setting_security_test.go 3.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102
  1. package service
  2. import (
  3. "path/filepath"
  4. "testing"
  5. "github.com/mhsanaei/3x-ui/v3/internal/database"
  6. "github.com/mhsanaei/3x-ui/v3/internal/database/model"
  7. )
  8. func setupSettingTestDB(t *testing.T) {
  9. t.Helper()
  10. if err := database.InitDB(filepath.Join(t.TempDir(), "x-ui.db")); err != nil {
  11. t.Fatal(err)
  12. }
  13. t.Cleanup(func() {
  14. if err := database.CloseDB(); err != nil {
  15. t.Fatal(err)
  16. }
  17. })
  18. }
  19. func TestGetAllSettingViewRedactsSecrets(t *testing.T) {
  20. setupSettingTestDB(t)
  21. s := &SettingService{}
  22. if err := s.saveSetting("tgBotToken", "telegram-secret"); err != nil {
  23. t.Fatal(err)
  24. }
  25. if err := s.saveSetting("twoFactorToken", "totp-secret"); err != nil {
  26. t.Fatal(err)
  27. }
  28. if err := s.saveSetting("ldapPassword", "ldap-secret"); err != nil {
  29. t.Fatal(err)
  30. }
  31. if err := s.saveSetting("smtpPassword", "smtp-secret"); err != nil {
  32. t.Fatal(err)
  33. }
  34. if err := database.GetDB().Create(&model.ApiToken{Name: "test", Token: "api-secret", Enabled: true}).Error; err != nil {
  35. t.Fatal(err)
  36. }
  37. view, err := s.GetAllSettingView()
  38. if err != nil {
  39. t.Fatal(err)
  40. }
  41. if view.TgBotToken != "" || view.TwoFactorToken != "" || view.LdapPassword != "" || view.SmtpPassword != "" {
  42. t.Fatalf("settings view leaked secrets: %#v", view)
  43. }
  44. if !view.HasTgBotToken || !view.HasTwoFactorToken || !view.HasLdapPassword || !view.HasApiToken || !view.HasSmtpPassword {
  45. t.Fatalf("settings view did not report configured secret flags: %#v", view)
  46. }
  47. }
  48. func TestUpdateAllSettingPreservesRedactedSecrets(t *testing.T) {
  49. setupSettingTestDB(t)
  50. s := &SettingService{}
  51. if err := s.saveSetting("tgBotToken", "telegram-secret"); err != nil {
  52. t.Fatal(err)
  53. }
  54. if err := s.saveSetting("ldapPassword", "ldap-secret"); err != nil {
  55. t.Fatal(err)
  56. }
  57. if err := s.saveSetting("twoFactorEnable", "true"); err != nil {
  58. t.Fatal(err)
  59. }
  60. if err := s.saveSetting("twoFactorToken", "totp-secret"); err != nil {
  61. t.Fatal(err)
  62. }
  63. if err := s.saveSetting("smtpPassword", "smtp-secret"); err != nil {
  64. t.Fatal(err)
  65. }
  66. view, err := s.GetAllSettingView()
  67. if err != nil {
  68. t.Fatal(err)
  69. }
  70. settings := &view.AllSetting
  71. if err := s.UpdateAllSetting(settings); err != nil {
  72. t.Fatal(err)
  73. }
  74. if got, _ := s.GetTgBotToken(); got != "telegram-secret" {
  75. t.Fatalf("tg token = %q, want preserved secret", got)
  76. }
  77. if got, _ := s.GetLdapPassword(); got != "ldap-secret" {
  78. t.Fatalf("ldap password = %q, want preserved secret", got)
  79. }
  80. if got, _ := s.GetTwoFactorToken(); got != "totp-secret" {
  81. t.Fatalf("2fa token = %q, want preserved secret", got)
  82. }
  83. if got, _ := s.GetSmtpPassword(); got != "smtp-secret" {
  84. t.Fatalf("smtp password = %q, want preserved secret", got)
  85. }
  86. }
  87. func TestSanitizePublicHTTPURLBlocksPrivateAddressUnlessAllowed(t *testing.T) {
  88. if _, err := SanitizePublicHTTPURL("http://127.0.0.1:8080/hook", false); err == nil {
  89. t.Fatal("expected localhost URL to be blocked")
  90. }
  91. if got, err := SanitizePublicHTTPURL("http://127.0.0.1:8080/hook", true); err != nil || got != "http://127.0.0.1:8080/hook" {
  92. t.Fatalf("allowPrivate result = %q, %v", got, err)
  93. }
  94. }