коммит произвёл
GitHub
родитель
d5190466de
Коммит
38208b8f06
@@ -9,6 +9,8 @@ import (
|
||||
"testing"
|
||||
|
||||
"github.com/stretchr/testify/assert"
|
||||
|
||||
"github.com/mattermost/mattermost/server/public/model"
|
||||
)
|
||||
|
||||
func TestStringArrayIntersection(t *testing.T) {
|
||||
@@ -432,3 +434,173 @@ func TestRoundOffToZeroesResolution(t *testing.T) {
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
func TestIsValidWebAuthRedirectURL(t *testing.T) {
|
||||
t.Run("Valid redirect URL with matching scheme and host", func(t *testing.T) {
|
||||
config := &model.Config{
|
||||
ServiceSettings: model.ServiceSettings{
|
||||
SiteURL: model.NewPointer("https://example.com"),
|
||||
},
|
||||
}
|
||||
redirectURL := "https://example.com/oauth/callback"
|
||||
|
||||
result := IsValidWebAuthRedirectURL(config, redirectURL)
|
||||
assert.True(t, result)
|
||||
})
|
||||
|
||||
t.Run("Valid redirect URL with matching scheme and host with port", func(t *testing.T) {
|
||||
config := &model.Config{
|
||||
ServiceSettings: model.ServiceSettings{
|
||||
SiteURL: model.NewPointer("https://example.com:8080"),
|
||||
},
|
||||
}
|
||||
redirectURL := "https://example.com:8080/oauth/callback"
|
||||
|
||||
result := IsValidWebAuthRedirectURL(config, redirectURL)
|
||||
assert.True(t, result)
|
||||
})
|
||||
|
||||
t.Run("Invalid redirect URL with different scheme", func(t *testing.T) {
|
||||
config := &model.Config{
|
||||
ServiceSettings: model.ServiceSettings{
|
||||
SiteURL: model.NewPointer("https://example.com"),
|
||||
},
|
||||
}
|
||||
redirectURL := "http://example.com/oauth/callback"
|
||||
|
||||
result := IsValidWebAuthRedirectURL(config, redirectURL)
|
||||
assert.False(t, result)
|
||||
})
|
||||
|
||||
t.Run("Invalid redirect URL with different host", func(t *testing.T) {
|
||||
config := &model.Config{
|
||||
ServiceSettings: model.ServiceSettings{
|
||||
SiteURL: model.NewPointer("https://example.com"),
|
||||
},
|
||||
}
|
||||
redirectURL := "https://malicious.com/oauth/callback"
|
||||
|
||||
result := IsValidWebAuthRedirectURL(config, redirectURL)
|
||||
assert.False(t, result)
|
||||
})
|
||||
|
||||
t.Run("Invalid redirect URL with different port", func(t *testing.T) {
|
||||
config := &model.Config{
|
||||
ServiceSettings: model.ServiceSettings{
|
||||
SiteURL: model.NewPointer("https://example.com:8080"),
|
||||
},
|
||||
}
|
||||
redirectURL := "https://example.com:9090/oauth/callback"
|
||||
|
||||
result := IsValidWebAuthRedirectURL(config, redirectURL)
|
||||
assert.False(t, result)
|
||||
})
|
||||
|
||||
t.Run("Invalid redirect URL - malformed URL", func(t *testing.T) {
|
||||
config := &model.Config{
|
||||
ServiceSettings: model.ServiceSettings{
|
||||
SiteURL: model.NewPointer("https://example.com"),
|
||||
},
|
||||
}
|
||||
redirectURL := "not-a-valid-url"
|
||||
|
||||
result := IsValidWebAuthRedirectURL(config, redirectURL)
|
||||
assert.False(t, result)
|
||||
})
|
||||
|
||||
t.Run("Invalid config - nil SiteURL", func(t *testing.T) {
|
||||
config := &model.Config{
|
||||
ServiceSettings: model.ServiceSettings{
|
||||
SiteURL: nil,
|
||||
},
|
||||
}
|
||||
