HH-547: allow cross-origin widget requests (#126)
* HH-547: allow cross-origin widget requests * fix(HH-547): align production preflight with wildcard CORS --------- Co-authored-by: Rogee <rogee@ipao.vip>
This commit is contained in:
@@ -22,7 +22,7 @@ func validReleaseConfig() *Config {
|
||||
}
|
||||
}
|
||||
|
||||
func TestReleaseTransportAndCORSValidationFailsClosed(t *testing.T) {
|
||||
func TestReleaseTransportValidationFailsClosed(t *testing.T) {
|
||||
tests := []struct {
|
||||
name string
|
||||
mutate func(*Config)
|
||||
@@ -30,9 +30,6 @@ func TestReleaseTransportAndCORSValidationFailsClosed(t *testing.T) {
|
||||
}{
|
||||
{"database TLS without identity verification", func(c *Config) { c.Database.DSN = "postgres://user:pass@db.acme.test/gochat?sslmode=require" }, "sslmode=disable, verify-full or verify-ca"},
|
||||
{"redis certificate not verified", func(c *Config) { c.Redis.DSN = "rediss://:redis-secret@redis.acme.test:6379?insecure_skip_verify=true" }, "cannot be disabled"},
|
||||
{"placeholder origin", func(c *Config) { c.Server.CORS.AllowedOrigins = []string{"https://example.com"} }, "not deployable"},
|
||||
{"non HTTPS origin", func(c *Config) { c.Server.CORS.AllowedOrigins = []string{"http://chat.acme.test"} }, "exact HTTPS origin"},
|
||||
{"wildcard origin", func(c *Config) { c.Server.CORS.AllowedOrigins = []string{"*.acme.test"} }, "exact HTTPS origin"},
|
||||
}
|
||||
for _, tt := range tests {
|
||||
t.Run(tt.name, func(t *testing.T) {
|
||||
|
||||
@@ -136,19 +136,6 @@ func Validate(cfg *Config) error {
|
||||
if redisURL.Scheme == "rediss" && strings.EqualFold(redisURL.Query().Get("insecure_skip_verify"), "true") {
|
||||
return fmt.Errorf("production Redis TLS certificate verification cannot be disabled")
|
||||
}
|
||||
if len(cfg.Server.CORS.AllowedOrigins) == 0 {
|
||||
return fmt.Errorf("production CORS requires at least one HTTPS origin")
|
||||
}
|
||||
for _, origin := range cfg.Server.CORS.AllowedOrigins {
|
||||
parsed, err := url.Parse(origin)
|
||||
lower := strings.ToLower(origin)
|
||||
if err != nil || parsed.Scheme != "https" || parsed.Host == "" || parsed.Path != "" || parsed.RawQuery != "" || parsed.Fragment != "" {
|
||||
return fmt.Errorf("production CORS origin must be an exact HTTPS origin: %q", origin)
|
||||
}
|
||||
if strings.Contains(origin, "*") || strings.Contains(lower, "localhost") || strings.Contains(lower, "example.") || strings.Contains(lower, "yourdomain") || containsPlaceholder(origin) {
|
||||
return fmt.Errorf("production CORS origin is not deployable: %q", origin)
|
||||
}
|
||||
}
|
||||
if cfg.JWT.AccessExpiryMinutes <= 0 || cfg.JWT.AccessExpiryMinutes > 15 {
|
||||
return fmt.Errorf("production JWT access_expiry_minutes must be between 1 and 15")
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user