Files
Gitea/services/migrations/migrate_test.go
T
TheFox0x7 1b1274486c fix(git)!: use internal proxy for all git operations (#39426)
Introduces gitproxy module which spawns a small forward proxy as scanner
for git calls
Replaces hostmatcher with matchlist which supports port rules
Deprecates ALLOWED_DOMAINS/BLOCKED_DOMAINS and ALLOW_LOCALNETWORKS
settings in migration in favor of full names we have in security
configs.
Removes `external` preset in favor of lax/strict modes, strict mode
requiring explicit ports if they aren't standard http/s ones.

Breaking changes:
- `external` preset no longer works as deny rule. To enforce that, use
`strict` mode and allow ranges to connect to
- Wildcards are no longer accepted in IP addresses
- `*` is no longer allowed as entry in lists
- domain rules now use curl like syntax `*.example.com` matching
subdomains but not `example.com`, `example.com` matching itself and all
subdomains. `example.*` is not a valid rule
- In the default `lax` mode, `[security] ALLOWED_HOST_LIST` no longer
restricts public hosts, set `EGRESS_MODE = strict` to keep an exclusive
list. A startup warning flags this
- Invalid list entries are logged at startup, invalid
`BLOCKED_HOST_LIST`/`BLOCKED_DOMAINS` entries stop it

Docs: https://gitea.com/gitea/docs/pulls/557
Signed-off-by: wxiaoguang <wxiaoguang@gmail.com>
Co-authored-by: silverwind <me@silverwind.io>
Co-authored-by: bircni <bircni@icloud.com>
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
2026-09-29 14:43:36 +02:00

71 lines
2.3 KiB
Go

// Copyright 2019 The Gitea Authors. All rights reserved.
// SPDX-License-Identifier: MIT
package migrations
import (
"errors"
"fmt"
"net/http"
"path/filepath"
"testing"
user_model "gitea.dev/models/user"
"gitea.dev/modules/git/gitcmd"
"gitea.dev/modules/setting"
"gitea.dev/modules/test"
"gitea.dev/modules/util"
"github.com/google/go-github/v92/github"
"github.com/stretchr/testify/assert"
)
func TestIsAuthenticationError(t *testing.T) {
errDummy := errors.New("dummy")
cases := []struct {
name string
want bool
err error
}{
{"git authentication failed", true, gitcmd.NewRunStdError(errDummy, "fatal: Authentication failed for 'https://host/repo.git/'")},
{"git could not read username", true, fmt.Errorf("%w", gitcmd.NewRunStdError(errDummy, "fatal: could not read Username for 'https://host'"))},
{"github unauthorized", true, util.SanitizeErrorCredentialURLs(&github.ErrorResponse{Response: &http.Response{StatusCode: http.StatusUnauthorized}})},
{"github other", false, &github.ErrorResponse{Response: &http.Response{StatusCode: http.StatusNotFound}}},
{"github nil response", false, &github.ErrorResponse{}},
{"unrelated error", false, errDummy},
}
for _, c := range cases {
t.Run(c.name, func(t *testing.T) {
assert.Equal(t, c.want, IsAuthenticationError(c.err))
})
}
}
func TestMigrateWhiteBlocklist(t *testing.T) {
adminUser := &user_model.User{IsAdmin: true}
nonAdminUser := &user_model.User{}
defer test.MockVariableValue(&setting.Migrations.AllowedHostList, "")()
defer test.MockVariableValue(&setting.Migrations.BlockedHostList, "8.8.4.4")()
assert.NoError(t, IsMigrateURLAllowed("https://8.8.8.8/go-gitea/gitea.git", nonAdminUser))
assert.Error(t, IsMigrateURLAllowed("https://8.8.4.4/go-gitea/gitea.git", nonAdminUser))
assert.Error(t, IsMigrateURLAllowed("https://[64:ff9b::a9fe:a9fe]/go-gitea/gitea.git", nonAdminUser))
old := setting.ImportLocalPaths
setting.ImportLocalPaths = false
assert.Error(t, IsMigrateURLAllowed("/home/foo/bar/goo", adminUser))
setting.ImportLocalPaths = true
abs, err := filepath.Abs(".")
assert.NoError(t, err)
assert.NoError(t, IsMigrateURLAllowed(abs, adminUser))
assert.Error(t, IsMigrateURLAllowed(abs, nonAdminUser))
nonAdminUser.AllowImportLocal = true
assert.NoError(t, IsMigrateURLAllowed(abs, nonAdminUser))
setting.ImportLocalPaths = old
}