feat: complete remaining Go backend modules
This commit is contained in:
1 parent
cea2751dc5
commit
aef5a97165
145 files changed
+18376
-199
No files matched your search
@@ -6,9 +6,24 @@ import (
|
||||
"io"
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
"net/url"
|
||||
"strings"
|
||||
"testing"
|
||||
"time"
|
||||
)
|
||||
|
||||
type assetRoundTripFunc func(*http.Request) (*http.Response, error)
|
||||
|
||||
func (function assetRoundTripFunc) RoundTrip(request *http.Request) (*http.Response, error) {
|
||||
return function(request)
|
||||
}
|
||||
|
||||
type remotePolicyFunc func(context.Context, *url.URL) error
|
||||
|
||||
func (function remotePolicyFunc) Validate(ctx context.Context, target *url.URL) error {
|
||||
return function(ctx, target)
|
||||
}
|
||||
|
||||
func TestHTTPRemoteFetcherRestrictsProtocolAndSize(t *testing.T) {
|
||||
fetcher := NewHTTPRemoteFetcher(http.DefaultClient, 4)
|
||||
if _, err := fetcher.Fetch(context.Background(), "file:///etc/passwd"); !errors.Is(err, ErrRemoteProtocol) {
|
||||
@@ -40,3 +55,37 @@ func TestHTTPRemoteFetcherReturnsBoundedBody(t *testing.T) {
|
||||
t.Fatalf("blob = %#v body=%q", blob, body)
|
||||
}
|
||||
}
|
||||
|
||||
func TestPolicyHTTPRemoteFetcherValidatesInitialAndRedirectDestinations(t *testing.T) {
|
||||
validated := make([]string, 0, 2)
|
||||
policy := remotePolicyFunc(func(_ context.Context, target *url.URL) error {
|
||||
validated = append(validated, target.Hostname())
|
||||
if target.Hostname() == "private.test" {
|
||||
return errors.New("private destination")
|
||||
}
|
||||
return nil
|
||||
})
|
||||
client := &http.Client{Timeout: time.Second, Transport: assetRoundTripFunc(func(request *http.Request) (*http.Response, error) {
|
||||
if request.URL.Hostname() == "public.test" {
|
||||
return &http.Response{StatusCode: http.StatusFound, Header: http.Header{"Location": []string{"http://private.test/asset"}}, Body: io.NopCloser(strings.NewReader("")), Request: request}, nil
|
||||
}
|
||||
t.Fatal("redirect target transport must not run")
|
||||
return nil, nil
|
||||
})}
|
||||
fetcher, err := NewPolicyHTTPRemoteFetcher(client, 4, policy)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if _, err := fetcher.Fetch(context.Background(), "https://public.test/asset"); err == nil {
|
||||
t.Fatal("policy-denied redirect was accepted")
|
||||
}
|
||||
if strings.Join(validated, ",") != "public.test,private.test" {
|
||||
t.Fatalf("validated destinations = %v", validated)
|
||||
}
|
||||
}
|
||||
|
||||
func TestNewPublicHTTPRemoteFetcherRequiresPolicy(t *testing.T) {
|
||||
if _, err := NewPublicHTTPRemoteFetcher(time.Second, 4, nil); err == nil {
|
||||
t.Fatal("nil public destination policy accepted")
|
||||
}
|
||||
}
|
||||
Reference in new issue
Block a user