mirror of
https://github.com/netbirdio/netbird.git
synced 2026-08-24 16:41:30 +02:00
Two review follow-ups. The API validated anonymize_level after trimming and lowercasing but persisted the value verbatim, so " default " passed as default yet reached the client — which only lowercases — as an unrecognized value it resolves to strict. Persist the normalized form so what was validated is what the client parses. The remote debug bundle job forwarded the management-supplied upload URL to the uploader unchecked and logged it at info level, where it can leak a host, credentials, or query tokens. Reject a malformed or non-https URL before generating the bundle, and keep the URL out of the info-level line while leaving the full parameters at debug. The accepted host is left unrestricted for now, pending a decision on management-directed uploads.
36 lines
1.1 KiB
Go
36 lines
1.1 KiB
Go
package internal
|
|
|
|
import (
|
|
"testing"
|
|
|
|
"github.com/stretchr/testify/assert"
|
|
"github.com/stretchr/testify/require"
|
|
)
|
|
|
|
// TestValidateBundleUploadURL covers the sanity check applied to a
|
|
// management-supplied upload URL before a remote debug bundle is generated.
|
|
func TestValidateBundleUploadURL(t *testing.T) {
|
|
for _, tc := range []struct {
|
|
name string
|
|
raw string
|
|
wantErr bool
|
|
}{
|
|
{name: "empty falls back to default", raw: ""},
|
|
{name: "https with host", raw: "https://upload.debug.netbird.io/upload"},
|
|
{name: "https self-hosted host", raw: "https://upload.example.com"},
|
|
{name: "plaintext rejected", raw: "http://upload.example.com", wantErr: true},
|
|
{name: "missing host rejected", raw: "https:///upload", wantErr: true},
|
|
{name: "non-url scheme rejected", raw: "ftp://upload.example.com", wantErr: true},
|
|
{name: "garbage rejected", raw: "://not a url", wantErr: true},
|
|
} {
|
|
t.Run(tc.name, func(t *testing.T) {
|
|
err := validateBundleUploadURL(tc.raw)
|
|
if tc.wantErr {
|
|
require.Error(t, err, "an invalid upload URL must be rejected")
|
|
return
|
|
}
|
|
assert.NoError(t, err, "a valid or empty upload URL must be accepted")
|
|
})
|
|
}
|
|
}
|