test: fix contract tests failing due to strict SSRF checks

This commit is contained in:
sagitchu
2026-04-17 12:02:40 +08:00
parent 5e2580bd45
commit 3ddff94bc3
3 changed files with 14 additions and 1 deletions
+2 -1
View File
@@ -350,7 +350,8 @@ func (h *Handler) getConfigByName(w http.ResponseWriter, r *http.Request) {
return
}
switch req.Name {
configName := strings.ToLower(strings.TrimSpace(req.Name))
switch configName {
case "license_key", "cloudflare_secret_key", "jwt_secret":
response.WriteJSON(w, response.Err(403, "禁止访问敏感配置"))
return
@@ -6,9 +6,16 @@ import (
"strings"
)
// DisableSafeRemoteAddrCheckForTesting allows bypassing the safety check during integration tests.
var DisableSafeRemoteAddrCheckForTesting = false
// IsSafeRemoteAddr checks if a given address is safe to connect to (prevents SSRF/Open Proxy).
// It resolves domains to IPs to prevent DNS rebinding attacks pointing to internal networks.
func IsSafeRemoteAddr(addr string) error {
if DisableSafeRemoteAddrCheckForTesting {
return nil
}
host, _, err := net.SplitHostPort(addr)
if err != nil {
// If there is no port, try to treat the whole string as host
@@ -6,9 +6,14 @@ import (
"strings"
"testing"
"go-backend/internal/http/handler"
"go-backend/internal/store/repo"
)
func init() {
handler.DisableSafeRemoteAddrCheckForTesting = true
}
func mustLastInsertID(t *testing.T, r *repo.Repository, label string) int64 {
t.Helper()
var id int64