From 3ddff94bc3c9d493ac297224f04c1de8f2a1475c Mon Sep 17 00:00:00 2001 From: sagitchu Date: Fri, 17 Apr 2026 12:02:40 +0800 Subject: [PATCH] test: fix contract tests failing due to strict SSRF checks --- go-backend/internal/http/handler/handler.go | 3 ++- go-backend/internal/http/handler/security_utils.go | 7 +++++++ go-backend/tests/contract/db_test_helper_test.go | 5 +++++ 3 files changed, 14 insertions(+), 1 deletion(-) diff --git a/go-backend/internal/http/handler/handler.go b/go-backend/internal/http/handler/handler.go index 97becfb..c3a8a7f 100644 --- a/go-backend/internal/http/handler/handler.go +++ b/go-backend/internal/http/handler/handler.go @@ -350,7 +350,8 @@ func (h *Handler) getConfigByName(w http.ResponseWriter, r *http.Request) { return } - switch req.Name { + configName := strings.ToLower(strings.TrimSpace(req.Name)) + switch configName { case "license_key", "cloudflare_secret_key", "jwt_secret": response.WriteJSON(w, response.Err(403, "禁止访问敏感配置")) return diff --git a/go-backend/internal/http/handler/security_utils.go b/go-backend/internal/http/handler/security_utils.go index cc11c5f..9cadac5 100644 --- a/go-backend/internal/http/handler/security_utils.go +++ b/go-backend/internal/http/handler/security_utils.go @@ -6,9 +6,16 @@ import ( "strings" ) +// DisableSafeRemoteAddrCheckForTesting allows bypassing the safety check during integration tests. +var DisableSafeRemoteAddrCheckForTesting = false + // IsSafeRemoteAddr checks if a given address is safe to connect to (prevents SSRF/Open Proxy). // It resolves domains to IPs to prevent DNS rebinding attacks pointing to internal networks. func IsSafeRemoteAddr(addr string) error { + if DisableSafeRemoteAddrCheckForTesting { + return nil + } + host, _, err := net.SplitHostPort(addr) if err != nil { // If there is no port, try to treat the whole string as host diff --git a/go-backend/tests/contract/db_test_helper_test.go b/go-backend/tests/contract/db_test_helper_test.go index 322ade9..b41ba20 100644 --- a/go-backend/tests/contract/db_test_helper_test.go +++ b/go-backend/tests/contract/db_test_helper_test.go @@ -6,9 +6,14 @@ import ( "strings" "testing" + "go-backend/internal/http/handler" "go-backend/internal/store/repo" ) +func init() { + handler.DisableSafeRemoteAddrCheckForTesting = true +} + func mustLastInsertID(t *testing.T, r *repo.Repository, label string) int64 { t.Helper() var id int64