pins ## Config `.golangci.yml` replaced with the canonical config. Material change: the old file declared `version: "2"` but kept settings under the legacy top-level `linters-settings` key, which golangci-lint v2 ignores — so the intended thresholds (`lll` 88, `funlen` 80/50, `cyclop` 15, `dupl` 100) were not being applied. The canonical file moves them under `linters.settings` and drops `issues.exclude-use-default`. ## Lint fixes (216 findings) - `lll` (96): wrapped lines to the 88-column limit - `noctx` (46): `httptest.NewRequestWithContext` with `t.Context()` throughout the tests - `goconst` (24): shared constants for template/JSON keys in `internal/handlers` and repeated test literals - `gosec` (23): app-page redirects now go through a `redirectToApp` helper that path-escapes the app ID (G710 open redirect); `http.ServeFile` of the internally derived deployment log path annotated like the adjacent `os.Stat` (G703) - `dupl` (22): extracted a generic `findAllByAppID` in `internal/models`, a `deleteAppResource` helper in `internal/handlers`, a shared `parsePush` in `internal/service/webhook`, and table-driven/helper-based dedup in tests - `nolintlint` (5): removed `//nolint:funlen` directives made obsolete by the new limits (plus one more that became obsolete after refactoring) - `nilerr` (3, surfaced during fixing): resource-delete lookups now propagate the find error to the caller No behavior changes intended; all tests pass and `make check` is green. Note: golangci-lint v2.12 warns that `gomodguard` is deprecated in favor of `gomodguard_v2` — a future canonical-config update should address this centrally. Co-authored-by: sneak <sneak@sneak.berlin> Reviewed-on: #187 Co-authored-by: clawbot <clawbot@noreply.example.org> Co-committed-by: clawbot <clawbot@noreply.example.org>
150 lines
3.9 KiB
Go
150 lines
3.9 KiB
Go
package middleware //nolint:testpackage // tests unexported types and globals
|
|
|
|
import (
|
|
"log/slog"
|
|
"net/http"
|
|
"net/http/httptest"
|
|
"testing"
|
|
"time"
|
|
|
|
"github.com/stretchr/testify/assert"
|
|
|
|
"sneak.berlin/go/upaas/internal/config"
|
|
)
|
|
|
|
func newTestMiddleware(t *testing.T) *Middleware {
|
|
t.Helper()
|
|
|
|
return &Middleware{
|
|
log: slog.Default(),
|
|
params: &Params{
|
|
Config: &config.Config{},
|
|
},
|
|
}
|
|
}
|
|
|
|
//nolint:paralleltest // mutates global loginLimiter
|
|
func TestLoginRateLimitAllowsUpToBurst(t *testing.T) {
|
|
// Reset the global limiter to get clean state
|
|
loginLimiter = newIPLimiter()
|
|
|
|
mw := newTestMiddleware(t)
|
|
|
|
handler := mw.LoginRateLimit()(http.HandlerFunc(
|
|
func(w http.ResponseWriter, _ *http.Request) {
|
|
w.WriteHeader(http.StatusOK)
|
|
},
|
|
))
|
|
|
|
// First 5 requests should succeed (burst)
|
|
for i := range 5 {
|
|
req := httptest.NewRequestWithContext(t.Context(), http.MethodPost, "/login", nil)
|
|
req.RemoteAddr = "192.168.1.1:12345"
|
|
rec := httptest.NewRecorder()
|
|
handler.ServeHTTP(rec, req)
|
|
assert.Equal(t, http.StatusOK, rec.Code, "request %d should succeed", i+1)
|
|
}
|
|
|
|
// 6th request should be rate limited
|
|
