mirror of
https://github.com/netbirdio/netbird.git
synced 2026-09-01 20:41:28 +02:00
This extends the management-requested remote debug-bundle job with two new, optional parameters. anonymize_level selects how aggressively the bundle is scrubbed: "default" keeps internal (private) IP ranges readable, while "strict" also anonymizes private, CGNAT and link-local addresses; the value is trimmed and lowercased, and an unknown level is rejected at creation. upload_url lets an operator point the peer at a specific upload service instead of the default one; it must be a well-formed https URL with a host, and an empty value falls back to the default upload server. Both fields flow through the job workload API and are surfaced in the create-debug-job modal on the dashboard. Validation is shared so the client executor and the management boundary agree on what a valid upload URL is, preventing drift between the two checks.
36 lines
1.1 KiB
Go
36 lines
1.1 KiB
Go
package internal
|
|
|
|
import (
|
|
"testing"
|
|
|
|
"github.com/stretchr/testify/assert"
|
|
"github.com/stretchr/testify/require"
|
|
)
|
|
|
|
// TestValidateBundleUploadURL covers the sanity check applied to a
|
|
// management-supplied upload URL before a remote debug bundle is generated.
|
|
func TestValidateBundleUploadURL(t *testing.T) {
|
|
for _, tc := range []struct {
|
|
name string
|
|
raw string
|
|
wantErr bool
|
|
}{
|
|
{name: "empty falls back to default", raw: ""},
|
|
{name: "https with host", raw: "https://upload.debug.netbird.io/upload"},
|
|
{name: "https self-hosted host", raw: "https://upload.example.com"},
|
|
{name: "plaintext rejected", raw: "http://upload.example.com", wantErr: true},
|
|
{name: "missing host rejected", raw: "https:///upload", wantErr: true},
|
|
{name: "non-url scheme rejected", raw: "ftp://upload.example.com", wantErr: true},
|
|
{name: "garbage rejected", raw: "://not a url", wantErr: true},
|
|
} {
|
|
t.Run(tc.name, func(t *testing.T) {
|
|
err := validateBundleUploadURL(tc.raw)
|
|
if tc.wantErr {
|
|
require.Error(t, err, "an invalid upload URL must be rejected")
|
|
return
|
|
}
|
|
assert.NoError(t, err, "a valid or empty upload URL must be accepted")
|
|
})
|
|
}
|
|
}
|