Compare commits
9
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
e8c5a7a1fb | ||
|
|
270e8d57e3 | ||
|
|
7db152499c | ||
|
|
a9bb4a1835 | ||
|
|
b64f23301b | ||
|
|
83d7c65bf2 | ||
|
|
1462024944 | ||
|
|
297332b0e1 | ||
|
|
384f9c8bdb |
@@ -0,0 +1,272 @@
|
||||
/**
|
||||
* DC-073: regression tests for the caddy-upstreams mute endpoints.
|
||||
*
|
||||
* Pre-fix, only the bare `/caddy/upstreams/mute` body-style endpoint
|
||||
* rejected unknown hosts with a 400 "not a known upstream". The
|
||||
* path-style `/:host/mute` and `/:host/unmute` endpoints skipped that
|
||||
* check entirely and would silently call `setMuted(phantom, true)`,
|
||||
* persisting a phantom entry into the watcher's muted Set (which is
|
||||
* disk-persisted via `_saveState()`).
|
||||
*
|
||||
* These tests prove:
|
||||
* (1) every endpoint now rejects an unknown host with 400
|
||||
* (2) the rejection happens BEFORE setMuted is invoked (no state
|
||||
* corruption — `fakeWatcher.setMuted` is asserted to be
|
||||
* untouched on the rejection path)
|
||||
* (3) the rejection message is the canonical "not a known upstream"
|
||||
* so callers can branch on it
|
||||
* (4) known hosts still mute / unmute correctly (no regression)
|
||||
* (5) the bare handler still accepts the body { host, muted: 'false' }
|
||||
* string-coercion quirk it had before (so the original
|
||||
* caddy-upstreams.routes.test.js suite keeps passing)
|
||||
*
|
||||
* @module __tests__/routes/caddy-upstreams-dc073
|
||||
*/
|
||||
|
||||
const express = require('express');
|
||||
const { validateAndMuteHost } = require('../../routes/caddy-upstreams').__test;
|
||||
|
||||
function buildRouter(deps) {
|
||||
const mod = require('../../routes/caddy-upstreams');
|
||||
return mod(deps);
|
||||
}
|
||||
|
||||
function buildApp(mod_deps) {
|
||||
const app = express();
|
||||
app.use(express.json());
|
||||
app.use((req, res, next) => {
|
||||
res.success = (data) => res.json({ success: true, ...data });
|
||||
res.errorResponse = (msg, code) => res.status(code || 500).json({ success: false, error: msg });
|
||||
next();
|
||||
});
|
||||
app.use(buildRouter({
|
||||
asyncHandler: (fn, _ctx) => async (req, res, next) => {
|
||||
try { await fn(req, res, next); } catch (e) { next(e); }
|
||||
},
|
||||
...mod_deps,
|
||||
}));
|
||||
// Error middleware MUST be registered AFTER routes so it actually catches.
