mirror of
https://github.com/go-gitea/gitea.git
synced 2026-10-02 04:35:53 +00:00
1b1274486c
Introduces gitproxy module which spawns a small forward proxy as scanner for git calls Replaces hostmatcher with matchlist which supports port rules Deprecates ALLOWED_DOMAINS/BLOCKED_DOMAINS and ALLOW_LOCALNETWORKS settings in migration in favor of full names we have in security configs. Removes `external` preset in favor of lax/strict modes, strict mode requiring explicit ports if they aren't standard http/s ones. Breaking changes: - `external` preset no longer works as deny rule. To enforce that, use `strict` mode and allow ranges to connect to - Wildcards are no longer accepted in IP addresses - `*` is no longer allowed as entry in lists - domain rules now use curl like syntax `*.example.com` matching subdomains but not `example.com`, `example.com` matching itself and all subdomains. `example.*` is not a valid rule - In the default `lax` mode, `[security] ALLOWED_HOST_LIST` no longer restricts public hosts, set `EGRESS_MODE = strict` to keep an exclusive list. A startup warning flags this - Invalid list entries are logged at startup, invalid `BLOCKED_HOST_LIST`/`BLOCKED_DOMAINS` entries stop it Docs: https://gitea.com/gitea/docs/pulls/557 Signed-off-by: wxiaoguang <wxiaoguang@gmail.com> Co-authored-by: silverwind <me@silverwind.io> Co-authored-by: bircni <bircni@icloud.com> Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
108 lines
3.4 KiB
Go
108 lines
3.4 KiB
Go
// Copyright 2021 The Gitea Authors. All rights reserved.
|
|
// SPDX-License-Identifier: MIT
|
|
|
|
package auth
|
|
|
|
import (
|
|
"net/http"
|
|
"net/http/httptest"
|
|
"sync/atomic"
|
|
"testing"
|
|
|
|
"gitea.dev/models/auth"
|
|
"gitea.dev/models/unittest"
|
|
user_model "gitea.dev/models/user"
|
|
"gitea.dev/modules/egress/policy"
|
|
"gitea.dev/services/oauth2_provider"
|
|
|
|
"github.com/golang-jwt/jwt/v5"
|
|
"github.com/stretchr/testify/assert"
|
|
"github.com/stretchr/testify/require"
|
|
)
|
|
|
|
func createAndParseToken(t *testing.T, grant *auth.OAuth2Grant) *oauth2_provider.OIDCToken {
|
|
signingKey, err := oauth2_provider.CreateJWTSigningKey("HS256", make([]byte, 32))
|
|
assert.NoError(t, err)
|
|
assert.NotNil(t, signingKey)
|
|
|
|
response, terr := oauth2_provider.NewAccessTokenResponse(t.Context(), grant, signingKey, signingKey)
|
|
assert.Nil(t, terr)
|
|
assert.NotNil(t, response)
|
|
|
|
parsedToken, err := jwt.ParseWithClaims(response.IDToken, &oauth2_provider.OIDCToken{}, func(token *jwt.Token) (any, error) {
|
|
assert.NotNil(t, token.Method)
|
|
assert.Equal(t, signingKey.SigningMethod().Alg(), token.Method.Alg())
|
|
return signingKey.VerifyKey(), nil
|
|
})
|
|
assert.NoError(t, err)
|
|
assert.True(t, parsedToken.Valid)
|
|
|
|
oidcToken, ok := parsedToken.Claims.(*oauth2_provider.OIDCToken)
|
|
assert.True(t, ok)
|
|
assert.NotNil(t, oidcToken)
|
|
|
|
return oidcToken
|
|
}
|
|
|
|
func TestNewAccessTokenResponse_OIDCToken(t *testing.T) {
|
|
assert.NoError(t, unittest.PrepareTestDatabase())
|
|
|
|
grants, err := auth.GetOAuth2GrantsByUserID(t.Context(), 3)
|
|
assert.NoError(t, err)
|
|
assert.Len(t, grants, 1)
|
|
|
|
// Scopes: openid
|
|
oidcToken := createAndParseToken(t, grants[0])
|
|
assert.Empty(t, oidcToken.Name)
|
|
assert.Empty(t, oidcToken.PreferredUsername)
|
|
assert.Empty(t, oidcToken.Profile)
|
|
assert.Empty(t, oidcToken.Picture)
|
|
assert.Empty(t, oidcToken.Website)
|
|
assert.Empty(t, oidcToken.UpdatedAt)
|
|
assert.Empty(t, oidcToken.Email)
|
|
assert.False(t, oidcToken.EmailVerified)
|
|
|
|
user := unittest.AssertExistsAndLoadBean(t, &user_model.User{ID: 5})
|
|
grants, err = auth.GetOAuth2GrantsByUserID(t.Context(), user.ID)
|
|
assert.NoError(t, err)
|
|
assert.Len(t, grants, 1)
|
|
|
|
// Scopes: openid profile email
|
|
oidcToken = createAndParseToken(t, grants[0])
|
|
assert.Equal(t, user.DisplayName(), oidcToken.Name)
|
|
assert.Equal(t, user.Name, oidcToken.PreferredUsername)
|
|
assert.Equal(t, user.HTMLURL(t.Context()), oidcToken.Profile)
|
|
assert.Equal(t, user.AvatarLink(t.Context()), oidcToken.Picture)
|
|
assert.Equal(t, user.Website, oidcToken.Website)
|
|
assert.Equal(t, user.UpdatedUnix, oidcToken.UpdatedAt)
|
|
assert.Equal(t, user.Email, oidcToken.Email)
|
|
assert.Equal(t, user.IsActive, oidcToken.EmailVerified)
|
|
}
|
|
|
|
func TestOAuth2AvatarClientBlocksLoopback(t *testing.T) {
|
|
var hit atomic.Bool
|
|
srv := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
hit.Store(true)
|
|
_, _ = w.Write([]byte("img"))
|
|
}))
|
|
defer srv.Close()
|
|
|
|
// the httptest server binds a loopback address, which the SSRF-protected dialer must refuse
|
|
resp, err := oauth2AvatarHTTPClient().Get(srv.URL)
|
|
if resp != nil {
|
|
_ = resp.Body.Close()
|
|
}
|
|
require.Error(t, err)
|
|
assert.False(t, hit.Load(), "avatar client must refuse to dial a loopback address")
|
|
}
|
|
|
|
func TestOAuth2AvatarClientBlocksCloudMetadata(t *testing.T) {
|
|
resp, err := oauth2AvatarHTTPClient().Get("http://169.254.169.254/latest/meta-data/")
|
|
if resp != nil {
|
|
_ = resp.Body.Close()
|
|
}
|
|
require.Error(t, err)
|
|
assert.ErrorIs(t, err, policy.ErrDenied,
|
|
"avatar client must refuse a link-local cloud-metadata address")
|
|
}
|