65 lines
2.4 KiB
Go
65 lines
2.4 KiB
Go
package config
|
|
|
|
import (
|
|
"os"
|
|
"strings"
|
|
"testing"
|
|
)
|
|
|
|
func TestNonprodRealAcceptsConfiguredExternalEndpointsOnly(t *testing.T) {
|
|
for _, tc := range []struct{ saas, mq string }{
|
|
{"http://saas.example.invalid", "amqp://synthetic:placeholder@mq.example.invalid:5672/test"},
|
|
{"https://saas.example.invalid", "amqps://synthetic:placeholder@mq.example.invalid:5671/test"},
|
|
} {
|
|
path := setCurrentDispatcherRuntimeEnvironment(t)
|
|
t.Setenv("SAAS_BASE_URL", tc.saas)
|
|
t.Setenv("RABBITMQ_URL", tc.mq)
|
|
settings, err := LoadDispatcherRuntimeEnvironment("nonprod-real")
|
|
if err != nil || settings.SaaSBaseURL != tc.saas || settings.RabbitMQURL != tc.mq {
|
|
t.Fatalf("explicit endpoints were rejected or rewritten: %v", err)
|
|
}
|
|
if _, err := os.Stat(path); !os.IsNotExist(err) {
|
|
t.Fatalf("validation opened SQLite: %v", err)
|
|
}
|
|
}
|
|
}
|
|
|
|
func TestMockAndSIPOnlyStillRejectExternalEndpoints(t *testing.T) {
|
|
for _, mode := range []string{"mock", "sip-only"} {
|
|
for _, name := range []string{"SAAS_BASE_URL", "RABBITMQ_URL"} {
|
|
t.Run(mode+"/"+name, func(t *testing.T) {
|
|
setDispatcherEnvironment(t)
|
|
value := "https://external.example.invalid"
|
|
if name == "RABBITMQ_URL" {
|
|
value = "amqps://synthetic:placeholder@external.example.invalid/test"
|
|
}
|
|
t.Setenv(name, value)
|
|
if _, err := LoadDispatcherEnvironment(mode); err == nil || strings.Contains(err.Error(), value) {
|
|
t.Fatalf("isolated mode accepted an external address or echoed it: %v", err)
|
|
}
|
|
})
|
|
}
|
|
}
|
|
}
|
|
|
|
func TestNonprodRealRejectsMalformedEndpointsWithoutLeakingConfiguration(t *testing.T) {
|
|
for _, tc := range []struct{ name, value string }{
|
|
{"SAAS_BASE_URL", "not-a-url"},
|
|
{"SAAS_BASE_URL", "ftp://external.example.invalid"},
|
|
{"SAAS_BASE_URL", "https://external.example.invalid?secret=placeholder"},
|
|
{"RABBITMQ_URL", "https://synthetic:placeholder@external.example.invalid"},
|
|
{"RABBITMQ_URL", "amqp://synthetic:placeholder@external.example.invalid#fragment"},
|
|
} {
|
|
t.Run(tc.name+"/"+tc.value, func(t *testing.T) {
|
|
path := setDispatcherEnvironment(t)
|
|
t.Setenv(tc.name, tc.value)
|
|
if _, err := LoadDispatcherEnvironment("nonprod-real"); err == nil || !strings.Contains(err.Error(), tc.name) || strings.Contains(err.Error(), tc.value) || strings.Contains(err.Error(), "placeholder") {
|
|
t.Fatalf("malformed endpoint was accepted or exposed: %v", err)
|
|
}
|
|
if _, err := os.Stat(path); !os.IsNotExist(err) {
|
|
t.Fatalf("rejected configuration opened SQLite: %v", err)
|
|
}
|
|
})
|
|
}
|
|
}
|