|
||||
app.use((err, req, res, next) => {
|
||||
if (err && err.statusCode === 400) {
|
||||
return res.status(400).json({ success: false, error: err.message });
|
||||
}
|
||||
return res.status(err?.statusCode || 500).json({ success: false, error: err?.message || 'unknown' });
|
||||
});
|
||||
return app;
|
||||
}
|
||||
|
||||
function makeKnownWatcher(known = ['known.svc.example:80', '1.1.1.1:80']) {
|
||||
const upstreams = new Map(known.map(h => [h, { host: h }]));
|
||||
return {
|
||||
upstreams,
|
||||
setMuted: jest.fn((host, muted) => ({ host, muted: !!muted })),
|
||||
snapshot: jest.fn(() => ({ upstreams: [], config: {} })),
|
||||
};
|
||||
}
|
||||
|
||||
describe('routes/caddy-upstreams — DC-073 phantom-mute regression', () => {
|
||||
describe('validateAndMuteHost helper (unit)', () => {
|
||||
test('rejects empty / non-string host', () => {
|
||||
const w = makeKnownWatcher();
|
||||
expect(() => validateAndMuteHost(w, '', true)).toThrow(/non-empty string/);
|
||||
expect(() => validateAndMuteHost(w, null, true)).toThrow(/non-empty string/);
|
||||
expect(() => validateAndMuteHost(w, undefined, true)).toThrow(/non-empty string/);
|
||||
expect(() => validateAndMuteHost(w, 12345, true)).toThrow(/non-empty string/);
|
||||
expect(w.setMuted).not.toHaveBeenCalled();
|
||||
});
|
||||
|
||||
test('rejects host longer than 253 chars', () => {
|
||||
const w = makeKnownWatcher();
|
||||
const long = 'a'.repeat(254);
|
||||
expect(() => validateAndMuteHost(w, long, true)).toThrow(/non-empty string/);
|
||||
expect(w.setMuted).not.toHaveBeenCalled();
|
||||
});
|
||||
|
||||
test('rejects host with charset-violating chars', () => {
|
||||
const w = makeKnownWatcher();
|
||||
for (const bad of ['host name', 'host?', 'host/abc', 'host;rm', 'host${x}', 'host<>']) {
|
||||
expect(() => validateAndMuteHost(w, bad, true)).toThrow(/valid host/);
|
||||
}
|
||||
expect(w.setMuted).not.toHaveBeenCalled();
|
||||
});
|
||||
|
||||
test('rejects host not in watcher.upstreams (phantom-mute vector)', () => {
|
||||
const w = makeKnownWatcher(['known:80']);
|
||||
// This is the regression: pre-fix, this call would have
|
||||
// silently added 'phantom.test:12345' to watcher.muted.
|
||||
expect(() => validateAndMuteHost(w, 'phantom.test:12345', true))
|
||||
.toThrow(/not a known upstream/);
|
||||
expect(w.setMuted).not.toHaveBeenCalled();
|
||||
});
|
||||
|
||||
test('accepts a known host and forwards setMuted(host, wantMuted)', () => {
|
||||
const w = makeKnownWatcher(['known:80']);
|
||||
const result = validateAndMuteHost(w, 'known:80', true);
|
||||
expect(w.setMuted).toHaveBeenCalledWith('known:80', true);
|
||||
expect(result).toEqual({ host: 'known:80', muted: true });
|
||||
|
||||
w.setMuted.mockClear();
|
||||
const result2 = validateAndMuteHost(w, 'known:80', false);
|
||||
expect(w.setMuted).toHaveBeenCalledWith('known:80', false);
|
||||
expect(result2).toEqual({ host: 'known:80', muted: false });
|
||||
});
|
||||
|
||||
test('handles missing watcher / upstreams map (defensive)', () => {
|
||||
expect(() => validateAndMuteHost(null, 'x:80', true)).toThrow(/not a known upstream/);
|
||||
expect(() => validateAndMuteHost({}, 'x:80', true)).toThrow(/not a known upstream/);
|
||||
expect(() => validateAndMuteHost({ upstreams: null }, 'x:80', true)).toThrow(/not a known upstream/);
|
||||
});
|
||||
});
|
||||
|
||||
describe('POST /caddy/upstreams/mute (bare body-style)', () => {
|
||||
test('rejects unknown host with 400 (was already correct, regression-proof)', async () => {
|
||||
const w = makeKnownWatcher(['known:80']);
