Commit 606c4ec959

606c4ec959835431f4ce86f74bb83118d52139c3

parent: e2caeed16c

Verified · cmc ci/build: success ci/test: success

cmc <hello@cleberg.net> · 2026-09-07 19:09 UTC

e2e: a refused webhook URL answers exit 1

The SSRF and scheme refusals moved from usage to failure in the
previous commit; the assertions pinned the old code.

Ref #187
e2e/webhook_test.go +4 −3
@@ -239,7 +239,8 @@ func TestWebhooks(t *testing.T) {
239239 recv.waitN(t, prev+1)
240240
241241 // SSRF: on a default instance (allow_local off), local targets are
242 // rejected at add time.
242 // rejected at add time. A refused value is exit 1 with the reason;
243 // exit 2 is for the shape of the command line (#187).
243244 inst2 := startInstance(t)
244245 k2 := inst2.newKey(t, "a2")
245246 inst2.admin(t, "admin", "user", "create", "a2", "--key", k2+".pub")
@@ -247,10 +248,10 @@ func TestWebhooks(t *testing.T) {
247248 t.Fatal("repo create failed")
248249 }
249250 _, errOut, code := inst2.ssh(t, k2, "", "webhook", "add", "a2/r", "http://127.0.0.1:9/x")
250 if code != 2 || !strings.Contains(errOut, "SSRF") {
251 if code != 1 || !strings.Contains(errOut, "SSRF") {
251252 t.Fatalf("local webhook target accepted: exit %d, %s", code, errOut)
252253 }
253 if _, _, code := inst2.ssh(t, k2, "", "webhook", "add", "a2/r", "ftp://example.com/x"); code != 2 {
254 if _, _, code := inst2.ssh(t, k2, "", "webhook", "add", "a2/r", "ftp://example.com/x"); code != 1 {
254255 t.Fatal("non-http scheme accepted")
255256 }
256257}