Compare commits
1 Commits
issue-88-t
...
e3e632676c
| Author | SHA1 | Date | |
|---|---|---|---|
| e3e632676c |
127
README.md
127
README.md
@@ -94,55 +94,6 @@ TTY detection, and security headers are always applied.
|
|||||||
| `METRICS_PASSWORD` | Basic auth password for `/metrics` | `""` |
|
| `METRICS_PASSWORD` | Basic auth password for `/metrics` | `""` |
|
||||||
| `SENTRY_DSN` | Sentry error reporting DSN | `""` |
|
| `SENTRY_DSN` | Sentry error reporting DSN | `""` |
|
||||||
| `SESSION_IDLE_TIMEOUT` | Idle session timeout (Go duration) | `24h` |
|
| `SESSION_IDLE_TIMEOUT` | Idle session timeout (Go duration) | `24h` |
|
||||||
| `RECEIVER_RATE_LIMIT` | Receiver requests/minute per IP per entrypoint | `120` |
|
|
||||||
| `TRUSTED_PROXIES` | CIDRs whose forwarded headers are trusted | `""` (none) |
|
|
||||||
|
|
||||||
#### Trusted proxies
|
|
||||||
|
|
||||||
`TRUSTED_PROXIES` is a comma-separated list of CIDR blocks (a bare
|
|
||||||
address such as `192.168.1.7` is accepted and treated as a single
|
|
||||||
host), for example `192.168.1.7, 2001:db8::5`. It decides whose
|
|
||||||
`X-Forwarded-For` header the rate limiters believe, so it should name
|
|
||||||
the addresses of your reverse proxies and nothing else.
|
|
||||||
|
|
||||||
`X-Forwarded-For` is honoured **only** when the connecting peer is
|
|
||||||
inside one of these blocks; for every other peer the client identity is
|
|
||||||
the connection's own address and the header is ignored. The default is
|
|
||||||
the empty list, which trusts nobody — anything else would let any
|
|
||||||
client pick its own rate limit bucket, minting a fresh one per request
|
|
||||||
or draining someone else's. Set it to the address of your reverse
|
|
||||||
proxy, and to nothing wider. A set but unparseable value aborts
|
|
||||||
startup.
|
|
||||||
|
|
||||||
`X-Real-IP` and `True-Client-IP` are **never** read, from any peer.
|
|
||||||
Reverse proxies append to `X-Forwarded-For` but forward other client
|
|
||||||
headers verbatim, so a single-valued header is client-controlled even
|
|
||||||
behind a trusted proxy.
|
|
||||||
|
|
||||||
Within a trusted request, `X-Forwarded-For` is read right to left,
|
|
||||||
because the rightmost entry is the one the nearest proxy appended and
|
|
||||||
everything left of it may have been written by the client. The first
|
|
||||||
hop that is not itself a trusted proxy is taken as the client. A hop
|
|
||||||
that is not a bare IP address — `ip:port`, a bracketed IPv6 literal,
|
|
||||||
the token `unknown` — ends the walk and the peer address is used
|
|
||||||
instead, since past such an entry the chain is not the shape assumed
|
|
||||||
here. The peer address is likewise used when the header is absent or
|
|
||||||
every hop in it is a trusted proxy.
|
|
||||||
|
|
||||||
Two operator requirements follow:
|
|
||||||
|
|
||||||
- Your proxy must **append** the peer address to `X-Forwarded-For`
|
|
||||||
(nginx `$proxy_add_x_forwarded_for`, HAProxy `option forwardfor`,
|
|
||||||
Caddy and AWS ALB by default), and must append a bare address with
|
|
||||||
no port.
|
|
||||||
- List proxy hosts **only**. Any address inside `TRUSTED_PROXIES`
|
|
||||||
chooses its own rate-limit key: its `X-Forwarded-For` is walked, so
|
|
||||||
it can name a different address on every request to get a fresh
|
|
||||||
bucket each time, or name another client's address to drain that
|
|
||||||
client's bucket. Never list a block that also covers clients — a
|
|
||||||
broad `10.0.0.0/8` on a network where clients live in the same range
|
|
||||||
makes all three limits, including the unauthenticated webhook
|
|
||||||
receiver, silently bypassable by every client in the block.
|
|
||||||
|
|
||||||
Sessions are bounded by two independent clocks, and end at whichever
|
Sessions are bounded by two independent clocks, and end at whichever
|
||||||
one runs out first:
|
one runs out first:
|
||||||
@@ -172,9 +123,7 @@ fatal configuration error: webhooker logs the offending variable and
|
|||||||
its value and refuses to start, rather than silently running with a
|
its value and refuses to start, rather than silently running with a
|
||||||
substituted default. `PORT=eighty`, `DEBUG=ture`, and
|
substituted default. `PORT=eighty`, `DEBUG=ture`, and
|
||||||
`RETENTION_SWEEP_INTERVAL=1 hour` all abort startup. `PORT` must
|
`RETENTION_SWEEP_INTERVAL=1 hour` all abort startup. `PORT` must
|
||||||
additionally be a number in the range 1–65535,
|
additionally be a number in the range 1–65535.
|
||||||
`RECEIVER_RATE_LIMIT` must be at least 1, and every entry in
|
|
||||||
`TRUSTED_PROXIES` must be a CIDR block or a bare IP address.
|
|
||||||
|
|
||||||
Boolean variables (`DEBUG`, `MAINTENANCE_MODE`) accept exactly the
|
Boolean variables (`DEBUG`, `MAINTENANCE_MODE`) accept exactly the
|
||||||
spellings Go's `strconv.ParseBool` accepts — `1`, `t`, `T`, `TRUE`,
|
spellings Go's `strconv.ParseBool` accepts — `1`, `t`, `T`, `TRUE`,
|
||||||
@@ -396,29 +345,13 @@ event routing.
|
|||||||
| `user_id` | UUID | Foreign key → User |
|
| `user_id` | UUID | Foreign key → User |
|
||||||
| `name` | string | Human-readable name |
|
| `name` | string | Human-readable name |
|
||||||
| `description` | string | Optional description |
|
| `description` | string | Optional description |
|
||||||
| `retention_days` | integer | Days to retain events (default: 30; 0 means retain forever) |
|
| `retention_days` | integer | Days to retain events (default: 30) |
|
||||||
|
|
||||||
**Relations:** Belongs to User. Has many Entrypoints. Has many Targets.
|
**Relations:** Belongs to User. Has many Entrypoints. Has many Targets.
|
||||||
|
|
||||||
The `retention_days` field controls how long event data is kept in the
|
The `retention_days` field controls how long event data is kept in the
|
||||||
webhook's dedicated database before automatic cleanup.
|
webhook's dedicated database before automatic cleanup.
|
||||||
|
|
||||||
Setting `retention_days` to `0` means "retain events forever". Because
|
|
||||||
the column carries a default of 30, a literal zero cannot survive an
|
|
||||||
insert, so a zero is rewritten on save to a sentinel of `365 * 1000`
|
|
||||||
days (`database.RetentionForeverDays`). The retention reaper recognises
|
|
||||||
that sentinel and skips the webhook entirely, and the web UI displays
|
|
||||||
such a webhook's retention as "forever" rather than as a day count.
|
|
||||||
|
|
||||||
A *finite* retention is capped at `database.MaxFiniteRetentionDays`
|
|
||||||
(106751 days, about 292 years), and a larger one is rejected with a
|
|
||||||
400. The cap is not arbitrary: the reaper computes its cutoff as a
|
|
||||||
`time.Duration`, an int64 nanosecond count, and a longer period
|
|
||||||
overflows it. An overflowed cutoff lands in the future, where it
|
|
||||||
matches every row, so the sweep would delete every event the webhook
|
|
||||||
has instead of none. The reaper also clamps the value it is given, so a
|
|
||||||
row written by an older version cannot trigger that either.
|
|
||||||
|
|
||||||
#### Entrypoint
|
#### Entrypoint
|
||||||
|
|
||||||
A receiver URL where external services POST webhook events. Each
|
A receiver URL where external services POST webhook events. Each
|
||||||
@@ -614,7 +547,7 @@ This separation provides:
|
|||||||
DB; the event database file is hard-deleted (permanently removed).
|
DB; the event database file is hard-deleted (permanently removed).
|
||||||
- **Per-webhook retention** — the `retention_days` field on each webhook
|
- **Per-webhook retention** — the `retention_days` field on each webhook
|
||||||
controls automatic cleanup of old events in that webhook's database
|
controls automatic cleanup of old events in that webhook's database
|
||||||
only, or disables cleanup entirely when set to `0` (retain forever).
|
only.
|
||||||
- **Performance** — each webhook's database has its own WAL, its own
|
- **Performance** — each webhook's database has its own WAL, its own
|
||||||
page cache, and its own lock, so concurrent event ingestion across
|
page cache, and its own lock, so concurrent event ingestion across
|
||||||
webhooks won't contend.
|
webhooks won't contend.
|
||||||
@@ -836,34 +769,17 @@ just delayed until the target is healthy again.
|
|||||||
|
|
||||||
### Rate Limiting
|
### Rate Limiting
|
||||||
|
|
||||||
Global blanket rate limiting middleware (e.g., a per-IP throttle shared
|
Global rate limiting middleware (e.g., per-IP throttling applied at the
|
||||||
with the web UI) **must not** apply to webhook receiver endpoints.
|
router level) **must not** apply to webhook receiver endpoints. Webhook
|
||||||
Webhook endpoints receive automated traffic from external services at
|
endpoints receive automated traffic from external services at
|
||||||
unpredictable rates, and blanket limits shared with other routes would
|
unpredictable rates, and blanket rate limits would cause legitimate
|
||||||
cause legitimate deliveries to be dropped.
|
deliveries to be dropped.
|
||||||
|
|
||||||
The receiver instead has its own dedicated abuse limit, scoped to the
|
Instead, each webhook has its own individually configurable rate limit,
|
||||||
`/webhook/{uuid}` route only and keyed per client IP per entrypoint: one
|
applied within the webhook handler itself. By default, no rate limit is
|
||||||
misbehaving sender is throttled without affecting other senders of the
|
applied — webhook endpoints accept traffic as fast as it arrives. Rate
|
||||||
same entrypoint or the same sender's other entrypoints. The limit is
|
limits can be configured per-webhook when needed (e.g., to protect
|
||||||
`RECEIVER_RATE_LIMIT` requests per minute (default 120, generous for
|
against a misbehaving sender).
|
||||||
legitimate webhook senders). Requests over the limit receive HTTP 429
|
|
||||||
with a `Retry-After` header. A set-but-invalid `RECEIVER_RATE_LIMIT`
|
|
||||||
value aborts startup rather than silently falling back to the default.
|
|
||||||
|
|
||||||
Every limiter here — receiver, login, and password change — identifies
|
|
||||||
the client the same way, through one shared key function: the
|
|
||||||
connection's own address, unless the peer is listed in
|
|
||||||
`TRUSTED_PROXIES`, in which case the forwarded client address is used
|
|
||||||
instead. See [Trusted proxies](#trusted-proxies). Deployed without that
|
|
||||||
variable set, a client behind a reverse proxy shares one bucket with
|
|
||||||
every other client behind the same proxy, which is the safe direction
|
|
||||||
to be wrong in: set `TRUSTED_PROXIES` to the proxy's address to get
|
|
||||||
per-client limits back.
|
|
||||||
|
|
||||||
Finer-grained per-webhook rate limits (configured in the web UI and
|
|
||||||
enforced in the webhook handler) can layer on top of this env-level
|
|
||||||
abuse limit later; they are tracked as future work.
|
|
||||||
|
|
||||||
### API Endpoints
|
### API Endpoints
|
||||||
|
|
||||||
@@ -1031,17 +947,9 @@ Applied to all routes in this order:
|
|||||||
8. **Sentry** — Error reporting to Sentry (if `SENTRY_DSN` is set;
|
8. **Sentry** — Error reporting to Sentry (if `SENTRY_DSN` is set;
|
||||||
configured with `Repanic: true` so panics still reach Recoverer)
|
configured with `Repanic: true` so panics still reach Recoverer)
|
||||||
|
|
||||||
Additionally, form endpoints (`/pages`, `/user/*`, `/sources`,
|
Additionally, form endpoints (`/pages`, `/sources`, `/source/*`) apply a
|
||||||
`/source/*`) apply a **MaxBodySize** middleware that limits
|
**MaxBodySize** middleware that limits POST/PUT/PATCH request bodies to
|
||||||
POST/PUT/PATCH request bodies to 1 MB. It is registered ahead of the
|
1 MB using `http.MaxBytesReader`, preventing oversized form submissions.
|
||||||
CSRF middleware in every one of those route groups, because
|
|
||||||
gorilla/csrf parses the form; if the cap were installed after it, form
|
|
||||||
parsing would run under net/http's 10 MB default and the 1 MB limit
|
|
||||||
would never apply. A request that declares a `Content-Length` over the
|
|
||||||
limit is answered with `413 Request Entity Too Large` before any other
|
|
||||||
middleware or handler runs; a chunked request, or one that lies about
|
|
||||||
its length, is hard-capped by `http.MaxBytesReader` and fails
|
|
||||||
downstream at form-parse time.
|
|
||||||
|
|
||||||
### Authentication
|
### Authentication
|
||||||
|
|
||||||
@@ -1063,8 +971,7 @@ downstream at form-parse time.
|
|||||||
- Production security headers on all responses: HSTS, X-Content-Type-Options
|
- Production security headers on all responses: HSTS, X-Content-Type-Options
|
||||||
(`nosniff`), X-Frame-Options (`DENY`), Content-Security-Policy, Referrer-Policy,
|
(`nosniff`), X-Frame-Options (`DENY`), Content-Security-Policy, Referrer-Policy,
|
||||||
and Permissions-Policy
|
and Permissions-Policy
|
||||||
- Request body size limits (1 MB) on all form POST endpoints, enforced
|
- Request body size limits (1 MB) on all form POST endpoints
|
||||||
by middleware that runs before CSRF parses the form
|
|
||||||
- **CSRF protection** via [gorilla/csrf](https://github.com/gorilla/csrf)
|
- **CSRF protection** via [gorilla/csrf](https://github.com/gorilla/csrf)
|
||||||
on all state-changing forms (cookie-based double-submit tokens with
|
on all state-changing forms (cookie-based double-submit tokens with
|
||||||
HMAC authentication). Applied to `/pages`, `/sources`, `/source`, and
|
HMAC authentication). Applied to `/pages`, `/sources`, `/source`, and
|
||||||
|
|||||||
4
TODO.md
4
TODO.md
@@ -26,10 +26,6 @@ capability in the README rationale).
|
|||||||
|
|
||||||
# Completed Steps
|
# Completed Steps
|
||||||
|
|
||||||
- 2026-08-11 Web UI cleanup: nav terminology unified on Webhooks, the
|
|
||||||
Profile settings placeholder removed, a progressive-enhancement copy
|
|
||||||
button for the entrypoint URL, and retention form copy that states the
|
|
||||||
actual policy (deletion by the reaper, 0 retains forever) (#57)
|
|
||||||
- 2026-08-09 Inactivity-based session timeout: sliding idle expiry
|
- 2026-08-09 Inactivity-based session timeout: sliding idle expiry
|
||||||
(`SESSION_IDLE_TIMEOUT`, default `24h`) refreshed on authenticated
|
(`SESSION_IDLE_TIMEOUT`, default `24h`) refreshed on authenticated
|
||||||
requests, with the 7-day absolute cap kept as an independent
|
requests, with the 7-day absolute cap kept as an independent
|
||||||
|
|||||||
@@ -5,10 +5,8 @@ import (
|
|||||||
"errors"
|
"errors"
|
||||||
"fmt"
|
"fmt"
|
||||||
"log/slog"
|
"log/slog"
|
||||||
"net/netip"
|
|
||||||
"os"
|
"os"
|
||||||
"strconv"
|
"strconv"
|
||||||
"strings"
|
|
||||||
"time"
|
"time"
|
||||||
|
|
||||||
"go.uber.org/fx"
|
"go.uber.org/fx"
|
||||||
@@ -37,21 +35,9 @@ const (
|
|||||||
// authenticated activity before it expires.
|
// authenticated activity before it expires.
|
||||||
defaultSessionIdleTimeout = 24 * time.Hour
|
defaultSessionIdleTimeout = 24 * time.Hour
|
||||||
|
|
||||||
// defaultReceiverRateLimit is the default number of requests
|
|
||||||
// per minute each client IP may send to a single webhook
|
|
||||||
// receiver entrypoint. Generous for legitimate webhook
|
|
||||||
// senders while bounding abuse of the one unauthenticated,
|
|
||||||
// internet-exposed endpoint.
|
|
||||||
defaultReceiverRateLimit = 120
|
|
||||||
|
|
||||||
// maxPort is the highest valid TCP port number. The lower
|
// maxPort is the highest valid TCP port number. The lower
|
||||||
// bound (at least 1) is enforced by envPositiveInt.
|
// bound (at least 1) is enforced by envPositiveInt.
|
||||||
maxPort = 65535
|
maxPort = 65535
|
||||||
|
|
||||||
// mappedV4Offset is the number of leading bits an IPv4-mapped
|
|
||||||
// IPv6 prefix spends on the ::ffff:0:0/96 wrapper, so a /104
|
|
||||||
// covers the same addresses as an IPv4 /8.
|
|
||||||
mappedV4Offset = 96
|
|
||||||
)
|
)
|
||||||
|
|
||||||
// ErrInvalidEnvironment is returned when WEBHOOKER_ENVIRONMENT
|
// ErrInvalidEnvironment is returned when WEBHOOKER_ENVIRONMENT
|
||||||
@@ -66,11 +52,6 @@ var ErrNonPositiveValue = errors.New("value must be positive")
|
|||||||
// TCP port number is set above the valid port range.
|
// TCP port number is set above the valid port range.
|
||||||
var ErrInvalidPort = errors.New("invalid port")
|
var ErrInvalidPort = errors.New("invalid port")
|
||||||
|
|
||||||
// ErrInvalidCIDR is returned when an environment variable holding a
|
|
||||||
// list of CIDR blocks contains an entry that is neither a CIDR block
|
|
||||||
// nor a bare IP address.
|
|
||||||
var ErrInvalidCIDR = errors.New("invalid CIDR")
|
|
||||||
|
|
||||||
//nolint:revive // ConfigParams is a standard fx naming convention.
|
//nolint:revive // ConfigParams is a standard fx naming convention.
|
||||||
type ConfigParams struct {
|
type ConfigParams struct {
|
||||||
fx.In
|
fx.In
|
||||||
@@ -98,21 +79,6 @@ type Config struct {
|
|||||||
// which a session expires. Non-positive disables idle expiry.
|
// which a session expires. Non-positive disables idle expiry.
|
||||||
SessionIdleTimeout time.Duration
|
SessionIdleTimeout time.Duration
|
||||||
|
|
||||||
// ReceiverRateLimit is the number of requests per minute each
|
|
||||||
// client IP may send to a single webhook receiver entrypoint.
|
|
||||||
ReceiverRateLimit int
|
|
||||||
|
|
||||||
// TrustedProxies is the set of networks whose members are
|
|
||||||
// allowed to speak for the client with X-Forwarded-For, the
|
|
||||||
// only forwarded header read. It is empty unless
|
|
||||||
// TRUSTED_PROXIES is set, and empty means no peer is
|
|
||||||
// trusted: forwarded headers are then ignored entirely and
|
|
||||||
// clients are identified by the connection's own address.
|
|
||||||
// Members can choose their own rate-limit key, so this must
|
|
||||||
// name proxy hosts only, never a block that also covers
|
|
||||||
// clients.
|
|
||||||
TrustedProxies []netip.Prefix
|
|
||||||
|
|
||||||
params *ConfigParams
|
params *ConfigParams
|
||||||
log *slog.Logger
|
log *slog.Logger
|
||||||
}
|
}
|
||||||
@@ -235,71 +201,6 @@ func envDuration(
|
|||||||
return d, nil
|
return d, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
// parseCIDR parses one trusted-proxy list entry, which may be a
|
|
||||||
// CIDR block ("10.0.0.0/8") or a bare address ("10.0.0.1", treated
|
|
||||||
// as a single-host block).
|
|
||||||
//
|
|
||||||
// Both forms are unmapped, because peer addresses are unmapped
|
|
||||||
// before they are matched against the list: an IPv4-mapped prefix
|
|
||||||
// left in that form would silently never match.
|
|
||||||
func parseCIDR(entry string) (netip.Prefix, error) {
|
|
||||||
if strings.Contains(entry, "/") {
|
|
||||||
prefix, err := netip.ParsePrefix(entry)
|
|
||||||
if err != nil {
|
|
||||||
return netip.Prefix{}, err //nolint:wrapcheck // wrapped by caller
|
|
||||||
}
|
|
||||||
|
|
||||||
if addr := prefix.Addr(); addr.Is4In6() &&
|
|
||||||
prefix.Bits() >= mappedV4Offset {
|
|
||||||
prefix = netip.PrefixFrom(
|
|
||||||
addr.Unmap(), prefix.Bits()-mappedV4Offset,
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
return prefix.Masked(), nil
|
|
||||||
}
|
|
||||||
|
|
||||||
addr, err := netip.ParseAddr(entry)
|
|
||||||
if err != nil {
|
|
||||||
return netip.Prefix{}, err //nolint:wrapcheck // wrapped by caller
|
|
||||||
}
|
|
||||||
|
|
||||||
return netip.PrefixFrom(addr.Unmap(), addr.Unmap().BitLen()), nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// envPrefixList returns the value of the named environment variable
|
|
||||||
// parsed as a comma-separated list of CIDR blocks (bare addresses
|
|
||||||
// allowed). An unset, empty, or blank value yields an empty list. A
|
|
||||||
// set value containing an unparseable entry is a hard error naming
|
|
||||||
// the key and the bad entry, so startup fails loudly rather than
|
|
||||||
// silently running with a list the operator did not intend.
|
|
||||||
func envPrefixList(key string) ([]netip.Prefix, error) {
|
|
||||||
v := strings.TrimSpace(os.Getenv(key))
|
|
||||||
if v == "" {
|
|
||||||
return nil, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
var prefixes []netip.Prefix
|
|
||||||
|
|
||||||
for entry := range strings.SplitSeq(v, ",") {
|
|
||||||
entry = strings.TrimSpace(entry)
|
|
||||||
if entry == "" {
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
|
|
||||||
prefix, err := parseCIDR(entry)
|
|
||||||
if err != nil {
|
|
||||||
return nil, fmt.Errorf(
|
|
||||||
"%w: %s: %q: %w", ErrInvalidCIDR, key, entry, err,
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
prefixes = append(prefixes, prefix)
|
|
||||||
}
|
|
||||||
|
|
||||||
return prefixes, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// resolveEnvironment reads WEBHOOKER_ENVIRONMENT, defaulting to
|
// resolveEnvironment reads WEBHOOKER_ENVIRONMENT, defaulting to
|
||||||
// dev, and rejects unrecognised values.
|
// dev, and rejects unrecognised values.
|
||||||
func resolveEnvironment() (string, error) {
|
func resolveEnvironment() (string, error) {
|
||||||
@@ -362,19 +263,6 @@ func loadFromEnv() (*Config, error) {
|
|||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
|
|
||||||
receiverRateLimit, err := envPositiveInt(
|
|
||||||
"RECEIVER_RATE_LIMIT",
|
|
||||||
defaultReceiverRateLimit,
|
|
||||||
)
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
|
|
||||||
trustedProxies, err := envPrefixList("TRUSTED_PROXIES")
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
|
|
||||||
return &Config{
|
return &Config{
|
||||||
DataDir: envString("DATA_DIR"),
|
DataDir: envString("DATA_DIR"),
|
||||||
Debug: debug,
|
Debug: debug,
|
||||||
@@ -386,8 +274,6 @@ func loadFromEnv() (*Config, error) {
|
|||||||
SentryDSN: envString("SENTRY_DSN"),
|
SentryDSN: envString("SENTRY_DSN"),
|
||||||
RetentionSweepInterval: retentionSweepInterval,
|
RetentionSweepInterval: retentionSweepInterval,
|
||||||
SessionIdleTimeout: sessionIdleTimeout,
|
SessionIdleTimeout: sessionIdleTimeout,
|
||||||
ReceiverRateLimit: receiverRateLimit,
|
|
||||||
TrustedProxies: trustedProxies,
|
|
||||||
}, nil
|
}, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -428,8 +314,6 @@ func New(lc fx.Lifecycle, params ConfigParams) (*Config, error) {
|
|||||||
"maintenanceMode", s.MaintenanceMode,
|
"maintenanceMode", s.MaintenanceMode,
|
||||||
"dataDir", s.DataDir,
|
"dataDir", s.DataDir,
|
||||||
"retentionSweepInterval", s.RetentionSweepInterval.String(),
|
"retentionSweepInterval", s.RetentionSweepInterval.String(),
|
||||||
"receiverRateLimit", s.ReceiverRateLimit,
|
|
||||||
"trustedProxies", len(s.TrustedProxies),
|
|
||||||
"hasSentryDSN", s.SentryDSN != "",
|
"hasSentryDSN", s.SentryDSN != "",
|
||||||
"hasMetricsAuth",
|
"hasMetricsAuth",
|
||||||
s.MetricsUsername != "" && s.MetricsPassword != "",
|
s.MetricsUsername != "" && s.MetricsPassword != "",
|
||||||
|
|||||||
@@ -14,18 +14,6 @@ import (
|
|||||||
"sneak.berlin/go/webhooker/internal/logger"
|
"sneak.berlin/go/webhooker/internal/logger"
|
||||||
)
|
)
|
||||||
|
|
||||||
// Shared subtest names for the env-parsing tables below, which all
|
|
||||||
// exercise the same three cases against different variables.
|
|
||||||
const (
|
|
||||||
caseUnsetUsesDefault = "unset uses default"
|
|
||||||
caseValidValueParsed = "valid value is parsed"
|
|
||||||
caseUnparseableFails = "unparseable value fails startup"
|
|
||||||
|
|
||||||
// cidrPrivateV4 is the sample trusted-proxy block the
|
|
||||||
// TRUSTED_PROXIES cases are built from.
|
|
||||||
cidrPrivateV4 = "10.0.0.0/8"
|
|
||||||
)
|
|
||||||
|
|
||||||
func TestEnvironmentConfig(t *testing.T) {
|
func TestEnvironmentConfig(t *testing.T) {
|
||||||
tests := []struct {
|
tests := []struct {
|
||||||
name string
|
name string
|
||||||
@@ -142,18 +130,18 @@ func TestRetentionSweepInterval(t *testing.T) {
|
|||||||
expected time.Duration
|
expected time.Duration
|
||||||
}{
|
}{
|
||||||
{
|
{
|
||||||
name: caseUnsetUsesDefault,
|
name: "unset uses default",
|
||||||
set: false,
|
set: false,
|
||||||
expected: time.Hour,
|
expected: time.Hour,
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
name: caseValidValueParsed,
|
name: "valid value is parsed",
|
||||||
set: true,
|
set: true,
|
||||||
value: "15m",
|
value: "15m",
|
||||||
expected: 15 * time.Minute,
|
expected: 15 * time.Minute,
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
name: caseUnparseableFails,
|
name: "unparseable value fails startup",
|
||||||
set: true,
|
set: true,
|
||||||
value: "not-a-duration",
|
value: "not-a-duration",
|
||||||
expectError: true,
|
expectError: true,
|
||||||
@@ -183,10 +171,9 @@ func TestRetentionSweepInterval(t *testing.T) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// startupError builds the app config.New belongs to and returns
|
// expectStartupError asserts that fx refuses to build the app,
|
||||||
// the error fx reports, which is non-nil whenever an environment
|
// which is what a set-but-unparseable duration must cause.
|
||||||
// value is set but invalid.
|
func expectStartupError(t *testing.T) {
|
||||||
func startupError(t *testing.T) error {
|
|
||||||
t.Helper()
|
t.Helper()
|
||||||
|
|
||||||
var cfg *config.Config
|
var cfg *config.Config
|
||||||
@@ -201,33 +188,7 @@ func startupError(t *testing.T) error {
|
|||||||
fx.Populate(&cfg),
|
fx.Populate(&cfg),
|
||||||
)
|
)
|
||||||
|
|
||||||
return app.Err()
|
assert.Error(t, app.Err())
|
||||||
}
|
|
||||||
|
|
||||||
// expectStartupError asserts that fx refuses to build the app,
|
|
||||||
// which is what a set-but-invalid environment value must cause.
|
|
||||||
func expectStartupError(t *testing.T) {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
assert.Error(t, startupError(t))
|
|
||||||
}
|
|
||||||
|
|
||||||
// expectStartupErrorFor asserts that startup fails, that the error
|
|
||||||
// names the offending variable so an operator can find it, and,
|
|
||||||
// when sentinel is non-nil, that it wraps that sentinel.
|
|
||||||
func expectStartupErrorFor(
|
|
||||||
t *testing.T,
|
|
||||||
key string,
|
|
||||||
sentinel error,
|
|
||||||
) {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
err := startupError(t)
|
|
||||||
require.ErrorContains(t, err, key)
|
|
||||||
|
|
||||||
if sentinel != nil {
|
|
||||||
require.ErrorIs(t, err, sentinel)
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
func testRetentionSweepIntervalSuccess(
|
func testRetentionSweepIntervalSuccess(
|
||||||
@@ -265,18 +226,18 @@ func TestSessionIdleTimeout(t *testing.T) {
|
|||||||
expected time.Duration
|
expected time.Duration
|
||||||
}{
|
}{
|
||||||
{
|
{
|
||||||
name: caseUnsetUsesDefault,
|
name: "unset uses default",
|
||||||
set: false,
|
set: false,
|
||||||
expected: 24 * time.Hour,
|
expected: 24 * time.Hour,
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
name: caseValidValueParsed,
|
name: "valid value is parsed",
|
||||||
set: true,
|
set: true,
|
||||||
value: "30m",
|
value: "30m",
|
||||||
expected: 30 * time.Minute,
|
expected: 30 * time.Minute,
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
name: caseUnparseableFails,
|
name: "unparseable value fails startup",
|
||||||
set: true,
|
set: true,
|
||||||
value: "not-a-duration",
|
value: "not-a-duration",
|
||||||
expectError: true,
|
expectError: true,
|
||||||
@@ -375,212 +336,3 @@ func TestDefaultDataDir(t *testing.T) {
|
|||||||
})
|
})
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestReceiverRateLimit(t *testing.T) {
|
|
||||||
tests := []struct {
|
|
||||||
name string
|
|
||||||
set bool
|
|
||||||
value string
|
|
||||||
expectError bool
|
|
||||||
// sentinel, when set, must be wrapped by the startup
|
|
||||||
// error; every error case must additionally name the
|
|
||||||
// variable in its message.
