mirror of
https://github.com/gohugoio/hugo.git
synced 2026-08-24 15:28:54 +00:00
79f030be5b
Whitelist now treats any pattern prefixed with "! " (the same negation
prefix used by hglob/predicate) as a deny rule. Deny matches take
precedence over allow, and a whitelist made up exclusively of deny
rules implicitly allows everything it does not deny.
The default security.http.urls now reads:
urls = ['(?i)^https?://[a-z]', '! (?i)localhost', '! @']
i.e. allow URLs whose host starts with a letter (the common
"https://example.com" shape), deny anything that looks like localhost,
and deny URLs with userinfo to foil "http://user@127.0.0.1/" bypasses.
Public IP literals are collateral blocks; users who need them (or their
own private hosts) override security.http.urls as before, mixing allow
and deny rules with the same "! " prefix, e.g.
[security.http]
urls = ['.*', '! ^https?://evil\.example\.com']
Fixes #14792
68 lines
2.0 KiB
Go
68 lines
2.0 KiB
Go
// Copyright 2021 The Hugo Authors. All rights reserved.
|
|
//
|
|
// Licensed under the Apache License, Version 2.0 (the "License");
|
|
// you may not use this file except in compliance with the License.
|
|
// You may obtain a copy of the License at
|
|
// http://www.apache.org/licenses/LICENSE-2.0
|
|
//
|
|
// Unless required by applicable law or agreed to in writing, software
|
|
// distributed under the License is distributed on an "AS IS" BASIS,
|
|
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
// See the License for the specific language governing permissions and
|
|
// limitations under the License.
|
|
|
|
package security
|
|
|
|
import (
|
|
"testing"
|
|
|
|
qt "github.com/frankban/quicktest"
|
|
)
|
|
|
|
func TestWhitelist(t *testing.T) {
|
|
t.Parallel()
|
|
c := qt.New(t)
|
|
|
|
c.Run("none", func(c *qt.C) {
|
|
c.Assert(MustNewWhitelist("none", "foo").Accept("foo"), qt.IsFalse)
|
|
c.Assert(MustNewWhitelist().Accept("foo"), qt.IsFalse)
|
|
c.Assert(MustNewWhitelist("").Accept("foo"), qt.IsFalse)
|
|
c.Assert(MustNewWhitelist(" ", " ").Accept("foo"), qt.IsFalse)
|
|
c.Assert(Whitelist{}.Accept("foo"), qt.IsFalse)
|
|
})
|
|
|
|
c.Run("One", func(c *qt.C) {
|
|
w := MustNewWhitelist("^foo.*")
|
|
c.Assert(w.Accept("foo"), qt.IsTrue)
|
|
c.Assert(w.Accept("mfoo"), qt.IsFalse)
|
|
})
|
|
|
|
c.Run("Multiple", func(c *qt.C) {
|
|
w := MustNewWhitelist("^foo.*", "^bar.*")
|
|
c.Assert(w.Accept("foo"), qt.IsTrue)
|
|
c.Assert(w.Accept("bar"), qt.IsTrue)
|
|
c.Assert(w.Accept("mbar"), qt.IsFalse)
|
|
})
|
|
|
|
c.Run("Negation takes precedence", func(c *qt.C) {
|
|
w := MustNewWhitelist(".*", "! ^foo")
|
|
c.Assert(w.Accept("bar"), qt.IsTrue)
|
|
c.Assert(w.Accept("foo"), qt.IsFalse)
|
|
c.Assert(w.Accept("foobar"), qt.IsFalse)
|
|
})
|
|
|
|
c.Run("Negation only", func(c *qt.C) {
|
|
// A whitelist with only deny rules accepts everything else.
|
|
w := MustNewWhitelist("! ^foo")
|
|
c.Assert(w.Accept("bar"), qt.IsTrue)
|
|
c.Assert(w.Accept("foo"), qt.IsFalse)
|
|
})
|
|
|
|
c.Run("Bad pattern", func(c *qt.C) {
|
|
_, err := NewWhitelist("[invalid")
|
|
c.Assert(err, qt.IsNotNil)
|
|
_, err = NewWhitelist("! [invalid")
|
|
c.Assert(err, qt.IsNotNil)
|
|
})
|
|
}
|