|
||||
const app = buildApp({ caddyUpstreamWatcher: w, healthChecker: { incidents: [] } });
|
||||
const server = app.listen(0);
|
||||
const { port } = server.address();
|
||||
const res = await fetch(`http://127.0.0.1:${port}/caddy/upstreams/mute`, {
|
||||
method: 'POST',
|
||||
headers: { 'Content-Type': 'application/json' },
|
||||
body: JSON.stringify({ host: 'phantom:12345' }),
|
||||
});
|
||||
const body = await res.json();
|
||||
server.close();
|
||||
expect(res.status).toBe(400);
|
||||
expect(body.error).toMatch(/not a known upstream/);
|
||||
expect(w.setMuted).not.toHaveBeenCalled();
|
||||
});
|
||||
|
||||
test('muted: "false" string still coerces to unmute (regression from caddy-upstreams.routes.test.js)', async () => {
|
||||
const w = makeKnownWatcher(['known:80']);
|
||||
const app = buildApp({ caddyUpstreamWatcher: w, healthChecker: { incidents: [] } });
|
||||
const server = app.listen(0);
|
||||
const { port } = server.address();
|
||||
const res = await fetch(`http://127.0.0.1:${port}/caddy/upstreams/mute`, {
|
||||
method: 'POST',
|
||||
headers: { 'Content-Type': 'application/json' },
|
||||
body: JSON.stringify({ host: 'known:80', muted: 'false' }),
|
||||
});
|
||||
const body = await res.json();
|
||||
server.close();
|
||||
expect(body.success).toBe(true);
|
||||
expect(w.setMuted).toHaveBeenCalledWith('known:80', false);
|
||||
});
|
||||
});
|
||||
|
||||
describe('POST /caddy/upstreams/:host/mute (path-style) — DC-073 main fix', () => {
|
||||
test('rejects unknown host with 400 instead of silent phantom-mute', async () => {
|
||||
const w = makeKnownWatcher(['known:80']);
|
||||
const app = buildApp({ caddyUpstreamWatcher: w, healthChecker: { incidents: [] } });
|
||||
const server = app.listen(0);
|
||||
const { port } = server.address();
|
||||
// Pre-fix this would have silently added 'phantom.test:12345' to
|
||||
// the watcher's muted Set and called _saveState(). Post-fix it
|
||||
// returns 400 and never touches the watcher.
|
||||
const res = await fetch(`http://127.0.0.1:${port}/caddy/upstreams/phantom.test:12345/mute`, {
|
||||
method: 'POST',
|
||||
});
|
||||
const body = await res.json();
|
||||
server.close();
|
||||
expect(res.status).toBe(400);
|
||||
expect(body.error).toMatch(/not a known upstream/);
|
||||
expect(w.setMuted).not.toHaveBeenCalled();
|
||||
});
|
||||
|
||||
test('mutes a known host via bare POST (no body)', async () => {
|
||||
const w = makeKnownWatcher(['known.svc.example:80']);
|
||||
const app = buildApp({ caddyUpstreamWatcher: w, healthChecker: { incidents: [] } });
|
||||
const server = app.listen(0);
|
||||
const { port } = server.address();
|
||||
const res = await fetch(`http://127.0.0.1:${port}/caddy/upstreams/known.svc.example:80/mute`, {
|
||||
method: 'POST',
|
||||
});
|
||||
const body = await res.json();
|
||||
server.close();
|
||||
expect(res.status).toBe(200);
|
||||
expect(body.success).toBe(true);
|
||||
expect(w.setMuted).toHaveBeenCalledWith('known.svc.example:80', true);
|
||||
});
|
||||
|
||||
test('mutes via ?muted=true query', async () => {
|
||||
const w = makeKnownWatcher(['known.svc.example:80']);
|
||||
const app = buildApp({ caddyUpstreamWatcher: w, healthChecker: { incidents: [] } });
|
||||
const server = app.listen(0);
|
||||
const { port } = server.address();
|
||||
const res = await fetch(`http://127.0.0.1:${port}/caddy/upstreams/known.svc.example:80/mute?muted=true`, {
|
||||
method: 'POST',
|
||||
});
|
||||
const body = await res.json();
|
||||
server.close();
|
||||
expect(w.setMuted).toHaveBeenCalledWith('known.svc.example:80', true);