|
|
||||||
sentinel error
|
|
||||||
expected int
|
|
||||||
}{
|
|
||||||
{
|
|
||||||
name: caseUnsetUsesDefault,
|
|
||||||
set: false,
|
|
||||||
expected: 120,
|
|
||||||
},
|
|
||||||
{
|
|
||||||
name: caseValidValueParsed,
|
|
||||||
set: true,
|
|
||||||
value: "30",
|
|
||||||
expected: 30,
|
|
||||||
},
|
|
||||||
{
|
|
||||||
name: caseUnparseableFails,
|
|
||||||
set: true,
|
|
||||||
value: "not-a-number",
|
|
||||||
expectError: true,
|
|
||||||
},
|
|
||||||
{
|
|
||||||
name: "zero fails startup",
|
|
||||||
set: true,
|
|
||||||
value: "0",
|
|
||||||
expectError: true,
|
|
||||||
sentinel: config.ErrNonPositiveValue,
|
|
||||||
},
|
|
||||||
{
|
|
||||||
name: "negative fails startup",
|
|
||||||
set: true,
|
|
||||||
value: "-5",
|
|
||||||
expectError: true,
|
|
||||||
sentinel: config.ErrNonPositiveValue,
|
|
||||||
},
|
|
||||||
}
|
|
||||||
|
|
||||||
for _, tt := range tests {
|
|
||||||
t.Run(tt.name, func(t *testing.T) {
|
|
||||||
// Cannot use t.Parallel() here because t.Setenv
|
|
||||||
// is incompatible with parallel subtests.
|
|
||||||
t.Setenv("WEBHOOKER_ENVIRONMENT", "dev")
|
|
||||||
|
|
||||||
if tt.set {
|
|
||||||
t.Setenv("RECEIVER_RATE_LIMIT", tt.value)
|
|
||||||
} else {
|
|
||||||
require.NoError(t, os.Unsetenv(
|
|
||||||
"RECEIVER_RATE_LIMIT",
|
|
||||||
))
|
|
||||||
}
|
|
||||||
|
|
||||||
if tt.expectError {
|
|
||||||
expectStartupErrorFor(
|
|
||||||
t, "RECEIVER_RATE_LIMIT", tt.sentinel,
|
|
||||||
)
|
|
||||||
} else {
|
|
||||||
testReceiverRateLimitSuccess(t, tt.expected)
|
|
||||||
}
|
|
||||||
})
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func testReceiverRateLimitSuccess(
|
|
||||||
t *testing.T,
|
|
||||||
expected int,
|
|
||||||
) {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
var cfg *config.Config
|
|
||||||
|
|
||||||
app := fxtest.New(
|
|
||||||
t,
|
|
||||||
fx.Provide(
|
|
||||||
globals.New,
|
|
||||||
logger.New,
|
|
||||||
config.New,
|
|
||||||
),
|
|
||||||
fx.Populate(&cfg),
|
|
||||||
)
|
|
||||||
require.NoError(t, app.Err())
|
|
||||||
|
|
||||||
app.RequireStart()
|
|
||||||
|
|
||||||
defer app.RequireStop()
|
|
||||||
|
|
||||||
assert.Equal(t, expected, cfg.ReceiverRateLimit)
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestTrustedProxies(t *testing.T) {
|
|
||||||
tests := []struct {
|
|
||||||
name string
|
|
||||||
set bool
|
|
||||||
value string
|
|
||||||
expectError bool
|
|
||||||
expected []string
|
|
||||||
}{
|
|
||||||
{
|
|
||||||
// The default must be "trust nobody": an empty list
|
|
||||||
// means forwarded headers are ignored, never that
|
|
||||||
// every peer may speak for the client.
|
|
||||||
name: caseUnsetUsesDefault,
|
|
||||||
set: false,
|
|
||||||
expected: []string{},
|
|
||||||
},
|
|
||||||
{
|
|
||||||
name: "blank value trusts nothing",
|
|
||||||
set: true,
|
|
||||||
value: " ",
|
|
||||||
expected: []string{},
|
|
||||||
},
|
|
||||||
{
|
|
||||||
name: caseValidValueParsed,
|
|
||||||
set: true,
|
|
||||||
value: cidrPrivateV4 + ", 192.168.1.7 ,2001:db8::/32",
|
|
||||||
expected: []string{
|
|
||||||
cidrPrivateV4, "192.168.1.7/32", "2001:db8::/32",
|
|
||||||
},
|
|
||||||
},
|
|
||||||
{
|
|
||||||
name: "host bits are masked off",
|
|
||||||
set: true,
|
|
||||||
value: "10.1.2.3/8",
|
|
||||||
expected: []string{cidrPrivateV4},
|
|
||||||
},
|
|
||||||
{
|
|
||||||
// Peer addresses are unmapped before they are
|
|
||||||
// matched, so an IPv4-mapped prefix kept in that
|
|
||||||
// form could never match anything.
|
|
||||||
name: "IPv4-mapped prefix is unmapped",
|
|
||||||
set: true,
|
|
||||||
value: "::ffff:10.0.0.0/104",
|
|
||||||
expected: []string{cidrPrivateV4},
|
|
||||||
},
|
|
||||||
{
|
|
||||||
name: caseUnparseableFails,
|
|
||||||
set: true,
|
|
||||||
value: cidrPrivateV4 + ",not-an-address",
|
|
||||||
expectError: true,
|
|
||||||
},
|
|
||||||
{
|
|
||||||
name: "out-of-range prefix length fails startup",
|
|
||||||
set: true,
|
|
||||||
value: "10.0.0.0/33",
|
|
||||||
expectError: true,
|
|
||||||
},
|
|
||||||
}
|
|
||||||
|
|
||||||
for _, tt := range tests {
|
|
||||||
t.Run(tt.name, func(t *testing.T) {
|
|
||||||
// Cannot use t.Parallel() here because t.Setenv
|
|
||||||
// is incompatible with parallel subtests.
|
|
||||||
t.Setenv("WEBHOOKER_ENVIRONMENT", "dev")
|
|
||||||
|
|
||||||
if tt.set {
|
|
||||||
t.Setenv("TRUSTED_PROXIES", tt.value)
|
|
||||||
} else {
|
|
||||||
require.NoError(t, os.Unsetenv("TRUSTED_PROXIES"))
|
|
||||||
}
|
|
||||||
|
|
||||||
if tt.expectError {
|
|
||||||
expectStartupErrorFor(
|
|
||||||
t, "TRUSTED_PROXIES", config.ErrInvalidCIDR,
|
|
||||||
)
|
|
||||||
} else {
|
|
||||||
testTrustedProxiesSuccess(t, tt.expected)
|
|
||||||
}
|
|
||||||
})
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func testTrustedProxiesSuccess(
|
|
||||||
t *testing.T,
|
|
||||||
expected []string,
|
|
||||||
) {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
var cfg *config.Config
|
|
||||||
|
|
||||||
app := fxtest.New(
|
|
||||||
t,
|
|
||||||
fx.Provide(
|
|
||||||
globals.New,
|
|
||||||
logger.New,
|
|
||||||
config.New,
|
|
||||||
),
|
|
||||||
fx.Populate(&cfg),
|
|
||||||
)
|
|
||||||
require.NoError(t, app.Err())
|
|
||||||
|
|
||||||
app.RequireStart()
|
|
||||||
|
|
||||||
defer app.RequireStop()
|
|
||||||
|
|
||||||
got := make([]string, 0, len(cfg.TrustedProxies))
|
|
||||||
for _, prefix := range cfg.TrustedProxies {
|
|
||||||
got = append(got, prefix.String())
|
|
||||||
}
|
|
||||||
|
|
||||||
assert.Equal(t, expected, got)
|
|
||||||
}
|
|
||||||
|
|||||||
@@ -18,11 +18,6 @@ const (
|
|||||||
testVersion = "test"
|
testVersion = "test"
|
||||||
// testContentType is the event content type used in tests.
|
// testContentType is the event content type used in tests.
|
||||||
testContentType = "application/json"
|
testContentType = "application/json"
|
||||||
// testWebhookName is the Webhook.Name used in tests.
|
|
||||||
testWebhookName = "test-webhook"
|
|
||||||
// testForeverLabel is Webhook.RetentionLabel for a retain-forever
|
|
||||||
// webhook.
|
|
||||||
testForeverLabel = "forever"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
func setupTestDB(
|
func setupTestDB(
|
||||||
|
|||||||
@@ -1,59 +1,6 @@
|
|||||||
package database
|
package database
|
||||||
|
|
||||||
import (
|
|
||||||
"math"
|
|
||||||
"strconv"
|
|
||||||
"time"
|
|
||||||
|
|
||||||
"gorm.io/gorm"
|
|
||||||
)
|
|
||||||
|
|
||||||
const (
|
|
||||||
// DefaultRetentionDays is the event retention period applied to a
|
|
||||||
// webhook created without an explicit retention value. It is the
|
|
||||||
// single source of truth for that policy and must stay in sync
|
|
||||||
// with the `gorm:"default:30"` column default on
|
|
||||||
// Webhook.RetentionDays below; a struct tag cannot reference a
|
|
||||||
// constant, so a test asserts the two agree.
|
|
||||||
DefaultRetentionDays = 30
|
|
||||||
|
|
||||||
// RetentionForeverDays is the sentinel RetentionDays value meaning
|
|
||||||
// "retain events forever". Users express that intent as 0, which
|
|
||||||
// Webhook.BeforeSave rewrites to this value: the column default
|
|
||||||
// substitutes DefaultRetentionDays for a zero value at insert
|
|
||||||
// time, so a zero can never survive a round trip to the database.
|
|
||||||
// Nothing outside this file may hardcode the number.
|
|
||||||
RetentionForeverDays = 365 * 1000
|
|
||||||
|
|
||||||
// MaxFiniteRetentionDays is the largest finite retention period the
|
|
||||||
// reaper's cutoff arithmetic can represent, and therefore the
|
|
||||||
// largest one a caller may request. It is derived from that
|
|
||||||
// arithmetic rather than picked: retentionCutoff computes
|
|
||||||
// retentionDays * hoursPerDay * time.Hour, and a time.Duration is
|
|
||||||
// an int64 nanosecond count, so math.MaxInt64 nanoseconds divided
|
|
||||||
// by an hour and then by a day is the exact ceiling — 106751 days,
|
|
||||||
// a little over 292 years.
|
|
||||||
//
|
|
||||||
// One day more overflows int64, wraps the product negative, and
|
|
||||||
// turns the cutoff into a timestamp in the far future that matches
|
|
||||||
// every row in the webhook's database. That is why this bound is
|
|
||||||
// enforced on input and why retentionCutoff saturates underneath
|
|
||||||
// it. Note that RetentionForeverDays deliberately sits above this
|
|
||||||
// ceiling: such webhooks are skipped before any cutoff is
|
|
||||||
// computed, and never reach the arithmetic at all.
|
|
||||||
MaxFiniteRetentionDays = int(
|
|
||||||
math.MaxInt64 / int64(time.Hour) / hoursPerDay,
|
|
||||||
)
|
|
||||||
)
|
|
||||||
|
|
||||||
// Webhook represents a webhook processing unit that groups entrypoints and targets
|
// Webhook represents a webhook processing unit that groups entrypoints and targets
|
||||||
//
|
|
||||||
// Every method below takes a pointer receiver. BeforeSave has to,
|
|
||||||
// because it mutates the record and GORM only invokes hooks declared
|
|
||||||
// that way; the display helpers follow suit so the receiver kinds do
|
|
||||||
// not mix. Handlers therefore put a *Webhook into template data:
|
|
||||||
// html/template cannot call a pointer method on a value held in a map,
|
|
||||||
// because a map element is not addressable.
|
|
||||||
type Webhook struct {
|
type Webhook struct {
|
||||||
BaseModel
|
BaseModel
|
||||||
|
|
||||||
@@ -61,9 +8,7 @@ type Webhook struct {
|
|||||||
Name string `gorm:"not null" json:"name"`
|
Name string `gorm:"not null" json:"name"`
|
||||||
Description string `json:"description"`
|
Description string `json:"description"`
|
||||||
|
|
||||||
// RetentionDays is the number of days to retain events. A value of
|
// RetentionDays is the number of days to retain events.
|
||||||
// RetentionForeverDays means retain forever. The column default
|
|
||||||
// must equal DefaultRetentionDays.
|
|
||||||
RetentionDays int `gorm:"default:30" json:"retentionDays"`
|
RetentionDays int `gorm:"default:30" json:"retentionDays"`
|
||||||
|
|
||||||
// Relations
|
// Relations
|
||||||
@@ -71,55 +16,3 @@ type Webhook struct {
|
|||||||
Entrypoints []Entrypoint `json:"entrypoints,omitempty"`
|
Entrypoints []Entrypoint `json:"entrypoints,omitempty"`
|
||||||
Targets []Target `json:"targets,omitempty"`
|
Targets []Target `json:"targets,omitempty"`
|
||||||
}
|
}
|
||||||
|
|
||||||
// BeforeSave normalises RetentionDays on every insert and update. A
|
|
||||||
// non-positive value is the user's way of asking for "retain forever",
|
|
||||||
// which is stored as the RetentionForeverDays sentinel.
|
|
||||||
//
|
|
||||||
// This has to happen in a hook rather than at the call sites. GORM
|
|
||||||
// substitutes the column default (DefaultRetentionDays) for a zero
|
|
||||||
// value while building the insert statement, which runs after
|
|
||||||
// BeforeSave; rewriting any later than this loses that race and the
|
|
||||||
// row lands at 30 days. Living on the model also means a future call
|
|
||||||
// site — a REST API, a fixture, a migration — cannot bypass it.
|
|
||||||
func (w *Webhook) BeforeSave(_ *gorm.DB) error {
|
|
||||||
if w.RetentionDays <= 0 {
|
|
||||||
w.RetentionDays = RetentionForeverDays
|
|
||||||
}
|
|
||||||
|
|
||||||
return nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// retainsForever reports whether a stored RetentionDays value means
|
|
||||||
// "keep events indefinitely". It is the single definition of that
|
|
||||||
// question, shared by Webhook.RetainsForever and by the reaper's
|
|
||||||
// cutoff computation so the two cannot disagree about which webhooks
|
|
||||||
// are exempt from reaping.
|
|
||||||
//
|
|
||||||
// It accepts the RetentionForeverDays sentinel written by BeforeSave
|
|
||||||
// and, defensively, the non-positive values that rows written before
|
|
||||||
// the sentinel existed may still carry.
|
|
||||||
func retainsForever(retentionDays int) bool {
|
|
||||||
return retentionDays <= 0 ||
|
|
||||||
retentionDays >= RetentionForeverDays
|
|
||||||
}
|
|
||||||
|
|
||||||
// RetainsForever reports whether this webhook's events are kept
|
|
||||||
// indefinitely.
|
|
||||||
func (w *Webhook) RetainsForever() bool {
|
|
||||||
return retainsForever(w.RetentionDays)
|
|
||||||
}
|
|
||||||
|
|
||||||
// RetentionLabel returns the webhook's retention policy as display
|
|
||||||
// text, so that no template has to know about the sentinel value.
|
|
||||||
func (w *Webhook) RetentionLabel() string {
|
|
||||||
if w.RetainsForever() {
|
|
||||||
return "forever"
|
|
||||||
}
|
|
||||||
|
|
||||||
if w.RetentionDays == 1 {
|
|
||||||
return "1 day"
|
|
||||||
}
|
|
||||||
|
|
||||||
return strconv.Itoa(w.RetentionDays) + " days"
|
|
||||||
}
|
|
||||||
|
|||||||
@@ -1,222 +0,0 @@
|
|||||||
package database_test
|
|
||||||
|
|
||||||
import (
|
|
||||||
"context"
|
|
||||||
"reflect"
|
|
||||||
"strconv"
|
|
||||||
"testing"
|
|
||||||
"time"
|
|
||||||
|
|
||||||
"github.com/google/uuid"
|
|
||||||
"github.com/stretchr/testify/assert"
|
|
||||||
"github.com/stretchr/testify/require"
|
|
||||||
"gorm.io/gorm"
|
|
||||||
"gorm.io/gorm/clause"
|
|
||||||
"sneak.berlin/go/webhooker/internal/database"
|
|
||||||
)
|
|
||||||
|
|
||||||
// startedTestDB returns a started main database for model-level tests.
|
|
||||||
func startedTestDB(t *testing.T) *gorm.DB {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
db, lc := setupTestDB(t)
|
|
||||||
|
|
||||||
ctx := context.Background()
|
|
||||||
require.NoError(t, lc.Start(ctx))
|
|
||||||
t.Cleanup(func() { require.NoError(t, lc.Stop(ctx)) })
|
|
||||||
|
|
||||||
return db.DB()
|
|
||||||
}
|
|
||||||
|
|
||||||
// storedRetention reads the retention_days column straight out of the
|
|
||||||
// row, so the assertion is about what was persisted rather than about
|
|
||||||
// whatever the in-memory struct happens to hold.
|
|
||||||
func storedRetention(t *testing.T, db *gorm.DB, id string) int {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
var got int
|
|
||||||
|
|
||||||
require.NoError(
|
|
||||||
t,
|
|
||||||
db.Model(&database.Webhook{}).
|
|
||||||
Where("id = ?", id).
|
|
||||||
Pluck("retention_days", &got).Error,
|
|
||||||
)
|
|
||||||
|
|
||||||
return got
|
|
||||||
}
|
|
||||||
|
|
||||||
// newWebhookWithRetention creates a webhook through the ordinary Create
|
|
||||||
// path, so the BeforeSave hook and the GORM column default both apply
|
|
||||||
// exactly as they do in production.
|
|
||||||
func newWebhookWithRetention(
|
|
||||||
t *testing.T,
|
|
||||||
db *gorm.DB,
|
|
||||||
wh *database.Webhook,
|
|
||||||
) string {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
wh.UserID = uuid.New().String()
|
|
||||||
wh.Name = testWebhookName
|
|
||||||
|
|
||||||
require.NoError(
|
|
||||||
t,
|
|
||||||
db.Omit(clause.Associations).Create(wh).Error,
|
|
||||||
)
|
|
||||||
|
|
||||||
return wh.ID
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestWebhookBeforeSave_ZeroBecomesForeverSentinel(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
db := startedTestDB(t)
|
|
||||||
|
|
||||||
wh := &database.Webhook{RetentionDays: 0}
|
|
||||||
id := newWebhookWithRetention(t, db, wh)
|
|
||||||
|
|
||||||
assert.Equal(
|
|
||||||
t,
|
|
||||||
database.RetentionForeverDays,
|
|
||||||
storedRetention(t, db, id),
|
|
||||||
"a zero retention must be stored as the sentinel, "+
|
|
||||||
"not replaced by the column default",
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestWebhookBeforeSave_NegativeBecomesForeverSentinel(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
db := startedTestDB(t)
|
|
||||||
|
|
||||||
wh := &database.Webhook{RetentionDays: -5}
|
|
||||||
id := newWebhookWithRetention(t, db, wh)
|
|
||||||
|
|
||||||
assert.Equal(
|
|
||||||
t,
|
|
||||||
database.RetentionForeverDays,
|
|
||||||
storedRetention(t, db, id),
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestWebhookBeforeSave_PositiveIsPreserved(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
db := startedTestDB(t)
|
|
||||||
|
|
||||||
wh := &database.Webhook{RetentionDays: 7}
|
|
||||||
id := newWebhookWithRetention(t, db, wh)
|
|
||||||
|
|
||||||
assert.Equal(t, 7, storedRetention(t, db, id))
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestWebhookBeforeSave_UpdateToZeroBecomesSentinel proves the hook
|
|
||||||
// fires on update as well as insert, via the same Save call the edit
|
|
||||||
// handler makes.
|
|
||||||
func TestWebhookBeforeSave_UpdateToZeroBecomesSentinel(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
db := startedTestDB(t)
|
|
||||||
|
|
||||||
wh := &database.Webhook{RetentionDays: 30}
|
|
||||||
id := newWebhookWithRetention(t, db, wh)
|
|
||||||
require.Equal(t, 30, storedRetention(t, db, id))
|
|
||||||
|
|
||||||
wh.RetentionDays = 0
|
|
||||||
require.NoError(t, db.Omit(clause.Associations).Save(wh).Error)
|
|
||||||
|
|
||||||
assert.Equal(
|
|
||||||
t,
|
|
||||||
database.RetentionForeverDays,
|
|
||||||
storedRetention(t, db, id),
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestWebhookRetentionColumnDefaultMatchesConstant guards the one place
|
|
||||||
// the default lives twice: a struct tag cannot reference a constant, so
|
|
||||||
// this asserts the tag and DefaultRetentionDays agree.
|
|
||||||
func TestWebhookRetentionColumnDefaultMatchesConstant(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
field, ok := reflect.TypeFor[database.Webhook]().
|
|
||||||
FieldByName("RetentionDays")
|
|
||||||
require.True(t, ok, "Webhook.RetentionDays must exist")
|
|
||||||
|
|
||||||
assert.Equal(
|
|
||||||
t,
|
|
||||||
"default:"+strconv.Itoa(database.DefaultRetentionDays),
|
|
||||||
field.Tag.Get("gorm"),
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestMaxFiniteRetentionDaysIsTheOverflowCeiling asserts that the
|
|
||||||
// constant is exactly where the cutoff arithmetic stops working, which
|
|
||||||
// is what makes it a derived bound rather than a round number someone
|
|
||||||
// liked. One day more wraps the int64 nanosecond count negative, and a
|
|
||||||
// negative span is precisely what turned a cutoff into a future
|
|
||||||
// timestamp that matched — and deleted — every row.
|
|
||||||
//
|
|
||||||
// The multiplications are done through variables on purpose: as
|
|
||||||
// constant expressions the overflowing one would not compile.
|
|
||||||
func TestMaxFiniteRetentionDaysIsTheOverflowCeiling(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
const hoursPerDay = 24
|
|
||||||
|
|
||||||
atCeiling := database.MaxFiniteRetentionDays
|
|
||||||
overCeiling := database.MaxFiniteRetentionDays + 1
|
|
||||||
|
|
||||||
assert.Positive(
|
|
||||||
t,
|
|
||||||
time.Duration(atCeiling*hoursPerDay)*time.Hour,
|
|
||||||
"the ceiling itself must still be representable",
|
|
||||||
)
|
|
||||||
assert.Negative(
|
|
||||||
t,
|
|
||||||
time.Duration(overCeiling*hoursPerDay)*time.Hour,
|
|
||||||
"one day past the ceiling must overflow",
|
|
||||||
)
|
|
||||||
|
|
||||||
assert.Less(
|
|
||||||
t,
|
|
||||||
database.MaxFiniteRetentionDays,
|
|
||||||
database.RetentionForeverDays,
|
|
||||||
"the sentinel sits above the ceiling and is only safe "+
|
|
||||||
"because retain-forever webhooks skip the arithmetic",
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestWebhookRetainsForeverAndLabel(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
cases := []struct {
|
|
||||||
name string
|
|
||||||
days int
|
|
||||||
forever bool
|
|
||||||
label string
|
|
||||||
}{
|
|
||||||
{
|
|
||||||
"sentinel",
|
|
||||||
database.RetentionForeverDays, true, testForeverLabel,
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"above sentinel",
|
|
||||||
database.RetentionForeverDays + 1, true, testForeverLabel,
|
|
||||||
},
|
|
||||||
{"legacy zero", 0, true, testForeverLabel},
|
|
||||||
{"legacy negative", -1, true, testForeverLabel},
|
|
||||||
{"default", database.DefaultRetentionDays, false, "30 days"},
|
|
||||||
{"one day", 1, false, "1 day"},
|
|
||||||
}
|
|
||||||
|
|
||||||
for _, tc := range cases {
|
|
||||||
t.Run(tc.name, func(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
wh := database.Webhook{RetentionDays: tc.days}
|
|
||||||
|
|
||||||
assert.Equal(t, tc.forever, wh.RetainsForever())
|
|
||||||
assert.Equal(t, tc.label, wh.RetentionLabel())
|
|
||||||
})
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -133,8 +133,7 @@ func (r *RetentionReaper) run(ctx context.Context) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// sweep lists every webhook from the main database and reaps expired
|
// sweep lists every webhook from the main database and reaps expired
|
||||||
// rows from each per-webhook database that has a finite retention
|
// rows from each per-webhook database whose RetentionDays is positive.
|
||||||
// policy. Webhooks set to retain forever are skipped entirely.
|
|
||||||
func (r *RetentionReaper) sweep(ctx context.Context) {
|
func (r *RetentionReaper) sweep(ctx context.Context) {
|
||||||
var webhooks []Webhook
|
var webhooks []Webhook
|
||||||
|
|
||||||
@@ -159,13 +158,8 @@ func (r *RetentionReaper) sweep(ctx context.Context) {
|
|||||||
|
|
||||||
wh := webhooks[i]
|
wh := webhooks[i]
|
||||||
|
|
||||||
// Skip retain-forever webhooks before building any query.
|
// RetentionDays of zero or less means retain forever.
|
||||||
// RetainsForever covers both the RetentionForeverDays
|
if wh.RetentionDays <= 0 {
|
||||||
// sentinel and the non-positive values that predate it: the
|
|
||||||
// sentinel is a positive number, so without this the reaper
|
|
||||||
// would compute a cutoff a thousand years in the past and
|
|
||||||
// issue a DELETE matching nothing on every single sweep.
|
|
||||||
if wh.RetainsForever() {
|
|
||||||
continue
|
continue
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -196,10 +190,9 @@ func (r *RetentionReaper) reapWebhook(
|
|||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
cutoff, ok := retentionCutoff(time.Now(), retentionDays)
|
cutoff := time.Now().Add(
|
||||||
if !ok {
|
-time.Duration(retentionDays*hoursPerDay) * time.Hour,
|
||||||
return
|
)
|
||||||
}
|
|
||||||
|
|
||||||
deleted, err := reapExpired(db, cutoff)
|
deleted, err := reapExpired(db, cutoff)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
@@ -222,37 +215,6 @@ func (r *RetentionReaper) reapWebhook(
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// retentionCutoff returns the timestamp before which a webhook's
|
|
||||||
// events have expired, and whether any cutoff applies at all. It
|
|
||||||
// reports false for a retain-forever policy, so no DELETE is issued.
|
|
||||||
//
|
|
||||||
// The day count is clamped to MaxFiniteRetentionDays first. This is
|
|
||||||
// defense in depth rather than decoration: a time.Duration is an int64
|
|
||||||
// nanosecond count, so an unclamped multiplication overflows above
|
|
||||||
// that ceiling and wraps the span negative. Subtracting a negative
|
|
||||||
// span moves the cutoff into the far future, where it matches every
|
|
||||||
// row in the database: the sweep then deletes every event, delivery,
|
|
||||||
// and delivery result, including ones created seconds ago. Rejecting
|
|
||||||
// out-of-range input at the form is the primary guard; saturating here
|
|
||||||
// means an old row, a migration, or a future call site cannot turn a
|
|
||||||
// too-large retention into total data loss.
|
|
||||||
func retentionCutoff(
|
|
||||||
now time.Time,
|
|
||||||
retentionDays int,
|
|
||||||
) (time.Time, bool) {
|
|
||||||
if retainsForever(retentionDays) {
|
|
||||||
return time.Time{}, false
|
|
||||||
}
|
|
||||||
|
|
||||||
if retentionDays > MaxFiniteRetentionDays {
|
|
||||||
retentionDays = MaxFiniteRetentionDays
|
|
||||||
}
|
|
||||||
|
|
||||||
return now.Add(
|
|
||||||
-time.Duration(retentionDays*hoursPerDay) * time.Hour,
|
|
||||||
), true
|
|
||||||
}
|
|
||||||
|
|
||||||
// reapExpired hard-deletes, in foreign-key-safe order, the delivery
|
// reapExpired hard-deletes, in foreign-key-safe order, the delivery
|
||||||
// results, deliveries, and events associated with events older than
|
// results, deliveries, and events associated with events older than
|
||||||
// cutoff. Deletes are unscoped so rows are physically removed rather
|
// cutoff. Deletes are unscoped so rows are physically removed rather
|
||||||
|
|||||||
@@ -77,7 +77,7 @@ func createWebhook(
|
|||||||
|
|
||||||
wh := &database.Webhook{
|
wh := &database.Webhook{
|
||||||
UserID: uuid.New().String(),
|
UserID: uuid.New().String(),
|
||||||
Name: testWebhookName,
|
Name: "test-webhook",
|
||||||
RetentionDays: retentionDays,
|
RetentionDays: retentionDays,
|
||||||
}
|
}
|
||||||
require.NoError(
|
require.NoError(
|
||||||
@@ -85,11 +85,10 @@ func createWebhook(
|
|||||||
db.Omit(clause.Associations).Create(wh).Error,
|
db.Omit(clause.Associations).Create(wh).Error,
|
||||||
)
|
)
|
||||||
|
|
||||||
// Webhook.BeforeSave rewrites a non-positive RetentionDays to the
|
// The RetentionDays column carries a GORM default of 30, so a
|
||||||
// retain-forever sentinel, and the column's GORM default would
|
// zero (or negative) value passed to Create is replaced by that
|
||||||
// otherwise substitute 30. Force the requested value with a
|
// default. Force the requested value explicitly so the
|
||||||
// column-level update so tests can plant legacy rows that predate
|
// retain-forever (<= 0) path can be exercised.
|
||||||
// the sentinel and still carry a literal 0 or negative value.
|
|
||||||
require.NoError(
|
require.NoError(
|
||||||
t,
|
t,
|
||||||
db.Model(wh).
|
db.Model(wh).
|
||||||
@@ -99,30 +98,6 @@ func createWebhook(
|
|||||||
return wh.ID
|
return wh.ID
|
||||||
}
|
}
|
||||||
|
|
||||||
// createWebhookNormally inserts a webhook through the ordinary Create
|
|
||||||
// path, with no column-level forcing, so Webhook.BeforeSave applies
|
|
||||||
// exactly as it does in production. Passing 0 therefore yields a row
|
|
||||||
// holding the RetentionForeverDays sentinel.
