Files
hugo/config/security/whitelist_test.go
T
Bjørn Erik Pedersen 79f030be5b config/security: Add "! " negation to Whitelist, harden default http.urls
Whitelist now treats any pattern prefixed with "! " (the same negation
prefix used by hglob/predicate) as a deny rule. Deny matches take
precedence over allow, and a whitelist made up exclusively of deny
rules implicitly allows everything it does not deny.

The default security.http.urls now reads:

    urls = ['(?i)^https?://[a-z]', '! (?i)localhost', '! @']

i.e. allow URLs whose host starts with a letter (the common
"https://example.com" shape), deny anything that looks like localhost,
and deny URLs with userinfo to foil "http://user@127.0.0.1/" bypasses.
Public IP literals are collateral blocks; users who need them (or their
own private hosts) override security.http.urls as before, mixing allow
and deny rules with the same "! " prefix, e.g.

    [security.http]
    urls = ['.*', '! ^https?://evil\.example\.com']

Fixes #14792
2026-04-22 20:15:19 +02:00

68 lines
2.0 KiB
Go

// Copyright 2021 The Hugo Authors. All rights reserved.
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
package security
import (
"testing"
qt "github.com/frankban/quicktest"
)
func TestWhitelist(t *testing.T) {
t.Parallel()
c := qt.New(t)
c.Run("none", func(c *qt.C) {
c.Assert(MustNewWhitelist("none", "foo").Accept("foo"), qt.IsFalse)
c.Assert(MustNewWhitelist().Accept("foo"), qt.IsFalse)
c.Assert(MustNewWhitelist("").Accept("foo"), qt.IsFalse)
c.Assert(MustNewWhitelist(" ", " ").Accept("foo"), qt.IsFalse)
c.Assert(Whitelist{}.Accept("foo"), qt.IsFalse)
})
c.Run("One", func(c *qt.C) {
w := MustNewWhitelist("^foo.*")
c.Assert(w.Accept("foo"), qt.IsTrue)
c.Assert(w.Accept("mfoo"), qt.IsFalse)
})
c.Run("Multiple", func(c *qt.C) {
w := MustNewWhitelist("^foo.*", "^bar.*")
c.Assert(w.Accept("foo"), qt.IsTrue)
c.Assert(w.Accept("bar"), qt.IsTrue)
c.Assert(w.Accept("mbar"), qt.IsFalse)
})
c.Run("Negation takes precedence", func(c *qt.C) {
w := MustNewWhitelist(".*", "! ^foo")
c.Assert(w.Accept("bar"), qt.IsTrue)
c.Assert(w.Accept("foo"), qt.IsFalse)
c.Assert(w.Accept("foobar"), qt.IsFalse)
})
c.Run("Negation only", func(c *qt.C) {
// A whitelist with only deny rules accepts everything else.
w := MustNewWhitelist("! ^foo")
c.Assert(w.Accept("bar"), qt.IsTrue)
c.Assert(w.Accept("foo"), qt.IsFalse)
})
c.Run("Bad pattern", func(c *qt.C) {
_, err := NewWhitelist("[invalid")
c.Assert(err, qt.IsNotNil)
_, err = NewWhitelist("! [invalid")
c.Assert(err, qt.IsNotNil)
})
}