url-fetch-safe.test.mjs
25 lines 949 B
Raw
sha256:c2dbf04d56308f3bbf2d06e6d2eb022b8948b1e827195fe525a44e5e18d5f9c0 feat(auth): Phase B Connect cloud agent (RFC 8628) + Hermes… Human minor ⚠ breaking 11 days ago
1 /**
2 * URL fetch guardrails for import.
3 */
4 import { describe, it } from 'node:test';
5 import assert from 'node:assert/strict';
6 import { isPrivateOrBlockedIp, fetchUrlForImport } from '../lib/url-fetch-safe.mjs';
7
8 describe('url-fetch-safe', () => {
9 it('isPrivateOrBlockedIp marks loopback and RFC1918', () => {
10 assert.equal(isPrivateOrBlockedIp('127.0.0.1'), true);
11 assert.equal(isPrivateOrBlockedIp('10.0.0.1'), true);
12 assert.equal(isPrivateOrBlockedIp('192.168.1.1'), true);
13 assert.equal(isPrivateOrBlockedIp('::1'), true);
14 assert.equal(isPrivateOrBlockedIp('fe80::1'), true);
15 assert.equal(isPrivateOrBlockedIp('fd00::1'), true);
16 });
17
18 it('rejects http scheme', async () => {
19 await assert.rejects(() => fetchUrlForImport('http://example.com/'), /Only https/);
20 });
21
22 it('rejects localhost hostname', async () => {
23 await assert.rejects(() => fetchUrlForImport('https://localhost/foo'), /localhost/);
24 });
25 });
File History 1 commit
sha256:93bcf8f9bd56d8c5b9339f4ec73b9ebd66571398d56262d38eedc2cfa9db9882 fix(test): align Band B landing assertion with desktop MCP … Human 11 days ago