mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-10-05 06:59:42 +02:00
fix: COD-29 harden downloads and extract auth policy
This commit is contained in:
@@ -0,0 +1,26 @@
|
||||
import { describe, expect, it } from 'vitest';
|
||||
import { isExplicitlyEnabled, isLoopbackBindHost } from '../src/web/network-auth-policy.js';
|
||||
|
||||
describe('network auth policy', () => {
|
||||
it.each(['localhost', '127.0.0.1', '127.42.0.9', '::1', '[::1]', '0:0:0:0:0:0:0:1', '::ffff:127.0.0.1'])(
|
||||
'treats %s as loopback',
|
||||
(host) => {
|
||||
expect(isLoopbackBindHost(host)).toBe(true);
|
||||
}
|
||||
);
|
||||
|
||||
it.each(['0.0.0.0', '192.168.1.10', '10.0.0.1', 'example.com', '::', '[::]', '::ffff:192.168.1.10'])(
|
||||
'treats %s as non-loopback',
|
||||
(host) => {
|
||||
expect(isLoopbackBindHost(host)).toBe(false);
|
||||
}
|
||||
);
|
||||
|
||||
it.each(['1', 'true', 'TRUE', ' yes ', 'on'])('treats %s as an explicit opt-in', (value) => {
|
||||
expect(isExplicitlyEnabled(value)).toBe(true);
|
||||
});
|
||||
|
||||
it.each([undefined, '', '0', 'false', 'no', 'off', 'enabled'])('does not treat %s as an explicit opt-in', (value) => {
|
||||
expect(isExplicitlyEnabled(value)).toBe(false);
|
||||
});
|
||||
});
|
||||
@@ -305,6 +305,22 @@ describe('file-routes', () => {
|
||||
expect(res.headers['content-type']).toBe('image/png');
|
||||
});
|
||||
|
||||
it('serves workspace SVG as an untrusted attachment instead of inline image/svg+xml', async () => {
|
||||
const content = Buffer.from('<svg><script>alert("xss")</script></svg>');
|
||||
mockedReadFile.mockResolvedValue(content as never);
|
||||
mockedStat.mockResolvedValue({ size: content.length } as never);
|
||||
|
||||
const res = await harness.app.inject({
|
||||
method: 'GET',
|
||||
url: `/api/sessions/${harness.ctx._sessionId}/file-raw?path=malicious.svg`,
|
||||
});
|
||||
|
||||
expect(res.statusCode).toBe(200);
|
||||
expect(res.headers['content-type']).toBe('application/octet-stream');
|
||||
expect(res.headers['content-disposition']).toContain('attachment; filename="malicious.svg"');
|
||||
expect(res.headers['x-content-type-options']).toBe('nosniff');
|
||||
});
|
||||
|
||||
it('rejects path traversal in raw file serving', async () => {
|
||||
mockedRealpathSync.mockReturnValue('/etc/shadow' as never);
|
||||
|
||||
|
||||
Reference in New Issue
Block a user