-
Notifications
You must be signed in to change notification settings - Fork 327
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
PB-39045 Fix fullBaseUrl should not fallback to Host header if PASSBO…
…LT_SECURITY_PREVENT_HOST_HEADER_FALLBACK is set to true
- Loading branch information
1 parent
d9bb992
commit 09a528d
Showing
12 changed files
with
272 additions
and
123 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
82 changes: 82 additions & 0 deletions
82
tests/TestCase/Middleware/AssertFullBaseUrlMiddlewareTest.php
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,82 @@ | ||
<?php | ||
declare(strict_types=1); | ||
|
||
/** | ||
* Passbolt ~ Open source password manager for teams | ||
* Copyright (c) Passbolt SA (https://www.passbolt.com) | ||
* | ||
* Licensed under GNU Affero General Public License version 3 of the or any later version. | ||
* For full copyright and license information, please see the LICENSE.txt | ||
* Redistributions of files must retain the above copyright notice. | ||
* | ||
* @copyright Copyright (c) Passbolt SA (https://www.passbolt.com) | ||
* @license https://opensource.org/licenses/AGPL-3.0 AGPL License | ||
* @link https://www.passbolt.com Passbolt(tm) | ||
* @since 4.11.1 | ||
*/ | ||
|
||
namespace App\Test\TestCase\Middleware; | ||
|
||
use App\Middleware\AssertFullBaseUrlMiddleware; | ||
use App\Test\Lib\AppIntegrationTestCase; | ||
use App\Test\Lib\Http\TestRequestHandler; | ||
use Cake\Core\Configure; | ||
use Cake\Http\Exception\InternalErrorException; | ||
use Cake\Http\Response; | ||
use Cake\Http\ServerRequest; | ||
|
||
/** | ||
* @covers \App\Middleware\AssertFullBaseUrlMiddleware | ||
*/ | ||
class AssertFullBaseUrlMiddlewareTest extends AppIntegrationTestCase | ||
{ | ||
/** | ||
* @dataProvider invalidFullBaseUrlValuesProvider | ||
* @param mixed $invalidFullBaseUrl Invalid values. | ||
* @return void | ||
*/ | ||
public function testAssertFullBaseUrlMiddleware_DisallowInvalidFullBaseUrl_FlagIsTrue($invalidFullBaseUrl): void | ||
{ | ||
Configure::write('passbolt.originalFullBaseUrl', $invalidFullBaseUrl); | ||
Configure::write('passbolt.security.fullBaseUrlEnforce', true); | ||
|
||
$this->expectException(InternalErrorException::class); | ||
|
||
$middleware = new AssertFullBaseUrlMiddleware(); | ||
$middleware->process((new ServerRequest()), new TestRequestHandler()); | ||
} | ||
|
||
public function invalidFullBaseUrlValuesProvider(): array | ||
{ | ||
return [ | ||
[false], | ||
[true], | ||
[null], | ||
[''], | ||
[[]], | ||
[new \stdClass()], | ||
]; | ||
} | ||
|
||
public function testAssertFullBaseUrlMiddleware_ValidFullBaseUrl_FlagIsTrue(): void | ||
{ | ||
Configure::write('passbolt.originalFullBaseUrl', 'https://passbolt.test'); | ||
Configure::write('passbolt.security.fullBaseUrlEnforce', true); | ||
|
||
$middleware = new AssertFullBaseUrlMiddleware(); | ||
$response = $middleware->process((new ServerRequest()), new TestRequestHandler()); | ||
|
||
$this->assertInstanceOf(Response::class, $response); | ||
} | ||
|
||
public function testAssertFullBaseUrlMiddleware_AllowInvalidFullBaseUrl_FlagIsFalse(): void | ||
{ | ||
Configure::write('passbolt.originalFullBaseUrl', false); | ||
Configure::write('passbolt.security.fullBaseUrlEnforce', false); | ||
|
||
$middleware = new AssertFullBaseUrlMiddleware(); | ||
$response = $middleware->process(new ServerRequest(), new TestRequestHandler()); | ||
|
||
$this->assertInstanceOf(Response::class, $response); | ||
} | ||
} |
98 changes: 0 additions & 98 deletions
98
tests/TestCase/Middleware/PreventHostHeaderFallbackMiddlewareTest.php
This file was deleted.
Oops, something went wrong.
Oops, something went wrong.