Files
OwnCord/Server/api/waf_test.go
T
J3vb f962d59cd6 fix: update tests and fix pending-join drain regression for CI
Update LiveKitSession tests to use _state discriminated union instead of
old flat field names (room, currentChannelId, latestToken, etc.) removed
in the state machine refactor. Also fix renderers.test.ts URL resolution
by setting a server host in beforeEach so isSafeUrl can parse relative
attachment URLs in jsdom. Stage all four Go test files so the CI Go job
runs them.

Additionally fix a regression in connectAndSetup's finally block: when a
pendingJoin is queued during a stale-join abort, preserve the connecting
state so handleVoiceToken's drain loop can pick it up rather than losing
it by resetting to idle.
2026-04-04 21:50:57 +02:00

116 lines
3.3 KiB
Go

package api
import (
"io"
"net/http"
"net/http/httptest"
"strings"
"testing"
"github.com/corazawaf/coraza/v3/types"
)
func TestHandleWAFInterruption_WritesJSONAndStatus(t *testing.T) {
rr := httptest.NewRecorder()
handleWAFInterruption(rr, &types.Interruption{
Action: "deny",
Status: http.StatusForbidden,
RuleID: 942100,
Data: "SQL Injection detected",
})
if rr.Code != http.StatusForbidden {
t.Fatalf("status = %d, want 403", rr.Code)
}
if rr.Header().Get("Content-Type") != "application/json" {
t.Fatalf("Content-Type = %q, want application/json", rr.Header().Get("Content-Type"))
}
if strings.TrimSpace(rr.Body.String()) != `{"error":"request blocked by security rules"}` {
t.Fatalf("body = %q, want blocked JSON", rr.Body.String())
}
}
func TestWAFMiddleware_AllowsBenignRequest(t *testing.T) {
called := false
middleware := NewWAFMiddleware(2)
handler := middleware(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
called = true
w.WriteHeader(http.StatusNoContent)
}))
req := httptest.NewRequest(http.MethodGet, "/api/v1/channels?q=hello", nil)
req.RemoteAddr = "127.0.0.1:9999"
rr := httptest.NewRecorder()
handler.ServeHTTP(rr, req)
if !called {
t.Fatal("expected downstream handler to be called")
}
if rr.Code != http.StatusNoContent {
t.Fatalf("status = %d, want 204", rr.Code)
}
}
func TestWAFMiddleware_InvalidParanoiaLevelStillAllowsBenignRequest(t *testing.T) {
called := false
middleware := NewWAFMiddleware(99)
handler := middleware(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
called = true
w.WriteHeader(http.StatusNoContent)
}))
req := httptest.NewRequest(http.MethodGet, "/api/v1/channels?q=hello", nil)
req.RemoteAddr = "127.0.0.1:9999"
rr := httptest.NewRecorder()
handler.ServeHTTP(rr, req)
if !called {
t.Fatal("expected downstream handler to be called")
}
if rr.Code != http.StatusNoContent {
t.Fatalf("status = %d, want 204", rr.Code)
}
}
func TestWAFMiddleware_BlocksScannerUserAgent(t *testing.T) {
middleware := NewWAFMiddleware(2)
handler := middleware(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
t.Fatal("downstream handler should not be called for blocked scanner request")
}))
req := httptest.NewRequest(http.MethodGet, "/api/v1/channels", nil)
req.Header.Set("User-Agent", "sqlmap/1.8")
req.RemoteAddr = "127.0.0.1:9999"
rr := httptest.NewRecorder()
handler.ServeHTTP(rr, req)
if rr.Code != http.StatusForbidden {
t.Fatalf("status = %d, want 403; body = %s", rr.Code, rr.Body.String())
}
}
func TestWAFMiddleware_PreservesReadableBodyForDownstream(t *testing.T) {
const requestBody = `{"message":"hello world"}`
middleware := NewWAFMiddleware(2)
handler := middleware(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
body, err := io.ReadAll(r.Body)
if err != nil {
t.Fatalf("ReadAll: %v", err)
}
if string(body) != requestBody {
t.Fatalf("body = %q, want %q", string(body), requestBody)
}
w.WriteHeader(http.StatusNoContent)
}))
req := httptest.NewRequest(http.MethodPost, "/api/v1/messages", strings.NewReader(requestBody))
req.Header.Set("Content-Type", "application/json")
req.RemoteAddr = "127.0.0.1:9999"
rr := httptest.NewRecorder()
handler.ServeHTTP(rr, req)
if rr.Code != http.StatusNoContent {
t.Fatalf("status = %d, want 204; body = %s", rr.Code, rr.Body.String())
}
}