|
||||
expect(body.success).toBe(true);
|
||||
});
|
||||
|
||||
test('unmutes via body { muted: false }', async () => {
|
||||
const w = makeKnownWatcher(['known.svc.example:80']);
|
||||
const app = buildApp({ caddyUpstreamWatcher: w, healthChecker: { incidents: [] } });
|
||||
const server = app.listen(0);
|
||||
const { port } = server.address();
|
||||
const res = await fetch(`http://127.0.0.1:${port}/caddy/upstreams/known.svc.example:80/mute`, {
|
||||
method: 'POST',
|
||||
headers: { 'Content-Type': 'application/json' },
|
||||
body: JSON.stringify({ muted: false }),
|
||||
});
|
||||
const body = await res.json();
|
||||
server.close();
|
||||
expect(w.setMuted).toHaveBeenCalledWith('known.svc.example:80', false);
|
||||
expect(body.success).toBe(true);
|
||||
});
|
||||
});
|
||||
|
||||
describe('POST /caddy/upstreams/:host/unmute (path-style) — DC-073 main fix', () => {
|
||||
test('rejects unknown host with 400 instead of silent phantom-unmute', async () => {
|
||||
const w = makeKnownWatcher(['known:80']);
|
||||
const app = buildApp({ caddyUpstreamWatcher: w, healthChecker: { incidents: [] } });
|
||||
const server = app.listen(0);
|
||||
const { port } = server.address();
|
||||
const res = await fetch(`http://127.0.0.1:${port}/caddy/upstreams/phantom.test:12345/unmute`, {
|
||||
method: 'POST',
|
||||
});
|
||||
const body = await res.json();
|
||||
server.close();
|
||||
expect(res.status).toBe(400);
|
||||
expect(body.error).toMatch(/not a known upstream/);
|
||||
expect(w.setMuted).not.toHaveBeenCalled();
|
||||
});
|
||||
|
||||
test('unmutes a known host', async () => {
|
||||
const w = makeKnownWatcher(['known.svc.example:80']);
|
||||
const app = buildApp({ caddyUpstreamWatcher: w, healthChecker: { incidents: [] } });
|
||||
const server = app.listen(0);
|
||||
const { port } = server.address();
|
||||
const res = await fetch(`http://127.0.0.1:${port}/caddy/upstreams/known.svc.example:80/unmute`, {
|
||||
method: 'POST',
|
||||
});
|
||||
const body = await res.json();
|
||||
server.close();
|
||||
expect(res.status).toBe(200);
|
||||
expect(w.setMuted).toHaveBeenCalledWith('known.svc.example:80', false);
|
||||
expect(body.success).toBe(true);
|
||||
});
|
||||
});
|
||||
|
||||
describe('router introspection (DC-057-style mount-count assertion)', () => {
|
||||
test('exactly one POST handler per (method,path) — no duplicate registration', () => {
|
||||
const w = makeKnownWatcher();
|
||||
const router = buildRouter({
|
||||
asyncHandler: (fn) => fn,
|
||||
caddyUpstreamWatcher: w,
|
||||
healthChecker: { incidents: [] },
|
||||
});
|
||||
const sigs = router.stack
|
||||
.filter((l) => l.route)
|
||||
.map((l) => Object.keys(l.route.methods).map((m) => `${m.toUpperCase()} ${l.route.path}`))
|
||||
.flat();
|
||||
// Each (method,path) should appear exactly once
|
||||
const counts = sigs.reduce((m, s) => (m[s] = (m[s] || 0) + 1, m), {});
|
||||
for (const [sig, n] of Object.entries(counts)) {
|
||||
expect({ sig, n }).toEqual({ sig, n: 1 });
|
||||
}
|
||||
});
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,277 @@
|
||||
/**
|
||||
* DC-070: Caddycode config sanitization — validate the structural config
|
||||
* that flows into generateSiteBlock(), and confirm that the post-fix
|
||||
* generation does NOT interpolate raw user input into Caddyfile text.
|
||||
*
|
||||
* The endpoint /caddycode/generate was, pre-fix, the single most exposed
|
||||
* surface in the Caddy-as-code path: every JSON field flowed verbatim into
|
||||
* the Caddyfile text that /caddycode→POST /load feeds to Caddy.
