[优化] 更新默认服务器块,添加 HTTPS 支持并启用 SSL 握手拒绝

This commit is contained in:
ryan
2026-04-01 10:02:40 +08:00
parent 49472b54bf
commit d425e34f71
2 changed files with 28 additions and 1 deletions
@@ -949,12 +949,18 @@ func TestRenderConfigUsesDefaultServerFallback(t *testing.T) {
if !strings.Contains(preview.MainConfig, "listen 80 default_server;") {
t.Fatal("expected preview main config to include default http server")
}
if !strings.Contains(preview.MainConfig, "listen 443 ssl default_server;") {
t.Fatal("expected preview main config to include default https server")
}
if !strings.Contains(preview.MainConfig, "server_name _;") {
t.Fatal("expected preview main config to include default server_name")
}
if !strings.Contains(preview.MainConfig, "return 404;") {
t.Fatal("expected preview main config to return 404 for unmatched hosts")
}
if !strings.Contains(preview.MainConfig, "ssl_reject_handshake on;") {
t.Fatal("expected preview main config to reject unmatched https handshakes")
}
}
func TestCreateTLSCertificateRejectsInvalidPEM(t *testing.T) {
@@ -1007,6 +1013,12 @@ func TestOpenRestyMainConfigTemplateRenderAndValidate(t *testing.T) {
if !strings.Contains(preview.MainConfig, "listen 80 default_server;") {
t.Fatal("expected preview main config to preserve managed default server block")
}
if !strings.Contains(preview.MainConfig, "listen 443 ssl default_server;") {
t.Fatal("expected preview main config to preserve managed default https server block")
}
if !strings.Contains(preview.MainConfig, "ssl_reject_handshake on;") {
t.Fatal("expected preview main config to preserve managed https handshake rejection")
}
invalidTemplate := strings.ReplaceAll(
common.OpenRestyMainConfigTemplate,