mirror of
https://github.com/pocket-id/pocket-id.git
synced 2026-09-28 05:49:03 +02:00
Merge branch 'main' into invite-email-domain
This commit is contained in:
@@ -46,6 +46,7 @@ type EnvConfigSchema struct {
|
||||
DbProvider DbProvider
|
||||
DbConnectionString string `env:"DB_CONNECTION_STRING" options:"file"`
|
||||
TrustProxy TrustProxyConfig `env:"TRUST_PROXY"`
|
||||
ProxyProtocol TrustProxyConfig `env:"PROXY_PROTOCOL"`
|
||||
TrustedPlatform string `env:"TRUSTED_PLATFORM"`
|
||||
AuditLogRetentionDays int `env:"AUDIT_LOG_RETENTION_DAYS"`
|
||||
AnalyticsDisabled bool `env:"ANALYTICS_DISABLED"`
|
||||
@@ -158,6 +159,9 @@ func ValidateEnvConfig(config *EnvConfigSchema) error {
|
||||
if config.SystemdSocket && config.UnixSocket != "" {
|
||||
return errors.New("SYSTEMD_SOCKET and UNIX_SOCKET are mutually exclusive")
|
||||
}
|
||||
if len(config.ProxyProtocol) > 0 && config.UnixSocket != "" {
|
||||
return errors.New("PROXY_PROTOCOL and UNIX_SOCKET are mutually exclusive")
|
||||
}
|
||||
|
||||
if config.AuditLogRetentionDays <= 0 {
|
||||
return errors.New("AUDIT_LOG_RETENTION_DAYS must be greater than 0")
|
||||
@@ -414,6 +418,11 @@ func (config *TrustProxyConfig) UnmarshalText(text []byte) error {
|
||||
proxies := strings.Split(value, ",")
|
||||
for i, proxy := range proxies {
|
||||
proxy = strings.TrimSpace(proxy)
|
||||
if net.ParseIP(proxy) == nil {
|
||||
if _, _, err := net.ParseCIDR(proxy); err != nil {
|
||||
return fmt.Errorf("invalid proxy IP address or CIDR %q", proxy)
|
||||
}
|
||||
}
|
||||
proxies[i] = proxy
|
||||
}
|
||||
|
||||
|
||||
@@ -118,6 +118,7 @@ func TestParseEnvConfig(t *testing.T) {
|
||||
t.Setenv("METRICS_ENABLED", "true")
|
||||
t.Setenv("TRACING_ENABLED", "false")
|
||||
t.Setenv("TRUST_PROXY", "true")
|
||||
t.Setenv("PROXY_PROTOCOL", "true")
|
||||
t.Setenv("ANALYTICS_DISABLED", "false")
|
||||
t.Setenv("ALLOW_INSECURE_CALLBACK_URLS", "false")
|
||||
|
||||
@@ -125,6 +126,7 @@ func TestParseEnvConfig(t *testing.T) {
|
||||
require.NoError(t, err)
|
||||
assert.True(t, EnvConfig.UiConfigDisabled)
|
||||
assert.Equal(t, TrustProxyConfig{"0.0.0.0/0", "::/0"}, EnvConfig.TrustProxy)
|
||||
assert.Equal(t, TrustProxyConfig{"0.0.0.0/0", "::/0"}, EnvConfig.ProxyProtocol)
|
||||
assert.False(t, EnvConfig.AnalyticsDisabled)
|
||||
assert.False(t, EnvConfig.AllowInsecureCallbackURLs)
|
||||
})
|
||||
@@ -147,6 +149,34 @@ func TestParseEnvConfig(t *testing.T) {
|
||||
assert.Nil(t, EnvConfig.TrustProxy)
|
||||
})
|
||||
|
||||
t.Run("should parse PROXY protocol trusted proxy IP addresses and CIDR ranges", func(t *testing.T) {
|
||||
EnvConfig = defaultConfig()
|
||||
t.Setenv("PROXY_PROTOCOL", "10.0.0.0/8, 192.168.1.10, ::1/128")
|
||||
|
||||
err := parseAndValidateEnvConfig(t)
|
||||
require.NoError(t, err)
|
||||
assert.Equal(t, TrustProxyConfig{"10.0.0.0/8", "192.168.1.10", "::1/128"}, EnvConfig.ProxyProtocol)
|
||||
})
|
||||
|
||||
t.Run("should reject an invalid PROXY protocol trusted proxy", func(t *testing.T) {
|
||||
EnvConfig = defaultConfig()
|
||||
t.Setenv("PROXY_PROTOCOL", "not-an-ip")
|
||||
|
||||
err := parseAndValidateEnvConfig(t)
|
||||
require.Error(t, err)
|
||||
assert.ErrorContains(t, err, "invalid proxy IP address or CIDR")
|
||||
})
|
||||
|
||||
t.Run("should reject PROXY protocol with a UNIX socket", func(t *testing.T) {
|
||||
EnvConfig = defaultConfig()
|
||||
t.Setenv("PROXY_PROTOCOL", "true")
|
||||
t.Setenv("UNIX_SOCKET", "/tmp/pocket-id.sock")
|
||||
|
||||
err := parseAndValidateEnvConfig(t)
|
||||
require.Error(t, err)
|
||||
assert.ErrorContains(t, err, "PROXY_PROTOCOL and UNIX_SOCKET are mutually exclusive")
|
||||
})
|
||||
|
||||
t.Run("should allow insecure callback URLs by default", func(t *testing.T) {
|
||||
assert.True(t, defaultConfig().AllowInsecureCallbackURLs)
|
||||
})
|
||||
|
||||
Reference in New Issue
Block a user