check / check (push) Waiting to run
Unset or empty, TRUSTED_PROXIES now defaults to 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16, so a reverse proxy reaching webhooker from one of those ranges gets per-client rate-limit buckets with nothing set. A set value replaces the default entirely; an unparseable one still fails startup. The startup warning for an empty list is gone. The README gives the default, one rule (if any client can reach webhooker, or the proxy in front of it, from an RFC 1918 source address, set the list to the proxy's address alone), and where to find that address: the remoteIP field of the http request log line. Loopback is not in the default. Model: opus-5-5
60 lines
1.9 KiB
Go
60 lines
1.9 KiB
Go
package config
|
|
|
|
import "log/slog"
|
|
|
|
// This file exposes the unexported environment parsing helpers to
|
|
// the external config_test package so each helper can be covered by
|
|
// its own table-driven test without weakening the package API.
|
|
|
|
// WarnEgressAllowlistForTest loads a Config from the current
|
|
// environment and emits its egress-allowlist startup warning to
|
|
// log, so a test can assert both that the warning fires only when
|
|
// the list is non-empty and that it names the blocks it opened.
|
|
func WarnEgressAllowlistForTest(log *slog.Logger) error {
|
|
c, err := loadFromEnv()
|
|
if err != nil {
|
|
return err
|
|
}
|
|
|
|
c.warnEgressAllowlist(log)
|
|
|
|
return nil
|
|
}
|
|
|
|
// EnvBoolForTest exposes envBool.
|
|
func EnvBoolForTest(key string, defaultValue bool) (bool, error) {
|
|
return envBool(key, defaultValue)
|
|
}
|
|
|
|
// EnvPositiveIntForTest exposes envPositiveInt.
|
|
func EnvPositiveIntForTest(key string, defaultValue int) (int, error) {
|
|
return envPositiveInt(key, defaultValue)
|
|
}
|
|
|
|
// EnvPortForTest exposes envPort.
|
|
func EnvPortForTest(key string, defaultValue int) (int, error) {
|
|
return envPort(key, defaultValue)
|
|
}
|
|
|
|
// EnvSentryDSNForTest exposes envSentryDSN.
|
|
func EnvSentryDSNForTest(key string) (string, error) {
|
|
return envSentryDSN(key)
|
|
}
|
|
|
|
// LoadDotEnvFileForTest exposes the loader LoadDotEnv runs, over a
|
|
// caller-named file rather than the process working directory, so
|
|
// each .env state can be covered without moving the test process.
|
|
func LoadDotEnvFileForTest(path string) error {
|
|
return loadDotEnvFile(path)
|
|
}
|
|
|
|
// EnvBindAddressForTest exposes envBindAddress.
|
|
func EnvBindAddressForTest(key, defaultValue string) (string, error) {
|
|
return envBindAddress(key, defaultValue)
|
|
}
|
|
|
|
// DefaultBindAddressForTest exposes the compiled-in BIND_ADDRESS
|
|
// default, so a test pins the documented value rather than repeating
|
|
// a literal that could drift from it.
|
|
const DefaultBindAddressForTest = defaultBindAddress
|