Commit 606c4ec959
Verified · cmc ci/build: success ci/test: success
e2e/webhook_test.go +4 −3
| @@ -239,7 +239,8 @@ func TestWebhooks(t *testing.T) { | ||
| 239 | 239 | recv.waitN(t, prev+1) |
| 240 | 240 | |
| 241 | 241 | // SSRF: on a default instance (allow_local off), local targets are |
| 242 | // rejected at add time. | |
| 242 | // rejected at add time. A refused value is exit 1 with the reason; | |
| 243 | // exit 2 is for the shape of the command line (#187). | |
| 243 | 244 | inst2 := startInstance(t) |
| 244 | 245 | k2 := inst2.newKey(t, "a2") |
| 245 | 246 | inst2.admin(t, "admin", "user", "create", "a2", "--key", k2+".pub") |
| @@ -247,10 +248,10 @@ func TestWebhooks(t *testing.T) { | ||
| 247 | 248 | t.Fatal("repo create failed") |
| 248 | 249 | } |
| 249 | 250 | _, errOut, code := inst2.ssh(t, k2, "", "webhook", "add", "a2/r", "http://127.0.0.1:9/x") |
| 250 | if code != 2 || !strings.Contains(errOut, "SSRF") { | |
| 251 | if code != 1 || !strings.Contains(errOut, "SSRF") { | |
| 251 | 252 | t.Fatalf("local webhook target accepted: exit %d, %s", code, errOut) |
| 252 | 253 | } |
| 253 | if _, _, code := inst2.ssh(t, k2, "", "webhook", "add", "a2/r", "ftp://example.com/x"); code != 2 { | |
| 254 | if _, _, code := inst2.ssh(t, k2, "", "webhook", "add", "a2/r", "ftp://example.com/x"); code != 1 { | |
| 254 | 255 | t.Fatal("non-http scheme accepted") |
| 255 | 256 | } |
| 256 | 257 | } |