package handlers_test import ( "net/http" "net/url" "testing" "github.com/stretchr/testify/assert" "github.com/stretchr/testify/require" "sneak.berlin/go/webhooker/internal/database" ) // privateRefusalHint is the sentence that tells an operator a private // destination is refused on purpose, and how to allow one. const privateRefusalHint = "Private and reserved addresses are " + "refused by default; the server's ALLOWED_EGRESS_CIDRS setting " + "allows named networks (see \"Allowing egress to your own " + "network\" in the README)." // TestTargetRefusal_PrivateDestinationSaysHowToAllowIt covers both // target types that take a URL, on add and on edit. func TestTargetRefusal_PrivateDestinationSaysHowToAllowIt( t *testing.T, ) { t.Parallel() env := setupSourceTest(t) targetTypes := []database.TargetType{ database.TargetTypeHTTP, database.TargetTypeSlack, } for _, targetType := range targetTypes { t.Run(string(targetType), func(t *testing.T) { t.Parallel() webhook := seedWebhookWithRetention(t, env.db, 30) targetsPath := "/source/" + webhook.ID + "/targets" form := url.Values{} form.Set("name", "private") form.Set("type", string(targetType)) form.Set("url", editBlockedURL) added := serveTarget( env, http.MethodPost, targetsPath, form, ) assert.Equal(t, http.StatusBadRequest, added.Code) assert.Contains( t, added.Body.String(), privateRefusalHint, ) form.Set("url", editOriginalURL) created := serveTarget( env, http.MethodPost, targetsPath, form, ) require.Equal( t, http.StatusSeeOther, created.Code, created.Body.String(), ) targets := targetsForWebhook(t, env.db, webhook.ID) require.Len(t, targets, 1) form.Set("url", editBlockedURL) edited := submitTargetEdit( env, webhook.ID, targets[0].ID, form, ) assert.Equal(t, http.StatusBadRequest, edited.Code) assert.Contains( t, edited.Body.String(), privateRefusalHint, ) }) } // No setting opens a link-local address, so its refusal must // not point at one. t.Run("link-local", func(t *testing.T) { t.Parallel() webhook := seedWebhookWithRetention(t, env.db, 30) form := url.Values{} form.Set("name", "metadata") form.Set("type", string(database.TargetTypeHTTP)) form.Set("url", "http://169.254.169.254/latest/meta-data/") w := serveTarget( env, http.MethodPost, "/source/"+webhook.ID+"/targets", form, ) assert.Equal(t, http.StatusBadRequest, w.Code) assert.NotContains(t, w.Body.String(), privateRefusalHint) }) }