redirectURL := "https://example.com/oauth/callback"
|
||||
|
||||
result := IsValidWebAuthRedirectURL(config, redirectURL)
|
||||
assert.False(t, result)
|
||||
})
|
||||
|
||||
t.Run("Invalid config - malformed SiteURL", func(t *testing.T) {
|
||||
config := &model.Config{
|
||||
ServiceSettings: model.ServiceSettings{
|
||||
SiteURL: model.NewPointer("not-a-valid-url"),
|
||||
},
|
||||
}
|
||||
redirectURL := "https://example.com/oauth/callback"
|
||||
|
||||
result := IsValidWebAuthRedirectURL(config, redirectURL)
|
||||
assert.False(t, result)
|
||||
})
|
||||
|
||||
t.Run("Valid redirect URL with subdomain", func(t *testing.T) {
|
||||
config := &model.Config{
|
||||
ServiceSettings: model.ServiceSettings{
|
||||
SiteURL: model.NewPointer("https://app.example.com"),
|
||||
},
|
||||
}
|
||||
redirectURL := "https://app.example.com/oauth/callback"
|
||||
|
||||
result := IsValidWebAuthRedirectURL(config, redirectURL)
|
||||
assert.True(t, result)
|
||||
})
|
||||
|
||||
t.Run("Invalid redirect URL with different subdomain", func(t *testing.T) {
|
||||
config := &model.Config{
|
||||
ServiceSettings: model.ServiceSettings{
|
||||
SiteURL: model.NewPointer("https://app.example.com"),
|
||||
},
|
||||
}
|
||||
redirectURL := "https://api.example.com/oauth/callback"
|
||||
|
||||
result := IsValidWebAuthRedirectURL(config, redirectURL)
|
||||
assert.False(t, result)
|
||||
})
|
||||
|
||||
t.Run("Valid redirect URL with path", func(t *testing.T) {
|
||||
config := &model.Config{
|
||||
ServiceSettings: model.ServiceSettings{
|
||||
SiteURL: model.NewPointer("https://example.com/mattermost"),
|
||||
},
|
||||
}
|
||||
redirectURL := "https://example.com/mattermost/oauth/callback"
|
||||
|
||||
result := IsValidWebAuthRedirectURL(config, redirectURL)
|
||||
assert.True(t, result)
|
||||
})
|
||||
|
||||
t.Run("Valid redirect URL with query parameters", func(t *testing.T) {
|
||||
config := &model.Config{
|
||||
ServiceSettings: model.ServiceSettings{
|
||||
SiteURL: model.NewPointer("https://example.com"),
|
||||
},
|
||||
}
|
||||
redirectURL := "https://example.com/oauth/callback?state=abc123&code=def456"
|
||||
|
||||
result := IsValidWebAuthRedirectURL(config, redirectURL)
|
||||
assert.True(t, result)
|
||||
})
|
||||
|
||||
t.Run("Valid redirect URL with fragment", func(t *testing.T) {
|
||||
config := &model.Config{
|
||||
ServiceSettings: model.ServiceSettings{
|
||||
SiteURL: model.NewPointer("https://example.com"),
|
||||
},
|
||||
}
|
||||
redirectURL := "https://example.com/oauth/callback#token=abc123"
|
||||
|
||||
result := IsValidWebAuthRedirectURL(config, redirectURL)
|
||||
assert.True(t, result)
|
||||
})
|
||||
|
||||
t.Run("Invalid redirect URL with @ symbol in host", func(t *testing.T) {
|
||||
config := &model.Config{
|
||||
ServiceSettings: model.ServiceSettings{
|
||||
SiteURL: model.NewPointer("https://qa-release.test.mattermost.cloud"),
|
||||
},
|
||||
}
|
||||
redirectURL := "https://qa-release.test.mattermost.cloud@example.com/oauth/callback"
|
||||
|
||||
result := IsValidWebAuthRedirectURL(config, redirectURL)
|
||||
assert.False(t, result)
|
||||
})
|
||||
}
|
||||
|
||||
Ссылка в новой задаче
Block a user