|
||||
*
|
||||
* Bug class under test:
|
||||
* 1. CRLF / newline in `domain` → close the block and inject a new site
|
||||
* 2. `"` (quote) in a header value → break out of the quoted-string
|
||||
* context and append arbitrary directives
|
||||
* 3. `}` in `tls`, `authService`, `stripPrefix`, or `upstream` →
|
||||
* prematurely close the parent block (or open a new one)
|
||||
* 4. `://` or `;` in `upstream` → header injection / path smuggling
|
||||
*
|
||||
* Post-fix: validateGenerationConfig rejects every one of these at the
|
||||
* route layer with 400 + enumerable errors; the helper-level tests here
|
||||
* pin the rejection rules independent of the route.
|
||||
*/
|
||||
|
||||
const { __test } = require('../../routes/caddycode');
|
||||
const { validateGenerationConfig, escapeCaddyQuotedString, generateSiteBlock } = __test;
|
||||
|
||||
const BASE_OK = {
|
||||
domain: 'app.example.com',
|
||||
upstream: 'localhost:8080',
|
||||
};
|
||||
|
||||
function check(cond, msg) {
|
||||
if (!cond) throw new Error('assertion failed: ' + msg);
|
||||
}
|
||||
|
||||
describe('DC-070: caddycode config sanitization', () => {
|
||||
describe('validateGenerationConfig — happy paths', () => {
|
||||
test('minimal valid config passes', () => {
|
||||
const r = validateGenerationConfig(BASE_OK);
|
||||
check(r.valid === true, `expected valid=true, got errors=${JSON.stringify(r.errors)}`);
|
||||
check(Array.isArray(r.errors) && r.errors.length === 0, 'expected no errors');
|
||||
});
|
||||
|
||||
test('full valid config (auth + headers + stripPrefix + tls CA) passes', () => {
|
||||
const r = validateGenerationConfig({
|
||||
domain: 'chat.example.com',
|
||||
upstream: 'localhost:8096',
|
||||
tls: 'letsencrypt',
|
||||
auth: true,
|
||||
authService: 'chat',
|
||||
upstreamProtocol: 'https',
|
||||
headers: {
|
||||
'X-Frame-Options': 'DENY',
|
||||
'X-Content-Type-Options': 'nosniff',
|
||||
'Strict-Transport-Security': 'max-age=63072000',
|
||||
},
|
||||
stripPrefix: '/api/v1',
|
||||
});
|
||||
check(r.valid === true, `expected valid, got errors=${JSON.stringify(r.errors)}`);
|
||||
});
|
||||
|
||||
test('IPv6 bracket-form upstream accepted', () => {
|
||||
const r = validateGenerationConfig({ domain: 'dns.example.com', upstream: '[::1]:5380' });
|
||||
check(r.valid === true, `IPv6 bracket should pass: ${JSON.stringify(r.errors)}`);
|
||||
});
|
||||
|
||||
test('bare host without :port rejected (DC-070 round 2)', () => {
|
||||
// Round-1 polish: Caddy reverse_proxy requires an explicit :port
|
||||
// segment. A bare `localhost` would produce a Caddyfile that
|
||||
// either fails to reload or silently picks a default port.