|
|
||||||
func createWebhookNormally(
|
|
||||||
t *testing.T,
|
|
||||||
db *gorm.DB,
|
|
||||||
retentionDays int,
|
|
||||||
) string {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
wh := &database.Webhook{
|
|
||||||
UserID: uuid.New().String(),
|
|
||||||
Name: testWebhookName,
|
|
||||||
RetentionDays: retentionDays,
|
|
||||||
}
|
|
||||||
require.NoError(
|
|
||||||
t,
|
|
||||||
db.Omit(clause.Associations).Create(wh).Error,
|
|
||||||
)
|
|
||||||
|
|
||||||
return wh.ID
|
|
||||||
}
|
|
||||||
|
|
||||||
// eventChain is the set of row IDs seeded for a single event.
|
// eventChain is the set of row IDs seeded for a single event.
|
||||||
type eventChain struct {
|
type eventChain struct {
|
||||||
eventID string
|
eventID string
|
||||||
@@ -281,111 +256,12 @@ func TestRetentionReaper_ReapsExpiredKeepsRecent(t *testing.T) {
|
|||||||
assertChainPresent(t, db, recent)
|
assertChainPresent(t, db, recent)
|
||||||
}
|
}
|
||||||
|
|
||||||
// TestRetentionReaper_SkipsSentinelReapsFiniteInSameSweep covers the
|
|
||||||
// end-to-end retain-forever path: a webhook created the normal way with
|
|
||||||
// a requested retention of 0 lands on the RetentionForeverDays
|
|
||||||
// sentinel, and the reaper leaves its ancient events alone while still
|
|
||||||
// reaping a finite-retention webhook in the very same sweep.
|
|
||||||
func TestRetentionReaper_SkipsSentinelReapsFiniteInSameSweep(
|
|
||||||
t *testing.T,
|
|
||||||
) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
env := setupRetentionTest(t)
|
|
||||||
|
|
||||||
foreverID := createWebhookNormally(t, env.mainDB.DB(), 0)
|
|
||||||
|
|
||||||
var stored database.Webhook
|
|
||||||
|
|
||||||
require.NoError(
|
|
||||||
t,
|
|
||||||
env.mainDB.DB().Where("id = ?", foreverID).
|
|
||||||
First(&stored).Error,
|
|
||||||
)
|
|
||||||
require.Equal(
|
|
||||||
t,
|
|
||||||
database.RetentionForeverDays,
|
|
||||||
stored.RetentionDays,
|
|
||||||
"a requested retention of 0 must persist as the sentinel",
|
|
||||||
)
|
|
||||||
|
|
||||||
finiteID := createWebhookNormally(t, env.mainDB.DB(), 30)
|
|
||||||
|
|
||||||
foreverDB, err := env.mgr.GetDB(foreverID)
|
|
||||||
require.NoError(t, err)
|
|
||||||
|
|
||||||
finiteDB, err := env.mgr.GetDB(finiteID)
|
|
||||||
require.NoError(t, err)
|
|
||||||
|
|
||||||
ancient := time.Now().Add(-365 * 24 * time.Hour)
|
|
||||||
kept := seedEventChain(t, foreverDB, foreverID, ancient)
|
|
||||||
doomed := seedEventChain(t, finiteDB, finiteID, ancient)
|
|
||||||
|
|
||||||
env.reaper.ExportSweep(context.Background())
|
|
||||||
|
|
||||||
assertChainPresent(t, foreverDB, kept)
|
|
||||||
assertChainGone(t, finiteDB, doomed)
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestRetentionReaper_HugeFiniteRetentionRetainsRecentEvents pins the
|
|
||||||
// overflow that made a large finite retention destroy everything.
|
|
||||||
//
|
|
||||||
// The cutoff is a time.Duration, an int64 nanosecond count. A day
|
|
||||||
// count above MaxFiniteRetentionDays multiplied out unclamped wraps
|
|
||||||
// negative, so subtracting it moves the cutoff into the far future,
|
|
||||||
// where "created_at < cutoff" matches every row: an event created a
|
|
||||||
// moment ago, and its delivery and delivery result, were all deleted
|
|
||||||
// on the first sweep. 200000 is inside that band and below the
|
|
||||||
// retain-forever sentinel, so it is treated as a finite policy and
|
|
||||||
// really does reach the arithmetic.
|
|
||||||
//
|
|
||||||
// The row is planted at the column level because such a value can no
|
|
||||||
// longer be submitted through the form; the point of the test is that
|
|
||||||
// a row from an older version, or a future call site, still cannot
|
|
||||||
// trigger the wipe.
|
|
||||||
func TestRetentionReaper_HugeFiniteRetentionRetainsRecentEvents(
|
|
||||||
t *testing.T,
|
|
||||||
) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
env := setupRetentionTest(t)
|
|
||||||
|
|
||||||
const overflowingRetentionDays = 200000
|
|
||||||
|
|
||||||
require.Greater(
|
|
||||||
t,
|
|
||||||
overflowingRetentionDays,
|
|
||||||
database.MaxFiniteRetentionDays,
|
|
||||||
"the test value must exceed what the cutoff can represent",
|
|
||||||
)
|
|
||||||
require.Less(
|
|
||||||
t,
|
|
||||||
overflowingRetentionDays,
|
|
||||||
database.RetentionForeverDays,
|
|
||||||
"the test value must not be rescued by the forever skip",
|
|
||||||
)
|
|
||||||
|
|
||||||
webhookID := createWebhook(
|
|
||||||
t, env.mainDB.DB(), overflowingRetentionDays,
|
|
||||||
)
|
|
||||||
|
|
||||||
db, err := env.mgr.GetDB(webhookID)
|
|
||||||
require.NoError(t, err)
|
|
||||||
|
|
||||||
fresh := seedEventChain(t, db, webhookID, time.Now())
|
|
||||||
|
|
||||||
env.reaper.ExportSweep(context.Background())
|
|
||||||
|
|
||||||
assertChainPresent(t, db, fresh)
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestRetentionReaper_RetainsForeverWhenNonPositive(t *testing.T) {
|
func TestRetentionReaper_RetainsForeverWhenNonPositive(t *testing.T) {
|
||||||
t.Parallel()
|
t.Parallel()
|
||||||
|
|
||||||
env := setupRetentionTest(t)
|
env := setupRetentionTest(t)
|
||||||
|
|
||||||
// A legacy row written before the sentinel existed still carries a
|
// RetentionDays of zero means retain forever.
|
||||||
// literal 0; the <= 0 guard must keep honouring it.
|
|
||||||
webhookID := createWebhook(t, env.mainDB.DB(), 0)
|
webhookID := createWebhook(t, env.mainDB.DB(), 0)
|
||||||
|
|
||||||
db, err := env.mgr.GetDB(webhookID)
|
db, err := env.mgr.GetDB(webhookID)
|
||||||
|
|||||||
@@ -92,12 +92,7 @@ func ValidateTargetURL(
|
|||||||
) error {
|
) error {
|
||||||
parsed, err := url.Parse(targetURL)
|
parsed, err := url.Parse(targetURL)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
// url.Parse embeds the whole URL in its error, and
|
return fmt.Errorf("invalid URL: %w", err)
|
||||||
// this one is logged and shown; mask it. Every other
|
|
||||||
// branch below reports only the hostname.
|
|
||||||
return fmt.Errorf(
|
|
||||||
"invalid URL: %w", maskURLError(err),
|
|
||||||
)
|
|
||||||
}
|
}
|
||||||
|
|
||||||
err = validateScheme(parsed.Scheme)
|
err = validateScheme(parsed.Scheme)
|
||||||
|
|||||||
@@ -1,202 +0,0 @@
|
|||||||
package delivery
|
|
||||||
|
|
||||||
import (
|
|
||||||
"encoding/json"
|
|
||||||
"fmt"
|
|
||||||
"strconv"
|
|
||||||
|
|
||||||
"sneak.berlin/go/webhooker/internal/database"
|
|
||||||
)
|
|
||||||
|
|
||||||
// configUnavailable is what a target's configuration renders
|
|
||||||
// as when it is absent, of an unknown type, or does not
|
|
||||||
// parse. The stored blob is never shown as a fallback: it can
|
|
||||||
// hold a credential (a Slack incoming webhook URL is a bearer
|
|
||||||
// token) and a UI that prints it leaks that credential into
|
|
||||||
// browser history, screenshots and screen shares.
|
|
||||||
const configUnavailable = "(unavailable)"
|
|
||||||
|
|
||||||
// ConfigField is one labelled, display-safe value derived
|
|
||||||
// from a target's stored configuration.
|
|
||||||
type ConfigField struct {
|
|
||||||
Label string
|
|
||||||
Value string
|
|
||||||
}
|
|
||||||
|
|
||||||
// TargetView is the display-safe projection of a target for
|
|
||||||
// the UI. It deliberately has no raw configuration field, so
|
|
||||||
// no template — present or future — can render the stored
|
|
||||||
// blob.
|
|
||||||
type TargetView struct {
|
|
||||||
ID string
|
|
||||||
Name string
|
|
||||||
Type database.TargetType
|
|
||||||
Active bool
|
|
||||||
Config []ConfigField
|
|
||||||
}
|
|
||||||
|
|
||||||
// NewTargetViews projects targets for rendering, replacing
|
|
||||||
// each stored configuration blob with named, display-safe
|
|
||||||
// fields.
|
|
||||||
func NewTargetViews(
|
|
||||||
targets []database.Target,
|
|
||||||
) []TargetView {
|
|
||||||
views := make([]TargetView, 0, len(targets))
|
|
||||||
|
|
||||||
for i := range targets {
|
|
||||||
t := &targets[i]
|
|
||||||
|
|
||||||
views = append(views, TargetView{
|
|
||||||
ID: t.ID,
|
|
||||||
Name: t.Name,
|
|
||||||
Type: t.Type,
|
|
||||||
Active: t.Active,
|
|
||||||
Config: targetConfigFields(t),
|
|
||||||
})
|
|
||||||
}
|
|
||||||
|
|
||||||
return views
|
|
||||||
}
|
|
||||||
|
|
||||||
// targetConfigFields returns the display-safe fields for a
|
|
||||||
// target's configuration. Anything it cannot parse becomes
|
|
||||||
// the neutral placeholder.
|
|
||||||
func targetConfigFields(
|
|
||||||
t *database.Target,
|
|
||||||
) []ConfigField {
|
|
||||||
switch t.Type {
|
|
||||||
case database.TargetTypeSlack:
|
|
||||||
return slackConfigFields(t.Config)
|
|
||||||
case database.TargetTypeHTTP:
|
|
||||||
return httpConfigFields(t)
|
|
||||||
case database.TargetTypeDatabase:
|
|
||||||
return databaseConfigFields(t.Config)
|
|
||||||
case database.TargetTypeLog:
|
|
||||||
// The log target takes no configuration.
|
|
||||||
return nil
|
|
||||||
default:
|
|
||||||
return unavailableConfigFields()
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// unavailableConfigFields is the neutral placeholder shown
|
|
||||||
// for a configuration that could not be presented.
|
|
||||||
func unavailableConfigFields() []ConfigField {
|
|
||||||
return []ConfigField{{
|
|
||||||
Label: "Configuration",
|
|
||||||
Value: configUnavailable,
|
|
||||||
}}
|
|
||||||
}
|
|
||||||
|
|
||||||
// slackConfigFields describes a Slack target. Only the masked
|
|
||||||
// webhook URL is shown; the full URL is the credential.
|
|
||||||
func slackConfigFields(configJSON string) []ConfigField {
|
|
||||||
cfg, err := parseSlackConfig(configJSON)
|
|
||||||
if err != nil {
|
|
||||||
return unavailableConfigFields()
|
|
||||||
}
|
|
||||||
|
|
||||||
return []ConfigField{{
|
|
||||||
Label: "Webhook URL",
|
|
||||||
Value: cfg.MaskedWebhookURL(),
|
|
||||||
}}
|
|
||||||
}
|
|
||||||
|
|
||||||
// httpConfigFields describes an HTTP target: its destination
|
|
||||||
// and its retry settings. Header values are not shown — they
|
|
||||||
// routinely carry authorization tokens — only how many are
|
|
||||||
// configured.
|
|
||||||
func httpConfigFields(t *database.Target) []ConfigField {
|
|
||||||
cfg, err := parseHTTPConfig(t.Config)
|
|
||||||
if err != nil {
|
|
||||||
return unavailableConfigFields()
|
|
||||||
}
|
|
||||||
|
|
||||||
fields := []ConfigField{{
|
|
||||||
Label: "Destination URL",
|
|
||||||
Value: cfg.URL,
|
|
||||||
}}
|
|
||||||
|
|
||||||
if cfg.Timeout > 0 {
|
|
||||||
fields = append(fields, ConfigField{
|
|
||||||
Label: "Timeout",
|
|
||||||
Value: strconv.Itoa(cfg.Timeout) + "s",
|
|
||||||
})
|
|
||||||
}
|
|
||||||
|
|
||||||
if len(cfg.Headers) > 0 {
|
|
||||||
fields = append(fields, ConfigField{
|
|
||||||
Label: "Headers",
|
|
||||||
Value: fmt.Sprintf(
|
|
||||||
"%d configured", len(cfg.Headers),
|
|
||||||
),
|
|
||||||
})
|
|
||||||
}
|
|
||||||
|
|
||||||
return append(fields, retryFields(t)...)
|
|
||||||
}
|
|
||||||
|
|
||||||
// retryFields describes a target's retry settings, which live
|
|
||||||
// on the target row rather than in its configuration blob.
|
|
||||||
func retryFields(t *database.Target) []ConfigField {
|
|
||||||
retries := strconv.Itoa(t.MaxRetries)
|
|
||||||
if t.MaxRetries == 0 {
|
|
||||||
retries += " (fire-and-forget)"
|
|
||||||
}
|
|
||||||
|
|
||||||
fields := []ConfigField{{
|
|
||||||
Label: "Max Retries",
|
|
||||||
Value: retries,
|
|
||||||
}}
|
|
||||||
|
|
||||||
if t.MaxQueueSize > 0 {
|
|
||||||
fields = append(fields, ConfigField{
|
|
||||||
Label: "Max Queue Size",
|
|
||||||
Value: strconv.Itoa(t.MaxQueueSize),
|
|
||||||
})
|
|
||||||
}
|
|
||||||
|
|
||||||
return fields
|
|
||||||
}
|
|
||||||
|
|
||||||
// databaseConfigFields describes an archive target. Its
|
|
||||||
// configuration is optional, and an absent or empty expiry
|
|
||||||
// means the archive is kept forever. An expiry that is set
|
|
||||||
// but not a valid duration is reported as unavailable rather
|
|
||||||
// than echoed back.
|
|
||||||
func databaseConfigFields(configJSON string) []ConfigField {
|
|
||||||
expiry := archiveExpiryNever
|
|
||||||
|
|
||||||
if configJSON != "" {
|
|
||||||
var cfg databaseTargetConfig
|
|
||||||
|
|
||||||
err := json.Unmarshal([]byte(configJSON), &cfg)
|
|
||||||
if err != nil {
|
|
||||||
return unavailableConfigFields()
|
|
||||||
}
|
|
||||||
|
|
||||||
if cfg.Expiry != "" {
|
|
||||||
if ValidateArchiveExpiry(cfg.Expiry) != nil {
|
|
||||||
return unavailableConfigFields()
|
|
||||||
}
|
|
||||||
|
|
||||||
expiry = cfg.Expiry
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
return []ConfigField{{
|
|
||||||
Label: "Archive Expiry",
|
|
||||||
Value: expiry,
|
|
||||||
}}
|
|
||||||
}
|
|
||||||
|
|
||||||
// MaskedWebhookURL returns the Slack webhook URL reduced to
|
|
||||||
// its scheme and host, with the path, query and any userinfo
|
|
||||||
// elided. The path segments are the credential, so none of
|
|
||||||
// them is shown: the field accepts an arbitrary URL, so no
|
|
||||||
// segment can be assumed non-secret. A URL that does not
|
|
||||||
// parse into a scheme and host yields the neutral
|
|
||||||
// placeholder, never the raw string.
|
|
||||||
func (c *SlackTargetConfig) MaskedWebhookURL() string {
|
|
||||||
return MaskURL(c.WebhookURL)
|
|
||||||
}
|
|
||||||
@@ -1,299 +0,0 @@
|
|||||||
package delivery_test
|
|
||||||
|
|
||||||
import (
|
|
||||||
"testing"
|
|
||||||
|
|
||||||
"github.com/stretchr/testify/assert"
|
|
||||||
"github.com/stretchr/testify/require"
|
|
||||||
"sneak.berlin/go/webhooker/internal/database"
|
|
||||||
"sneak.berlin/go/webhooker/internal/delivery"
|
|
||||||
)
|
|
||||||
|
|
||||||
const (
|
|
||||||
// slackSecretPath is the credential-bearing part of a
|
|
||||||
// Slack incoming webhook URL: everything after the host.
|
|
||||||
slackSecretPath = "/services/T00000000/B00000000/" +
|
|
||||||
"XXXXXXXXXXXXXXXXXXXXXXXX"
|
|
||||||
slackWebhookURL = "https://hooks.slack.com" +
|
|
||||||
slackSecretPath
|
|
||||||
|
|
||||||
viewExampleOrigin = "https://example.com"
|
|
||||||
viewExampleHook = viewExampleOrigin + "/hook"
|
|
||||||
viewUnavailable = "(unavailable)"
|
|
||||||
viewExpiryNever = "never"
|
|
||||||
)
|
|
||||||
|
|
||||||
func TestMaskedWebhookURL(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
tests := map[string]struct {
|
|
||||||
url string
|
|
||||||
want string
|
|
||||||
}{
|
|
||||||
"slack webhook": {
|
|
||||||
url: slackWebhookURL,
|
|
||||||
want: "https://hooks.slack.com/...",
|
|
||||||
},
|
|
||||||
"query string dropped": {
|
|
||||||
url: viewExampleOrigin + "/a?token=secret",
|
|
||||||
want: viewExampleOrigin + "/...",
|
|
||||||
},
|
|
||||||
// Fabricated userinfo in a test URL, not a real
|
|
||||||
// credential.
|
|
||||||
//nolint:gosec // G101
|
|
||||||
"userinfo dropped": {
|
|
||||||
url: "https://user:pw@example.com/a/b",
|
|
||||||
want: viewExampleOrigin + "/...",
|
|
||||||
},
|
|
||||||
"no path": {
|
|
||||||
url: viewExampleOrigin,
|
|
||||||
want: viewExampleOrigin,
|
|
||||||
},
|
|
||||||
"root path": {
|
|
||||||
url: viewExampleOrigin + "/",
|
|
||||||
want: viewExampleOrigin,
|
|
||||||
},
|
|
||||||
"not a url": {
|
|
||||||
url: "definitely not a url",
|
|
||||||
want: viewUnavailable,
|
|
||||||
},
|
|
||||||
"empty": {
|
|
||||||
url: "",
|
|
||||||
want: viewUnavailable,
|
|
||||||
},
|
|
||||||
}
|
|
||||||
|
|
||||||
for name, tc := range tests {
|
|
||||||
t.Run(name, func(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
cfg := &delivery.SlackTargetConfig{
|
|
||||||
WebhookURL: tc.url,
|
|
||||||
}
|
|
||||||
|
|
||||||
assert.Equal(
|
|
||||||
t, tc.want, cfg.MaskedWebhookURL(),
|
|
||||||
)
|
|
||||||
})
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestMaskedWebhookURL_NeverLeaksPath is the direct
|
|
||||||
// expression of the rule: whatever the input, the masked
|
|
||||||
// value never contains a path segment of it.
|
|
||||||
func TestMaskedWebhookURL_NeverLeaksPath(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
cfg := &delivery.SlackTargetConfig{
|
|
||||||
WebhookURL: slackWebhookURL,
|
|
||||||
}
|
|
||||||
|
|
||||||
masked := cfg.MaskedWebhookURL()
|
|
||||||
|
|
||||||
assert.NotContains(t, masked, "T00000000")
|
|
||||||
assert.NotContains(t, masked, "B00000000")
|
|
||||||
assert.NotContains(
|
|
||||||
t, masked, "XXXXXXXXXXXXXXXXXXXXXXXX",
|
|
||||||
)
|
|
||||||
assert.NotContains(t, masked, slackSecretPath)
|
|
||||||
}
|
|
||||||
|
|
||||||
// fieldMap turns a view's config fields into a lookup so
|
|
||||||
// assertions read by label.
|
|
||||||
func fieldMap(fields []delivery.ConfigField) map[string]string {
|
|
||||||
out := make(map[string]string, len(fields))
|
|
||||||
for _, f := range fields {
|
|
||||||
out[f.Label] = f.Value
|
|
||||||
}
|
|
||||||
|
|
||||||
return out
|
|
||||||
}
|
|
||||||
|
|
||||||
// viewFor projects a single target and returns its view.
|
|
||||||
func viewFor(
|
|
||||||
t *testing.T,
|
|
||||||
target database.Target,
|
|
||||||
) delivery.TargetView {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
views := delivery.NewTargetViews(
|
|
||||||
[]database.Target{target},
|
|
||||||
)
|
|
||||||
require.Len(t, views, 1)
|
|
||||||
|
|
||||||
return views[0]
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestNewTargetViews_Slack(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
view := viewFor(t, database.Target{
|
|
||||||
Name: "slack-target",
|
|
||||||
Type: database.TargetTypeSlack,
|
|
||||||
Active: true,
|
|
||||||
Config: `{"webhookUrl":"` +
|
|
||||||
slackWebhookURL + `"}`,
|
|
||||||
})
|
|
||||||
|
|
||||||
assert.Equal(t, "slack-target", view.Name)
|
|
||||||
assert.Equal(
|
|
||||||
t,
|
|
||||||
map[string]string{
|
|
||||||
"Webhook URL": "https://hooks.slack.com/...",
|
|
||||||
},
|
|
||||||
fieldMap(view.Config),
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestNewTargetViews_HTTP(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
view := viewFor(t, database.Target{
|
|
||||||
Type: database.TargetTypeHTTP,
|
|
||||||
Config: `{"url":"` + viewExampleHook + `",` +
|
|
||||||
`"timeout":30,` +
|
|
||||||
`"headers":{"Authorization":"Bearer sekrit"}}`,
|
|
||||||
MaxRetries: 5,
|
|
||||||
MaxQueueSize: 100,
|
|
||||||
})
|
|
||||||
|
|
||||||
fields := fieldMap(view.Config)
|
|
||||||
|
|
||||||
assert.Equal(
|
|
||||||
t,
|
|
||||||
map[string]string{
|
|
||||||
"Destination URL": viewExampleHook,
|
|
||||||
"Timeout": "30s",
|
|
||||||
"Headers": "1 configured",
|
|
||||||
"Max Retries": "5",
|
|
||||||
"Max Queue Size": "100",
|
|
||||||
},
|
|
||||||
fields,
|
|
||||||
)
|
|
||||||
|
|
||||||
// Header values can be credentials and are never shown.
|
|
||||||
for _, v := range fields {
|
|
||||||
assert.NotContains(t, v, "sekrit")
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestNewTargetViews_HTTPFireAndForget(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
view := viewFor(t, database.Target{
|
|
||||||
Type: database.TargetTypeHTTP,
|
|
||||||
Config: `{"url":"` + viewExampleHook + `"}`,
|
|
||||||
})
|
|
||||||
|
|
||||||
assert.Equal(
|
|
||||||
t,
|
|
||||||
map[string]string{
|
|
||||||
"Destination URL": viewExampleHook,
|
|
||||||
"Max Retries": "0 (fire-and-forget)",
|
|
||||||
},
|
|
||||||
fieldMap(view.Config),
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestNewTargetViews_Database(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
tests := map[string]struct {
|
|
||||||
config string
|
|
||||||
want string
|
|
||||||
}{
|
|
||||||
"empty config": {config: "", want: viewExpiryNever},
|
|
||||||
"empty expiry": {config: `{}`, want: viewExpiryNever},
|
|
||||||
"explicit": {
|
|
||||||
config: `{"expiry":"720h"}`,
|
|
||||||
want: "720h",
|
|
||||||
},
|
|
||||||
"never literal": {
|
|
||||||
config: `{"expiry":"` + viewExpiryNever + `"}`,
|
|
||||||
want: viewExpiryNever,
|
|
||||||
},
|
|
||||||
}
|
|
||||||
|
|
||||||
for name, tc := range tests {
|
|
||||||
t.Run(name, func(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
view := viewFor(t, database.Target{
|
|
||||||
Type: database.TargetTypeDatabase,
|
|
||||||
Config: tc.config,
|
|
||||||
})
|
|
||||||
|
|
||||||
assert.Equal(
|
|
||||||
t,
|
|
||||||
map[string]string{"Archive Expiry": tc.want},
|
|
||||||
fieldMap(view.Config),
|
|
||||||
)
|
|
||||||
})
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestNewTargetViews_Log(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
view := viewFor(t, database.Target{
|
|
||||||
Type: database.TargetTypeLog,
|
|
||||||
Config: "",
|
|
||||||
})
|
|
||||||
|
|
||||||
assert.Empty(t, view.Config)
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestNewTargetViews_Unpresentable proves that no config the
|
|
||||||
// view cannot present falls back to the stored blob.
|
|
||||||
func TestNewTargetViews_Unpresentable(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
const blob = `{"webhookUrl":"https://hooks.slack.com` +
|
|
||||||
slackSecretPath + `"`
|
|
||||||
|
|
||||||
tests := map[string]database.Target{
|
|
||||||
"unknown target type": {
|
|
||||||
Type: database.TargetType("carrier-pigeon"),
|
|
||||||
Config: blob,
|
|
||||||
},
|
|
||||||
"unparseable json": {
|
|
||||||
Type: database.TargetTypeSlack,
|
|
||||||
Config: blob,
|
|
||||||
},
|
|
||||||
"empty slack config": {
|
|
||||||
Type: database.TargetTypeSlack,
|
|
||||||
},
|
|
||||||
"slack config without url": {
|
|
||||||
Type: database.TargetTypeSlack,
|
|
||||||
Config: `{}`,
|
|
||||||
},
|
|
||||||
"unparseable http json": {
|
|
||||||
Type: database.TargetTypeHTTP,
|
|
||||||
Config: `{"url":`,
|
|
||||||
},
|
|
||||||
"unparseable archive json": {
|
|
||||||
Type: database.TargetTypeDatabase,
|
|
||||||
Config: `{"expiry":`,
|
|
||||||
},
|
|
||||||
"invalid archive expiry": {
|
|
||||||
Type: database.TargetTypeDatabase,
|
|
||||||
Config: `{"expiry":"a fortnight"}`,
|
|
||||||
},
|
|
||||||
}
|
|
||||||
|
|
||||||
for name, target := range tests {
|
|
||||||
t.Run(name, func(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
view := viewFor(t, target)
|
|
||||||
|
|
||||||
assert.Equal(
|
|
||||||
t,
|
|
||||||
map[string]string{
|
|
||||||
"Configuration": viewUnavailable,
|
|
||||||
},
|
|
||||||
fieldMap(view.Config),
|
|
||||||
)
|
|
||||||
})
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -363,8 +363,7 @@ func (t *httpTarget) doHTTPRequest(
|
|||||||
)
|
)
|
||||||
if reqErr != nil {
|
if reqErr != nil {
|
||||||
return 0, "", 0, fmt.Errorf(
|
return 0, "", 0, fmt.Errorf(
|
||||||
"creating request: %w",
|
"creating request: %w", reqErr,
|
||||||
maskURLError(reqErr),
|
|
||||||
)
|
)
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -493,19 +492,8 @@ func applyRequestHeaders(
|
|||||||
// executeHTTPRequest sends an HTTP request using the provided
|
// executeHTTPRequest sends an HTTP request using the provided
|
||||||
// client. URLs are validated by the config parsers and the
|
// client. URLs are validated by the config parsers and the
|
||||||
// SSRF-safe transport before reaching here.
|
// SSRF-safe transport before reaching here.
|
||||||
//
|
|
||||||
// Transport failures are masked here, at the single point
|
|
||||||
// where every target's request errors are born, because the
|
|
||||||
// caller stores them in DeliveryResult.Error: an unmasked
|
|
||||||
// *url.Error would write the target URL — the credential for
|
|
||||||
// a Slack incoming webhook — into the per-webhook database.
|
|
||||||
func executeHTTPRequest(
|
func executeHTTPRequest(
|
||||||
client *http.Client, req *http.Request,
|
client *http.Client, req *http.Request,
|
||||||
) (*http.Response, error) {
|
) (*http.Response, error) {
|
||||||
resp, err := client.Do(req) //#nosec G704 -- validated URL, SSRF-safe transport
|
return client.Do(req) //#nosec G704 -- validated URL, SSRF-safe transport
|
||||||
if err != nil {
|
|
||||||
return nil, maskURLError(err)
|
|
||||||
}
|
|
||||||
|
|
||||||
return resp, nil
|
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -125,7 +125,7 @@ func (t *slackTarget) attempt(
|
|||||||
if err != nil {
|
if err != nil {
|
||||||
return attemptResult{
|
return attemptResult{
|
||||||
success: false,
|
success: false,
|
||||||
errMsg: maskURLError(err).Error(),
|
errMsg: err.Error(),
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -1,61 +0,0 @@
|
|||||||
package delivery
|
|
||||||
|
|
||||||
import (
|
|
||||||
"errors"
|
|
||||||
"net/url"
|
|
||||||
)
|
|
||||||
|
|
||||||
// urlPathElision stands in for a URL's elided path.
|
|
||||||
const urlPathElision = "/..."
|
|
||||||
|
|
||||||
// MaskURL renders a URL as scheme plus host with everything
|
|
||||||
// that can carry a secret removed. A delivery target URL is
|
|
||||||
// itself a credential — a Slack incoming webhook URL is a
|
|
||||||
// bearer token — so the path, query and userinfo are never
|
|
||||||
// reproduced, in a page, a log line or a stored error. A URL
|
|
||||||
// that does not parse into a scheme and host yields the
|
|
||||||
// neutral placeholder, never the raw string.
|
|
||||||
func MaskURL(raw string) string {
|
|
||||||
parsed, err := url.Parse(raw)
|
|
||||||
if err != nil || parsed.Scheme == "" ||
|
|
||||||
parsed.Host == "" {
|
|
||||||
return configUnavailable
|
|
||||||
}
|
|
||||||
|
|
||||||
masked := parsed.Scheme + "://" + parsed.Host
|
|
||||||
|
|
||||||
if parsed.Path != "" && parsed.Path != "/" {
|
|
||||||
masked += urlPathElision
|
|
||||||
}
|
|
||||||
|
|
||||||
return masked
|
|
||||||
}
|
|
||||||
|
|
||||||
// maskURLError strips the credential from an error raised
|
|
||||||
// against a request URL. The net/http and net/url packages
|
|
||||||
// embed the full request URL in every *url.Error they return,
|
|
||||||
// so an unmodified transport error persisted into
|
|
||||||
// DeliveryResult.Error writes the credential to disk.
