58 lines
1.9 KiB
Python
58 lines
1.9 KiB
Python
import os
|
|
import tempfile
|
|
import unittest
|
|
|
|
_TEST_DATA_DIR = None
|
|
if "SOVEREIGNAI_DATA_DIR" not in os.environ:
|
|
_TEST_DATA_DIR = tempfile.TemporaryDirectory(prefix="sovereignai-web-tests-")
|
|
os.environ["SOVEREIGNAI_DATA_DIR"] = _TEST_DATA_DIR.name
|
|
|
|
from fastapi import HTTPException
|
|
|
|
from app.main import _PageText, _validate_public_http_url
|
|
|
|
|
|
class WebSecurityTests(unittest.TestCase):
|
|
def test_rejects_local_and_private_targets(self) -> None:
|
|
for url in (
|
|
"http://127.0.0.1/",
|
|
"http://10.0.0.5/",
|
|
"http://192.168.1.1/",
|
|
"http://169.254.169.254/latest/meta-data/",
|
|
"http://[::1]/",
|
|
"http://router.local/",
|
|
"file:///etc/passwd",
|
|
):
|
|
with self.subTest(url=url), self.assertRaises(HTTPException):
|
|
_validate_public_http_url(url)
|
|
|
|
def test_rejects_credentials_and_unapproved_ports(self) -> None:
|
|
for url in (
|
|
"https://user:pass@example.com/",
|
|
"http://example.com:8080/",
|
|
):
|
|
with self.subTest(url=url), self.assertRaises(HTTPException):
|
|
_validate_public_http_url(url)
|
|
|
|
def test_allows_public_ip_and_preserves_url(self) -> None:
|
|
url = "https://8.8.8.8/dns-query?q=hello"
|
|
|
|
self.assertEqual(_validate_public_http_url(url), url)
|
|
|
|
def test_html_extractor_omits_script_and_style_contents(self) -> None:
|
|
parser = _PageText()
|
|
parser.feed(
|
|
"<html><head><title>Research</title><style>hidden css</style></head>"
|
|
"<body><p>Visible text</p><script>secret instruction</script></body></html>"
|
|
)
|
|
text = " ".join(" ".join(parser.parts).split())
|
|
|
|
self.assertEqual(" ".join(parser.title.split()), "Research")
|
|
self.assertIn("Visible text", text)
|
|
self.assertNotIn("hidden css", text)
|
|
self.assertNotIn("secret instruction", text)
|
|
|
|
|
|
if __name__ == "__main__":
|
|
unittest.main()
|