url-fetch-safe.test.mjs
25 lines 949 B
Raw
sha256:baa800aedf841dbf32081aa7b2befa288ac33dfc7175ac55014c55c4d8c742f9 docs: move durable-auth freeze/evidence to local developmen… Human 10 days ago
1 /**
2 * URL fetch guardrails for import.
3 */
4 import { describe, it } from 'node:test';
5 import assert from 'node:assert/strict';
6 import { isPrivateOrBlockedIp, fetchUrlForImport } from '../lib/url-fetch-safe.mjs';
7
8 describe('url-fetch-safe', () => {
9 it('isPrivateOrBlockedIp marks loopback and RFC1918', () => {
10 assert.equal(isPrivateOrBlockedIp('127.0.0.1'), true);
11 assert.equal(isPrivateOrBlockedIp('10.0.0.1'), true);
12 assert.equal(isPrivateOrBlockedIp('192.168.1.1'), true);
13 assert.equal(isPrivateOrBlockedIp('::1'), true);
14 assert.equal(isPrivateOrBlockedIp('fe80::1'), true);
15 assert.equal(isPrivateOrBlockedIp('fd00::1'), true);
16 });
17
18 it('rejects http scheme', async () => {
19 await assert.rejects(() => fetchUrlForImport('http://example.com/'), /Only https/);
20 });
21
22 it('rejects localhost hostname', async () => {
23 await assert.rejects(() => fetchUrlForImport('https://localhost/foo'), /localhost/);
24 });
25 });
File History 1 commit
sha256:baa800aedf841dbf32081aa7b2befa288ac33dfc7175ac55014c55c4d8c742f9 docs: move durable-auth freeze/evidence to local developmen… Human 10 days ago