|
|
||||||
//
|
|
||||||
// The masked error keeps the operation and the wrapped cause,
|
|
||||||
// so a DNS failure still reads differently from a refused
|
|
||||||
// connection, a TLS handshake failure or a timeout, and Is,
|
|
||||||
// As, Timeout and Temporary keep working on it. Only the
|
|
||||||
// path, query and userinfo of the URL are dropped. Errors
|
|
||||||
// that carry no URL are returned unchanged.
|
|
||||||
//
|
|
||||||
// Call it where the error is raised, before any wrapping: it
|
|
||||||
// replaces the *url.Error itself, so any context wrapped
|
|
||||||
// around it first would be discarded.
|
|
||||||
func maskURLError(err error) error {
|
|
||||||
var urlErr *url.Error
|
|
||||||
if !errors.As(err, &urlErr) {
|
|
||||||
return err
|
|
||||||
}
|
|
||||||
|
|
||||||
return &url.Error{
|
|
||||||
Op: urlErr.Op,
|
|
||||||
URL: MaskURL(urlErr.URL),
|
|
||||||
Err: urlErr.Err,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,196 +0,0 @@
|
|||||||
package delivery_test
|
|
||||||
|
|
||||||
import (
|
|
||||||
"context"
|
|
||||||
"encoding/json"
|
|
||||||
"net/http"
|
|
||||||
"net/http/httptest"
|
|
||||||
"testing"
|
|
||||||
|
|
||||||
"github.com/google/uuid"
|
|
||||||
"github.com/stretchr/testify/assert"
|
|
||||||
"github.com/stretchr/testify/require"
|
|
||||||
"gorm.io/gorm"
|
|
||||||
"sneak.berlin/go/webhooker/internal/database"
|
|
||||||
"sneak.berlin/go/webhooker/internal/delivery"
|
|
||||||
)
|
|
||||||
|
|
||||||
// The path of a Slack incoming webhook URL is the credential:
|
|
||||||
// whoever holds these segments can post to the channel
|
|
||||||
// forever. None of them may reach a stored delivery error,
|
|
||||||
// which lives on disk in the per-webhook database and is
|
|
||||||
// serialized by the JSON tag on DeliveryResult.Error.
|
|
||||||
const (
|
|
||||||
maskSecretPath = "/services/T00000000/B00000000/" +
|
|
||||||
"XXXXXXXXXXXXXXXXXXXXXXXX"
|
|
||||||
)
|
|
||||||
|
|
||||||
// assertNoCredential fails if the whole path or any single
|
|
||||||
// segment of it survived into the message, so a partial leak
|
|
||||||
// fails the test too.
|
|
||||||
func assertNoCredential(t *testing.T, msg string) {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
segments := []string{
|
|
||||||
maskSecretPath,
|
|
||||||
"services",
|
|
||||||
"T00000000",
|
|
||||||
"B00000000",
|
|
||||||
"XXXXXXXXXXXXXXXXXXXXXXXX",
|
|
||||||
}
|
|
||||||
|
|
||||||
for _, segment := range segments {
|
|
||||||
assert.NotContains(t, msg, segment)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// storedDeliveryError returns the error string persisted for a
|
|
||||||
// delivery, which is what an operator and any future API read.
|
|
||||||
func storedDeliveryError(
|
|
||||||
t *testing.T, db *gorm.DB, deliveryID string,
|
|
||||||
) string {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
var result database.DeliveryResult
|
|
||||||
|
|
||||||
require.NoError(t, db.Where(
|
|
||||||
"delivery_id = ?", deliveryID,
|
|
||||||
).First(&result).Error)
|
|
||||||
|
|
||||||
return result.Error
|
|
||||||
}
|
|
||||||
|
|
||||||
// deliverSlackTo runs a Slack delivery against webhookURL and
|
|
||||||
// returns the error string it persisted.
|
|
||||||
func deliverSlackTo(
|
|
||||||
t *testing.T, webhookURL string,
|
|
||||||
) string {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
db := testWebhookDB(t)
|
|
||||||
e := testEngine(t, 1)
|
|
||||||
targetID := uuid.New().String()
|
|
||||||
|
|
||||||
slackCfg, err := json.Marshal(
|
|
||||||
delivery.SlackTargetConfig{
|
|
||||||
WebhookURL: webhookURL,
|
|
||||||
},
|
|
||||||
)
|
|
||||||
require.NoError(t, err)
|
|
||||||
|
|
||||||
event := seedEvent(t, db, `{"test":true}`)
|
|
||||||
|
|
||||||
dlv := seedDelivery(
|
|
||||||
t, db, event.ID, targetID,
|
|
||||||
database.DeliveryStatusPending,
|
|
||||||
)
|
|
||||||
|
|
||||||
d := buildSlackDelivery(
|
|
||||||
dlv, event, targetID,
|
|
||||||
"test-slack-mask", string(slackCfg),
|
|
||||||
)
|
|
||||||
|
|
||||||
e.ExportDeliverSlack(context.TODO(), db, d)
|
|
||||||
|
|
||||||
assertDeliveryStatus(t, db, dlv.ID,
|
|
||||||
database.DeliveryStatusFailed,
|
|
||||||
)
|
|
||||||
|
|
||||||
return storedDeliveryError(t, db, dlv.ID)
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestDeliverSlack_TransportErrorMasksWebhookURL is the
|
|
||||||
// load-bearing regression test: a transport failure must not
|
|
||||||
// persist the webhook URL's credential into the database, and
|
|
||||||
// must still say what went wrong and where.
|
|
||||||
func TestDeliverSlack_TransportErrorMasksWebhookURL(
|
|
||||||
t *testing.T,
|
|
||||||
) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
// A server closed before use gives a deterministic
|
|
||||||
// transport failure against a known host.
|
|
||||||
ts := httptest.NewServer(http.NewServeMux())
|
|
||||||
host := ts.URL
|
|
||||||
|
|
||||||
ts.Close()
|
|
||||||
|
|
||||||
errMsg := deliverSlackTo(t, host+maskSecretPath)
|
|
||||||
|
|
||||||
require.NotEmpty(t, errMsg)
|
|
||||||
assertNoCredential(t, errMsg)
|
|
||||||
|
|
||||||
// The diagnostic value survives: the operation, the host
|
|
||||||
// and the transport failure are all still reported, and
|
|
||||||
// only the path is elided.
|
|
||||||
assert.Contains(t, errMsg, "sending request")
|
|
||||||
assert.Contains(t, errMsg, "Post")
|
|
||||||
assert.Contains(t, errMsg, host+"/...")
|
|
||||||
assert.Contains(t, errMsg, "connection refused")
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestDeliverSlack_UnparsableURLMasksWebhookURL covers the
|
|
||||||
// other error path out of a Slack attempt: url.Parse also
|
|
||||||
// embeds the whole URL in the error it returns.
|
|
||||||
func TestDeliverSlack_UnparsableURLMasksWebhookURL(
|
|
||||||
t *testing.T,
|
|
||||||
) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
errMsg := deliverSlackTo(
|
|
||||||
t,
|
|
||||||
"https://hooks.slack.com"+maskSecretPath+"\n",
|
|
||||||
)
|
|
||||||
|
|
||||||
require.NotEmpty(t, errMsg)
|
|
||||||
assertNoCredential(t, errMsg)
|
|
||||||
assert.Contains(t, errMsg, "invalid control character")
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestDoHTTPRequest_TransportErrorMasksURL proves the HTTP
|
|
||||||
// target's transport errors are masked too; its destination
|
|
||||||
// URL can carry a token in a query string.
|
|
||||||
func TestDoHTTPRequest_TransportErrorMasksURL(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
ts := httptest.NewServer(http.NewServeMux())
|
|
||||||
host := ts.URL
|
|
||||||
|
|
||||||
ts.Close()
|
|
||||||
|
|
||||||
e := testEngine(t, 1)
|
|
||||||
|
|
||||||
cfg, err := e.ExportParseHTTPConfig(
|
|
||||||
newHTTPTargetConfig(host + maskSecretPath),
|
|
||||||
)
|
|
||||||
require.NoError(t, err)
|
|
||||||
|
|
||||||
statusCode, _, _, reqErr := e.ExportDoHTTPRequest(
|
|
||||||
context.TODO(), cfg,
|
|
||||||
&database.Event{Body: `{"test":true}`},
|
|
||||||
)
|
|
||||||
require.Error(t, reqErr)
|
|
||||||
assert.Zero(t, statusCode)
|
|
||||||
|
|
||||||
assertNoCredential(t, reqErr.Error())
|
|
||||||
assert.Contains(t, reqErr.Error(), host+"/...")
|
|
||||||
assert.Contains(
|
|
||||||
t, reqErr.Error(), "connection refused",
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestValidateTargetURL_UnparsableURLIsMasked proves the SSRF
|
|
||||||
// validator's error does not carry the submitted URL, which
|
|
||||||
// the handler both logs and shows.
|
|
||||||
func TestValidateTargetURL_UnparsableURLIsMasked(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
err := delivery.ValidateTargetURL(
|
|
||||||
context.TODO(),
|
|
||||||
"https://hooks.slack.com"+maskSecretPath+"\n",
|
|
||||||
)
|
|
||||||
require.Error(t, err)
|
|
||||||
|
|
||||||
assertNoCredential(t, err.Error())
|
|
||||||
assert.Contains(t, err.Error(), "invalid URL")
|
|
||||||
}
|
|
||||||
@@ -29,8 +29,10 @@ func (h *Handlers) HandleLoginPage() http.HandlerFunc {
|
|||||||
// HandleLoginSubmit handles the login form submission (POST)
|
// HandleLoginSubmit handles the login form submission (POST)
|
||||||
func (h *Handlers) HandleLoginSubmit() http.HandlerFunc {
|
func (h *Handlers) HandleLoginSubmit() http.HandlerFunc {
|
||||||
return func(w http.ResponseWriter, r *http.Request) {
|
return func(w http.ResponseWriter, r *http.Request) {
|
||||||
// The body size cap is enforced by the MaxBodySize
|
// Limit request body to prevent memory exhaustion
|
||||||
// middleware, which runs before CSRF parses the form.
|
r.Body = http.MaxBytesReader(w, r.Body, 1<<maxBodyShift)
|
||||||
|
|
||||||
|
// Parse form data
|
||||||
err := r.ParseForm()
|
err := r.ParseForm()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
h.log.Error("failed to parse form", "error", err)
|
h.log.Error("failed to parse form", "error", err)
|
||||||
|
|||||||
@@ -26,6 +26,8 @@ const (
|
|||||||
maxBodyShift = 20
|
maxBodyShift = 20
|
||||||
// recentEventLimit is the number of recent events to show.
|
// recentEventLimit is the number of recent events to show.
|
||||||
recentEventLimit = 20
|
recentEventLimit = 20
|
||||||
|
// defaultRetentionDays is the default event retention period.
|
||||||
|
defaultRetentionDays = 30
|
||||||
// paginationPerPage is the number of items per page.
|
// paginationPerPage is the number of items per page.
|
||||||
paginationPerPage = 25
|
paginationPerPage = 25
|
||||||
|
|
||||||
|
|||||||
@@ -31,8 +31,9 @@ func (h *Handlers) HandlePasswordChange() http.HandlerFunc {
|
|||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
// The body size cap is enforced by the MaxBodySize
|
// Limit request body to prevent memory exhaustion.
|
||||||
// middleware, which runs before CSRF parses the form.
|
r.Body = http.MaxBytesReader(w, r.Body, 1<<maxBodyShift)
|
||||||
|
|
||||||
err := r.ParseForm()
|
err := r.ParseForm()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
h.log.Error("failed to parse form", "error", err)
|
h.log.Error("failed to parse form", "error", err)
|
||||||
|
|||||||
@@ -1,187 +0,0 @@
|
|||||||
package handlers_test
|
|
||||||
|
|
||||||
import (
|
|
||||||
"context"
|
|
||||||
"net/http"
|
|
||||||
"net/http/httptest"
|
|
||||||
"testing"
|
|
||||||
|
|
||||||
"github.com/go-chi/chi"
|
|
||||||
"github.com/stretchr/testify/assert"
|
|
||||||
"github.com/stretchr/testify/require"
|
|
||||||
"gorm.io/gorm/clause"
|
|
||||||
"sneak.berlin/go/webhooker/internal/database"
|
|
||||||
"sneak.berlin/go/webhooker/internal/handlers"
|
|
||||||
"sneak.berlin/go/webhooker/internal/session"
|
|
||||||
)
|
|
||||||
|
|
||||||
// The secret path segments of a Slack incoming webhook URL.
|
|
||||||
// Holding them is enough to post to the channel forever, so
|
|
||||||
// they must never reach the rendered page.
|
|
||||||
const (
|
|
||||||
slackSecretPath = "/services/T00000000/B00000000/" +
|
|
||||||
"XXXXXXXXXXXXXXXXXXXXXXXX"
|
|
||||||
slackWebhookURL = "https://hooks.slack.com" +
|
|
||||||
slackSecretPath
|
|
||||||
)
|
|
||||||
|
|
||||||
// seedConfiguredTarget inserts a target with a stored config
|
|
||||||
// blob and returns it.
|
|
||||||
func seedConfiguredTarget(
|
|
||||||
t *testing.T,
|
|
||||||
db *database.Database,
|
|
||||||
webhookID string,
|
|
||||||
targetType database.TargetType,
|
|
||||||
config string,
|
|
||||||
) *database.Target {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
tgt := &database.Target{
|
|
||||||
WebhookID: webhookID,
|
|
||||||
Name: "t-" + string(targetType),
|
|
||||||
Type: targetType,
|
|
||||||
Active: true,
|
|
||||||
Config: config,
|
|
||||||
}
|
|
||||||
|
|
||||||
require.NoError(
|
|
||||||
t,
|
|
||||||
db.DB().Omit(clause.Associations).Create(tgt).Error,
|
|
||||||
)
|
|
||||||
|
|
||||||
return tgt
|
|
||||||
}
|
|
||||||
|
|
||||||
// renderSourceDetailPage runs the real source detail handler
|
|
||||||
// for a webhook and returns the rendered HTML.
|
|
||||||
func renderSourceDetailPage(
|
|
||||||
t *testing.T,
|
|
||||||
h *handlers.Handlers,
|
|
||||||
sess *session.Session,
|
|
||||||
webhookID string,
|
|
||||||
) string {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
req := httptest.NewRequestWithContext(
|
|
||||||
context.Background(),
|
|
||||||
http.MethodGet,
|
|
||||||
"/source/"+webhookID,
|
|
||||||
nil,
|
|
||||||
)
|
|
||||||
|
|
||||||
for _, c := range authenticatedCookies(
|
|
||||||
t, sess, deleteTestUserID, deleteTestUsername,
|
|
||||||
) {
|
|
||||||
req.AddCookie(c)
|
|
||||||
}
|
|
||||||
|
|
||||||
rctx := chi.NewRouteContext()
|
|
||||||
rctx.URLParams.Add(paramSourceID, webhookID)
|
|
||||||
|
|
||||||
req = req.WithContext(
|
|
||||||
context.WithValue(
|
|
||||||
req.Context(), chi.RouteCtxKey, rctx,
|
|
||||||
),
|
|
||||||
)
|
|
||||||
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
h.HandleSourceDetail().ServeHTTP(w, req)
|
|
||||||
|
|
||||||
require.Equal(t, http.StatusOK, w.Code)
|
|
||||||
|
|
||||||
return w.Body.String()
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestHandleSourceDetail_MasksSlackWebhookURL is the
|
|
||||||
// load-bearing regression test for the credential leak: the
|
|
||||||
// rendered page must show the Slack target without any of the
|
|
||||||
// secret path segments of its webhook URL.
|
|
||||||
func TestHandleSourceDetail_MasksSlackWebhookURL(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
var (
|
|
||||||
h *handlers.Handlers
|
|
||||||
sess *session.Session
|
|
||||||
db *database.Database
|
|
||||||
)
|
|
||||||
|
|
||||||
app := newTestApp(t, &h, &sess, &db)
|
|
||||||
app.RequireStart()
|
|
||||||
|
|
||||||
t.Cleanup(app.RequireStop)
|
|
||||||
|
|
||||||
wh := seedWebhook(t, db)
|
|
||||||
seedConfiguredTarget(
|
|
||||||
t, db, wh.ID,
|
|
||||||
database.TargetTypeSlack,
|
|
||||||
`{"webhookUrl":"`+slackWebhookURL+`"}`,
|
|
||||||
)
|
|
||||||
|
|
||||||
body := renderSourceDetailPage(t, h, sess, wh.ID)
|
|
||||||
|
|
||||||
assert.NotContains(t, body, slackSecretPath)
|
|
||||||
assert.NotContains(t, body, "T00000000")
|
|
||||||
assert.NotContains(t, body, "B00000000")
|
|
||||||
assert.NotContains(
|
|
||||||
t, body, "XXXXXXXXXXXXXXXXXXXXXXXX",
|
|
||||||
)
|
|
||||||
assert.NotContains(t, body, "webhookUrl")
|
|
||||||
|
|
||||||
assert.Contains(t, body, "Webhook URL")
|
|
||||||
assert.Contains(t, body, "https://hooks.slack.com/...")
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestHandleSourceDetail_RendersNamedTargetFields proves the
|
|
||||||
// other target types render labelled fields rather than the
|
|
||||||
// stored blob.
|
|
||||||
func TestHandleSourceDetail_RendersNamedTargetFields(
|
|
||||||
t *testing.T,
|
|
||||||
) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
var (
|
|
||||||
h *handlers.Handlers
|
|
||||||
sess *session.Session
|
|
||||||
db *database.Database
|
|
||||||
)
|
|
||||||
|
|
||||||
app := newTestApp(t, &h, &sess, &db)
|
|
||||||
app.RequireStart()
|
|
||||||
|
|
||||||
t.Cleanup(app.RequireStop)
|
|
||||||
|
|
||||||
wh := seedWebhook(t, db)
|
|
||||||
|
|
||||||
seedConfiguredTarget(
|
|
||||||
t, db, wh.ID,
|
|
||||||
database.TargetTypeHTTP,
|
|
||||||
`{"url":"https://example.com/hook","timeout":30,`+
|
|
||||||
`"headers":{"Authorization":"Bearer sekrit"}}`,
|
|
||||||
)
|
|
||||||
seedConfiguredTarget(
|
|
||||||
t, db, wh.ID,
|
|
||||||
database.TargetTypeDatabase,
|
|
||||||
`{"expiry":"720h"}`,
|
|
||||||
)
|
|
||||||
seedConfiguredTarget(
|
|
||||||
t, db, wh.ID,
|
|
||||||
database.TargetType("carrier-pigeon"),
|
|
||||||
`{"beak":"sharp"}`,
|
|
||||||
)
|
|
||||||
|
|
||||||
body := renderSourceDetailPage(t, h, sess, wh.ID)
|
|
||||||
|
|
||||||
assert.Contains(t, body, "Destination URL")
|
|
||||||
assert.Contains(t, body, "https://example.com/hook")
|
|
||||||
assert.Contains(t, body, "Timeout")
|
|
||||||
assert.Contains(t, body, "1 configured")
|
|
||||||
assert.NotContains(t, body, "sekrit")
|
|
||||||
|
|
||||||
assert.Contains(t, body, "Archive Expiry")
|
|
||||||
assert.Contains(t, body, "720h")
|
|
||||||
|
|
||||||
// An unknown type gets the neutral placeholder, never the
|
|
||||||
// stored blob.
|
|
||||||
assert.Contains(t, body, "(unavailable)")
|
|
||||||
assert.NotContains(t, body, "beak")
|
|
||||||
}
|
|
||||||
@@ -1,134 +0,0 @@
|
|||||||
package handlers_test
|
|
||||||
|
|
||||||
import (
|
|
||||||
"context"
|
|
||||||
"net/http"
|
|
||||||
"net/http/httptest"
|
|
||||||
"testing"
|
|
||||||
|
|
||||||
"github.com/go-chi/chi"
|
|
||||||
"github.com/stretchr/testify/assert"
|
|
||||||
"github.com/stretchr/testify/require"
|
|
||||||
"gorm.io/gorm/clause"
|
|
||||||
"sneak.berlin/go/webhooker/internal/database"
|
|
||||||
"sneak.berlin/go/webhooker/internal/handlers"
|
|
||||||
"sneak.berlin/go/webhooker/internal/session"
|
|
||||||
)
|
|
||||||
|
|
||||||
// seedDeliveredEvent records an event and a delivery for it in
|
|
||||||
// the webhook's own database, so the log page has a delivery
|
|
||||||
// to render against the target.
|
|
||||||
func seedDeliveredEvent(
|
|
||||||
t *testing.T,
|
|
||||||
dbMgr *database.WebhookDBManager,
|
|
||||||
webhookID, targetID string,
|
|
||||||
) {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
webhookDB, err := dbMgr.GetDB(webhookID)
|
|
||||||
require.NoError(t, err)
|
|
||||||
|
|
||||||
event := &database.Event{
|
|
||||||
WebhookID: webhookID,
|
|
||||||
Method: http.MethodPost,
|
|
||||||
Body: `{"test":true}`,
|
|
||||||
ContentType: "application/json",
|
|
||||||
}
|
|
||||||
|
|
||||||
require.NoError(t, webhookDB.Omit(
|
|
||||||
clause.Associations,
|
|
||||||
).Create(event).Error)
|
|
||||||
|
|
||||||
dlv := &database.Delivery{
|
|
||||||
EventID: event.ID,
|
|
||||||
TargetID: targetID,
|
|
||||||
Status: database.DeliveryStatusDelivered,
|
|
||||||
}
|
|
||||||
|
|
||||||
require.NoError(t, webhookDB.Omit(
|
|
||||||
clause.Associations,
|
|
||||||
).Create(dlv).Error)
|
|
||||||
}
|
|
||||||
|
|
||||||
// renderSourceLogsPage runs the real event log handler for a
|
|
||||||
// webhook and returns the rendered HTML.
|
|
||||||
func renderSourceLogsPage(
|
|
||||||
t *testing.T,
|
|
||||||
h *handlers.Handlers,
|
|
||||||
sess *session.Session,
|
|
||||||
webhookID string,
|
|
||||||
) string {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
req := httptest.NewRequestWithContext(
|
|
||||||
context.Background(),
|
|
||||||
http.MethodGet,
|
|
||||||
"/source/"+webhookID+"/logs",
|
|
||||||
nil,
|
|
||||||
)
|
|
||||||
|
|
||||||
for _, c := range authenticatedCookies(
|
|
||||||
t, sess, deleteTestUserID, deleteTestUsername,
|
|
||||||
) {
|
|
||||||
req.AddCookie(c)
|
|
||||||
}
|
|
||||||
|
|
||||||
rctx := chi.NewRouteContext()
|
|
||||||
rctx.URLParams.Add(paramSourceID, webhookID)
|
|
||||||
|
|
||||||
req = req.WithContext(
|
|
||||||
context.WithValue(
|
|
||||||
req.Context(), chi.RouteCtxKey, rctx,
|
|
||||||
),
|
|
||||||
)
|
|
||||||
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
h.HandleSourceLogs().ServeHTTP(w, req)
|
|
||||||
|
|
||||||
require.Equal(t, http.StatusOK, w.Code)
|
|
||||||
|
|
||||||
return w.Body.String()
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestHandleSourceLogs_MasksSlackWebhookURL proves the event
|
|
||||||
// log page is handed a display-safe projection of each target
|
|
||||||
// rather than the stored row, so the credential cannot be
|
|
||||||
// rendered from its template data.
|
|
||||||
func TestHandleSourceLogs_MasksSlackWebhookURL(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
var (
|
|
||||||
h *handlers.Handlers
|
|
||||||
sess *session.Session
|
|
||||||
db *database.Database
|
|
||||||
dbMgr *database.WebhookDBManager
|
|
||||||
)
|
|
||||||
|
|
||||||
app := newTestApp(t, &h, &sess, &db, &dbMgr)
|
|
||||||
app.RequireStart()
|
|
||||||
|
|
||||||
t.Cleanup(app.RequireStop)
|
|
||||||
|
|
||||||
wh := seedWebhook(t, db)
|
|
||||||
tgt := seedConfiguredTarget(
|
|
||||||
t, db, wh.ID,
|
|
||||||
database.TargetTypeSlack,
|
|
||||||
`{"webhookUrl":"`+slackWebhookURL+`"}`,
|
|
||||||
)
|
|
||||||
|
|
||||||
seedDeliveredEvent(t, dbMgr, wh.ID, tgt.ID)
|
|
||||||
|
|
||||||
body := renderSourceLogsPage(t, h, sess, wh.ID)
|
|
||||||
|
|
||||||
assert.NotContains(t, body, slackSecretPath)
|
|
||||||
assert.NotContains(t, body, "T00000000")
|
|
||||||
assert.NotContains(t, body, "B00000000")
|
|
||||||
assert.NotContains(
|
|
||||||
t, body, "XXXXXXXXXXXXXXXXXXXXXXXX",
|
|
||||||
)
|
|
||||||
assert.NotContains(t, body, "webhookUrl")
|
|
||||||
|
|
||||||
// The page still identifies the delivery's target.
|
|
||||||
assert.Contains(t, body, tgt.Name)
|
|
||||||
assert.Contains(t, body, "delivered")
|
|
||||||
}
|
|
||||||
@@ -25,88 +25,11 @@ type WebhookListItem struct {
|
|||||||
// errMissingURL signals that a required URL was not provided.
|
// errMissingURL signals that a required URL was not provided.
|
||||||
var errMissingURL = errors.New("missing URL")
|
var errMissingURL = errors.New("missing URL")
|
||||||
|
|
||||||
// errInvalidRetention signals a retention_days form value that is not
|
|
||||||
// a non-negative whole number.
|
|
||||||
var errInvalidRetention = errors.New("invalid retention days")
|
|
||||||
|
|
||||||
// errRetentionTooLarge signals a retention_days form value that is a
|
|
||||||
// whole number but larger than the reaper's cutoff arithmetic can
|
|
||||||
// represent. It is distinguished from errInvalidRetention so the form
|
|
||||||
// can tell the user the actual ceiling instead of implying their input
|
|
||||||
// was not a number.
|
|
||||||
var errRetentionTooLarge = errors.New("retention days out of range")
|
|
||||||
|
|
||||||
// retentionErrorMessage returns the message the create and edit forms
|
|
||||||
// show the user for a rejected retention_days value. Any error other
|
|
||||||
// than errRetentionTooLarge falls back to the generic wording, so an
|
|
||||||
// unrecognised parse failure still produces a sensible 400 rather than
|
|
||||||
// an empty alert.
|
|
||||||
func retentionErrorMessage(err error) string {
|
|
||||||
if errors.Is(err, errRetentionTooLarge) {
|
|
||||||
return "Retention must be at most " +
|
|
||||||
strconv.Itoa(database.MaxFiniteRetentionDays) +
|
|
||||||
" days, or 0 to retain events forever."
|
|
||||||
}
|
|
||||||
|
|
||||||
return "Retention must be a whole number of days, or 0 to " +
|
|
||||||
"retain events forever."
|
|
||||||
}
|
|
||||||
|
|
||||||
// parseRetentionDays interprets a retention_days form value.
|
|
||||||
//
|
|
||||||
// An empty value yields fallback, which lets the create path apply the
|
|
||||||
// default and the edit path leave the stored value unchanged. A value
|
|
||||||
// of 0 is returned as 0 and is rewritten to the retain-forever
|
|
||||||
// sentinel by database.Webhook's BeforeSave hook. Anything unparseable
|
|
||||||
// or negative is an error rather than a silently substituted default.
|
|
||||||
//
|
|
||||||
// The upper bound is not cosmetic. The reaper computes its cutoff as a
|
|
||||||
// time.Duration, an int64 nanosecond count, so a day count above
|
|
||||||
// database.MaxFiniteRetentionDays overflows, puts the cutoff in the
|
|
||||||
// future, and deletes every event the webhook has. A finite value
|
|
||||||
// above that ceiling is therefore a 400.
|
|
||||||
//
|
|
||||||
// A value at or above the retain-forever sentinel is not out of range:
|
|
||||||
// it is what the edit form pre-fills for a retain-forever webhook, so
|
|
||||||
// submitting the form back unchanged has to keep meaning "forever"
|
|
||||||
// rather than being rejected.
|
|
||||||
func parseRetentionDays(raw string, fallback int) (int, error) {
|
|
||||||
raw = strings.TrimSpace(raw)
|
|
||||||
if raw == "" {
|
|
||||||
return fallback, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
v, err := strconv.Atoi(raw)
|
|
||||||
if err != nil || v < 0 {
|
|
||||||
return 0, errInvalidRetention
|
|
||||||
}
|
|
||||||
|
|
||||||
if v >= database.RetentionForeverDays {
|
|
||||||
return database.RetentionForeverDays, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
if v > database.MaxFiniteRetentionDays {
|
|
||||||
return 0, errRetentionTooLarge
|
|
||||||
}
|
|
||||||
|
|
||||||
return v, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// EventWithDeliveries holds an event and its deliveries.
|
// EventWithDeliveries holds an event and its deliveries.
|
||||||
type EventWithDeliveries struct {
|
type EventWithDeliveries struct {
|
||||||
database.Event
|
database.Event
|
||||||
|
|
||||||
Deliveries []DeliveryView
|
Deliveries []database.Delivery
|
||||||
}
|
|
||||||
|
|
||||||
// DeliveryView is the display-safe projection of a delivery
|
|
||||||
// for the event log page. Its target is a TargetView, so the
|
|
||||||
// stored configuration blob — which holds the target's
|
|
||||||
// credential — has no path to the template.
|
|
||||||
type DeliveryView struct {
|
|
||||||
ID string
|
|
||||||
Status database.DeliveryStatus
|
|
||||||
Target delivery.TargetView
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// HandleSourceList shows a list of user's webhooks.
|
// HandleSourceList shows a list of user's webhooks.
|
||||||
@@ -183,30 +106,11 @@ func (h *Handlers) buildWebhookListItems(
|
|||||||
// HandleSourceCreate shows the form to create a new webhook.
|
// HandleSourceCreate shows the form to create a new webhook.