|
||||
const r = validateGenerationConfig({ domain: 'app.example.com', upstream: 'localhost' });
|
||||
check(r.valid === false, `bare host should reject: ${JSON.stringify(r.errors)}`);
|
||||
});
|
||||
|
||||
test('upstream with non-numeric port rejected', () => {
|
||||
const r = validateGenerationConfig({ domain: 'app.example.com', upstream: 'localhost:abc' });
|
||||
check(r.valid === false, `non-numeric port should reject: ${JSON.stringify(r.errors)}`);
|
||||
});
|
||||
});
|
||||
|
||||
describe('validateGenerationConfig — injection rejection', () => {
|
||||
test('CRLF in domain rejected', () => {
|
||||
const r = validateGenerationConfig({ ...BASE_OK, domain: 'evil.com\nnew.site.example.com {' });
|
||||
check(r.valid === false, 'CRLF should reject');
|
||||
check(r.errors.some((e) => /domain/.test(e)), `expected error to mention domain, got ${JSON.stringify(r.errors)}`);
|
||||
});
|
||||
|
||||
test('brace in domain rejected', () => {
|
||||
const r = validateGenerationConfig({ ...BASE_OK, domain: 'evil} malicious' });
|
||||
check(r.valid === false, 'brace should reject');
|
||||
});
|
||||
|
||||
test('"://" in upstream rejected', () => {
|
||||
const r = validateGenerationConfig({ ...BASE_OK, upstream: 'http://evil.tld/x' });
|
||||
check(r.valid === false, ':// should reject');
|
||||
});
|
||||
|
||||
test('space + brace in upstream rejected', () => {
|
||||
const r = validateGenerationConfig({ ...BASE_OK, upstream: 'localhost:8080 } evil {' });
|
||||
check(r.valid === false, 'whitespace+brace in upstream should reject');
|
||||
});
|
||||
|
||||
test('CRLF in header value rejected', () => {
|
||||
const r = validateGenerationConfig({
|
||||
...BASE_OK,
|
||||
headers: { 'X-Custom': 'innocent\r\nHost: evil.tld' },
|
||||
});
|
||||
check(r.valid === false, 'CRLF in header value should reject');
|
||||
check(r.errors.some((e) => /CR or LF/i.test(e)), `expected CR/LF error: ${JSON.stringify(r.errors)}`);
|
||||
});
|
||||
|
||||
test('bad header key charset rejected', () => {
|
||||
const r = validateGenerationConfig({
|
||||
...BASE_OK,
|
||||
headers: { 'X Bad Key': 'innocent' },
|
||||
});
|
||||
check(r.valid === false, 'space in header key should reject');
|
||||
});
|
||||
|
||||
test('non-string tls rejected', () => {
|
||||
const r = validateGenerationConfig({ ...BASE_OK, tls: 'evil directive' });
|
||||
check(r.valid === false, 'whitespace+word tls should reject');
|
||||
});
|
||||
|
||||
test('empty authService when auth=true rejected', () => {
|
||||
const r = validateGenerationConfig({ ...BASE_OK, auth: true });
|
||||
check(r.valid === false, 'auth=true requires authService');
|
||||
});
|
||||
|
||||
test('upstreamProtocol other than http/https rejected', () => {
|
||||
const r = validateGenerationConfig({ ...BASE_OK, upstreamProtocol: 'javascript' });
|
||||
check(r.valid === false, 'non-http protocol should reject');
|
||||
});
|
||||
|
||||
test('stripPrefix without leading slash rejected', () => {
|
||||
const r = validateGenerationConfig({ ...BASE_OK, stripPrefix: 'app/v1' });
|
||||
check(r.valid === false, 'stripPrefix without leading slash should reject');
|
||||
});
|
||||
|
||||
test('stripPrefix with brace rejected', () => {
|
||||
const r = validateGenerationConfig({ ...BASE_OK, stripPrefix: '/api/{evil}' });
|
||||
check(r.valid === false, 'stripPrefix with brace should reject');
|
||||
});
|
||||
|
||||
test('multiple errors returned together (enumerable)', () => {
|
||||
const r = validateGenerationConfig({
|
||||
domain: 'evil }',
|
||||
upstream: 'localhost:8080 } malicious {',
|
||||
tls: 'bad tls',
|
||||
auth: true,
|
||||
headers: { 'X B': 'oops' },
|
||||
});
|
||||
check(r.valid === false, 'should reject');
|
||||
check(r.errors.length >= 4, `expected multiple errors, got ${r.errors.length}: ${JSON.stringify(r.errors)}`);
|
||||
});
|
||||
});
|
||||
|
||||
describe('escapeCaddyQuotedString', () => {
|
||||
test('escapes backslash and quote', () => {
|
||||
check(escapeCaddyQuotedString('a"b\\c') === 'a\\"b\\\\c', 'should escape both');
|
||||
});
|
||||
|
||||
test('safe string passes through verbatim', () => {
|
||||
check(escapeCaddyQuotedString('hello') === 'hello', 'safe string unchanged');
|
||||
});
|
||||
|
||||
test('empty string survives', () => {
|
||||
check(escapeCaddyQuotedString('') === '', 'empty string survives');
|
||||
});
|
||||
});
|
||||
|
||||
describe('generateSiteBlock — quote-breakout defence-in-depth', () => {
|
||||
test('post-validation, header value with " is properly escaped', () => {
|
||||
// The validator REJECTS this upstream (CRLF + quote) but the
|
||||
// generator must also escape `"` even if a future code path bypasses
|
||||
// validation. This test pins the dual-defence.
