Files
BetterDesk/web-nodejs/tests/ssrfGuard.test.js
UNITRONIX 647a3221f9 Harden console security and wire fixes into the update flow.
Hash RustDesk access tokens at rest (phase 1), add SSRF guards for admin network tools with LAN monitoring support, run dedicated console service user on Linux, and hook post-update verification plus service patching into both betterdesk.sh and the in-app updater.
2026-06-06 14:40:51 +02:00

60 lines
2.1 KiB
JavaScript

'use strict';
const {
isBlockedIp,
assertSafeHostname,
assertSafeResolvedHost,
assertSafeHttpUrl,
SsrfBlockedError,
} = require('../lib/ssrfGuard');
describe('ssrfGuard', () => {
describe('isBlockedIp', () => {
it('blocks loopback and RFC1918', () => {
expect(isBlockedIp('127.0.0.1')).toBe(true);
expect(isBlockedIp('10.0.0.1')).toBe(true);
expect(isBlockedIp('192.168.1.1')).toBe(true);
expect(isBlockedIp('169.254.169.254')).toBe(true);
});
it('allows public IPv4', () => {
expect(isBlockedIp('8.8.8.8')).toBe(false);
expect(isBlockedIp('1.1.1.1')).toBe(false);
});
it('allows RFC1918 in monitoring mode', () => {
expect(isBlockedIp('192.168.1.1', { allowPrivate: true })).toBe(false);
expect(isBlockedIp('10.0.0.1', { allowPrivate: true })).toBe(false);
expect(isBlockedIp('127.0.0.1', { allowPrivate: true })).toBe(true);
});
});
describe('assertSafeHostname', () => {
it('rejects localhost', () => {
expect(() => assertSafeHostname('localhost')).toThrow(SsrfBlockedError);
});
it('rejects private IPs', () => {
expect(() => assertSafeHostname('10.0.0.5')).toThrow(SsrfBlockedError);
});
});
describe('assertSafeHttpUrl', () => {
it('rejects file and internal schemes', async () => {
await expect(assertSafeHttpUrl('file:///etc/passwd')).rejects.toThrow(SsrfBlockedError);
await expect(assertSafeHttpUrl('http://127.0.0.1/')).rejects.toThrow(SsrfBlockedError);
});
it('allows public http URLs for public IPs without DNS', async () => {
const parsed = await assertSafeHttpUrl('http://1.1.1.1/');
expect(parsed.hostname).toBe('1.1.1.1');
});
});
describe('assertSafeResolvedHost', () => {
it('accepts public IPs without DNS lookup', async () => {
await expect(assertSafeResolvedHost('1.1.1.1')).resolves.toBe('1.1.1.1');
});
});
});