mirror of
https://github.com/netbirdio/netbird.git
synced 2026-10-05 21:19:08 +02:00
Validate upload server config at startup
This commit is contained in:
@@ -15,7 +15,7 @@ import (
|
||||
"github.com/netbirdio/netbird/upload-server/types"
|
||||
)
|
||||
|
||||
const testSigningKey = "test-signing-key"
|
||||
const testSigningKey = "test-signing-key-with-enough-length"
|
||||
|
||||
func signedQuery(t *testing.T, objectKey string) string {
|
||||
t.Helper()
|
||||
@@ -24,12 +24,12 @@ func signedQuery(t *testing.T, objectKey string) string {
|
||||
}
|
||||
|
||||
func Test_LocalHandlerGetUploadURL(t *testing.T) {
|
||||
mockURL := "http://localhost:8080"
|
||||
mockURL := "https://localhost:8080"
|
||||
t.Setenv("SERVER_URL", mockURL)
|
||||
t.Setenv("STORE_DIR", t.TempDir())
|
||||
|
||||
mux := http.NewServeMux()
|
||||
err := configureLocalHandlers(mux, newRateLimiter())
|
||||
err := configureLocalHandlers(mux, newTestRateLimiter(t))
|
||||
require.NoError(t, err)
|
||||
|
||||
req := httptest.NewRequest(http.MethodGet, types.GetURLPath+"?id=test-file", nil)
|
||||
@@ -50,13 +50,13 @@ func Test_LocalHandlerGetUploadURL(t *testing.T) {
|
||||
|
||||
func Test_LocalHandlePutRequest(t *testing.T) {
|
||||
mockDir := t.TempDir()
|
||||
mockURL := "http://localhost:8080"
|
||||
mockURL := "https://localhost:8080"
|
||||
t.Setenv("SERVER_URL", mockURL)
|
||||
t.Setenv("STORE_DIR", mockDir)
|
||||
t.Setenv(signingKeyVar, testSigningKey)
|
||||
|
||||
mux := http.NewServeMux()
|
||||
err := configureLocalHandlers(mux, newRateLimiter())
|
||||
err := configureLocalHandlers(mux, newTestRateLimiter(t))
|
||||
require.NoError(t, err)
|
||||
|
||||
fileContent := []byte("test file content")
|
||||
@@ -76,13 +76,13 @@ func Test_LocalHandlePutRequest(t *testing.T) {
|
||||
|
||||
func Test_LocalHandlePutRequest_PathTraversal(t *testing.T) {
|
||||
mockDir := t.TempDir()
|
||||
mockURL := "http://localhost:8080"
|
||||
mockURL := "https://localhost:8080"
|
||||
t.Setenv("SERVER_URL", mockURL)
|
||||
t.Setenv("STORE_DIR", mockDir)
|
||||
t.Setenv(signingKeyVar, testSigningKey)
|
||||
|
||||
mux := http.NewServeMux()
|
||||
err := configureLocalHandlers(mux, newRateLimiter())
|
||||
err := configureLocalHandlers(mux, newTestRateLimiter(t))
|
||||
require.NoError(t, err)
|
||||
|
||||
fileContent := []byte("malicious content")
|
||||
@@ -101,11 +101,11 @@ func Test_LocalHandlePutRequest_PathTraversal(t *testing.T) {
|
||||
|
||||
func Test_LocalHandlePutRequest_DirTraversal(t *testing.T) {
|
||||
mockDir := t.TempDir()
|
||||
t.Setenv("SERVER_URL", "http://localhost:8080")
|
||||
t.Setenv("SERVER_URL", "https://localhost:8080")
|
||||
t.Setenv("STORE_DIR", mockDir)
|
||||
t.Setenv(signingKeyVar, testSigningKey)
|
||||
|
||||
l := &local{url: "http://localhost:8080", dir: mockDir, signer: &signer{key: []byte(testSigningKey)}}
|
||||
l := &local{url: "https://localhost:8080", dir: mockDir, signer: &signer{key: []byte(testSigningKey)}}
|
||||
|
||||
body := bytes.NewReader([]byte("bad"))
|
||||
req := httptest.NewRequest(http.MethodPut,
|
||||
@@ -124,12 +124,12 @@ func Test_LocalHandlePutRequest_DirTraversal(t *testing.T) {
|
||||
|
||||
func Test_LocalHandlePutRequest_DuplicateFile(t *testing.T) {
|
||||
mockDir := t.TempDir()
|
||||
t.Setenv("SERVER_URL", "http://localhost:8080")
|
||||
t.Setenv("SERVER_URL", "https://localhost:8080")
|
||||
t.Setenv("STORE_DIR", mockDir)
|
||||
t.Setenv(signingKeyVar, testSigningKey)
|
||||
|
||||
mux := http.NewServeMux()
|
||||
err := configureLocalHandlers(mux, newRateLimiter())
|
||||
err := configureLocalHandlers(mux, newTestRateLimiter(t))
|
||||
require.NoError(t, err)
|
||||
|
||||
req := httptest.NewRequest(http.MethodPut,
|
||||
@@ -151,12 +151,12 @@ func Test_LocalHandlePutRequest_DuplicateFile(t *testing.T) {
|
||||
|
||||
func Test_LocalHandlePutRequest_BodyTooLarge(t *testing.T) {
|
||||
mockDir := t.TempDir()
|
||||
t.Setenv("SERVER_URL", "http://localhost:8080")
|
||||
t.Setenv("SERVER_URL", "https://localhost:8080")
|
||||
t.Setenv("STORE_DIR", mockDir)
|
||||
t.Setenv(signingKeyVar, testSigningKey)
|
||||
|
||||
mux := http.NewServeMux()
|
||||
err := configureLocalHandlers(mux, newRateLimiter())
|
||||
err := configureLocalHandlers(mux, newTestRateLimiter(t))
|
||||
require.NoError(t, err)
|
||||
|
||||
largeBody := make([]byte, maxUploadSize+1)
|
||||
@@ -170,3 +170,12 @@ func Test_LocalHandlePutRequest_BodyTooLarge(t *testing.T) {
|
||||
_, err = os.Stat(filepath.Join(mockDir, "dir", "big.txt"))
|
||||
require.True(t, os.IsNotExist(err))
|
||||
}
|
||||
|
||||
func Test_ConfigureLocalHandlersRejectsPlaintextURL(t *testing.T) {
|
||||
t.Setenv("SERVER_URL", "http://localhost:8080")
|
||||
t.Setenv("STORE_DIR", t.TempDir())
|
||||
t.Setenv(signingKeyVar, testSigningKey)
|
||||
|
||||
err := configureLocalHandlers(http.NewServeMux(), newTestRateLimiter(t))
|
||||
require.Error(t, err)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user