mirror of
https://github.com/Sagit-chu/flvx.git
synced 2026-10-08 18:56:37 +08:00
test: fix contract tests failing due to strict SSRF checks
This commit is contained in:
@@ -350,7 +350,8 @@ func (h *Handler) getConfigByName(w http.ResponseWriter, r *http.Request) {
|
|||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
switch req.Name {
|
configName := strings.ToLower(strings.TrimSpace(req.Name))
|
||||||
|
switch configName {
|
||||||
case "license_key", "cloudflare_secret_key", "jwt_secret":
|
case "license_key", "cloudflare_secret_key", "jwt_secret":
|
||||||
response.WriteJSON(w, response.Err(403, "禁止访问敏感配置"))
|
response.WriteJSON(w, response.Err(403, "禁止访问敏感配置"))
|
||||||
return
|
return
|
||||||
|
|||||||
@@ -6,9 +6,16 @@ import (
|
|||||||
"strings"
|
"strings"
|
||||||
)
|
)
|
||||||
|
|
||||||
|
// DisableSafeRemoteAddrCheckForTesting allows bypassing the safety check during integration tests.
|
||||||
|
var DisableSafeRemoteAddrCheckForTesting = false
|
||||||
|
|
||||||
// IsSafeRemoteAddr checks if a given address is safe to connect to (prevents SSRF/Open Proxy).
|
// IsSafeRemoteAddr checks if a given address is safe to connect to (prevents SSRF/Open Proxy).
|
||||||
// It resolves domains to IPs to prevent DNS rebinding attacks pointing to internal networks.
|
// It resolves domains to IPs to prevent DNS rebinding attacks pointing to internal networks.
|
||||||
func IsSafeRemoteAddr(addr string) error {
|
func IsSafeRemoteAddr(addr string) error {
|
||||||
|
if DisableSafeRemoteAddrCheckForTesting {
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
|
||||||
host, _, err := net.SplitHostPort(addr)
|
host, _, err := net.SplitHostPort(addr)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
// If there is no port, try to treat the whole string as host
|
// If there is no port, try to treat the whole string as host
|
||||||
|
|||||||
@@ -6,9 +6,14 @@ import (
|
|||||||
"strings"
|
"strings"
|
||||||
"testing"
|
"testing"
|
||||||
|
|
||||||
|
"go-backend/internal/http/handler"
|
||||||
"go-backend/internal/store/repo"
|
"go-backend/internal/store/repo"
|
||||||
)
|
)
|
||||||
|
|
||||||
|
func init() {
|
||||||
|
handler.DisableSafeRemoteAddrCheckForTesting = true
|
||||||
|
}
|
||||||
|
|
||||||
func mustLastInsertID(t *testing.T, r *repo.Repository, label string) int64 {
|
func mustLastInsertID(t *testing.T, r *repo.Repository, label string) int64 {
|
||||||
t.Helper()
|
t.Helper()
|
||||||
var id int64
|
var id int64
|
||||||
|
|||||||
Reference in New Issue
Block a user