Fix command url validation (#15239)
* Fix command url validation * Add Host and Scheme check in IsValidHttpUrl func * Add unit tests Co-authored-by: Mattermod <mattermod@users.noreply.github.com>
Этот коммит содержится в:
коммит произвёл
GitHub
родитель
32fc41d807
Коммит
f73157dd8f
@@ -86,6 +86,9 @@ func TestCommandIsValid(t *testing.T) {
|
|||||||
o.URL = "1234"
|
o.URL = "1234"
|
||||||
require.NotNil(t, o.IsValid(), "should be invalid")
|
require.NotNil(t, o.IsValid(), "should be invalid")
|
||||||
|
|
||||||
|
o.URL = "https:////example.com"
|
||||||
|
require.NotNil(t, o.IsValid(), "should be invalid")
|
||||||
|
|
||||||
o.URL = "https://example.com"
|
o.URL = "https://example.com"
|
||||||
require.Nil(t, o.IsValid())
|
require.Nil(t, o.IsValid())
|
||||||
|
|
||||||
|
|||||||
@@ -496,7 +496,7 @@ func IsValidHttpUrl(rawUrl string) bool {
|
|||||||
return false
|
return false
|
||||||
}
|
}
|
||||||
|
|
||||||
if _, err := url.ParseRequestURI(rawUrl); err != nil {
|
if u, err := url.ParseRequestURI(rawUrl); err != nil || u.Scheme == "" || u.Host == "" {
|
||||||
return false
|
return false
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -776,3 +776,93 @@ func TestSanitizeUnicode(t *testing.T) {
|
|||||||
})
|
})
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func TestIsValidHttpUrl(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
testCases := []struct {
|
||||||
|
Description string
|
||||||
|
Value string
|
||||||
|
Expected bool
|
||||||
|
}{
|
||||||
|
{
|
||||||
|
"empty url",
|
||||||
|
"",
|
||||||
|
false,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"bad url",
|
||||||
|
"bad url",
|
||||||
|
false,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"relative url",
|
||||||
|
"/api/test",
|
||||||
|
false,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"relative url ending with slash",
|
||||||
|
"/some/url/",
|
||||||
|
false,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"url with invalid scheme",
|
||||||
|
"htp://mattermost.com",
|
||||||
|
false,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"url with just http",
|
||||||
|
"http://",
|
||||||
|
false,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"url with just https",
|
||||||
|
"https://",
|
||||||
|
false,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"url with extra slashes",
|
||||||
|
"https:///mattermost.com",
|
||||||
|
false,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"correct url with http scheme",
|
||||||
|
"http://mattemost.com",
|
||||||
|
true,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"correct url with https scheme",
|
||||||
|
"https://mattermost.com/api/test",
|
||||||
|
true,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"correct url with port",
|
||||||
|
"https://localhost:8080/test",
|
||||||
|
true,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"correct url without scheme",
|
||||||
|
"mattermost.com/some/url/",
|
||||||
|
false,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"correct url with extra slashes",
|
||||||
|
"https://mattermost.com/some//url",
|
||||||
|
true,
|
||||||
|
},
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, testCase := range testCases {
|
||||||
|
testCase := testCase
|
||||||
|
t.Run(testCase.Description, func(t *testing.T) {
|
||||||
|
defer func() {
|
||||||
|
if r := recover(); r != nil {
|
||||||
|
t.Errorf("panic: %v", r)
|
||||||
|
}
|
||||||
|
}()
|
||||||
|
|
||||||
|
t.Parallel()
|
||||||
|
require.Equal(t, testCase.Expected, IsValidHttpUrl(testCase.Value))
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|||||||
Ссылка в новой задаче
Block a user