2021-04-18 18:34:59 +00:00
|
|
|
/*-*- mode:c;indent-tabs-mode:nil;c-basic-offset:2;tab-width:8;coding:utf-8 -*-│
|
|
|
|
│vi: set net ft=c ts=2 sts=2 sw=2 fenc=utf-8 :vi│
|
|
|
|
╞══════════════════════════════════════════════════════════════════════════════╡
|
|
|
|
│ Copyright 2021 Justine Alexandra Roberts Tunney │
|
|
|
|
│ │
|
|
|
|
│ Permission to use, copy, modify, and/or distribute this software for │
|
|
|
|
│ any purpose with or without fee is hereby granted, provided that the │
|
|
|
|
│ above copyright notice and this permission notice appear in all copies. │
|
|
|
|
│ │
|
|
|
|
│ THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL │
|
|
|
|
│ WARRANTIES WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED │
|
|
|
|
│ WARRANTIES OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE │
|
|
|
|
│ AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL │
|
|
|
|
│ DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR │
|
|
|
|
│ PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR OTHER │
|
|
|
|
│ TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR │
|
|
|
|
│ PERFORMANCE OF THIS SOFTWARE. │
|
|
|
|
╚─────────────────────────────────────────────────────────────────────────────*/
|
2022-09-13 06:10:38 +00:00
|
|
|
#include "libc/mem/gc.internal.h"
|
2021-04-18 18:34:59 +00:00
|
|
|
#include "libc/testlib/ezbench.h"
|
|
|
|
#include "libc/testlib/testlib.h"
|
|
|
|
#include "net/http/escape.h"
|
|
|
|
#include "net/http/http.h"
|
|
|
|
|
|
|
|
TEST(IsAcceptablePath, test) {
|
2021-04-23 17:45:19 +00:00
|
|
|
EXPECT_TRUE(IsAcceptablePath("*", 1));
|
2021-04-18 18:34:59 +00:00
|
|
|
EXPECT_TRUE(IsAcceptablePath("/", 1));
|
|
|
|
EXPECT_TRUE(IsAcceptablePath("index.html", 10));
|
|
|
|
EXPECT_TRUE(IsAcceptablePath("/index.html", 11));
|
|
|
|
EXPECT_TRUE(IsAcceptablePath("/index.html", -1));
|
2021-04-23 17:45:19 +00:00
|
|
|
EXPECT_TRUE(IsAcceptablePath("/redbean.png", -1));
|
2021-04-18 18:34:59 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
TEST(IsAcceptablePath, testEmptyString_allowedIfYouLikeImplicitLeadingSlash) {
|
|
|
|
EXPECT_TRUE(IsAcceptablePath(0, 0));
|
|
|
|
EXPECT_TRUE(IsAcceptablePath(0, -1));
|
|
|
|
EXPECT_TRUE(IsAcceptablePath("", 0));
|
|
|
|
}
|
|
|
|
|
|
|
|
TEST(IsAcceptablePath, testHiddenFiles_notAllowed) {
|
|
|
|
EXPECT_FALSE(IsAcceptablePath("/.index.html", 12));
|
|
|
|
EXPECT_FALSE(IsAcceptablePath("/x/.index.html", 14));
|
|
|
|
}
|
|
|
|
|
|
|
|
TEST(IsAcceptablePath, testDoubleSlash_notAllowed) {
|
|
|
|
EXPECT_FALSE(IsAcceptablePath("//", 2));
|
|
|
|
EXPECT_FALSE(IsAcceptablePath("foo//", 5));
|
|
|
|
EXPECT_FALSE(IsAcceptablePath("/foo//", 6));
|
|
|
|
EXPECT_FALSE(IsAcceptablePath("/foo//bar", 9));
|
|
|
|
}
|
|
|
|
|
|
|
|
TEST(IsAcceptablePath, testNoncanonicalDirectories_areForbidden) {
|
|
|
|
EXPECT_FALSE(IsAcceptablePath(".", 1));
|
|
|
|
EXPECT_FALSE(IsAcceptablePath("..", 2));
|
|
|
|
EXPECT_FALSE(IsAcceptablePath("/.", 2));
|
|
|
|
EXPECT_FALSE(IsAcceptablePath("/..", 3));
|
|
|
|
EXPECT_FALSE(IsAcceptablePath("./", 2));
|
|
|
|
EXPECT_FALSE(IsAcceptablePath("../", 3));
|
|
|
|
EXPECT_FALSE(IsAcceptablePath("/./", 3));
|
|
|
|
EXPECT_FALSE(IsAcceptablePath("/../", 4));
|
|
|
|
EXPECT_FALSE(IsAcceptablePath("x/.", 3));
|
|
|
|
EXPECT_FALSE(IsAcceptablePath("x/..", 4));
|
|
|
|
EXPECT_FALSE(IsAcceptablePath("x/./", 4));
|
|
|
|
EXPECT_FALSE(IsAcceptablePath("x/../", 5));
|
|
|
|
EXPECT_FALSE(IsAcceptablePath("/x/./", 5));
|
|
|
|
EXPECT_FALSE(IsAcceptablePath("/x/../", 6));
|
|
|
|
}
|
|
|
|
|
|
|
|
TEST(IsAcceptablePath, testNoncanonicalWindowsDirs_areForbidden) {
|
|
|
|
EXPECT_FALSE(IsAcceptablePath(".", 1));
|
|
|
|
EXPECT_FALSE(IsAcceptablePath("..", 2));
|
|
|
|
EXPECT_FALSE(IsAcceptablePath("\\.", 2));
|
|
|
|
EXPECT_FALSE(IsAcceptablePath("\\..", 3));
|
|
|
|
EXPECT_FALSE(IsAcceptablePath(".\\", 2));
|
|
|
|
EXPECT_FALSE(IsAcceptablePath("..\\", 3));
|
|
|
|
EXPECT_FALSE(IsAcceptablePath("\\.\\", 3));
|
|
|
|
EXPECT_FALSE(IsAcceptablePath("\\..\\", 4));
|
|
|
|
EXPECT_FALSE(IsAcceptablePath("x\\.", 3));
|
|
|
|
EXPECT_FALSE(IsAcceptablePath("x\\..", 4));
|
|
|
|
EXPECT_FALSE(IsAcceptablePath("x\\.\\", 4));
|
|
|
|
EXPECT_FALSE(IsAcceptablePath("x\\..\\", 5));
|
|
|
|
EXPECT_FALSE(IsAcceptablePath("\\x\\.\\", 5));
|
|
|
|
EXPECT_FALSE(IsAcceptablePath("\\x\\..\\", 6));
|
|
|
|
}
|
|
|
|
|
|
|
|
TEST(IsAcceptablePath, testOverlongSlashDot_isDetected) {
|
|
|
|
EXPECT_FALSE(IsAcceptablePath("/\300\256", 3));
|
|
|
|
EXPECT_FALSE(IsAcceptablePath("/\300\257", 3));
|
|
|
|
EXPECT_FALSE(IsAcceptablePath("\300\256\300\256", 4));
|
|
|
|
}
|
|
|
|
|
|
|
|
BENCH(IsAcceptablePath, bench) {
|
2021-04-23 17:45:19 +00:00
|
|
|
EZBENCH2("IsAcceptablePath", donothing, IsAcceptablePath("*", 1));
|
2021-04-18 18:34:59 +00:00
|
|
|
EZBENCH2("IsAcceptablePath", donothing, IsAcceptablePath("/index.html", 11));
|
|
|
|
}
|