mirror of
https://github.com/MengMengCode/CLICD.git
synced 2026-08-05 05:36:07 +08:00
38debab1aa
- Implement tests for custom KVM and LXC image creation, ensuring invalid sources and architecture mismatches are rejected. - Introduce access policy management in CLI, allowing configuration of allowed sources and trusted proxies. - Add NAT network configuration with validation for RFC1918 compliance and subnet parsing. - Create panel access policy management, including normalization and evaluation of access decisions based on client IPs and forwarded headers. - Develop middleware for enforcing access policies in the server, returning appropriate responses for allowed and denied requests. - Enhance custom image downloading and validation, ensuring integrity and security of downloaded root filesystem archives. - Include comprehensive tests for all new functionalities to ensure reliability and correctness.
57 lines
1.6 KiB
Go
57 lines
1.6 KiB
Go
package config
|
|
|
|
import "testing"
|
|
|
|
func TestParseNATNetwork(t *testing.T) {
|
|
network, err := ParseNATNetwork("172.28.40.0/24")
|
|
if err != nil {
|
|
t.Fatalf("ParseNATNetwork returned error: %v", err)
|
|
}
|
|
if network.Subnet != "172.28.40.0/24" ||
|
|
network.Gateway != "172.28.40.1" ||
|
|
network.Netmask != "255.255.255.0" ||
|
|
network.DHCPStart != "172.28.40.2" ||
|
|
network.DHCPEnd != "172.28.40.254" ||
|
|
network.DHCPMax != 253 {
|
|
t.Fatalf("unexpected network values: %+v", network)
|
|
}
|
|
}
|
|
|
|
func TestParseNATNetworkMasksHostBits(t *testing.T) {
|
|
network, err := ParseNATNetwork("10.44.8.99/20")
|
|
if err != nil {
|
|
t.Fatalf("ParseNATNetwork returned error: %v", err)
|
|
}
|
|
if network.Subnet != "10.44.0.0/20" || network.Gateway != "10.44.0.1" || network.DHCPEnd != "10.44.15.254" {
|
|
t.Fatalf("unexpected masked network values: %+v", network)
|
|
}
|
|
}
|
|
|
|
func TestParseNATNetworkRejectsUnsafeRanges(t *testing.T) {
|
|
for _, raw := range []string{
|
|
"203.0.113.0/24",
|
|
"10.0.0.0/15",
|
|
"10.0.0.0/29",
|
|
"not-a-subnet",
|
|
} {
|
|
if _, err := ParseNATNetwork(raw); err == nil {
|
|
t.Fatalf("ParseNATNetwork(%q) unexpectedly succeeded", raw)
|
|
}
|
|
}
|
|
}
|
|
|
|
func TestNormalizeNATNetworkDefaultsUsesEnvironment(t *testing.T) {
|
|
t.Setenv("CLICD_LXC_SUBNET", "172.30.8.0/24")
|
|
t.Setenv("CLICD_KVM_SUBNET", "10.230.0.0/20")
|
|
previous := AppConfig
|
|
AppConfig = &ClicdConfig{}
|
|
t.Cleanup(func() { AppConfig = previous })
|
|
|
|
if !normalizeNATNetworkDefaults() {
|
|
t.Fatal("expected defaults to change")
|
|
}
|
|
if AppConfig.LXCNATSubnet != "172.30.8.0/24" || AppConfig.KVMNATSubnet != "10.230.0.0/20" {
|
|
t.Fatalf("unexpected configured subnets: LXC=%s KVM=%s", AppConfig.LXCNATSubnet, AppConfig.KVMNATSubnet)
|
|
}
|
|
}
|