|
||||||
func (h *Handlers) HandleSourceCreate() http.HandlerFunc {
|
func (h *Handlers) HandleSourceCreate() http.HandlerFunc {
|
||||||
return func(w http.ResponseWriter, r *http.Request) {
|
return func(w http.ResponseWriter, r *http.Request) {
|
||||||
h.renderTemplate(
|
data := map[string]any{
|
||||||
w, r, "sources_new.html",
|
tmplKeyError: "",
|
||||||
newSourceFormData("", "", ""),
|
}
|
||||||
)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// newSourceFormData builds the template data for the webhook creation
|
h.renderTemplate(w, r, "sources_new.html", data)
|
||||||
// form.
|
|
||||||
//
|
|
||||||
// It carries the retention default so the pre-filled value comes from
|
|
||||||
// database.DefaultRetentionDays rather than being a third hardcoded
|
|
||||||
// copy of the same policy, and it carries the submitted name and
|
|
||||||
// description so that re-rendering the form after a validation failure
|
|
||||||
// gives the user their input back instead of a blank form. The edit
|
|
||||||
// form already behaves that way; create now matches it.
|
|
||||||
func newSourceFormData(
|
|
||||||
errMsg, name, description string,
|
|
||||||
) map[string]any {
|
|
||||||
return map[string]any{
|
|
||||||
tmplKeyError: errMsg,
|
|
||||||
"Name": name,
|
|
||||||
"Description": description,
|
|
||||||
"DefaultRetentionDays": database.DefaultRetentionDays,
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -223,8 +127,10 @@ func (h *Handlers) HandleSourceCreateSubmit() http.HandlerFunc {
|
|||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
// The body size cap is enforced by the MaxBodySize
|
r.Body = http.MaxBytesReader(
|
||||||
// middleware, which runs before CSRF parses the form.
|
w, r.Body, 1<<maxBodyShift,
|
||||||
|
)
|
||||||
|
|
||||||
err := r.ParseForm()
|
err := r.ParseForm()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
http.Error(
|
http.Error(
|
||||||
@@ -239,31 +145,23 @@ func (h *Handlers) HandleSourceCreateSubmit() http.HandlerFunc {
|
|||||||
retentionStr := r.FormValue("retention_days")
|
retentionStr := r.FormValue("retention_days")
|
||||||
|
|
||||||
if name == "" {
|
if name == "" {
|
||||||
|
data := map[string]any{
|
||||||
|
tmplKeyError: "Name is required",
|
||||||
|
}
|
||||||
|
|
||||||
w.WriteHeader(http.StatusBadRequest)
|
w.WriteHeader(http.StatusBadRequest)
|
||||||
h.renderTemplate(
|
h.renderTemplate(w, r, "sources_new.html", data)
|
||||||
w, r, "sources_new.html",
|
|
||||||
newSourceFormData(
|
|
||||||
"Name is required", name, description,
|
|
||||||
),
|
|
||||||
)
|
|
||||||
|
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
retentionDays, retErr := parseRetentionDays(
|
retentionDays := defaultRetentionDays
|
||||||
retentionStr, database.DefaultRetentionDays,
|
|
||||||
)
|
|
||||||
if retErr != nil {
|
|
||||||
w.WriteHeader(http.StatusBadRequest)
|
|
||||||
h.renderTemplate(
|
|
||||||
w, r, "sources_new.html",
|
|
||||||
newSourceFormData(
|
|
||||||
retentionErrorMessage(retErr),
|
|
||||||
name, description,
|
|
||||||
),
|
|
||||||
)
|
|
||||||
|
|
||||||
return
|
if retentionStr != "" {
|
||||||
|
v, convErr := strconv.Atoi(retentionStr)
|
||||||
|
if convErr == nil && v > 0 {
|
||||||
|
retentionDays = v
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
h.createWebhookWithEntrypoint(
|
h.createWebhookWithEntrypoint(
|
||||||
@@ -417,17 +315,12 @@ func (h *Handlers) renderSourceDetail(
|
|||||||
scheme = fwdProto
|
scheme = fwdProto
|
||||||
}
|
}
|
||||||
|
|
||||||
// The template calls Webhook methods, which take pointer
|
|
||||||
// receivers; html/template cannot address a value stored in a map.
|
|
||||||
data := map[string]any{
|
data := map[string]any{
|
||||||
tmplKeyWebhook: &webhook,
|
tmplKeyWebhook: webhook,
|
||||||
"Entrypoints": entrypoints,
|
"Entrypoints": entrypoints,
|
||||||
// Targets are projected to a display-safe view: the
|
"Targets": targets,
|
||||||
// stored config blob holds credentials and must never
|
"Events": events,
|
||||||
// reach a template.
|
"BaseURL": scheme + "://" + host,
|
||||||
"Targets": delivery.NewTargetViews(targets),
|
|
||||||
"Events": events,
|
|
||||||
"BaseURL": scheme + "://" + host,
|
|
||||||
}
|
}
|
||||||
|
|
||||||
h.renderTemplate(w, r, "source_detail.html", data)
|
h.renderTemplate(w, r, "source_detail.html", data)
|
||||||
@@ -459,7 +352,7 @@ func (h *Handlers) HandleSourceEdit() http.HandlerFunc {
|
|||||||
}
|
}
|
||||||
|
|
||||||
data := map[string]any{
|
data := map[string]any{
|
||||||
tmplKeyWebhook: &webhook,
|
tmplKeyWebhook: webhook,
|
||||||
tmplKeyError: "",
|
tmplKeyError: "",
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -493,8 +386,10 @@ func (h *Handlers) HandleSourceEditSubmit() http.HandlerFunc {
|
|||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
// The body size cap is enforced by the MaxBodySize
|
r.Body = http.MaxBytesReader(
|
||||||
// middleware, which runs before CSRF parses the form.
|
w, r.Body, 1<<maxBodyShift,
|
||||||
|
)
|
||||||
|
|
||||||
err = r.ParseForm()
|
err = r.ParseForm()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
http.Error(
|
http.Error(
|
||||||
@@ -514,12 +409,14 @@ func (h *Handlers) applyWebhookEdit(
|
|||||||
r *http.Request,
|
r *http.Request,
|
||||||
webhook *database.Webhook,
|
webhook *database.Webhook,
|
||||||
) {
|
) {
|
||||||
// The body size cap is enforced by the MaxBodySize middleware,
|
r.Body = http.MaxBytesReader(
|
||||||
// which runs before CSRF parses the form.
|
w, r.Body, 1<<maxBodyShift,
|
||||||
|
)
|
||||||
|
|
||||||
name := r.FormValue("name")
|
name := r.FormValue("name")
|
||||||
if name == "" {
|
if name == "" {
|
||||||
data := map[string]any{
|
data := map[string]any{
|
||||||
tmplKeyWebhook: webhook,
|
tmplKeyWebhook: *webhook,
|
||||||
tmplKeyError: "Name is required",
|
tmplKeyError: "Name is required",
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -531,25 +428,7 @@ func (h *Handlers) applyWebhookEdit(
|
|||||||
|
|
||||||
webhook.Name = name
|
webhook.Name = name
|
||||||
webhook.Description = r.FormValue("description")
|
webhook.Description = r.FormValue("description")
|
||||||
|
h.parseRetention(r, webhook)
|
||||||
// An empty field falls back to the stored value, so submitting the
|
|
||||||
// form without touching retention leaves the policy alone.
|
|
||||||
retentionDays, retErr := parseRetentionDays(
|
|
||||||
r.FormValue("retention_days"), webhook.RetentionDays,
|
|
||||||
)
|
|
||||||
if retErr != nil {
|
|
||||||
data := map[string]any{
|
|
||||||
tmplKeyWebhook: webhook,
|
|
||||||
tmplKeyError: retentionErrorMessage(retErr),
|
|
||||||
}
|
|
||||||
|
|
||||||
w.WriteHeader(http.StatusBadRequest)
|
|
||||||
h.renderTemplate(w, r, "source_edit.html", data)
|
|
||||||
|
|
||||||
return
|
|
||||||
}
|
|
||||||
|
|
||||||
webhook.RetentionDays = retentionDays
|
|
||||||
|
|
||||||
err := h.db.DB().Save(webhook).Error
|
err := h.db.DB().Save(webhook).Error
|
||||||
if err != nil {
|
if err != nil {
|
||||||
@@ -563,6 +442,23 @@ func (h *Handlers) applyWebhookEdit(
|
|||||||
)
|
)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// parseRetention parses and applies retention_days from the
|
||||||
|
// form.
|
||||||
|
func (h *Handlers) parseRetention(
|
||||||
|
r *http.Request,
|
||||||
|
webhook *database.Webhook,
|
||||||
|
) {
|
||||||
|
retStr := r.FormValue("retention_days")
|
||||||
|
if retStr == "" {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
v, err := strconv.Atoi(retStr)
|
||||||
|
if err == nil && v > 0 {
|
||||||
|
webhook.RetentionDays = v
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
// HandleSourceDelete handles webhook deletion.
|
// HandleSourceDelete handles webhook deletion.
|
||||||
func (h *Handlers) HandleSourceDelete() http.HandlerFunc {
|
func (h *Handlers) HandleSourceDelete() http.HandlerFunc {
|
||||||
return func(w http.ResponseWriter, r *http.Request) {
|
return func(w http.ResponseWriter, r *http.Request) {
|
||||||
@@ -759,7 +655,7 @@ func (h *Handlers) HandleSourceLogs() http.HandlerFunc {
|
|||||||
}
|
}
|
||||||
|
|
||||||
data := map[string]any{
|
data := map[string]any{
|
||||||
tmplKeyWebhook: &webhook,
|
tmplKeyWebhook: webhook,
|
||||||
"Events": evts,
|
"Events": evts,
|
||||||
"Page": page,
|
"Page": page,
|
||||||
"TotalPages": totalPages,
|
"TotalPages": totalPages,
|
||||||
@@ -774,27 +670,22 @@ func (h *Handlers) HandleSourceLogs() http.HandlerFunc {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// loadTargetMap loads targets into a map of display-safe
|
// loadTargetMap loads targets into a map keyed by target ID.
|
||||||
// views keyed by target ID. The projection happens here so
|
|
||||||
// that no caller can hand a raw target, configuration blob
|
|
||||||
// and all, to a template.
|
|
||||||
func (h *Handlers) loadTargetMap(
|
func (h *Handlers) loadTargetMap(
|
||||||
webhookID string,
|
webhookID string,
|
||||||
) map[string]delivery.TargetView {
|
) map[string]database.Target {
|
||||||
var targets []database.Target
|
var targets []database.Target
|
||||||
|
|
||||||
h.db.DB().Where(
|
h.db.DB().Where(
|
||||||
"webhook_id = ?", webhookID,
|
"webhook_id = ?", webhookID,
|
||||||
).Find(&targets)
|
).Find(&targets)
|
||||||
|
|
||||||
views := delivery.NewTargetViews(targets)
|
|
||||||
|
|
||||||
targetMap := make(
|
targetMap := make(
|
||||||
map[string]delivery.TargetView, len(views),
|
map[string]database.Target, len(targets),
|
||||||
)
|
)
|
||||||
|
|
||||||
for _, v := range views {
|
for _, t := range targets {
|
||||||
targetMap[v.ID] = v
|
targetMap[t.ID] = t
|
||||||
}
|
}
|
||||||
|
|
||||||
return targetMap
|
return targetMap
|
||||||
@@ -819,7 +710,7 @@ func (h *Handlers) parsePage(r *http.Request) int {
|
|||||||
func (h *Handlers) loadEventsWithDeliveries(
|
func (h *Handlers) loadEventsWithDeliveries(
|
||||||
w http.ResponseWriter,
|
w http.ResponseWriter,
|
||||||
webhook database.Webhook,
|
webhook database.Webhook,
|
||||||
targetMap map[string]delivery.TargetView,
|
targetMap map[string]database.Target,
|
||||||
page int,
|
page int,
|
||||||
) ([]EventWithDeliveries, int64) {
|
) ([]EventWithDeliveries, int64) {
|
||||||
var totalEvents int64
|
var totalEvents int64
|
||||||
@@ -858,37 +749,20 @@ func (h *Handlers) loadEventsWithDeliveries(
|
|||||||
for i := range events {
|
for i := range events {
|
||||||
result[i].Event = events[i]
|
result[i].Event = events[i]
|
||||||
|
|
||||||
var deliveries []database.Delivery
|
|
||||||
|
|
||||||
webhookDB.Where(
|
webhookDB.Where(
|
||||||
"event_id = ?", events[i].ID,
|
"event_id = ?", events[i].ID,
|
||||||
).Find(&deliveries)
|
).Find(&result[i].Deliveries)
|
||||||
|
|
||||||
result[i].Deliveries = newDeliveryViews(
|
for j := range result[i].Deliveries {
|
||||||
deliveries, targetMap,
|
tid := result[i].Deliveries[j].TargetID
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
return result, totalEvents
|
if target, ok := targetMap[tid]; ok {
|
||||||
}
|
result[i].Deliveries[j].Target = target
|
||||||
|
}
|
||||||
// newDeliveryViews projects deliveries for rendering,
|
|
||||||
// resolving each one's target to its display-safe view.
|
|
||||||
func newDeliveryViews(
|
|
||||||
deliveries []database.Delivery,
|
|
||||||
targetMap map[string]delivery.TargetView,
|
|
||||||
) []DeliveryView {
|
|
||||||
views := make([]DeliveryView, len(deliveries))
|
|
||||||
|
|
||||||
for i := range deliveries {
|
|
||||||
views[i] = DeliveryView{
|
|
||||||
ID: deliveries[i].ID,
|
|
||||||
Status: deliveries[i].Status,
|
|
||||||
Target: targetMap[deliveries[i].TargetID],
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
return views
|
return result, totalEvents
|
||||||
}
|
}
|
||||||
|
|
||||||
// HandleEntrypointCreate handles adding a new entrypoint.
|
// HandleEntrypointCreate handles adding a new entrypoint.
|
||||||
@@ -916,8 +790,10 @@ func (h *Handlers) HandleEntrypointCreate() http.HandlerFunc {
|
|||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
// The body size cap is enforced by the MaxBodySize
|
r.Body = http.MaxBytesReader(
|
||||||
// middleware, which runs before CSRF parses the form.
|
w, r.Body, 1<<maxBodyShift,
|
||||||
|
)
|
||||||
|
|
||||||
err = r.ParseForm()
|
err = r.ParseForm()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
http.Error(
|
http.Error(
|
||||||
@@ -974,8 +850,10 @@ func (h *Handlers) HandleTargetCreate() http.HandlerFunc {
|
|||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
// The body size cap is enforced by the MaxBodySize
|
r.Body = http.MaxBytesReader(
|
||||||
// middleware, which runs before CSRF parses the form.
|
w, r.Body, 1<<maxBodyShift,
|
||||||
|
)
|
||||||
|
|
||||||
err = r.ParseForm()
|
err = r.ParseForm()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
http.Error(
|
http.Error(
|
||||||
@@ -995,8 +873,10 @@ func (h *Handlers) processTargetCreate(
|
|||||||
r *http.Request,
|
r *http.Request,
|
||||||
webhook database.Webhook,
|
webhook database.Webhook,
|
||||||
) {
|
) {
|
||||||
// The body size cap is enforced by the MaxBodySize middleware,
|
r.Body = http.MaxBytesReader(
|
||||||
// which runs before CSRF parses the form.
|
w, r.Body, 1<<maxBodyShift,
|
||||||
|
)
|
||||||
|
|
||||||
name := r.FormValue("name")
|
name := r.FormValue("name")
|
||||||
targetType := database.TargetType(r.FormValue("type"))
|
targetType := database.TargetType(r.FormValue("type"))
|
||||||
targetURL := r.FormValue("url")
|
targetURL := r.FormValue("url")
|
||||||
@@ -1134,12 +1014,9 @@ func (h *Handlers) buildURLTargetConfig(
|
|||||||
r.Context(), targetURL,
|
r.Context(), targetURL,
|
||||||
)
|
)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
// The submitted URL can be a credential (a Slack
|
|
||||||
// incoming webhook URL is a bearer token), so the log
|
|
||||||
// records only its scheme and host.
|
|
||||||
h.log.Warn(
|
h.log.Warn(
|
||||||
"target URL blocked by SSRF protection",
|
"target URL blocked by SSRF protection",
|
||||||
"url", delivery.MaskURL(targetURL),
|
"url", targetURL,
|
||||||
"error", err,
|
"error", err,
|
||||||
)
|
)
|
||||||
http.Error(
|
http.Error(
|
||||||
|
|||||||
@@ -1,589 +0,0 @@
|
|||||||
package handlers_test
|
|
||||||
|
|
||||||
import (
|
|
||||||
"context"
|
|
||||||
"net/http"
|
|
||||||
"net/http/httptest"
|
|
||||||
"net/url"
|
|
||||||
"strconv"
|
|
||||||
"strings"
|
|
||||||
"testing"
|
|
||||||
|
|
||||||
"github.com/go-chi/chi"
|
|
||||||
"github.com/stretchr/testify/assert"
|
|
||||||
"github.com/stretchr/testify/require"
|
|
||||||
"gorm.io/gorm/clause"
|
|
||||||
"sneak.berlin/go/webhooker/internal/database"
|
|
||||||
"sneak.berlin/go/webhooker/internal/handlers"
|
|
||||||
"sneak.berlin/go/webhooker/internal/session"
|
|
||||||
)
|
|
||||||
|
|
||||||
const (
|
|
||||||
// sourceTestUserID is the session user id used by the webhook
|
|
||||||
// management tests.
|
|
||||||
sourceTestUserID = "source-test-user"
|
|
||||||
// sourceIDParam is the chi URL parameter naming a webhook.
|
|
||||||
sourceIDParam = "sourceID"
|
|
||||||
)
|
|
||||||
|
|
||||||
// formRequest builds an urlencoded POST to path carrying the given
|
|
||||||
// cookies, plus any chi URL parameters the handler reads.
|
|
||||||
func formRequest(
|
|
||||||
path string,
|
|
||||||
cookies []*http.Cookie,
|
|
||||||
form url.Values,
|
|
||||||
urlParams map[string]string,
|
|
||||||
) *http.Request {
|
|
||||||
req := httptest.NewRequestWithContext(
|
|
||||||
context.Background(),
|
|
||||||
http.MethodPost,
|
|
||||||
path,
|
|
||||||
strings.NewReader(form.Encode()),
|
|
||||||
)
|
|
||||||
req.Header.Set(
|
|
||||||
"Content-Type", "application/x-www-form-urlencoded",
|
|
||||||
)
|
|
||||||
|
|
||||||
for _, c := range cookies {
|
|
||||||
req.AddCookie(c)
|
|
||||||
}
|
|
||||||
|
|
||||||
rctx := chi.NewRouteContext()
|
|
||||||
for k, v := range urlParams {
|
|
||||||
rctx.URLParams.Add(k, v)
|
|
||||||
}
|
|
||||||
|
|
||||||
return req.WithContext(
|
|
||||||
context.WithValue(req.Context(), chi.RouteCtxKey, rctx),
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
// getRequest builds a GET to path carrying the given cookies, plus any
|
|
||||||
// chi URL parameters the handler reads.
|
|
||||||
func getRequest(
|
|
||||||
t *testing.T,
|
|
||||||
path string,
|
|
||||||
cookies []*http.Cookie,
|
|
||||||
urlParams map[string]string,
|
|
||||||
) *http.Request {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
req := httptest.NewRequestWithContext(
|
|
||||||
context.Background(), http.MethodGet, path, nil,
|
|
||||||
)
|
|
||||||
|
|
||||||
for _, c := range cookies {
|
|
||||||
req.AddCookie(c)
|
|
||||||
}
|
|
||||||
|
|
||||||
rctx := chi.NewRouteContext()
|
|
||||||
for k, v := range urlParams {
|
|
||||||
rctx.URLParams.Add(k, v)
|
|
||||||
}
|
|
||||||
|
|
||||||
return req.WithContext(
|
|
||||||
context.WithValue(req.Context(), chi.RouteCtxKey, rctx),
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
// submitCreate posts the webhook creation form with the given
|
|
||||||
// retention_days value (omitted entirely when retention is nil) and
|
|
||||||
// returns the recorder.
|
|
||||||
func submitCreate(
|
|
||||||
t *testing.T,
|
|
||||||
h *handlers.Handlers,
|
|
||||||
cookies []*http.Cookie,
|
|
||||||
name string,
|
|
||||||
retention *string,
|
|
||||||
) *httptest.ResponseRecorder {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
form := url.Values{}
|
|
||||||
form.Set("name", name)
|
|
||||||
|
|
||||||
if retention != nil {
|
|
||||||
form.Set("retention_days", *retention)
|
|
||||||
}
|
|
||||||
|
|
||||||
req := formRequest("/sources/new", cookies, form, nil)
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
|
|
||||||
h.HandleSourceCreateSubmit().ServeHTTP(w, req)
|
|
||||||
|
|
||||||
return w
|
|
||||||
}
|
|
||||||
|
|
||||||
// onlyWebhook loads the single webhook belonging to the test user.
|
|
||||||
func onlyWebhook(
|
|
||||||
t *testing.T,
|
|
||||||
db *database.Database,
|
|
||||||
) database.Webhook {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
var webhooks []database.Webhook
|
|
||||||
|
|
||||||
require.NoError(
|
|
||||||
t,
|
|
||||||
db.DB().Where("user_id = ?", sourceTestUserID).
|
|
||||||
Find(&webhooks).Error,
|
|
||||||
)
|
|
||||||
require.Len(t, webhooks, 1)
|
|
||||||
|
|
||||||
return webhooks[0]
|
|
||||||
}
|
|
||||||
|
|
||||||
// seedWebhookWithRetention inserts a webhook owned by the test user
|
|
||||||
// with an exact stored retention value, bypassing Webhook.BeforeSave
|
|
||||||
// via a column-level update so that legacy rows can be planted too.
|
|
||||||
func seedWebhookWithRetention(
|
|
||||||
t *testing.T,
|
|
||||||
db *database.Database,
|
|
||||||
retentionDays int,
|
|
||||||
) database.Webhook {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
wh := &database.Webhook{
|
|
||||||
UserID: sourceTestUserID,
|
|
||||||
Name: "seeded",
|
|
||||||
RetentionDays: retentionDays,
|
|
||||||
}
|
|
||||||
require.NoError(
|
|
||||||
t,
|
|
||||||
db.DB().Omit(clause.Associations).Create(wh).Error,
|
|
||||||
)
|
|
||||||
require.NoError(
|
|
||||||
t,
|
|
||||||
db.DB().Model(wh).
|
|
||||||
Update("retention_days", retentionDays).Error,
|
|
||||||
)
|
|
||||||
|
|
||||||
wh.RetentionDays = retentionDays
|
|
||||||
|
|
||||||
return *wh
|
|
||||||
}
|
|
||||||
|
|
||||||
// storedRetentionDays reads the retention_days column for a webhook.
|
|
||||||
func storedRetentionDays(
|
|
||||||
t *testing.T,
|
|
||||||
db *database.Database,
|
|
||||||
id string,
|
|
||||||
) int {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
var got int
|
|
||||||
|
|
||||||
require.NoError(
|
|
||||||
t,
|
|
||||||
db.DB().Model(&database.Webhook{}).
|
|
||||||
Where("id = ?", id).
|
|
||||||
Pluck("retention_days", &got).Error,
|
|
||||||
)
|
|
||||||
|
|
||||||
return got
|
|
||||||
}
|
|
||||||
|
|
||||||
// sourceTestEnv bundles the handler, session, and database a webhook
|
|
||||||
// management test drives.
|
|
||||||
type sourceTestEnv struct {
|
|
||||||
handlers *handlers.Handlers
|
|
||||||
db *database.Database
|
|
||||||
cookies []*http.Cookie
|
|
||||||
}
|
|
||||||
|
|
||||||
func setupSourceTest(t *testing.T) *sourceTestEnv {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
var h *handlers.Handlers
|
|
||||||
|
|
||||||
var sess *session.Session
|
|
||||||
|
|
||||||
var db *database.Database
|
|
||||||
|
|
||||||
app := newTestApp(t, &h, &sess, &db)
|
|
||||||
app.RequireStart()
|
|
||||||
|
|
||||||
t.Cleanup(app.RequireStop)
|
|
||||||
|
|
||||||
return &sourceTestEnv{
|
|
||||||
handlers: h,
|
|
||||||
db: db,
|
|
||||||
cookies: authenticatedCookies(
|
|
||||||
t, sess, sourceTestUserID, "sourceuser",
|
|
||||||
),
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestHandleSourceCreateSubmit_ZeroRetentionPersistsForever is the core
|
|
||||||
// regression test for the bug: the create form's 0 must reach the
|
|
||||||
// database as the retain-forever sentinel rather than being replaced by
|
|
||||||
// the column's default of 30.
|
|
||||||
func TestHandleSourceCreateSubmit_ZeroRetentionPersistsForever(
|
|
||||||
t *testing.T,
|
|
||||||
) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
env := setupSourceTest(t)
|
|
||||||
zero := "0"
|
|
||||||
|
|
||||||
w := submitCreate(t, env.handlers, env.cookies, "forever", &zero)
|
|
||||||
require.Equal(t, http.StatusSeeOther, w.Code)
|
|
||||||
|
|
||||||
wh := onlyWebhook(t, env.db)
|
|
||||||
assert.Equal(
|
|
||||||
t,
|
|
||||||
database.RetentionForeverDays,
|
|
||||||
storedRetentionDays(t, env.db, wh.ID),
|
|
||||||
)
|
|
||||||
assert.True(t, wh.RetainsForever())
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestHandleSourceCreateSubmit_OmittedRetentionUsesDefault(
|
|
||||||
t *testing.T,
|
|
||||||
) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
env := setupSourceTest(t)
|
|
||||||
|
|
||||||
w := submitCreate(t, env.handlers, env.cookies, "defaulted", nil)
|
|
||||||
require.Equal(t, http.StatusSeeOther, w.Code)
|
|
||||||
|
|
||||||
wh := onlyWebhook(t, env.db)
|
|
||||||
assert.Equal(
|
|
||||||
t,
|
|
||||||
database.DefaultRetentionDays,
|
|
||||||
storedRetentionDays(t, env.db, wh.ID),
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestHandleSourceCreate_PrefillsDefaultFromConstant keeps the create
|
|
||||||
// form's pre-filled retention from becoming a third hardcoded copy of
|
|
||||||
// the 30-day policy.
|
|
||||||
func TestHandleSourceCreate_PrefillsDefaultFromConstant(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
env := setupSourceTest(t)
|
|
||||||
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
env.handlers.HandleSourceCreate().ServeHTTP(
|
|
||||||
w, getRequest(t, "/sources/new", env.cookies, nil),
|
|
||||||
)
|
|
||||||
|
|
||||||
require.Equal(t, http.StatusOK, w.Code)
|
|
||||||
|
|
||||||
body := w.Body.String()
|
|
||||||
|
|
||||||
assert.Contains(
|
|
||||||
t, body,
|
|
||||||
`value="`+strconv.Itoa(database.DefaultRetentionDays)+`"`,
|
|
||||||
)
|
|
||||||
assert.NotContains(
|
|
||||||
t, body, `max="365"`,
|
|
||||||
"a max below the sentinel would block retain-forever",
|
|
||||||
)
|
|
||||||
assert.Contains(t, body, `min="0"`)
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestHandleSourceCreateSubmit_InvalidRetentionIsRejected(
|
|
||||||
t *testing.T,
|
|
||||||
) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
for _, raw := range []string{"abc", "-1", "3.5"} {
|
|
||||||
t.Run(raw, func(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
env := setupSourceTest(t)
|
|
||||||
|
|
||||||
w := submitCreate(
|
|
||||||
t, env.handlers, env.cookies, "bad", &raw,
|
|
||||||
)
|
|
||||||
|
|
||||||
assert.Equal(t, http.StatusBadRequest, w.Code)
|
|
||||||
assert.Contains(
|
|
||||||
t, w.Body.String(), "Retention must be",
|
|
||||||
)
|
|
||||||
|
|
||||||
var count int64
|
|
||||||
|
|
||||||
require.NoError(
|
|
||||||
t,
|
|
||||||
env.db.DB().Model(&database.Webhook{}).
|
|
||||||
Where("user_id = ?", sourceTestUserID).
|
|
||||||
Count(&count).Error,
|
|
||||||
)
|
|
||||||
assert.Zero(
|
|
||||||
t, count,
|
|
||||||
"no webhook may be created from a rejected form",
|
|
||||||
)
|
|
||||||
})
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestHandleSourceCreateSubmit_OverflowingRetentionIsRejected covers
|
|
||||||
// the data-loss path directly: a finite retention above the largest one
|
|
||||||
// the reaper's cutoff arithmetic can represent must never reach the
|
|
||||||
// database, because the sweep would compute a future cutoff and delete
|
|
||||||
// every event the webhook has.
|
|
||||||
func TestHandleSourceCreateSubmit_OverflowingRetentionIsRejected(
|
|
||||||
t *testing.T,
|
|
||||||
) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
tooBig := strconv.Itoa(database.MaxFiniteRetentionDays + 1)
|
|
||||||
|
|
||||||
env := setupSourceTest(t)
|
|
||||||
|
|
||||||
w := submitCreate(t, env.handlers, env.cookies, "huge", &tooBig)
|
|
||||||
|
|
||||||
assert.Equal(t, http.StatusBadRequest, w.Code)
|
|
||||||
assert.Contains(
|
|
||||||
t, w.Body.String(),
|
|
||||||
strconv.Itoa(database.MaxFiniteRetentionDays),
|
|
||||||
"the form tells the user the actual ceiling",
|
|
||||||
)
|
|
||||||
|
|
||||||
var count int64
|
|
||||||
|
|
||||||
require.NoError(
|
|
||||||
t,
|
|
||||||
env.db.DB().Model(&database.Webhook{}).
|
|
||||||
Where("user_id = ?", sourceTestUserID).
|
|
||||||
Count(&count).Error,
|
|
||||||
)
|
|
||||||
assert.Zero(
|
|
||||||
t, count,
|
|
||||||
"no webhook may be created from a rejected form",
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestHandleSourceCreateSubmit_SentinelIsAcceptedAsForever guards the
|
|
||||||
// boundary between "too large to represent" and "retain forever": the
|
|
||||||
// sentinel is above MaxFiniteRetentionDays, but it is the value the
|
|
||||||
// edit form pre-fills, so it must be accepted rather than rejected as
|
|
||||||
// out of range.
