2019-09-27 21:59:23 +00:00
|
|
|
# Pleroma: A lightweight social networking server
|
2020-03-02 05:08:45 +00:00
|
|
|
# Copyright © 2017-2020 Pleroma Authors <https://pleroma.social/>
|
2019-09-27 21:59:23 +00:00
|
|
|
# SPDX-License-Identifier: AGPL-3.0-only
|
|
|
|
|
2020-06-23 15:16:47 +00:00
|
|
|
defmodule Pleroma.Web.Plugs.RemoteIpTest do
|
2020-10-06 22:02:46 +00:00
|
|
|
use ExUnit.Case
|
2019-09-27 21:59:23 +00:00
|
|
|
use Plug.Test
|
|
|
|
|
2020-06-24 06:30:32 +00:00
|
|
|
alias Pleroma.Web.Plugs.RemoteIp
|
2019-09-27 21:59:23 +00:00
|
|
|
|
2020-10-06 22:02:46 +00:00
|
|
|
import Pleroma.Tests.Helpers, only: [clear_config: 2]
|
|
|
|
|
|
|
|
setup do:
|
|
|
|
clear_config(RemoteIp,
|
|
|
|
enabled: true,
|
|
|
|
headers: ["x-forwarded-for"],
|
|
|
|
proxies: [],
|
|
|
|
reserved: [
|
|
|
|
"127.0.0.0/8",
|
|
|
|
"::1/128",
|
|
|
|
"fc00::/7",
|
|
|
|
"10.0.0.0/8",
|
|
|
|
"172.16.0.0/12",
|
|
|
|
"192.168.0.0/16"
|
|
|
|
]
|
|
|
|
)
|
2020-02-13 18:55:47 +00:00
|
|
|
|
2019-09-27 21:59:23 +00:00
|
|
|
test "disabled" do
|
|
|
|
Pleroma.Config.put(RemoteIp, enabled: false)
|
|
|
|
|
|
|
|
%{remote_ip: remote_ip} = conn(:get, "/")
|
|
|
|
|
|
|
|
conn =
|
|
|
|
conn(:get, "/")
|
|
|
|
|> put_req_header("x-forwarded-for", "1.1.1.1")
|
|
|
|
|> RemoteIp.call(nil)
|
|
|
|
|
|
|
|
assert conn.remote_ip == remote_ip
|
|
|
|
end
|
|
|
|
|
|
|
|
test "enabled" do
|
|
|
|
conn =
|
|
|
|
conn(:get, "/")
|
|
|
|
|> put_req_header("x-forwarded-for", "1.1.1.1")
|
|
|
|
|> RemoteIp.call(nil)
|
|
|
|
|
|
|
|
assert conn.remote_ip == {1, 1, 1, 1}
|
|
|
|
end
|
|
|
|
|
|
|
|
test "custom headers" do
|
|
|
|
Pleroma.Config.put(RemoteIp, enabled: true, headers: ["cf-connecting-ip"])
|
|
|
|
|
|
|
|
conn =
|
|
|
|
conn(:get, "/")
|
|
|
|
|> put_req_header("x-forwarded-for", "1.1.1.1")
|
|
|
|
|> RemoteIp.call(nil)
|
|
|
|
|
|
|
|
refute conn.remote_ip == {1, 1, 1, 1}
|
|
|
|
|
|
|
|
conn =
|
|
|
|
conn(:get, "/")
|
|
|
|
|> put_req_header("cf-connecting-ip", "1.1.1.1")
|
|
|
|
|> RemoteIp.call(nil)
|
|
|
|
|
|
|
|
assert conn.remote_ip == {1, 1, 1, 1}
|
|
|
|
end
|
|
|
|
|
|
|
|
test "custom proxies" do
|
|
|
|
conn =
|
|
|
|
conn(:get, "/")
|
|
|
|
|> put_req_header("x-forwarded-for", "173.245.48.1, 1.1.1.1, 173.245.48.2")
|
|
|
|
|> RemoteIp.call(nil)
|
|
|
|
|
|
|
|
refute conn.remote_ip == {1, 1, 1, 1}
|
|
|
|
|
|
|
|
Pleroma.Config.put([RemoteIp, :proxies], ["173.245.48.0/20"])
|
|
|
|
|
|
|
|
conn =
|
|
|
|
conn(:get, "/")
|
|
|
|
|> put_req_header("x-forwarded-for", "173.245.48.1, 1.1.1.1, 173.245.48.2")
|
|
|
|
|> RemoteIp.call(nil)
|
|
|
|
|
|
|
|
assert conn.remote_ip == {1, 1, 1, 1}
|
|
|
|
end
|
2020-10-06 22:08:26 +00:00
|
|
|
|
|
|
|
test "proxies set without CIDR format" do
|
|
|
|
Pleroma.Config.put([RemoteIp, :proxies], ["173.245.48.1"])
|
|
|
|
|
|
|
|
conn =
|
|
|
|
conn(:get, "/")
|
|
|
|
|> put_req_header("x-forwarded-for", "173.245.48.1, 1.1.1.1")
|
|
|
|
|> RemoteIp.call(nil)
|
|
|
|
|
|
|
|
assert conn.remote_ip == {1, 1, 1, 1}
|
2020-10-07 19:32:09 +00:00
|
|
|
end
|
2020-10-07 19:16:53 +00:00
|
|
|
|
|
|
|
test "proxies set `nonsensical` CIDR" do
|
|
|
|
Pleroma.Config.put([RemoteIp, :reserved], ["127.0.0.0/8"])
|
|
|
|
Pleroma.Config.put([RemoteIp, :proxies], ["10.0.0.3/24"])
|
|
|
|
|
|
|
|
conn =
|
|
|
|
conn(:get, "/")
|
|
|
|
|> put_req_header("x-forwarded-for", "10.0.0.3, 1.1.1.1")
|
|
|
|
|> RemoteIp.call(nil)
|
|
|
|
|
|
|
|
assert conn.remote_ip == {1, 1, 1, 1}
|
2020-10-06 22:08:26 +00:00
|
|
|
end
|
2019-09-27 21:59:23 +00:00
|
|
|
end
|