1
0

outbound_validation_test.go 2.8 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667
  1. package xray
  2. import (
  3. "strings"
  4. "testing"
  5. )
  6. // TestValidateOutboundConfig_RejectsUnencryptedPublicVless covers xray-core
  7. // v26.7.11's refusal to build an unencrypted vless outbound to a public
  8. // address — the check now runs in-process, so the panel can surface it before
  9. // a config reaches the core and bricks startup. A private-address outbound and
  10. // a TLS outbound stay valid.
  11. func TestValidateOutboundConfig_RejectsUnencryptedPublicVless(t *testing.T) {
  12. publicPlaintext := `{
  13. "protocol": "vless",
  14. "settings": {"address": "1.2.3.4", "port": 443, "id": "b831381d-6324-4d53-ad4f-8cda48b30811", "encryption": "none"},
  15. "streamSettings": {"network": "tcp", "security": "none"}
  16. }`
  17. if err := ValidateOutboundConfig([]byte(publicPlaintext)); err == nil {
  18. t.Fatal("expected a public unencrypted vless outbound to be rejected")
  19. } else if !strings.Contains(err.Error(), "prohibited") {
  20. t.Fatalf("expected a prohibition error, got: %v", err)
  21. }
  22. privatePlaintext := `{
  23. "protocol": "vless",
  24. "settings": {"address": "10.0.0.1", "port": 443, "id": "b831381d-6324-4d53-ad4f-8cda48b30811", "encryption": "none"},
  25. "streamSettings": {"network": "tcp", "security": "none"}
  26. }`
  27. if err := ValidateOutboundConfig([]byte(privatePlaintext)); err != nil {
  28. t.Fatalf("a private-address plaintext vless outbound must stay valid, got: %v", err)
  29. }
  30. publicTLS := `{
  31. "protocol": "vless",
  32. "settings": {"address": "1.2.3.4", "port": 443, "id": "b831381d-6324-4d53-ad4f-8cda48b30811", "encryption": "none"},
  33. "streamSettings": {"network": "tcp", "security": "tls", "tlsSettings": {"serverName": "example.com"}}
  34. }`
  35. if err := ValidateOutboundConfig([]byte(publicTLS)); err != nil {
  36. t.Fatalf("a TLS-secured public vless outbound must stay valid, got: %v", err)
  37. }
  38. }
  39. // The core feeds remoteDNS to netip.MustParseAddr when it creates the outbound, so a
  40. // non-IP entry ("local" until 26.9.30) panics it at startup; conf.Build() lets it through.
  41. func TestValidateOutboundConfig_RejectsWireguardRemoteDNSThatIsNotAnIP(t *testing.T) {
  42. outbound := func(remoteDNS string) []byte {
  43. return []byte(`{
  44. "protocol": "wireguard",
  45. "settings": {
  46. "secretKey": "yAnz5TF+lXXJte14tji3zlMNq+hd2rYUIgJBgB3fBmk=",
  47. "address": ["10.0.0.2/32"],
  48. "peers": [{"publicKey": "xTIBA5rboUvnH4htodjb6e697QjLERt1NAB4mZqp8Dg=", "endpoint": "162.159.192.1:2408"}],
  49. "remoteDNS": ` + remoteDNS + `
  50. }
  51. }`)
  52. }
  53. for _, rejected := range []string{`["local"]`, `["1.1.1.1", "dns.google"]`} {
  54. err := ValidateOutboundConfig(outbound(rejected))
  55. if err == nil || !strings.Contains(err.Error(), "remoteDNS") {
  56. t.Errorf("remoteDNS %s: want a remoteDNS refusal, got %v", rejected, err)
  57. }
  58. }
  59. if err := ValidateOutboundConfig(outbound(`["1.1.1.1", "2606:4700:4700::1111"]`)); err != nil {
  60. t.Fatalf("IP remoteDNS entries must stay valid, got: %v", err)
  61. }
  62. }