|
|
||||||
func TestHandleSourceCreateSubmit_SentinelIsAcceptedAsForever(
|
|
||||||
t *testing.T,
|
|
||||||
) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
env := setupSourceTest(t)
|
|
||||||
sentinel := strconv.Itoa(database.RetentionForeverDays)
|
|
||||||
|
|
||||||
w := submitCreate(t, env.handlers, env.cookies, "forever", &sentinel)
|
|
||||||
require.Equal(t, http.StatusSeeOther, w.Code)
|
|
||||||
|
|
||||||
wh := onlyWebhook(t, env.db)
|
|
||||||
assert.Equal(
|
|
||||||
t,
|
|
||||||
database.RetentionForeverDays,
|
|
||||||
storedRetentionDays(t, env.db, wh.ID),
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestHandleSourceCreateSubmit_RejectedFormKeepsUserInput checks that a
|
|
||||||
// validation failure hands the user's typing back, matching what the
|
|
||||||
// edit form already does. Losing a long description to a mistyped
|
|
||||||
// retention value is the kind of thing that makes people give up on a
|
|
||||||
// form.
|
|
||||||
func TestHandleSourceCreateSubmit_RejectedFormKeepsUserInput(
|
|
||||||
t *testing.T,
|
|
||||||
) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
env := setupSourceTest(t)
|
|
||||||
|
|
||||||
const (
|
|
||||||
name = "kept-name"
|
|
||||||
description = "a description worth not losing"
|
|
||||||
)
|
|
||||||
|
|
||||||
form := url.Values{}
|
|
||||||
form.Set("name", name)
|
|
||||||
form.Set("description", description)
|
|
||||||
form.Set("retention_days", "nonsense")
|
|
||||||
|
|
||||||
req := formRequest("/sources/new", env.cookies, form, nil)
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
|
|
||||||
env.handlers.HandleSourceCreateSubmit().ServeHTTP(w, req)
|
|
||||||
|
|
||||||
require.Equal(t, http.StatusBadRequest, w.Code)
|
|
||||||
|
|
||||||
body := w.Body.String()
|
|
||||||
|
|
||||||
assert.Contains(t, body, `value="`+name+`"`)
|
|
||||||
assert.Contains(t, body, description)
|
|
||||||
}
|
|
||||||
|
|
||||||
// submitEdit posts the webhook edit form for the given webhook.
|
|
||||||
func submitEdit(
|
|
||||||
t *testing.T,
|
|
||||||
env *sourceTestEnv,
|
|
||||||
wh database.Webhook,
|
|
||||||
retention string,
|
|
||||||
) *httptest.ResponseRecorder {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
form := url.Values{}
|
|
||||||
form.Set("name", wh.Name)
|
|
||||||
form.Set("description", wh.Description)
|
|
||||||
form.Set("retention_days", retention)
|
|
||||||
|
|
||||||
req := formRequest(
|
|
||||||
"/source/"+wh.ID+"/edit",
|
|
||||||
env.cookies,
|
|
||||||
form,
|
|
||||||
map[string]string{sourceIDParam: wh.ID},
|
|
||||||
)
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
|
|
||||||
env.handlers.HandleSourceEditSubmit().ServeHTTP(w, req)
|
|
||||||
|
|
||||||
return w
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestHandleSourceEditSubmit_ZeroRetentionPersistsForever(
|
|
||||||
t *testing.T,
|
|
||||||
) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
env := setupSourceTest(t)
|
|
||||||
wh := seedWebhookWithRetention(
|
|
||||||
t, env.db, database.DefaultRetentionDays,
|
|
||||||
)
|
|
||||||
|
|
||||||
w := submitEdit(t, env, wh, "0")
|
|
||||||
require.Equal(t, http.StatusSeeOther, w.Code)
|
|
||||||
|
|
||||||
assert.Equal(
|
|
||||||
t,
|
|
||||||
database.RetentionForeverDays,
|
|
||||||
storedRetentionDays(t, env.db, wh.ID),
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestHandleSourceEditSubmit_InvalidRetentionIsRejected(
|
|
||||||
t *testing.T,
|
|
||||||
) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
env := setupSourceTest(t)
|
|
||||||
wh := seedWebhookWithRetention(
|
|
||||||
t, env.db, database.DefaultRetentionDays,
|
|
||||||
)
|
|
||||||
|
|
||||||
w := submitEdit(t, env, wh, "not-a-number")
|
|
||||||
|
|
||||||
assert.Equal(t, http.StatusBadRequest, w.Code)
|
|
||||||
assert.Contains(t, w.Body.String(), "Retention must be")
|
|
||||||
assert.Equal(
|
|
||||||
t,
|
|
||||||
database.DefaultRetentionDays,
|
|
||||||
storedRetentionDays(t, env.db, wh.ID),
|
|
||||||
"a rejected form must not change the stored retention",
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestHandleSourceEditSubmit_EmptyRetentionLeavesValueUnchanged(
|
|
||||||
t *testing.T,
|
|
||||||
) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
env := setupSourceTest(t)
|
|
||||||
wh := seedWebhookWithRetention(t, env.db, 7)
|
|
||||||
|
|
||||||
w := submitEdit(t, env, wh, "")
|
|
||||||
require.Equal(t, http.StatusSeeOther, w.Code)
|
|
||||||
|
|
||||||
assert.Equal(t, 7, storedRetentionDays(t, env.db, wh.ID))
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestSourceEditForm_ForeverWebhookRoundTrips walks the exact path that
|
|
||||||
// the removed max="365" cap used to break: render the edit form for a
|
|
||||||
// retain-forever webhook, confirm the pre-filled sentinel is not capped
|
|
||||||
// by browser validation, then submit that pre-filled value straight
|
|
||||||
// back and confirm the retention policy survives untouched.
|
|
||||||
func TestSourceEditForm_ForeverWebhookRoundTrips(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
env := setupSourceTest(t)
|
|
||||||
wh := seedWebhookWithRetention(
|
|
||||||
t, env.db, database.RetentionForeverDays,
|
|
||||||
)
|
|
||||||
|
|
||||||
req := getRequest(
|
|
||||||
t, "/source/"+wh.ID+"/edit", env.cookies,
|
|
||||||
map[string]string{sourceIDParam: wh.ID},
|
|
||||||
)
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
env.handlers.HandleSourceEdit().ServeHTTP(w, req)
|
|
||||||
|
|
||||||
require.Equal(t, http.StatusOK, w.Code)
|
|
||||||
|
|
||||||
sentinel := strconv.Itoa(database.RetentionForeverDays)
|
|
||||||
body := w.Body.String()
|
|
||||||
|
|
||||||
assert.Contains(
|
|
||||||
t, body, `value="`+sentinel+`"`,
|
|
||||||
"the edit form pre-fills the stored retention",
|
|
||||||
)
|
|
||||||
assert.NotContains(
|
|
||||||
t, body, `max="365"`,
|
|
||||||
"a max below the sentinel would block saving any edit",
|
|
||||||
)
|
|
||||||
// "Currently forever." is the rendered RetentionLabel, not the
|
|
||||||
// static hint below the input, which says "Enter 0 to retain events
|
|
||||||
// forever." A bare Contains of "forever" would pass for any
|
|
||||||
// webhook and would assert nothing about this one.
|
|
||||||
assert.Contains(
|
|
||||||
t, body, "Currently forever.",
|
|
||||||
"the form reports this webhook's policy as forever",
|
|
||||||
)
|
|
||||||
|
|
||||||
// Submit the pre-filled value back, exactly as a browser would.
|
|
||||||
post := submitEdit(t, env, wh, sentinel)
|
|
||||||
require.Equal(t, http.StatusSeeOther, post.Code)
|
|
||||||
|
|
||||||
assert.Equal(
|
|
||||||
t,
|
|
||||||
database.RetentionForeverDays,
|
|
||||||
storedRetentionDays(t, env.db, wh.ID),
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestSourceListAndDetail_ShowForeverNotTheSentinelNumber checks that
|
|
||||||
// the retain-forever value is never rendered to the user as a raw day
|
|
||||||
// count on either read-only view.
|
|
||||||
func TestSourceListAndDetail_ShowForeverNotTheSentinelNumber(
|
|
||||||
t *testing.T,
|
|
||||||
) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
env := setupSourceTest(t)
|
|
||||||
wh := seedWebhookWithRetention(
|
|
||||||
t, env.db, database.RetentionForeverDays,
|
|
||||||
)
|
|
||||||
sentinel := strconv.Itoa(database.RetentionForeverDays)
|
|
||||||
|
|
||||||
listW := httptest.NewRecorder()
|
|
||||||
env.handlers.HandleSourceList().ServeHTTP(
|
|
||||||
listW, getRequest(t, "/sources", env.cookies, nil),
|
|
||||||
)
|
|
||||||
|
|
||||||
require.Equal(t, http.StatusOK, listW.Code)
|
|
||||||
assert.Contains(t, listW.Body.String(), "Retention: forever")
|
|
||||||
assert.NotContains(t, listW.Body.String(), sentinel)
|
|
||||||
|
|
||||||
detailW := httptest.NewRecorder()
|
|
||||||
env.handlers.HandleSourceDetail().ServeHTTP(
|
|
||||||
detailW,
|
|
||||||
getRequest(
|
|
||||||
t, "/source/"+wh.ID, env.cookies,
|
|
||||||
map[string]string{sourceIDParam: wh.ID},
|
|
||||||
),
|
|
||||||
)
|
|
||||||
|
|
||||||
require.Equal(t, http.StatusOK, detailW.Code)
|
|
||||||
assert.Contains(t, detailW.Body.String(), "Retention: forever")
|
|
||||||
assert.NotContains(t, detailW.Body.String(), sentinel)
|
|
||||||
}
|
|
||||||
@@ -4,29 +4,14 @@ import (
|
|||||||
"context"
|
"context"
|
||||||
"net/http"
|
"net/http"
|
||||||
"net/http/httptest"
|
"net/http/httptest"
|
||||||
"strconv"
|
|
||||||
"testing"
|
"testing"
|
||||||
"time"
|
|
||||||
|
|
||||||
"github.com/stretchr/testify/assert"
|
"github.com/stretchr/testify/assert"
|
||||||
"sneak.berlin/go/webhooker/internal/database"
|
"sneak.berlin/go/webhooker/internal/database"
|
||||||
"sneak.berlin/go/webhooker/internal/delivery"
|
|
||||||
"sneak.berlin/go/webhooker/internal/handlers"
|
"sneak.berlin/go/webhooker/internal/handlers"
|
||||||
"sneak.berlin/go/webhooker/internal/session"
|
"sneak.berlin/go/webhooker/internal/session"
|
||||||
)
|
)
|
||||||
|
|
||||||
// Template data keys the page templates read. The handlers package has
|
|
||||||
// its own unexported constants for these; this is the external test
|
|
||||||
// package, so it needs its own.
|
|
||||||
const (
|
|
||||||
dataKeyWebhook = "Webhook"
|
|
||||||
dataKeyError = "Error"
|
|
||||||
)
|
|
||||||
|
|
||||||
// testWebhookID is the identifier given to the webhook under test on
|
|
||||||
// pages that render one.
|
|
||||||
const testWebhookID = "wh-1"
|
|
||||||
|
|
||||||
// renderPage renders a page template through the real template set as
|
// renderPage renders a page template through the real template set as
|
||||||
// an authenticated user and returns the resulting HTML.
|
// an authenticated user and returns the resulting HTML.
|
||||||
func renderPage(
|
func renderPage(
|
||||||
@@ -68,21 +53,10 @@ func TestNavbarUsesWebhookTerminology(t *testing.T) {
|
|||||||
|
|
||||||
t.Cleanup(app.RequireStop)
|
t.Cleanup(app.RequireStop)
|
||||||
|
|
||||||
// One item, so the list body renders too: it calls
|
|
||||||
// WebhookListItem.RetentionLabel, promoted from the embedded
|
|
||||||
// Webhook and therefore a pointer method. An empty list would
|
|
||||||
// skip that call and hide a template error behind the
|
|
||||||
// navigation assertions below.
|
|
||||||
item := handlers.WebhookListItem{}
|
|
||||||
item.Name = "wh"
|
|
||||||
item.ID = testWebhookID
|
|
||||||
item.RetentionDays = 14
|
|
||||||
|
|
||||||
body := renderPage(t, h, sess, "sources_list.html", map[string]any{
|
body := renderPage(t, h, sess, "sources_list.html", map[string]any{
|
||||||
"Webhooks": []handlers.WebhookListItem{item},
|
"Webhooks": []handlers.WebhookListItem{},
|
||||||
})
|
})
|
||||||
|
|
||||||
assert.Contains(t, body, "Retention: 14 days")
|
|
||||||
assert.Contains(t, body, `class="btn-text">Webhooks</a>`)
|
assert.Contains(t, body, `class="btn-text">Webhooks</a>`)
|
||||||
assert.Contains(
|
assert.Contains(
|
||||||
t, body, `class="btn-text w-full text-left">Webhooks</a>`,
|
t, body, `class="btn-text w-full text-left">Webhooks</a>`,
|
||||||
@@ -116,16 +90,12 @@ func TestEditPageUsesWebhookTerminology(t *testing.T) {
|
|||||||
|
|
||||||
t.Cleanup(app.RequireStop)
|
t.Cleanup(app.RequireStop)
|
||||||
|
|
||||||
// The webhook goes in as a pointer because source_edit.html calls
|
webhook := database.Webhook{Name: "wh", RetentionDays: 14}
|
||||||
// Webhook.RetentionLabel, a pointer method: a map element is not
|
webhook.ID = "wh-1"
|
||||||
// addressable, so a value here renders an error instead of the
|
|
||||||
// page.
|
|
||||||
webhook := &database.Webhook{Name: "wh", RetentionDays: 14}
|
|
||||||
webhook.ID = testWebhookID
|
|
||||||
|
|
||||||
body := renderPage(t, h, sess, "source_edit.html", map[string]any{
|
body := renderPage(t, h, sess, "source_edit.html", map[string]any{
|
||||||
dataKeyWebhook: webhook,
|
"Webhook": webhook,
|
||||||
dataKeyError: "",
|
"Error": "",
|
||||||
})
|
})
|
||||||
|
|
||||||
assert.Contains(t, body, "Edit Webhook")
|
assert.Contains(t, body, "Edit Webhook")
|
||||||
@@ -133,109 +103,6 @@ func TestEditPageUsesWebhookTerminology(t *testing.T) {
|
|||||||
assert.Contains(t, body, `href="/source/wh-1"`)
|
assert.Contains(t, body, `href="/source/wh-1"`)
|
||||||
}
|
}
|
||||||
|
|
||||||
// TestCreateFormRetentionCopyMatchesBehaviour pins the create form's
|
|
||||||
// retention copy to what the code does: the reaper permanently deletes
|
|
||||||
// events past the cutoff, an empty field falls back to
|
|
||||||
// DefaultRetentionDays, and 0 is rewritten to the retain-forever
|
|
||||||
// sentinel by Webhook.BeforeSave.
|
|
||||||
func TestCreateFormRetentionCopyMatchesBehaviour(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
var h *handlers.Handlers
|
|
||||||
|
|
||||||
var sess *session.Session
|
|
||||||
|
|
||||||
app := newTestApp(t, &h, &sess)
|
|
||||||
app.RequireStart()
|
|
||||||
|
|
||||||
t.Cleanup(app.RequireStop)
|
|
||||||
|
|
||||||
body := renderPage(t, h, sess, "sources_new.html", map[string]any{
|
|
||||||
"Name": "",
|
|
||||||
"Description": "",
|
|
||||||
"DefaultRetentionDays": database.DefaultRetentionDays,
|
|
||||||
dataKeyError: "",
|
|
||||||
})
|
|
||||||
|
|
||||||
assert.Contains(
|
|
||||||
t, body,
|
|
||||||
"permanently deletes events older than this",
|
|
||||||
"the form must say retention is enforced by deletion",
|
|
||||||
)
|
|
||||||
assert.Contains(t, body, "Enter 0 to retain events forever")
|
|
||||||
assert.Contains(
|
|
||||||
t, body,
|
|
||||||
"leave blank to use the default of "+
|
|
||||||
strconv.Itoa(database.DefaultRetentionDays)+" days",
|
|
||||||
"blank means the default, not forever",
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestEditFormRetentionCopyMatchesBehaviour pins the edit form's
|
|
||||||
// retention copy, including that it states the stored policy via
|
|
||||||
// RetentionLabel and that an empty field leaves that policy unchanged
|
|
||||||
// rather than meaning forever.
|
|
||||||
func TestEditFormRetentionCopyMatchesBehaviour(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
var h *handlers.Handlers
|
|
||||||
|
|
||||||
var sess *session.Session
|
|
||||||
|
|
||||||
app := newTestApp(t, &h, &sess)
|
|
||||||
app.RequireStart()
|
|
||||||
|
|
||||||
t.Cleanup(app.RequireStop)
|
|
||||||
|
|
||||||
finite := &database.Webhook{Name: "wh", RetentionDays: 14}
|
|
||||||
finite.ID = testWebhookID
|
|
||||||
|
|
||||||
body := renderPage(t, h, sess, "source_edit.html", map[string]any{
|
|
||||||
dataKeyWebhook: finite,
|
|
||||||
dataKeyError: "",
|
|
||||||
})
|
|
||||||
|
|
||||||
assert.Contains(t, body, "Currently 14 days.")
|
|
||||||
assert.Contains(
|
|
||||||
t, body,
|
|
||||||
"permanently deletes events older than this",
|
|
||||||
)
|
|
||||||
assert.Contains(t, body, "Enter 0 to retain events forever")
|
|
||||||
assert.Contains(
|
|
||||||
t, body,
|
|
||||||
"leave blank to keep the current setting",
|
|
||||||
"blank means unchanged, not forever",
|
|
||||||
)
|
|
||||||
|
|
||||||
forever := &database.Webhook{
|
|
||||||
Name: "wh",
|
|
||||||
RetentionDays: database.RetentionForeverDays,
|
|
||||||
}
|
|
||||||
forever.ID = "wh-2"
|
|
||||||
|
|
||||||
foreverBody := renderPage(
|
|
||||||
t, h, sess, "source_edit.html", map[string]any{
|
|
||||||
dataKeyWebhook: forever,
|
|
||||||
dataKeyError: "",
|
|
||||||
},
|
|
||||||
)
|
|
||||||
|
|
||||||
assert.Contains(
|
|
||||||
t, foreverBody, "Currently forever.",
|
|
||||||
"a retain-forever webhook must not read as a day count",
|
|
||||||
)
|
|
||||||
assert.Contains(
|
|
||||||
t, foreverBody,
|
|
||||||
"No events are deleted while retention is set to forever",
|
|
||||||
)
|
|
||||||
assert.NotContains(
|
|
||||||
t, foreverBody,
|
|
||||||
"permanently deletes events older than this",
|
|
||||||
"the reaper skips retain-forever webhooks, so the form "+
|
|
||||||
"must not claim it deletes their events",
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestEntrypointCopyButtonIsProgressiveEnhancement proves the copy
|
// TestEntrypointCopyButtonIsProgressiveEnhancement proves the copy
|
||||||
// affordance degrades: the button ships with the hidden attribute, so a
|
// affordance degrades: the button ships with the hidden attribute, so a
|
||||||
// browser that never runs app.js shows no dead control, and the URL is
|
// browser that never runs app.js shows no dead control, and the URL is
|
||||||
@@ -255,25 +122,12 @@ func TestEntrypointCopyButtonIsProgressiveEnhancement(t *testing.T) {
|
|||||||
entrypoint := database.Entrypoint{Path: "abc123"}
|
entrypoint := database.Entrypoint{Path: "abc123"}
|
||||||
entrypoint.ID = "ep-1"
|
entrypoint.ID = "ep-1"
|
||||||
|
|
||||||
// The webhook goes in as a pointer because source_detail.html
|
|
||||||
// calls Webhook.RetentionLabel, a pointer method: a map element
|
|
||||||
// is not addressable, so a value here aborts execution partway
|
|
||||||
// down the page, after the copy button has already been flushed
|
|
||||||
// to the response.
|
|
||||||
webhook := &database.Webhook{Name: "wh", RetentionDays: 14}
|
|
||||||
webhook.ID = testWebhookID
|
|
||||||
webhook.CreatedAt = time.Date(
|
|
||||||
2026, time.January, 2, 3, 4, 5, 0, time.UTC,
|
|
||||||
)
|
|
||||||
|
|
||||||
body := renderPage(t, h, sess, "source_detail.html", map[string]any{
|
body := renderPage(t, h, sess, "source_detail.html", map[string]any{
|
||||||
dataKeyWebhook: webhook,
|
"Webhook": database.Webhook{Name: "wh"},
|
||||||
"Entrypoints": []database.Entrypoint{entrypoint},
|
"Entrypoints": []database.Entrypoint{entrypoint},
|
||||||
// The handler passes delivery.NewTargetViews(targets), never
|
"Targets": []database.Target{},
|
||||||
// raw targets, so the test data has to have that same shape.
|
"Events": []database.Event{},
|
||||||
"Targets": delivery.NewTargetViews(nil),
|
"BaseURL": "https://hooks.example.com",
|
||||||
"Events": []database.Event{},
|
|
||||||
"BaseURL": "https://hooks.example.com",
|
|
||||||
})
|
})
|
||||||
|
|
||||||
assert.Contains(
|
assert.Contains(
|
||||||
@@ -286,14 +140,4 @@ func TestEntrypointCopyButtonIsProgressiveEnhancement(t *testing.T) {
|
|||||||
`hidden data-copy-target="entrypoint-url-ep-1"`,
|
`hidden data-copy-target="entrypoint-url-ep-1"`,
|
||||||
"the button must start hidden and be revealed by script",
|
"the button must start hidden and be revealed by script",
|
||||||
)
|
)
|
||||||
|
|
||||||
// renderTemplate streams to the ResponseWriter, so an abort
|
|
||||||
// midway still leaves everything above it in the body. This pins
|
|
||||||
// content from the last line of the template, which is below the
|
|
||||||
// assertions above: without it, a page that renders the copy
|
|
||||||
// button and then 500s passes.
|
|
||||||
assert.Contains(
|
|
||||||
t, body, "Retention: 14 days",
|
|
||||||
"the page must render to completion, not abort partway",
|
|
||||||
)
|
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -309,36 +309,10 @@ func (s *Middleware) NoCache() func(http.Handler) http.Handler {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// bodyLimitedMethod reports whether the request method carries a
|
// MaxBodySize returns middleware that limits the request body size
|
||||||
// body that the MaxBodySize middleware should cap.
|
// for POST requests. If the body exceeds the given limit in
|
||||||
func bodyLimitedMethod(method string) bool {
|
// bytes, the server returns 413 Request Entity Too Large. This
|
||||||
return method == http.MethodPost ||
|
// prevents clients from sending arbitrarily large form bodies.
|
||||||
method == http.MethodPut ||
|
|
||||||
method == http.MethodPatch
|
|
||||||
}
|
|
||||||
|
|
||||||
// MaxBodySize returns middleware that limits the size of
|
|
||||||
// POST/PUT/PATCH request bodies to maxBytes. It must be registered
|
|
||||||
// before any middleware that parses the body — notably CSRF, which
|
|
||||||
// calls r.PostFormValue — so that form parsing happens under this
|
|
||||||
// cap rather than net/http's 10 MB default.
|
|
||||||
//
|
|
||||||
// Two enforcement paths exist, because http.MaxBytesReader alone
|
|
||||||
// cannot produce a 413: it reports the overflow as an error from
|
|
||||||
// Read, by which point the body parser downstream has already
|
|
||||||
// converted that error into its own response.
|
|
||||||
//
|
|
||||||
// - Declared oversize: the request announces a Content-Length
|
|
||||||
// greater than maxBytes. The middleware answers 413 Request
|
|
||||||
// Entity Too Large immediately and does not call the next
|
|
||||||
// handler, so neither CSRF nor the endpoint handler runs.
|
|
||||||
// - Undeclared oversize: the request is chunked (Content-Length
|
|
||||||
// of -1) or lies about its Content-Length. There is nothing to
|
|
||||||
// check up front, so http.MaxBytesReader hard-caps the body at
|
|
||||||
// maxBytes and the request fails downstream — the form parse
|
|
||||||
// errors out and CSRF rejects it with 403. The response is less
|
|
||||||
// precise than a 413, but the body is still never buffered
|
|
||||||
// beyond the cap, which is the property that matters.
|
|
||||||
func (s *Middleware) MaxBodySize(
|
func (s *Middleware) MaxBodySize(
|
||||||
maxBytes int64,
|
maxBytes int64,
|
||||||
) func(http.Handler) http.Handler {
|
) func(http.Handler) http.Handler {
|
||||||
@@ -347,31 +321,14 @@ func (s *Middleware) MaxBodySize(
|
|||||||
w http.ResponseWriter,
|
w http.ResponseWriter,
|
||||||
r *http.Request,
|
r *http.Request,
|
||||||
) {
|
) {
|
||||||
if !bodyLimitedMethod(r.Method) {
|
if r.Method == http.MethodPost ||
|
||||||
next.ServeHTTP(w, r)
|
r.Method == http.MethodPut ||
|
||||||
|
r.Method == http.MethodPatch {
|
||||||
return
|
r.Body = http.MaxBytesReader(
|
||||||
}
|
w, r.Body, maxBytes,
|
||||||
|
|
||||||
if r.ContentLength > maxBytes {
|
|
||||||
s.log.Warn(
|
|
||||||
"request body exceeds limit",
|
|
||||||
"method", r.Method,
|
|
||||||
"path", r.URL.Path,
|
|
||||||
"content_length", r.ContentLength,
|
|
||||||
"limit", maxBytes,
|
|
||||||
)
|
)
|
||||||
http.Error(
|
|
||||||
w,
|
|
||||||
"Request Entity Too Large",
|
|
||||||
http.StatusRequestEntityTooLarge,
|
|
||||||
)
|
|
||||||
|
|
||||||
return
|
|
||||||
}
|
}
|
||||||
|
|
||||||
r.Body = http.MaxBytesReader(w, r.Body, maxBytes)
|
|
||||||
|
|
||||||
next.ServeHTTP(w, r)
|
next.ServeHTTP(w, r)
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -3,12 +3,10 @@ package middleware_test
|
|||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
"encoding/base64"
|
"encoding/base64"
|
||||||
"io"
|
|
||||||
"log/slog"
|
"log/slog"
|
||||||
"net/http"
|
"net/http"
|
||||||
"net/http/httptest"
|
"net/http/httptest"
|
||||||
"os"
|
"os"
|
||||||
"strings"
|
|
||||||
"testing"
|
"testing"
|
||||||
"time"
|
"time"
|
||||||
|
|
||||||
@@ -650,153 +648,6 @@ func TestNoCache_SetsHeaders(t *testing.T) {
|
|||||||
)
|
)
|
||||||
}
|
}
|
||||||
|
|
||||||
// --- MaxBodySize Middleware Tests ---
|
|
||||||
|
|
||||||
const testBodyLimit int64 = 64
|
|
||||||
|
|
||||||
// maxBodySizeHandler wraps a sentinel handler in MaxBodySize with
|
|
||||||
// testBodyLimit. The sentinel records whether it ran and how much of
|
|
||||||
// the body it managed to read, so tests can distinguish "never
|
|
||||||
// reached" from "reached but truncated".
|
|
||||||
type maxBodySizeResult struct {
|
|
||||||
called bool
|
|
||||||
read int
|
|
||||||
readErr error
|
|
||||||
response *httptest.ResponseRecorder
|
|
||||||
}
|
|
||||||
|
|
||||||
func runMaxBodySize(
|
|
||||||
t *testing.T,
|
|
||||||
req *http.Request,
|
|
||||||
) *maxBodySizeResult {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
m, _ := testMiddleware(t, config.EnvironmentDev)
|
|
||||||
res := &maxBodySizeResult{response: httptest.NewRecorder()}
|
|
||||||
|
|
||||||
handler := m.MaxBodySize(testBodyLimit)(http.HandlerFunc(
|
|
||||||
func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
res.called = true
|
|
||||||
|
|
||||||
body, err := io.ReadAll(r.Body)
|
|
||||||
res.read = len(body)
|
|
||||||
res.readErr = err
|
|
||||||
|
|
||||||
w.WriteHeader(http.StatusOK)
|
|
||||||
},
|
|
||||||
))
|
|
||||||
|
|
||||||
handler.ServeHTTP(res.response, req)
|
|
||||||
|
|
||||||
return res
|
|
||||||
}
|
|
||||||
|
|
||||||
// postWithBody builds a POST request whose Content-Length is
|
|
||||||
// accurate for the given payload size.
|
|
||||||
func postWithBody(size int) *http.Request {
|
|
||||||
req := httptest.NewRequestWithContext(
|
|
||||||
context.Background(),
|
|
||||||
http.MethodPost, "/pages/login",
|
|
||||||
strings.NewReader(strings.Repeat("a", size)),
|
|
||||||
)
|
|
||||||
req.Header.Set(
|
|
||||||
"Content-Type", "application/x-www-form-urlencoded",
|
|
||||||
)
|
|
||||||
|
|
||||||
return req
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestMaxBodySize_DeclaredOversize_413AndHandlerNotReached(
|
|
||||||
t *testing.T,
|
|
||||||
) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
res := runMaxBodySize(t, postWithBody(int(testBodyLimit)+1))
|
|
||||||
|
|
||||||
assert.False(
|
|
||||||
t, res.called,
|
|
||||||
"handler must not be reached for an oversized body",
|
|
||||||
)
|
|
||||||
assert.Equal(
|
|
||||||
t, http.StatusRequestEntityTooLarge, res.response.Code,
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestMaxBodySize_AtLimit_PassesThrough(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
res := runMaxBodySize(t, postWithBody(int(testBodyLimit)))
|
|
||||||
|
|
||||||
assert.True(
|
|
||||||
t, res.called,
|
|
||||||
"handler should be reached for a body at the limit",
|
|
||||||
)
|
|
||||||
require.NoError(t, res.readErr)
|
|
||||||
assert.Equal(t, int(testBodyLimit), res.read)
|
|
||||||
assert.Equal(t, http.StatusOK, res.response.Code)
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestMaxBodySize_UnderLimit_PassesThrough(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
res := runMaxBodySize(t, postWithBody(1))
|
|
||||||
|
|
||||||
assert.True(t, res.called)
|
|
||||||
require.NoError(t, res.readErr)
|
|
||||||
assert.Equal(t, 1, res.read)
|
|
||||||
assert.Equal(t, http.StatusOK, res.response.Code)
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestMaxBodySize_GetWithOversizeBody_NotCapped(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
req := httptest.NewRequestWithContext(
|
|
||||||
context.Background(),
|
|
||||||
http.MethodGet, "/pages/login",
|
|
||||||
strings.NewReader(
|
|
||||||
strings.Repeat("a", int(testBodyLimit)+1),
|
|
||||||
),
|
|
||||||
)
|
|
||||||
|
|
||||||
res := runMaxBodySize(t, req)
|
|
||||||
|
|
||||||
assert.True(
|
|
||||||
t, res.called,
|
|
||||||
"GET requests are not subject to the POST body cap",
|
|
||||||
)
|
|
||||||
require.NoError(t, res.readErr)
|
|
||||||
assert.Equal(t, int(testBodyLimit)+1, res.read)
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestMaxBodySize_UndeclaredOversize_TruncatedAtCap covers the
|
|
||||||
// chunked / lying-Content-Length case: there is nothing to check up
|
|
||||||
// front, so the request reaches the handler but MaxBytesReader
|
|
||||||
// hard-caps the body and the read fails at the limit.
