fix: harden evidence URI validation
This commit is contained in:
@@ -476,6 +476,7 @@ const invalidHttpUris = [
|
||||
"https://example.com/manifest?token=CANARY-HTTP",
|
||||
"https://example.com/manifest#CANARY-HTTP",
|
||||
"ftp://example.com/manifest/CANARY-HTTP",
|
||||
"\nhttps://example.com/CANARY-HTTP",
|
||||
];
|
||||
|
||||
test.each(invalidHttpUris)("rejects unsafe HTTP descriptor URI %# without leaking it", (uri) => {
|
||||
@@ -506,6 +507,8 @@ test.each(invalidHttpBounds)("rejects invalid HTTP bound %s=%s", (field, value)
|
||||
const invalidS3Uris = [
|
||||
"https://bucket/prefix", "s3:///prefix", "s3://user:CANARY-S3@bucket/prefix",
|
||||
"s3://bucket/prefix?token=CANARY-S3", "s3://bucket/prefix#CANARY-S3",
|
||||
"s3://bucket:123/CANARY-S3", "s3://bucket/%2e%2e/CANARY-S3",
|
||||
"s3://127.0.0.1/CANARY-S3", "s3://UPPERCASE/CANARY-S3",
|
||||
];
|
||||
|
||||
test.each(invalidS3Uris)("rejects invalid S3 URI %# without leaking it", (uri) => {
|
||||
@@ -520,6 +523,7 @@ const invalidS3Endpoints = [
|
||||
{ endpoint_url: "https://objects.example#CANARY-S3", trusted_endpoint: true },
|
||||
{ endpoint_url: "https://objects.example", trusted_endpoint: false },
|
||||
{ endpoint_url: "http://objects.example", trusted_endpoint: true, allow_insecure_endpoint: false },
|
||||
{ endpoint_url: "HTTP://objects.example", trusted_endpoint: true, allow_insecure_endpoint: false },
|
||||
{ trusted_endpoint: true },
|
||||
{ allow_private_endpoint: true },
|
||||
{ allow_insecure_endpoint: true },
|
||||
|
||||
Reference in New Issue
Block a user