diff options
| author | Dennis Fink | 2026-08-10 19:36:49 +0200 |
|---|---|---|
| committer | Dennis Fink | 2026-08-10 19:36:49 +0200 |
| commit | 8350bef3e3baea6042ed3780a054cc65707e9f8d (patch) | |
| tree | 81ab5f102045f53d23f89e22a41b2f6a2eef9b52 /tests/conftest.py | |
| parent | afcdb411882a6c157c3b5008e1c633d3e40cd984 (diff) | |
| download | webmentions-ssg-8350bef3e3baea6042ed3780a054cc65707e9f8d.tar.gz webmentions-ssg-8350bef3e3baea6042ed3780a054cc65707e9f8d.zip | |
fix(receiver): prevent requests to non-public addresses
Resolve source hostnames before fetching and reject addresses that are
not globally routable to prevent SSRF against local or private services.
Repeat the check for every HTTP request so redirects cannot bypass the
initial source validation. Treat DNS resolution failures during
verification as temporary fetch errors.
Diffstat (limited to '')
| -rw-r--r-- | tests/conftest.py | 24 |
1 files changed, 24 insertions, 0 deletions
diff --git a/tests/conftest.py b/tests/conftest.py index 94ba650..f1ef4b5 100644 --- a/tests/conftest.py +++ b/tests/conftest.py @@ -18,6 +18,14 @@ HTTPHandler = Callable[ ] +class FakeHostAnswers: + def __init__(self, *addresses: str): + self._addresses = addresses + + def addresses(self): + return iter(self._addresses) + + @pytest.fixture def app() -> Iterator[Flask]: """ @@ -101,6 +109,12 @@ def install_httpx_mock( Replace the HTTPX transport without replacing HTTPX itself. """ + monkeypatch.setattr( + receiver_module, + "ensure_public_url", + lambda url: None, + ) + real_client = httpx.Client def install(handler: HTTPHandler) -> None: @@ -123,3 +137,13 @@ def install_httpx_mock( ) return install + + +@pytest.fixture +def public_dns( + monkeypatch: pytest.MonkeyPatch, +) -> None: + monkeypatch.setattr( + "webmentions_ssg.url_security.dns.resolver.resolve_name", + lambda hostname: FakeHostAnswers("93.184.216.34"), + ) |