|
|
||||||
func TestMaxBodySize_UndeclaredOversize_TruncatedAtCap(
|
|
||||||
t *testing.T,
|
|
||||||
) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
req := postWithBody(int(testBodyLimit) + 1)
|
|
||||||
// Simulate a chunked request: no declared length.
|
|
||||||
req.ContentLength = -1
|
|
||||||
|
|
||||||
res := runMaxBodySize(t, req)
|
|
||||||
|
|
||||||
assert.True(
|
|
||||||
t, res.called,
|
|
||||||
"an undeclared oversize body cannot be rejected up front",
|
|
||||||
)
|
|
||||||
require.Error(
|
|
||||||
t, res.readErr,
|
|
||||||
"reading past the cap must fail",
|
|
||||||
)
|
|
||||||
assert.Equal(
|
|
||||||
t, int(testBodyLimit), res.read,
|
|
||||||
"the handler must not see more than the cap",
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
// --- Helper Tests ---
|
// --- Helper Tests ---
|
||||||
|
|
||||||
func TestIpFromHostPort(t *testing.T) {
|
func TestIpFromHostPort(t *testing.T) {
|
||||||
|
|||||||
@@ -2,9 +2,6 @@ package middleware
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"net/http"
|
"net/http"
|
||||||
"net/netip"
|
|
||||||
"slices"
|
|
||||||
"strings"
|
|
||||||
"time"
|
"time"
|
||||||
|
|
||||||
"github.com/go-chi/httprate"
|
"github.com/go-chi/httprate"
|
||||||
@@ -27,127 +24,15 @@ const (
|
|||||||
// passwordChangeRateInterval is the time window for the
|
// passwordChangeRateInterval is the time window for the
|
||||||
// password change rate limit.
|
// password change rate limit.
|
||||||
passwordChangeRateInterval = 1 * time.Minute
|
passwordChangeRateInterval = 1 * time.Minute
|
||||||
|
|
||||||
// receiverRateInterval is the time window for the webhook
|
|
||||||
// receiver rate limit. The configured limit is expressed in
|
|
||||||
// requests per minute.
|
|
||||||
receiverRateInterval = 1 * time.Minute
|
|
||||||
)
|
)
|
||||||
|
|
||||||
// normalizeAddr strips the IPv4-in-IPv6 wrapper and any zone from
|
|
||||||
// addr so that comparisons and bucket keys are canonical.
|
|
||||||
func normalizeAddr(addr netip.Addr) netip.Addr {
|
|
||||||
return addr.Unmap().WithZone("")
|
|
||||||
}
|
|
||||||
|
|
||||||
// isTrustedProxy reports whether addr belongs to a network the
|
|
||||||
// operator listed in TRUSTED_PROXIES. The list is empty by default,
|
|
||||||
// so by default nothing is trusted.
|
|
||||||
func (m *Middleware) isTrustedProxy(addr netip.Addr) bool {
|
|
||||||
for _, prefix := range m.params.Config.TrustedProxies {
|
|
||||||
if prefix.Contains(addr) {
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
|
|
||||||
// forwardedClientAddr returns the client address named by this
|
|
||||||
// request's X-Forwarded-For chain. It is consulted only for requests
|
|
||||||
// whose direct peer is a trusted proxy.
|
|
||||||
//
|
|
||||||
// X-Forwarded-For is the only header read. X-Real-IP and
|
|
||||||
// True-Client-IP are deliberately ignored: the reverse proxies in
|
|
||||||
// common use append to X-Forwarded-For and pass any other header the
|
|
||||||
// client sent through untouched, so believing a single-valued header
|
|
||||||
// would let a client behind the trusted proxy name its own bucket —
|
|
||||||
// the very bypass this gating exists to close.
|
|
||||||
//
|
|
||||||
// The chain is walked right to left, because the rightmost entry is
|
|
||||||
// the one the nearest proxy appended and everything to its left may
|
|
||||||
// have been written by the client. The first hop that is not itself
|
|
||||||
// a trusted proxy is the client. A hop that cannot be read as a bare
|
|
||||||
// address ends the walk: past it the chain is not the shape assumed
|
|
||||||
// here, so the caller falls back to the peer address.
|
|
||||||
func (m *Middleware) forwardedClientAddr(
|
|
||||||
r *http.Request,
|
|
||||||
) (netip.Addr, bool) {
|
|
||||||
hops := strings.Split(
|
|
||||||
strings.Join(r.Header.Values("X-Forwarded-For"), ","), ",",
|
|
||||||
)
|
|
||||||
|
|
||||||
for _, hop := range slices.Backward(hops) {
|
|
||||||
hop = strings.TrimSpace(hop)
|
|
||||||
if hop == "" {
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
|
|
||||||
addr, err := netip.ParseAddr(hop)
|
|
||||||
if err != nil {
|
|
||||||
return netip.Addr{}, false
|
|
||||||
}
|
|
||||||
|
|
||||||
if addr = normalizeAddr(addr); !m.isTrustedProxy(addr) {
|
|
||||||
return addr, true
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
return netip.Addr{}, false
|
|
||||||
}
|
|
||||||
|
|
||||||
// rateLimitKey is the client identity every rate limiter in this
|
|
||||||
// package buckets on. Forwarded headers are honoured only when the
|
|
||||||
// direct peer (RemoteAddr) is inside the configured trusted-proxy
|
|
||||||
// set; otherwise the peer address itself is the key. Without that
|
|
||||||
// gate any client could mint a fresh bucket per request, or starve
|
|
||||||
// another client's bucket, by picking an X-Forwarded-For value —
|
|
||||||
// which makes every limit here decorative against a deliberate
|
|
||||||
// attacker.
|
|
||||||
func (m *Middleware) rateLimitKey(r *http.Request) (string, error) {
|
|
||||||
return m.clientKey(r), nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// clientKey computes the bucket key described on rateLimitKey.
|
|
||||||
func (m *Middleware) clientKey(r *http.Request) string {
|
|
||||||
peer, err := netip.ParseAddr(ipFromHostPort(r.RemoteAddr))
|
|
||||||
if err != nil {
|
|
||||||
// Not an address we can reason about; key on the raw
|
|
||||||
// value rather than collapsing such peers into one
|
|
||||||
// shared bucket.
|
|
||||||
return r.RemoteAddr
|
|
||||||
}
|
|
||||||
|
|
||||||
peer = normalizeAddr(peer)
|
|
||||||
if !m.isTrustedProxy(peer) {
|
|
||||||
return peer.String()
|
|
||||||
}
|
|
||||||
|
|
||||||
if addr, ok := m.forwardedClientAddr(r); ok {
|
|
||||||
return addr.String()
|
|
||||||
}
|
|
||||||
|
|
||||||
return peer.String()
|
|
||||||
}
|
|
||||||
|
|
||||||
// tooManyRequests returns the 429 handler shared by every limiter:
|
|
||||||
// it logs the rejection with logMessage and answers with
|
|
||||||
// responseMessage. httprate adds the Retry-After header (RFC 6585).
|
|
||||||
func (m *Middleware) tooManyRequests(
|
|
||||||
logMessage, responseMessage string,
|
|
||||||
) http.HandlerFunc {
|
|
||||||
return func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
m.log.Warn(logMessage, "path", r.URL.Path)
|
|
||||||
http.Error(w, responseMessage, http.StatusTooManyRequests)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// LoginRateLimit returns middleware that enforces per-IP rate
|
// LoginRateLimit returns middleware that enforces per-IP rate
|
||||||
// limiting on login attempts using go-chi/httprate. Only POST
|
// limiting on login attempts using go-chi/httprate. Only POST
|
||||||
// requests are rate-limited; GET requests (rendering the login
|
// requests are rate-limited; GET requests (rendering the login
|
||||||
// form) pass through unaffected. When the rate limit is exceeded,
|
// form) pass through unaffected. When the rate limit is exceeded,
|
||||||
// a 429 Too Many Requests response is returned. Clients are
|
// a 429 Too Many Requests response is returned. IP extraction
|
||||||
// identified by rateLimitKey.
|
// honours X-Forwarded-For, X-Real-IP, and True-Client-IP headers
|
||||||
|
// for reverse-proxy setups.
|
||||||
func (m *Middleware) LoginRateLimit() func(http.Handler) http.Handler {
|
func (m *Middleware) LoginRateLimit() func(http.Handler) http.Handler {
|
||||||
return m.postRateLimit(
|
return m.postRateLimit(
|
||||||
loginRateLimit,
|
loginRateLimit,
|
||||||
@@ -176,7 +61,9 @@ func (m *Middleware) PasswordChangeRateLimit() func(http.Handler) http.Handler {
|
|||||||
// limit on POST requests only; all other methods pass through
|
// limit on POST requests only; all other methods pass through
|
||||||
// unaffected. Requests over the limit receive a 429 with the
|
// unaffected. Requests over the limit receive a 429 with the
|
||||||
// given response message, and each rejection is logged with the
|
// given response message, and each rejection is logged with the
|
||||||
// given log message. Clients are identified by rateLimitKey.
|
// given log message. IP extraction honours X-Forwarded-For,
|
||||||
|
// X-Real-IP, and True-Client-IP headers for reverse-proxy
|
||||||
|
// setups.
|
||||||
func (m *Middleware) postRateLimit(
|
func (m *Middleware) postRateLimit(
|
||||||
limit int,
|
limit int,
|
||||||
interval time.Duration,
|
interval time.Duration,
|
||||||
@@ -185,10 +72,19 @@ func (m *Middleware) postRateLimit(
|
|||||||
limiter := httprate.Limit(
|
limiter := httprate.Limit(
|
||||||
limit,
|
limit,
|
||||||
interval,
|
interval,
|
||||||
httprate.WithKeyFuncs(m.rateLimitKey),
|
httprate.WithKeyFuncs(httprate.KeyByRealIP),
|
||||||
httprate.WithLimitHandler(
|
httprate.WithLimitHandler(http.HandlerFunc(
|
||||||
m.tooManyRequests(logMessage, responseMessage),
|
func(w http.ResponseWriter, r *http.Request) {
|
||||||
),
|
m.log.Warn(logMessage,
|
||||||
|
"path", r.URL.Path,
|
||||||
|
)
|
||||||
|
http.Error(
|
||||||
|
w,
|
||||||
|
responseMessage,
|
||||||
|
http.StatusTooManyRequests,
|
||||||
|
)
|
||||||
|
},
|
||||||
|
)),
|
||||||
)
|
)
|
||||||
|
|
||||||
return func(next http.Handler) http.Handler {
|
return func(next http.Handler) http.Handler {
|
||||||
@@ -209,25 +105,3 @@ func (m *Middleware) postRateLimit(
|
|||||||
})
|
})
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// ReceiverRateLimit returns middleware that rate-limits the
|
|
||||||
// public webhook receiver endpoint per client IP per request
|
|
||||||
// path (the path contains the entrypoint UUID, so each sender
|
|
||||||
// is limited per entrypoint without affecting other senders or
|
|
||||||
// other entrypoints). The limit is Config.ReceiverRateLimit
|
|
||||||
// requests per minute. Requests over the limit receive a 429.
|
|
||||||
// Clients are identified by rateLimitKey.
|
|
||||||
func (m *Middleware) ReceiverRateLimit() func(http.Handler) http.Handler {
|
|
||||||
return httprate.Limit(
|
|
||||||
m.params.Config.ReceiverRateLimit,
|
|
||||||
receiverRateInterval,
|
|
||||||
httprate.WithKeyFuncs(
|
|
||||||
m.rateLimitKey,
|
|
||||||
httprate.KeyByEndpoint,
|
|
||||||
),
|
|
||||||
httprate.WithLimitHandler(m.tooManyRequests(
|
|
||||||
"webhook receiver rate limit exceeded",
|
|
||||||
"Too many requests. Please slow down.",
|
|
||||||
)),
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|||||||
@@ -2,12 +2,8 @@ package middleware_test
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
"fmt"
|
|
||||||
"log/slog"
|
|
||||||
"net/http"
|
"net/http"
|
||||||
"net/http/httptest"
|
"net/http/httptest"
|
||||||
"net/netip"
|
|
||||||
"os"
|
|
||||||
"testing"
|
"testing"
|
||||||
|
|
||||||
"github.com/stretchr/testify/assert"
|
"github.com/stretchr/testify/assert"
|
||||||
@@ -183,429 +179,3 @@ func TestLoginRateLimit_IndependentPerIP(t *testing.T) {
|
|||||||
"different IP should not be affected",
|
"different IP should not be affected",
|
||||||
)
|
)
|
||||||
}
|
}
|
||||||
|
|
||||||
// okHandler is the terminal handler the limiter middleware wraps
|
|
||||||
// in these tests: it answers 200 to anything that reaches it.
|
|
||||||
func okHandler() http.Handler {
|
|
||||||
return http.HandlerFunc(
|
|
||||||
func(w http.ResponseWriter, _ *http.Request) {
|
|
||||||
w.WriteHeader(http.StatusOK)
|
|
||||||
},
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
// rateLimitMiddleware builds a Middleware around cfg, whose
|
|
||||||
// TrustedProxies field is what the rate limit key function gates
|
|
||||||
// forwarded-header trust on.
|
|
||||||
func rateLimitMiddleware(
|
|
||||||
t *testing.T, cfg *config.Config,
|
|
||||||
) *middleware.Middleware {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
log := slog.New(slog.NewTextHandler(
|
|
||||||
os.Stderr,
|
|
||||||
&slog.HandlerOptions{Level: slog.LevelDebug},
|
|
||||||
))
|
|
||||||
|
|
||||||
return middleware.NewForTest(log, cfg, nil)
|
|
||||||
}
|
|
||||||
|
|
||||||
// trustedProxies parses CIDR strings for a test Config.
|
|
||||||
func trustedProxies(cidrs ...string) []netip.Prefix {
|
|
||||||
prefixes := make([]netip.Prefix, 0, len(cidrs))
|
|
||||||
for _, cidr := range cidrs {
|
|
||||||
prefixes = append(prefixes, netip.MustParsePrefix(cidr))
|
|
||||||
}
|
|
||||||
|
|
||||||
return prefixes
|
|
||||||
}
|
|
||||||
|
|
||||||
// postWithHeaders sends one POST to the handler from peer with the
|
|
||||||
// given headers set and returns the recorder.
|
|
||||||
func postWithHeaders(
|
|
||||||
handler http.Handler,
|
|
||||||
peer, path string,
|
|
||||||
headers map[string]string,
|
|
||||||
) *httptest.ResponseRecorder {
|
|
||||||
req := httptest.NewRequestWithContext(
|
|
||||||
context.Background(), http.MethodPost, path, nil,
|
|
||||||
)
|
|
||||||
req.RemoteAddr = peer
|
|
||||||
|
|
||||||
for name, value := range headers {
|
|
||||||
req.Header.Set(name, value)
|
|
||||||
}
|
|
||||||
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
handler.ServeHTTP(w, req)
|
|
||||||
|
|
||||||
return w
|
|
||||||
}
|
|
||||||
|
|
||||||
// receiverLimitedHandler builds a ReceiverRateLimit-wrapped
|
|
||||||
// handler with the given per-minute limit and no trusted proxies.
|
|
||||||
func receiverLimitedHandler(
|
|
||||||
t *testing.T, limit int,
|
|
||||||
) http.Handler {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
m := rateLimitMiddleware(
|
|
||||||
t, &config.Config{ReceiverRateLimit: limit},
|
|
||||||
)
|
|
||||||
|
|
||||||
return m.ReceiverRateLimit()(okHandler())
|
|
||||||
}
|
|
||||||
|
|
||||||
// receiverPost sends one POST to the handler from the given IP
|
|
||||||
// and path and returns the recorder.
|
|
||||||
func receiverPost(
|
|
||||||
handler http.Handler, ip, path string,
|
|
||||||
) *httptest.ResponseRecorder {
|
|
||||||
req := httptest.NewRequestWithContext(
|
|
||||||
context.Background(),
|
|
||||||
http.MethodPost, path, nil,
|
|
||||||
)
|
|
||||||
req.RemoteAddr = ip
|
|
||||||
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
handler.ServeHTTP(w, req)
|
|
||||||
|
|
||||||
return w
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestReceiverRateLimit_LimitsPerIPAndPath(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
const limit = 3
|
|
||||||
|
|
||||||
handler := receiverLimitedHandler(t, limit)
|
|
||||||
|
|
||||||
// The first limit requests from one IP to one entrypoint
|
|
||||||
// pass.
|
|
||||||
for i := range limit {
|
|
||||||
w := receiverPost(
|
|
||||||
handler, "9.9.9.9:1234", "/webhook/uuid-a",
|
|
||||||
)
|
|
||||||
assert.Equal(
|
|
||||||
t, http.StatusOK, w.Code,
|
|
||||||
"request %d should pass", i,
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
// The next request over the limit is rejected with a 429
|
|
||||||
// carrying a Retry-After header.
|
|
||||||
w := receiverPost(
|
|
||||||
handler, "9.9.9.9:1234", "/webhook/uuid-a",
|
|
||||||
)
|
|
||||||
assert.Equal(t, http.StatusTooManyRequests, w.Code)
|
|
||||||
assert.NotEmpty(
|
|
||||||
t, w.Header().Get("Retry-After"),
|
|
||||||
"429 must carry a Retry-After header",
|
|
||||||
)
|
|
||||||
|
|
||||||
// The same IP is not limited on a different entrypoint.
|
|
||||||
w = receiverPost(
|
|
||||||
handler, "9.9.9.9:1234", "/webhook/uuid-b",
|
|
||||||
)
|
|
||||||
assert.Equal(
|
|
||||||
t, http.StatusOK, w.Code,
|
|
||||||
"a different entrypoint must not be affected",
|
|
||||||
)
|
|
||||||
|
|
||||||
// A different IP is not limited on the same entrypoint.
|
|
||||||
w = receiverPost(
|
|
||||||
handler, "8.8.8.8:1234", "/webhook/uuid-a",
|
|
||||||
)
|
|
||||||
assert.Equal(
|
|
||||||
t, http.StatusOK, w.Code,
|
|
||||||
"a different client IP must not be affected",
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestReceiverRateLimit_CountsEveryMethod proves the receiver
|
|
||||||
// limit counts non-POST requests too: a GET shares the bucket
|
|
||||||
// with a POST and is itself rejected once over the limit.
|
|
||||||
func TestReceiverRateLimit_CountsEveryMethod(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
const (
|
|
||||||
limit = 2
|
|
||||||
ip = "7.7.7.7:1234"
|
|
||||||
path = "/webhook/uuid-c"
|
|
||||||
)
|
|
||||||
|
|
||||||
handler := receiverLimitedHandler(t, limit)
|
|
||||||
|
|
||||||
get := func() *httptest.ResponseRecorder {
|
|
||||||
req := httptest.NewRequestWithContext(
|
|
||||||
context.Background(), http.MethodGet, path, nil,
|
|
||||||
)
|
|
||||||
req.RemoteAddr = ip
|
|
||||||
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
handler.ServeHTTP(w, req)
|
|
||||||
|
|
||||||
return w
|
|
||||||
}
|
|
||||||
|
|
||||||
// One POST plus one GET fill the bucket, so the GET must
|
|
||||||
// have been counted.
|
|
||||||
assert.Equal(
|
|
||||||
t, http.StatusOK, receiverPost(handler, ip, path).Code,
|
|
||||||
)
|
|
||||||
assert.Equal(t, http.StatusOK, get().Code)
|
|
||||||
|
|
||||||
assert.Equal(
|
|
||||||
t, http.StatusTooManyRequests, get().Code,
|
|
||||||
"a GET over the limit must be rate-limited",
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
const (
|
|
||||||
loginPath = "/pages/login"
|
|
||||||
headerXFF = "X-Forwarded-For"
|
|
||||||
headerReal = "X-Real-IP"
|
|
||||||
headerTrue = "True-Client-IP"
|
|
||||||
)
|
|
||||||
|
|
||||||
// assertSharedBucket drives the login limiter from peer with the
|
|
||||||
// trusted-proxy set proxies, sending one more request than the limit
|
|
||||||
// allows and varying the headers on each with headers(i). Every
|
|
||||||
// request must land in the same bucket, so the last one is rejected:
|
|
||||||
// if any of the varying header values reached the key, the run would
|
|
||||||
// have minted fresh buckets and nothing would be rejected.
|
|
||||||
func assertSharedBucket(
|
|
||||||
t *testing.T,
|
|
||||||
proxies []netip.Prefix,
|
|
||||||
peer string,
|
|
||||||
headers func(i int) map[string]string,
|
|
||||||
msg string,
|
|
||||||
) {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
m := rateLimitMiddleware(
|
|
||||||
t, &config.Config{TrustedProxies: proxies},
|
|
||||||
)
|
|
||||||
handler := m.LoginRateLimit()(okHandler())
|
|
||||||
|
|
||||||
for i := range middleware.LoginRateLimitConst {
|
|
||||||
w := postWithHeaders(handler, peer, loginPath, headers(i))
|
|
||||||
assert.Equal(
|
|
||||||
t, http.StatusOK, w.Code,
|
|
||||||
"request %d should pass", i,
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
w := postWithHeaders(
|
|
||||||
handler, peer, loginPath,
|
|
||||||
headers(middleware.LoginRateLimitConst),
|
|
||||||
)
|
|
||||||
assert.Equal(t, http.StatusTooManyRequests, w.Code, msg)
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestRateLimitKey_SpoofedForwardedFromUntrustedPeer is the test
|
|
||||||
// this gating exists for: with no trusted proxies configured (the
|
|
||||||
// default), a client that rotates a forwarded header on every
|
|
||||||
// request must stay in one bucket. If forwarded headers were
|
|
||||||
// trusted unconditionally, each spoofed value would mint a fresh
|
|
||||||
// bucket and the limit would stop no one.
|
|
||||||
func TestRateLimitKey_SpoofedForwardedFromUntrustedPeer(
|
|
||||||
t *testing.T,
|
|
||||||
) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
for _, header := range []string{
|
|
||||||
headerXFF, headerReal, headerTrue,
|
|
||||||
} {
|
|
||||||
t.Run(header, func(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
assertSharedBucket(
|
|
||||||
t, nil, "203.0.113.9:44444",
|
|
||||||
func(i int) map[string]string {
|
|
||||||
return map[string]string{
|
|
||||||
header: fmt.Sprintf(
|
|
||||||
"198.51.100.%d", i+1,
|
|
||||||
),
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"a spoofed "+header+" from an untrusted peer "+
|
|
||||||
"must not mint a fresh bucket",
|
|
||||||
)
|
|
||||||
})
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestRateLimitKey_SingleValuedHeadersIgnoredFromTrustedPeer is the
|
|
||||||
// regression test for the bypass hiding inside the trusted case.
|
|
||||||
// Real reverse proxies (nginx, HAProxy, Caddy, ALB) set only
|
|
||||||
// X-Forwarded-For and pass every other client header through
|
|
||||||
// verbatim, so a client behind the configured proxy can send its own
|
|
||||||
// X-Real-IP or True-Client-IP. Reading either would hand that client
|
|
||||||
// a fresh bucket per request from inside exactly the deployment
|
|
||||||
// TRUSTED_PROXIES exists to serve, so neither header is read at all.
|
|
||||||
func TestRateLimitKey_SingleValuedHeadersIgnoredFromTrustedPeer(
|
|
||||||
t *testing.T,
|
|
||||||
) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
for _, header := range []string{headerReal, headerTrue} {
|
|
||||||
t.Run(header, func(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
assertSharedBucket(
|
|
||||||
t, trustedProxies("10.0.0.0/8"),
|
|
||||||
"10.0.0.1:44444",
|
|
||||||
func(i int) map[string]string {
|
|
||||||
return map[string]string{
|
|
||||||
header: fmt.Sprintf(
|
|
||||||
"198.51.100.%d", i+1,
|
|
||||||
),
|
|
||||||
}
|
|
||||||
},
|
|
||||||
header+" from a trusted peer must not mint a "+
|
|
||||||
"fresh bucket: only X-Forwarded-For is read",
|
|
||||||
)
|
|
||||||
})
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestRateLimitKey_MalformedRightmostHopFallsBackToPeer covers the
|
|
||||||
// other end of the chain walk. The rightmost X-Forwarded-For entry
|
|
||||||
// is the one the trusted proxy appended; if it cannot be read as an
|
|
||||||
// address the chain is not the shape the walk assumes, and every
|
|
||||||
// entry to its left may have come from the client. The walk must
|
|
||||||
// stop and fall back to the peer rather than select one of them.
|
|
||||||
func TestRateLimitKey_MalformedRightmostHopFallsBackToPeer(
|
|
||||||
t *testing.T,
|
|
||||||
) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
// Forms seen in the wild: host:port (Azure Application
|
|
||||||
// Gateway, IIS ARR), a bracketed IPv6 literal, and the
|
|
||||||
// RFC 7239 placeholder token.
|
|
||||||
for _, tail := range []string{
|
|
||||||
"198.51.100.7:1234", "[2001:db8::1]", "unknown",
|
|
||||||
} {
|
|
||||||
t.Run(tail, func(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
assertSharedBucket(
|
|
||||||
t, trustedProxies("10.0.0.0/8"),
|
|
||||||
"10.0.0.1:44444",
|
|
||||||
func(i int) map[string]string {
|
|
||||||
return map[string]string{
|
|
||||||
headerXFF: fmt.Sprintf(
|
|
||||||
"9.9.9.%d, %s", i+1, tail,
|
|
||||||
),
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"an unparseable rightmost hop must fall back "+
|
|
||||||
"to the peer address, not select a "+
|
|
||||||
"client-controlled entry",
|
|
||||||
)
|
|
||||||
})
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestRateLimitKey_ForwardedHonouredFromTrustedPeer checks the
|
|
||||||
// other half: when the direct peer is a configured trusted proxy,
|
|
||||||
// the forwarded client address is what buckets are keyed on, so
|
|
||||||
// one sender behind the proxy cannot exhaust another's limit.
|
|
||||||
func TestRateLimitKey_ForwardedHonouredFromTrustedPeer(
|
|
||||||
t *testing.T,
|
|
||||||
) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
m := rateLimitMiddleware(t, &config.Config{
|
|
||||||
TrustedProxies: trustedProxies("10.0.0.0/8"),
|
|
||||||
})
|
|
||||||
handler := m.LoginRateLimit()(okHandler())
|
|
||||||
|
|
||||||
const peer = "10.0.0.1:44444"
|
|
||||||
|
|
||||||
first := map[string]string{headerXFF: "198.51.100.7"}
|
|
||||||
|
|
||||||
for range middleware.LoginRateLimitConst {
|
|
||||||
postWithHeaders(handler, peer, loginPath, first)
|
|
||||||
}
|
|
||||||
|
|
||||||
w := postWithHeaders(handler, peer, loginPath, first)
|
|
||||||
assert.Equal(
|
|
||||||
t, http.StatusTooManyRequests, w.Code,
|
|
||||||
"the forwarded client's own bucket must fill up",
|
|
||||||
)
|
|
||||||
|
|
||||||
w = postWithHeaders(
|
|
||||||
handler, peer, loginPath,
|
|
||||||
map[string]string{headerXFF: "198.51.100.8"},
|
|
||||||
)
|
|
||||||
assert.Equal(
|
|
||||||
t, http.StatusOK, w.Code,
|
|
||||||
"a forwarded header from a trusted peer must be honoured",
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestRateLimitKey_ChainWalkSkipsClientPrepended covers the
|
|
||||||
// residual spoofing route behind a trusted proxy: the client
|
|
||||||
// controls the leftmost X-Forwarded-For entries, so the key is the
|
|
||||||
// rightmost hop that is not itself trusted. Rotating the prepended
|
|
||||||
// entry must not create new buckets.
|
|
||||||
func TestRateLimitKey_ChainWalkSkipsClientPrepended(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
assertSharedBucket(
|
|
||||||
t, trustedProxies("10.0.0.0/8"), "10.0.0.1:44444",
|
|
||||||
func(i int) map[string]string {
|
|
||||||
return map[string]string{
|
|
||||||
headerXFF: fmt.Sprintf(
|
|
||||||
"9.9.9.%d, 198.51.100.7, 10.0.0.2", i+1,
|
|
||||||
),
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"a client-prepended X-Forwarded-For entry must not "+
|
|
||||||
"mint a fresh bucket",
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestReceiverRateLimit_IgnoresForwardedFromUntrustedPeer proves
|
|
||||||
// the receiver limiter uses the same gated key function as the
|
|
||||||
// POST limiters.
|
|
||||||
func TestReceiverRateLimit_IgnoresForwardedFromUntrustedPeer(
|
|
||||||
t *testing.T,
|
|
||||||
) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
const (
|
|
||||||
limit = 3
|
|
||||||
peer = "203.0.113.10:44444"
|
|
||||||
path = "/webhook/uuid-d"
|
|
||||||
)
|
|
||||||
|
|
||||||
handler := receiverLimitedHandler(t, limit)
|
|
||||||
|
|
||||||
for i := range limit {
|
|
||||||
w := postWithHeaders(
|
|
||||||
handler, peer, path,
|
|
||||||
map[string]string{
|
|
||||||
headerXFF: fmt.Sprintf(
|
|
||||||
"198.51.100.%d", i+1,
|
|
||||||
),
|
|
||||||
},
|
|
||||||
)
|
|
||||||
assert.Equal(
|
|
||||||
t, http.StatusOK, w.Code,
|
|
||||||
"request %d should pass", i,
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
w := postWithHeaders(
|
|
||||||
handler, peer, path,
|
|
||||||
map[string]string{headerXFF: "198.51.100.200"},
|
|
||||||
)
|
|
||||||
assert.Equal(
|
|
||||||
t, http.StatusTooManyRequests, w.Code,
|
|
||||||
"a spoofed X-Forwarded-For from an untrusted peer must "+
|
|
||||||
"not mint a fresh receiver bucket",
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|||||||
@@ -1,36 +0,0 @@
|
|||||||
package server
|
|
||||||
|
|
||||||
import (
|
|
||||||
"log/slog"
|
|
||||||
"net/http"
|
|
||||||
|
|
||||||
"sneak.berlin/go/webhooker/internal/config"
|
|
||||||
"sneak.berlin/go/webhooker/internal/handlers"
|
|
||||||
"sneak.berlin/go/webhooker/internal/middleware"
|
|
||||||
)
|
|
||||||
|
|
||||||
// MaxFormBodySizeForTest exposes the form body cap so tests can
|
|
||||||
// build requests that sit exactly at, below, and above it.
