fix(auth): harden Windows storage bridge
This commit is contained in:
@@ -2,6 +2,7 @@ package safeio
|
||||
|
||||
import (
|
||||
"errors"
|
||||
"fmt"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"testing"
|
||||
@@ -93,3 +94,34 @@ func TestWriteCanonicalNewFileRejectsExistingTargets(t *testing.T) {
|
||||
t.Fatalf("WriteCanonicalNewFile(existing) error = %v, want ErrUnsafeFile", err)
|
||||
}
|
||||
}
|
||||
|
||||
func TestListCanonicalPrivateDirectoryBoundsAndSortsValidatedEntries(t *testing.T) {
|
||||
temporaryRoot, err := filepath.EvalSymlinks(os.TempDir())
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
root, err := os.MkdirTemp(temporaryRoot, "tht-safeio-list-")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
t.Cleanup(func() { _ = os.RemoveAll(root) })
|
||||
if err := ProtectPrivateDirectory(root); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
for index := 255; index >= 0; index-- {
|
||||
path := filepath.Join(root, fmt.Sprintf("%064x.json", index))
|
||||
if err := WriteCanonicalNewFile(path, []byte("record"), 0o600); err != nil {
|
||||
t.Fatalf("WriteCanonicalNewFile(%d) error = %v", index, err)
|
||||
}
|
||||
}
|
||||
entries, err := ListCanonicalPrivateDirectory(root, 256)
|
||||
if err != nil || len(entries) != 256 || entries[0].Name != fmt.Sprintf("%064x.json", 0) || entries[255].Name != fmt.Sprintf("%064x.json", 255) {
|
||||
t.Fatalf("bounded ordered entries = %#v error = %v", entries, err)
|
||||
}
|
||||
if err := WriteCanonicalNewFile(filepath.Join(root, fmt.Sprintf("%064x.json", 256)), []byte("record"), 0o600); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if _, err := ListCanonicalPrivateDirectory(root, 256); !errors.Is(err, ErrUnsafeFile) {
|
||||
t.Fatalf("257-entry listing error = %v, want ErrUnsafeFile", err)
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user