package webhook import ( "context" "strings" "testing" ) // Chapter 23.3 names the ranges a webhook may never reach. Each is here. func TestDeniedAddresses(t *testing.T) { for _, addr := range []string{ "127.0.0.1:443", "127.9.9.9:443", "10.1.2.3:443", "172.16.0.1:443", "172.31.255.255:443", "192.168.1.1:443", "169.254.169.254:443", "100.64.0.1:443", "[::1]:443", "[fc00::1]:443", "[fe80::1]:443", "0.0.0.0:443", "[::]:443", "224.0.0.1:443", } { if err := AllowedAddr(addr); err == nil { t.Errorf("%s was allowed", addr) } } for _, addr := range []string{ "93.184.216.34:443", "8.8.8.8:443", "172.32.0.1:443", "[2606:2800::1]:443", } { if err := AllowedAddr(addr); err != nil { t.Errorf("%s was refused: %v", addr, err) } } } // The check is on the resolved address, and localhost is a plain name that answers loopback. func TestResolvedNotSpelled(t *testing.T) { ctx := context.Background() if err := Allowed(ctx, "https://localhost/hook"); err == nil { t.Error("localhost was allowed") } if err := Allowed(ctx, "https://127.0.0.1/hook"); err == nil { t.Error("a loopback literal was allowed") } } func TestSchemeAndShape(t *testing.T) { ctx := context.Background() for _, u := range []string{ "http://example.com/hook", // plain http would send the signature in clear "file:///etc/passwd", "gopher://example.com/", "https://", "not a url at all", "ftp://example.com/", } { if err := Allowed(ctx, u); err == nil { t.Errorf("%q was allowed", u) } } } // The config names the secret and never holds it, so the server's value must reproduce it. func TestSign(t *testing.T) { got := Sign("s3cret", []byte(`{"a":1}`)) if !strings.HasPrefix(got, "sha256=") || len(got) != 71 { t.Errorf("signature looks wrong: %s", got) } if Sign("s3cret", []byte(`{"a":1}`)) != got { t.Error("signing is not deterministic") } if Sign("other", []byte(`{"a":1}`)) == got { t.Error("a different secret produced the same signature") } if Sign("s3cret", []byte(`{"a":2}`)) == got { t.Error("a different body produced the same signature") } } func TestDeniedRangesAreListed(t *testing.T) { got := strings.Join(DeniedRanges(), " ") for _, want := range []string{"127.0.0.0/8", "169.254.0.0/16", "fc00::/7", "100.64.0.0/10"} { if !strings.Contains(got, want) { t.Errorf("%s is not in the list shown to operators", want) } } }