|
|
||||||
const MaxFormBodySizeForTest = maxFormBodySize
|
|
||||||
|
|
||||||
// NewRouterForTest builds the real route tree via SetupRoutes with
|
|
||||||
// the supplied middleware and handlers, bypassing the fx lifecycle
|
|
||||||
// and the HTTP listener. Tests use it so that route-group middleware
|
|
||||||
// registration order is exercised exactly as it ships, rather than
|
|
||||||
// against a hand-rebuilt chain that could drift from routes.go.
|
|
||||||
func NewRouterForTest(
|
|
||||||
log *slog.Logger,
|
|
||||||
cfg *config.Config,
|
|
||||||
mw *middleware.Middleware,
|
|
||||||
h *handlers.Handlers,
|
|
||||||
) http.Handler {
|
|
||||||
s := &Server{
|
|
||||||
log: log,
|
|
||||||
mw: mw,
|
|
||||||
h: h,
|
|
||||||
params: ServerParams{Config: cfg},
|
|
||||||
}
|
|
||||||
s.SetupRoutes()
|
|
||||||
|
|
||||||
return s.router
|
|
||||||
}
|
|
||||||
@@ -90,11 +90,9 @@ func (s *Server) setupRoutes() {
|
|||||||
|
|
||||||
func (s *Server) setupPageRoutes() {
|
func (s *Server) setupPageRoutes() {
|
||||||
s.router.Route("/pages", func(r chi.Router) {
|
s.router.Route("/pages", func(r chi.Router) {
|
||||||
// MaxBodySize must precede CSRF: gorilla/csrf parses the
|
|
||||||
// form, so the cap has to be installed before it runs.
|
|
||||||
r.Use(s.mw.MaxBodySize(maxFormBodySize))
|
|
||||||
r.Use(s.mw.CSRF())
|
r.Use(s.mw.CSRF())
|
||||||
r.Use(s.mw.NoCache())
|
r.Use(s.mw.NoCache())
|
||||||
|
r.Use(s.mw.MaxBodySize(maxFormBodySize))
|
||||||
|
|
||||||
r.Group(func(r chi.Router) {
|
r.Group(func(r chi.Router) {
|
||||||
r.Use(s.mw.LoginRateLimit())
|
r.Use(s.mw.LoginRateLimit())
|
||||||
@@ -108,9 +106,6 @@ func (s *Server) setupPageRoutes() {
|
|||||||
|
|
||||||
func (s *Server) setupUserRoutes() {
|
func (s *Server) setupUserRoutes() {
|
||||||
s.router.Route("/user/{username}", func(r chi.Router) {
|
s.router.Route("/user/{username}", func(r chi.Router) {
|
||||||
// MaxBodySize must precede CSRF: gorilla/csrf parses the
|
|
||||||
// form, so the cap has to be installed before it runs.
|
|
||||||
r.Use(s.mw.MaxBodySize(maxFormBodySize))
|
|
||||||
r.Use(s.mw.CSRF())
|
r.Use(s.mw.CSRF())
|
||||||
r.Use(s.mw.NoCache())
|
r.Use(s.mw.NoCache())
|
||||||
r.Use(s.mw.RequireAuth())
|
r.Use(s.mw.RequireAuth())
|
||||||
@@ -123,24 +118,20 @@ func (s *Server) setupUserRoutes() {
|
|||||||
|
|
||||||
func (s *Server) setupSourceRoutes() {
|
func (s *Server) setupSourceRoutes() {
|
||||||
s.router.Route("/sources", func(r chi.Router) {
|
s.router.Route("/sources", func(r chi.Router) {
|
||||||
// MaxBodySize must precede CSRF: gorilla/csrf parses the
|
|
||||||
// form, so the cap has to be installed before it runs.
|
|
||||||
r.Use(s.mw.MaxBodySize(maxFormBodySize))
|
|
||||||
r.Use(s.mw.CSRF())
|
r.Use(s.mw.CSRF())
|
||||||
r.Use(s.mw.NoCache())
|
r.Use(s.mw.NoCache())
|
||||||
r.Use(s.mw.RequireAuth())
|
r.Use(s.mw.RequireAuth())
|
||||||
|
r.Use(s.mw.MaxBodySize(maxFormBodySize))
|
||||||
r.Get("/", s.h.HandleSourceList())
|
r.Get("/", s.h.HandleSourceList())
|
||||||
r.Get("/new", s.h.HandleSourceCreate())
|
r.Get("/new", s.h.HandleSourceCreate())
|
||||||
r.Post("/new", s.h.HandleSourceCreateSubmit())
|
r.Post("/new", s.h.HandleSourceCreateSubmit())
|
||||||
})
|
})
|
||||||
|
|
||||||
s.router.Route("/source/{sourceID}", func(r chi.Router) {
|
s.router.Route("/source/{sourceID}", func(r chi.Router) {
|
||||||
// MaxBodySize must precede CSRF: gorilla/csrf parses the
|
|
||||||
// form, so the cap has to be installed before it runs.
|
|
||||||
r.Use(s.mw.MaxBodySize(maxFormBodySize))
|
|
||||||
r.Use(s.mw.CSRF())
|
r.Use(s.mw.CSRF())
|
||||||
r.Use(s.mw.NoCache())
|
r.Use(s.mw.NoCache())
|
||||||
r.Use(s.mw.RequireAuth())
|
r.Use(s.mw.RequireAuth())
|
||||||
|
r.Use(s.mw.MaxBodySize(maxFormBodySize))
|
||||||
r.Get("/", s.h.HandleSourceDetail())
|
r.Get("/", s.h.HandleSourceDetail())
|
||||||
r.Get("/edit", s.h.HandleSourceEdit())
|
r.Get("/edit", s.h.HandleSourceEdit())
|
||||||
r.Post("/edit", s.h.HandleSourceEditSubmit())
|
r.Post("/edit", s.h.HandleSourceEditSubmit())
|
||||||
@@ -171,7 +162,7 @@ func (s *Server) setupSourceRoutes() {
|
|||||||
}
|
}
|
||||||
|
|
||||||
func (s *Server) setupWebhookRoutes() {
|
func (s *Server) setupWebhookRoutes() {
|
||||||
s.router.With(s.mw.ReceiverRateLimit()).HandleFunc(
|
s.router.HandleFunc(
|
||||||
"/webhook/{uuid}",
|
"/webhook/{uuid}",
|
||||||
s.h.HandleWebhook(),
|
s.h.HandleWebhook(),
|
||||||
)
|
)
|
||||||
|
|||||||
@@ -1,383 +0,0 @@
|
|||||||
package server_test
|
|
||||||
|
|
||||||
import (
|
|
||||||
"context"
|
|
||||||
"html"
|
|
||||||
"net/http"
|
|
||||||
"net/http/httptest"
|
|
||||||
"net/url"
|
|
||||||
"regexp"
|
|
||||||
"strings"
|
|
||||||
"testing"
|
|
||||||
|
|
||||||
"github.com/stretchr/testify/assert"
|
|
||||||
"github.com/stretchr/testify/require"
|
|
||||||
"go.uber.org/fx"
|
|
||||||
"go.uber.org/fx/fxtest"
|
|
||||||
"sneak.berlin/go/webhooker/internal/config"
|
|
||||||
"sneak.berlin/go/webhooker/internal/database"
|
|
||||||
"sneak.berlin/go/webhooker/internal/delivery"
|
|
||||||
"sneak.berlin/go/webhooker/internal/globals"
|
|
||||||
"sneak.berlin/go/webhooker/internal/handlers"
|
|
||||||
"sneak.berlin/go/webhooker/internal/healthcheck"
|
|
||||||
"sneak.berlin/go/webhooker/internal/logger"
|
|
||||||
"sneak.berlin/go/webhooker/internal/middleware"
|
|
||||||
"sneak.berlin/go/webhooker/internal/server"
|
|
||||||
"sneak.berlin/go/webhooker/internal/session"
|
|
||||||
)
|
|
||||||
|
|
||||||
// csrfCookieName is the cookie gorilla/csrf issues when it runs. Its
|
|
||||||
// presence or absence on a response is how these tests tell whether
|
|
||||||
// the CSRF middleware executed.
|
|
||||||
const csrfCookieName = "_gorilla_csrf"
|
|
||||||
|
|
||||||
type noopNotifier struct{}
|
|
||||||
|
|
||||||
func (n *noopNotifier) Notify([]delivery.Task) {}
|
|
||||||
|
|
||||||
// noopEvictor satisfies handlers.New's delivery.WebhookEvictor
|
|
||||||
// dependency. These tests never delete a webhook, so there is
|
|
||||||
// nothing to record.
|
|
||||||
type noopEvictor struct{}
|
|
||||||
|
|
||||||
func (e *noopEvictor) EvictWebhook(string) {}
|
|
||||||
|
|
||||||
// testEnv is the real router from routes.go plus the collaborators
|
|
||||||
// tests need to seed users and forge sessions.
|
|
||||||
type testEnv struct {
|
|
||||||
router http.Handler
|
|
||||||
sess *session.Session
|
|
||||||
db *database.Database
|
|
||||||
}
|
|
||||||
|
|
||||||
// newTestEnv wires the dependency graph with fx and builds the
|
|
||||||
// production route tree, so middleware registration order is
|
|
||||||
// exercised exactly as it ships.
|
|
||||||
func newTestEnv(t *testing.T) *testEnv {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
var (
|
|
||||||
log *logger.Logger
|
|
||||||
cfg *config.Config
|
|
||||||
mw *middleware.Middleware
|
|
||||||
hnd *handlers.Handlers
|
|
||||||
sess *session.Session
|
|
||||||
db *database.Database
|
|
||||||
)
|
|
||||||
|
|
||||||
app := fxtest.New(
|
|
||||||
t,
|
|
||||||
fx.Provide(
|
|
||||||
globals.New,
|
|
||||||
logger.New,
|
|
||||||
func() *config.Config {
|
|
||||||
return &config.Config{
|
|
||||||
DataDir: t.TempDir(),
|
|
||||||
Environment: config.EnvironmentDev,
|
|
||||||
}
|
|
||||||
},
|
|
||||||
database.New,
|
|
||||||
database.NewWebhookDBManager,
|
|
||||||
healthcheck.New,
|
|
||||||
session.New,
|
|
||||||
func() delivery.Notifier { return &noopNotifier{} },
|
|
||||||
func() delivery.WebhookEvictor { return &noopEvictor{} },
|
|
||||||
middleware.New,
|
|
||||||
handlers.New,
|
|
||||||
),
|
|
||||||
fx.Populate(&log, &cfg, &mw, &hnd, &sess, &db),
|
|
||||||
)
|
|
||||||
app.RequireStart()
|
|
||||||
t.Cleanup(app.RequireStop)
|
|
||||||
|
|
||||||
return &testEnv{
|
|
||||||
router: server.NewRouterForTest(log.Get(), cfg, mw, hnd),
|
|
||||||
sess: sess,
|
|
||||||
db: db,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// oversizeValue returns a form value one byte past the route-group
|
|
||||||
// body cap, so an encoded form containing it is guaranteed oversize.
|
|
||||||
func oversizeValue() string {
|
|
||||||
return strings.Repeat("a", int(server.MaxFormBodySizeForTest)+1)
|
|
||||||
}
|
|
||||||
|
|
||||||
// csrfCookieSet reports whether the response issued a gorilla/csrf
|
|
||||||
// cookie, which only happens if the CSRF middleware ran.
|
|
||||||
func csrfCookieSet(w *httptest.ResponseRecorder) bool {
|
|
||||||
for _, c := range w.Result().Cookies() {
|
|
||||||
if c.Name == csrfCookieName {
|
|
||||||
return true
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
|
|
||||||
// get issues a GET through the router with the supplied cookies.
|
|
||||||
func (e *testEnv) get(
|
|
||||||
path string,
|
|
||||||
cookies []*http.Cookie,
|
|
||||||
) *httptest.ResponseRecorder {
|
|
||||||
req := httptest.NewRequestWithContext(
|
|
||||||
context.Background(), http.MethodGet, path, nil,
|
|
||||||
)
|
|
||||||
|
|
||||||
for _, c := range cookies {
|
|
||||||
req.AddCookie(c)
|
|
||||||
}
|
|
||||||
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
e.router.ServeHTTP(w, req)
|
|
||||||
|
|
||||||
return w
|
|
||||||
}
|
|
||||||
|
|
||||||
// post issues a urlencoded form POST through the router. The body is
|
|
||||||
// a strings.Reader, so the request carries an accurate
|
|
||||||
// Content-Length — the signal MaxBodySize checks up front.
|
|
||||||
func (e *testEnv) post(
|
|
||||||
path string,
|
|
||||||
form url.Values,
|
|
||||||
cookies []*http.Cookie,
|
|
||||||
) *httptest.ResponseRecorder {
|
|
||||||
req := httptest.NewRequestWithContext(
|
|
||||||
context.Background(), http.MethodPost, path,
|
|
||||||
strings.NewReader(form.Encode()),
|
|
||||||
)
|
|
||||||
req.Header.Set(
|
|
||||||
"Content-Type", "application/x-www-form-urlencoded",
|
|
||||||
)
|
|
||||||
|
|
||||||
for _, c := range cookies {
|
|
||||||
req.AddCookie(c)
|
|
||||||
}
|
|
||||||
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
e.router.ServeHTTP(w, req)
|
|
||||||
|
|
||||||
return w
|
|
||||||
}
|
|
||||||
|
|
||||||
// csrfFrom renders the page at path and returns the CSRF token from
|
|
||||||
// its form together with every cookie needed for the follow-up POST.
|
|
||||||
func (e *testEnv) csrfFrom(
|
|
||||||
t *testing.T,
|
|
||||||
path string,
|
|
||||||
cookies []*http.Cookie,
|
|
||||||
) (string, []*http.Cookie) {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
w := e.get(path, cookies)
|
|
||||||
require.Equal(t, http.StatusOK, w.Code)
|
|
||||||
|
|
||||||
pattern := regexp.MustCompile(
|
|
||||||
`name="csrf_token" value="([^"]+)"`,
|
|
||||||
)
|
|
||||||
|
|
||||||
match := pattern.FindStringSubmatch(w.Body.String())
|
|
||||||
require.Len(t, match, 2, "form must embed a CSRF token")
|
|
||||||
|
|
||||||
// html/template escapes "+" and "=" in attribute values, and
|
|
||||||
// gorilla/csrf tokens are standard base64, so the value read
|
|
||||||
// out of the markup has to be unescaped before it is submitted.
|
|
||||||
token := html.UnescapeString(match[1])
|
|
||||||
|
|
||||||
combined := make([]*http.Cookie, 0, len(cookies))
|
|
||||||
combined = append(combined, cookies...)
|
|
||||||
combined = append(combined, w.Result().Cookies()...)
|
|
||||||
|
|
||||||
return token, combined
|
|
||||||
}
|
|
||||||
|
|
||||||
// authCookies forges an authenticated session for the given user.
|
|
||||||
func (e *testEnv) authCookies(
|
|
||||||
t *testing.T,
|
|
||||||
userID, username string,
|
|
||||||
) []*http.Cookie {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
req := httptest.NewRequestWithContext(
|
|
||||||
context.Background(), http.MethodGet, "/setup", nil,
|
|
||||||
)
|
|
||||||
w := httptest.NewRecorder()
|
|
||||||
|
|
||||||
s, err := e.sess.Get(req)
|
|
||||||
require.NoError(t, err)
|
|
||||||
|
|
||||||
e.sess.SetUser(s, userID, username)
|
|
||||||
require.NoError(t, e.sess.Save(req, w, s))
|
|
||||||
|
|
||||||
cookies := w.Result().Cookies()
|
|
||||||
require.NotEmpty(t, cookies, "session cookie should be set")
|
|
||||||
|
|
||||||
return cookies
|
|
||||||
}
|
|
||||||
|
|
||||||
// seedUser creates a user with the given password and returns the
|
|
||||||
// stored hash so tests can assert whether it later changed.
|
|
||||||
func (e *testEnv) seedUser(
|
|
||||||
t *testing.T,
|
|
||||||
username, password string,
|
|
||||||
) (string, string) {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
hash, err := database.HashPassword(password)
|
|
||||||
require.NoError(t, err)
|
|
||||||
|
|
||||||
user := &database.User{Username: username, Password: hash}
|
|
||||||
require.NoError(t, e.db.DB().Create(user).Error)
|
|
||||||
|
|
||||||
return user.ID, hash
|
|
||||||
}
|
|
||||||
|
|
||||||
// storedHash reads the current password hash for a username.
|
|
||||||
func (e *testEnv) storedHash(t *testing.T, username string) string {
|
|
||||||
t.Helper()
|
|
||||||
|
|
||||||
var user database.User
|
|
||||||
|
|
||||||
require.NoError(t,
|
|
||||||
e.db.DB().Where("username = ?", username).
|
|
||||||
First(&user).Error,
|
|
||||||
)
|
|
||||||
|
|
||||||
return user.Password
|
|
||||||
}
|
|
||||||
|
|
||||||
// --- /pages group ---
|
|
||||||
|
|
||||||
// TestPagesLogin_OversizeBody_RejectedBeforeCSRF proves the cap runs
|
|
||||||
// ahead of gorilla/csrf: the response is a clean 413 and no CSRF
|
|
||||||
// cookie was issued, so neither the CSRF middleware nor the login
|
|
||||||
// handler ran.
|
|
||||||
func TestPagesLogin_OversizeBody_RejectedBeforeCSRF(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
env := newTestEnv(t)
|
|
||||||
|
|
||||||
form := url.Values{}
|
|
||||||
form.Set("username", oversizeValue())
|
|
||||||
form.Set("password", "irrelevant")
|
|
||||||
|
|
||||||
w := env.post("/pages/login", form, nil)
|
|
||||||
|
|
||||||
assert.Equal(
|
|
||||||
t, http.StatusRequestEntityTooLarge, w.Code,
|
|
||||||
)
|
|
||||||
assert.False(
|
|
||||||
t, csrfCookieSet(w),
|
|
||||||
"CSRF middleware must not run for an oversized body",
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestPagesLogin_UnderLimit_NoToken_CSRFRejects is the control for
|
|
||||||
// the test above: an identically shaped but under-limit POST does
|
|
||||||
// reach gorilla/csrf, which rejects it and issues its cookie. Without
|
|
||||||
// this, the missing-cookie assertion above would prove nothing.
|
|
||||||
func TestPagesLogin_UnderLimit_NoToken_CSRFRejects(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
env := newTestEnv(t)
|
|
||||||
|
|
||||||
form := url.Values{}
|
|
||||||
form.Set("username", "someone")
|
|
||||||
form.Set("password", "irrelevant")
|
|
||||||
|
|
||||||
w := env.post("/pages/login", form, nil)
|
|
||||||
|
|
||||||
assert.Equal(t, http.StatusForbidden, w.Code)
|
|
||||||
assert.True(
|
|
||||||
t, csrfCookieSet(w),
|
|
||||||
"CSRF middleware should run for an under-limit body",
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestPagesLogin_UnderLimit_ValidToken_ReachesHandler proves the
|
|
||||||
// reorder did not break CSRF token handling: a token harvested from
|
|
||||||
// the rendered login form is still accepted and the request lands in
|
|
||||||
// the handler.
|
|
||||||
func TestPagesLogin_UnderLimit_ValidToken_ReachesHandler(
|
|
||||||
t *testing.T,
|
|
||||||
) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
env := newTestEnv(t)
|
|
||||||
|
|
||||||
token, cookies := env.csrfFrom(t, "/pages/login", nil)
|
|
||||||
|
|
||||||
form := url.Values{}
|
|
||||||
form.Set("csrf_token", token)
|
|
||||||
form.Set("username", "nosuchuser")
|
|
||||||
form.Set("password", "wrongpassword")
|
|
||||||
|
|
||||||
w := env.post("/pages/login", form, cookies)
|
|
||||||
|
|
||||||
assert.Equal(t, http.StatusUnauthorized, w.Code)
|
|
||||||
assert.Contains(
|
|
||||||
t, w.Body.String(), "Invalid username or password",
|
|
||||||
"request should reach the login handler",
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
// --- /user/{username} group ---
|
|
||||||
|
|
||||||
// TestPasswordChange_OversizeBody_RejectedAndPasswordUnchanged
|
|
||||||
// covers the route that previously had no middleware body cap at
|
|
||||||
// all. The request carries a valid session and a valid CSRF token,
|
|
||||||
// so the only thing that can stop it is the size cap; the unchanged
|
|
||||||
// password hash is the observable proof the handler never ran.
|
|
||||||
func TestPasswordChange_OversizeBody_RejectedAndPasswordUnchanged(
|
|
||||||
t *testing.T,
|
|
||||||
) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
env := newTestEnv(t)
|
|
||||||
|
|
||||||
userID, originalHash := env.seedUser(t, "pwuser", "oldpassword")
|
|
||||||
cookies := env.authCookies(t, userID, "pwuser")
|
|
||||||
token, cookies := env.csrfFrom(t, "/user/pwuser/", cookies)
|
|
||||||
|
|
||||||
form := url.Values{}
|
|
||||||
form.Set("csrf_token", token)
|
|
||||||
form.Set("current_password", "oldpassword")
|
|
||||||
form.Set("new_password", oversizeValue())
|
|
||||||
form.Set("confirm_password", oversizeValue())
|
|
||||||
|
|
||||||
w := env.post("/user/pwuser/password", form, cookies)
|
|
||||||
|
|
||||||
assert.Equal(
|
|
||||||
t, http.StatusRequestEntityTooLarge, w.Code,
|
|
||||||
)
|
|
||||||
assert.Equal(
|
|
||||||
t, originalHash, env.storedHash(t, "pwuser"),
|
|
||||||
"handler must not run, so the password must be unchanged",
|
|
||||||
)
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestPasswordChange_UnderLimit_Succeeds proves that adding the cap
|
|
||||||
// to the /user/{username} group did not break the route it guards.
|
|
||||||
func TestPasswordChange_UnderLimit_Succeeds(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
env := newTestEnv(t)
|
|
||||||
|
|
||||||
userID, originalHash := env.seedUser(t, "okuser", "oldpassword")
|
|
||||||
cookies := env.authCookies(t, userID, "okuser")
|
|
||||||
token, cookies := env.csrfFrom(t, "/user/okuser/", cookies)
|
|
||||||
|
|
||||||
form := url.Values{}
|
|
||||||
form.Set("csrf_token", token)
|
|
||||||
form.Set("current_password", "oldpassword")
|
|
||||||
form.Set("new_password", "brandnewpassword")
|
|
||||||
form.Set("confirm_password", "brandnewpassword")
|
|
||||||
|
|
||||||
w := env.post("/user/okuser/password", form, cookies)
|
|
||||||
|
|
||||||
assert.Equal(t, http.StatusOK, w.Code)
|
|
||||||
assert.NotEqual(
|
|
||||||
t, originalHash, env.storedHash(t, "okuser"),
|
|
||||||
"an under-limit password change should still apply",
|
|
||||||
)
|
|
||||||
}
|
|
||||||
@@ -11,10 +11,10 @@ console.log("Webhooker loaded");
|
|||||||
(function () {
|
(function () {
|
||||||
"use strict";
|
"use strict";
|
||||||
|
|
||||||
const revertDelayMs = 2000;
|
var revertDelayMs = 2000;
|
||||||
|
|
||||||
function flash(button, message) {
|
function flash(button, message) {
|
||||||
const original = button.getAttribute("data-copy-label");
|
var original = button.getAttribute("data-copy-label");
|
||||||
button.textContent = message;
|
button.textContent = message;
|
||||||
window.setTimeout(function () {
|
window.setTimeout(function () {
|
||||||
button.textContent = original;
|
button.textContent = original;
|
||||||
@@ -22,7 +22,7 @@ console.log("Webhooker loaded");
|
|||||||
}
|
}
|
||||||
|
|
||||||
function wire(button) {
|
function wire(button) {
|
||||||
const target = document.getElementById(
|
var target = document.getElementById(
|
||||||
button.getAttribute("data-copy-target")
|
button.getAttribute("data-copy-target")
|
||||||
);
|
);
|
||||||
if (!target) {
|
if (!target) {
|
||||||
@@ -48,8 +48,10 @@ console.log("Webhooker loaded");
|
|||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
const buttons = document.querySelectorAll("[data-copy-target]");
|
var buttons = document.querySelectorAll("[data-copy-target]");
|
||||||
buttons.forEach(wire);
|
for (var i = 0; i < buttons.length; i++) {
|
||||||
|
wire(buttons[i]);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
if (document.readyState === "loading") {
|
if (document.readyState === "loading") {
|
||||||
|
|||||||
@@ -150,11 +150,8 @@
|
|||||||
</form>
|
</form>
|
||||||
</div>
|
</div>
|
||||||
</div>
|
</div>
|
||||||
{{range .Config}}
|
{{if .Config}}
|
||||||
<div class="text-xs text-gray-500 break-all mt-1">
|
<code class="text-xs text-gray-500 break-all block mt-1">{{.Config}}</code>
|
||||||
<span class="font-medium text-gray-700">{{.Label}}:</span>
|
|
||||||
<span>{{.Value}}</span>
|
|
||||||
</div>
|
|
||||||
{{end}}
|
{{end}}
|
||||||
</div>
|
</div>
|
||||||
{{else}}
|
{{else}}
|
||||||
@@ -189,7 +186,7 @@
|
|||||||
|
|
||||||
<!-- Info -->
|
<!-- Info -->
|
||||||
<div class="mt-4 text-sm text-gray-400">
|
<div class="mt-4 text-sm text-gray-400">
|
||||||
<p>Retention: {{.Webhook.RetentionLabel}} · Created: {{.Webhook.CreatedAt.Format "2006-01-02 15:04:05 UTC"}}</p>
|
<p>Retention: {{.Webhook.RetentionDays}} days · Created: {{.Webhook.CreatedAt.Format "2006-01-02 15:04:05 UTC"}}</p>
|
||||||
</div>
|
</div>
|
||||||
</div>
|
</div>
|
||||||
{{end}}
|
{{end}}
|
||||||
|
|||||||
@@ -28,8 +28,7 @@
|
|||||||
|
|
||||||
<div class="form-group">
|
<div class="form-group">
|
||||||
<label for="retention_days" class="label">Retention (days)</label>
|
<label for="retention_days" class="label">Retention (days)</label>
|
||||||
<input type="number" id="retention_days" name="retention_days" value="{{.Webhook.RetentionDays}}" min="0" class="input">
|
<input type="number" id="retention_days" name="retention_days" value="{{.Webhook.RetentionDays}}" min="1" max="365" class="input">
|
||||||
<p class="text-xs text-gray-500 mt-1">Currently {{.Webhook.RetentionLabel}}.{{if .Webhook.RetainsForever}} No events are deleted while retention is set to forever.{{else}} A periodic cleanup permanently deletes events older than this, along with their delivery records.{{end}} Enter 0 to retain events forever; leave blank to keep the current setting.</p>
|
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
<div class="flex gap-3">
|
<div class="flex gap-3">
|
||||||
|
|||||||
@@ -25,7 +25,7 @@
|
|||||||
<p class="text-sm text-gray-500 mt-1">{{.Description}}</p>
|
<p class="text-sm text-gray-500 mt-1">{{.Description}}</p>
|
||||||
{{end}}
|
{{end}}
|
||||||
</div>
|
</div>
|
||||||
<span class="badge-info">Retention: {{.RetentionLabel}}</span>
|
<span class="badge-info">{{.RetentionDays}}d retention</span>
|
||||||
</div>
|
</div>
|
||||||
<div class="flex gap-6 mt-4 text-sm text-gray-500">
|
<div class="flex gap-6 mt-4 text-sm text-gray-500">
|
||||||
<span>{{.EntrypointCount}} entrypoint{{if ne .EntrypointCount 1}}s{{end}}</span>
|
<span>{{.EntrypointCount}} entrypoint{{if ne .EntrypointCount 1}}s{{end}}</span>
|
||||||
|
|||||||
@@ -18,18 +18,18 @@
|
|||||||
<input type="hidden" name="csrf_token" value="{{.CSRFToken}}">
|
<input type="hidden" name="csrf_token" value="{{.CSRFToken}}">
|
||||||
<div class="form-group">
|
<div class="form-group">
|
||||||
<label for="name" class="label">Name</label>
|
<label for="name" class="label">Name</label>
|
||||||
<input type="text" id="name" name="name" value="{{.Name}}" required autofocus placeholder="My Webhook" class="input">
|
<input type="text" id="name" name="name" required autofocus placeholder="My Webhook" class="input">
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
<div class="form-group">
|
<div class="form-group">
|
||||||
<label for="description" class="label">Description</label>
|
<label for="description" class="label">Description</label>
|
||||||
<textarea id="description" name="description" rows="3" placeholder="Optional description" class="input">{{.Description}}</textarea>
|
<textarea id="description" name="description" rows="3" placeholder="Optional description" class="input"></textarea>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
<div class="form-group">
|
<div class="form-group">
|
||||||
<label for="retention_days" class="label">Retention (days)</label>
|
<label for="retention_days" class="label">Retention (days)</label>
|
||||||
<input type="number" id="retention_days" name="retention_days" value="{{.DefaultRetentionDays}}" min="0" class="input">
|
<input type="number" id="retention_days" name="retention_days" value="30" min="1" max="365" class="input">
|
||||||
<p class="text-xs text-gray-500 mt-1">A periodic cleanup permanently deletes events older than this, along with their delivery records. Enter 0 to retain events forever; leave blank to use the default of {{.DefaultRetentionDays}} days.</p>
|
<p class="text-xs text-gray-500 mt-1">How long to keep event data.</p>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
<div class="flex gap-3">
|
<div class="flex gap-3">
|
||||||
|
|||||||
Reference in New Issue
Block a user