req := httptest.NewRequestWithContext(t.Context(), http.MethodPost, "/login", nil)
|
|
req.RemoteAddr = "192.168.1.1:12345"
|
|
rec := httptest.NewRecorder()
|
|
handler.ServeHTTP(rec, req)
|
|
assert.Equal(t, http.StatusTooManyRequests, rec.Code,
|
|
"6th request should be rate limited")
|
|
}
|
|
|
|
//nolint:paralleltest // mutates global loginLimiter
|
|
func TestLoginRateLimitIsolatesIPs(t *testing.T) {
|
|
loginLimiter = newIPLimiter()
|
|
|
|
mw := newTestMiddleware(t)
|
|
|
|
handler := mw.LoginRateLimit()(http.HandlerFunc(
|
|
func(w http.ResponseWriter, _ *http.Request) {
|
|
w.WriteHeader(http.StatusOK)
|
|
},
|
|
))
|
|
|
|
// Exhaust IP1's budget
|
|
for range 5 {
|
|
req := httptest.NewRequestWithContext(t.Context(), http.MethodPost, "/login", nil)
|
|
req.RemoteAddr = testProxyAddr
|
|
rec := httptest.NewRecorder()
|
|
handler.ServeHTTP(rec, req)
|
|
}
|
|
|
|
// IP1 should be blocked
|
|
req := httptest.NewRequestWithContext(t.Context(), http.MethodPost, "/login", nil)
|
|
req.RemoteAddr = testProxyAddr
|
|
rec := httptest.NewRecorder()
|
|
handler.ServeHTTP(rec, req)
|
|
assert.Equal(t, http.StatusTooManyRequests, rec.Code)
|
|
|
|
// IP2 should still work
|
|
req2 := httptest.NewRequestWithContext(t.Context(), http.MethodPost, "/login", nil)
|
|
req2.RemoteAddr = "10.0.0.2:1234"
|
|
rec2 := httptest.NewRecorder()
|
|
handler.ServeHTTP(rec2, req2)
|
|
assert.Equal(t, http.StatusOK, rec2.Code, "different IP should not be rate limited")
|
|
}
|
|
|
|
//nolint:paralleltest // mutates global loginLimiter
|
|
func TestLoginRateLimitReturns429Body(t *testing.T) {
|
|
loginLimiter = newIPLimiter()
|
|
|
|
mw := newTestMiddleware(t)
|
|
|
|
handler := mw.LoginRateLimit()(http.HandlerFunc(
|
|
func(w http.ResponseWriter, _ *http.Request) {
|
|
w.WriteHeader(http.StatusOK)
|
|
},
|
|
))
|
|
|
|
// Exhaust burst
|
|
for range 5 {
|
|
req := httptest.NewRequestWithContext(t.Context(), http.MethodPost, "/login", nil)
|
|
req.RemoteAddr = "172.16.0.1:5555"
|
|
rec := httptest.NewRecorder()
|
|
handler.ServeHTTP(rec, req)
|
|
}
|
|
|
|
req := httptest.NewRequestWithContext(t.Context(), http.MethodPost, "/login", nil)
|
|
req.RemoteAddr = "172.16.0.1:5555"
|
|
rec := httptest.NewRecorder()
|
|
handler.ServeHTTP(rec, req)
|
|
assert.Equal(t, http.StatusTooManyRequests, rec.Code)
|
|
assert.Contains(t, rec.Body.String(), "Too Many Requests")
|
|
assert.NotEmpty(t, rec.Header().Get("Retry-After"),
|
|
"should include Retry-After header")
|
|
}
|
|
|
|
func TestIPLimiterEvictsStaleEntries(t *testing.T) {
|
|
t.Parallel()
|
|
|
|
il := newIPLimiter()
|
|
|
|
// Add an entry and backdate its lastSeen
|
|
il.mu.Lock()
|
|
il.limiters["1.2.3.4"] = &ipLimiterEntry{
|
|
limiter: nil,
|
|
lastSeen: time.Now().Add(-15 * time.Minute),
|
|
}
|
|
il.limiters["5.6.7.8"] = &ipLimiterEntry{
|
|
limiter: nil,
|
|
lastSeen: time.Now(),
|
|
}
|
|
il.mu.Unlock()
|
|
|
|
// Trigger sweep
|
|
il.mu.Lock()
|
|
il.sweep(time.Now())
|
|
il.mu.Unlock()
|
|
|
|
il.mu.Lock()
|
|
defer il.mu.Unlock()
|
|
|
|
assert.NotContains(t, il.limiters, "1.2.3.4", "stale entry should be evicted")
|
|
assert.Contains(t, il.limiters, "5.6.7.8", "fresh entry should remain")
|
|
}
|