|
||||
const cfg = {
|
||||
domain: 'app.example.com',
|
||||
upstream: 'localhost:8080',
|
||||
headers: { 'X-Custom': 'a"b' },
|
||||
};
|
||||
// The validator rejects CRLF + chars outside the charset, but a bare
|
||||
// `"` is technically allowed by /[\r\n]/ (only CR/LF). However the
|
||||
// GENERATOR must still escape it. Verify by calling generateSiteBlock
|
||||
// directly with a manually-validated config.
|
||||
const out = generateSiteBlock(cfg);
|
||||
// The header line should appear as: X-Custom "a\"b"
|
||||
// i.e. the raw `"` in the value MUST be escaped, otherwise the Caddyfile
|
||||
// line breaks out of the quoted context.
|
||||
check(out.includes('X-Custom "a\\"b"'), `expected escaped quote, got: ${out}`);
|
||||
});
|
||||
});
|
||||
|
||||
describe('route integration — /caddycode/generate wires validation', () => {
|
||||
const express = require('express');
|
||||
const request = require('supertest');
|
||||
const routes = require('../../routes/caddycode');
|
||||
|
||||
function buildApp() {
|
||||
const app = express();
|
||||
app.use(express.json());
|
||||
const wrap = (fn) => (req, res, next) => Promise.resolve(fn(req, res, next)).catch(next);
|
||||
return { app, wrap };
|
||||
}
|
||||
|
||||
test('valid config → 200 + caddyfile', async () => {
|
||||
const { app, wrap } = buildApp();
|
||||
app.use('/api/v1', routes({ asyncHandler: wrap }));
|
||||
const res = await request(app)
|
||||
.post('/api/v1/caddycode/generate')
|
||||
.send({ domain: 'app.example.com', upstream: 'localhost:8080' });
|
||||
check(res.status === 200, `expected 200, got ${res.status}`);
|
||||
check(typeof res.body.caddyfile === 'string', 'expected caddyfile string');
|
||||
check(res.body.caddyfile.includes('app.example.com'), 'caddyfile should include domain');
|
||||
});
|
||||
|
||||
test('CRLF in domain → 400 + enumerable errors', async () => {
|
||||
const { app, wrap } = buildApp();
|
||||
app.use('/api/v1', routes({ asyncHandler: wrap }));
|
||||
const res = await request(app)
|
||||
.post('/api/v1/caddycode/generate')
|
||||
.send({ domain: 'evil.com\nnew block', upstream: 'localhost:8080' });
|
||||
check(res.status === 400, `expected 400, got ${res.status}: ${JSON.stringify(res.body)}`);
|
||||
check(res.body.success === false, 'success should be false');
|
||||
check(Array.isArray(res.body.errors), `expected enumerable errors array, got body=${JSON.stringify(res.body)}`);
|
||||
check(res.body.errors.length >= 1, 'at least one error');
|
||||
});
|
||||
|
||||
test('"://" in upstream → 400', async () => {
|
||||
const { app, wrap } = buildApp();
|
||||
app.use('/api/v1', routes({ asyncHandler: wrap }));
|
||||
const res = await request(app)
|
||||
.post('/api/v1/caddycode/generate')
|
||||
.send({ domain: 'app.example.com', upstream: 'http://evil.tld/x' });
|
||||
check(res.status === 400, `expected 400, got ${res.status}`);
|
||||
});
|
||||
|
||||
test('header with CRLF → 400 + specific error', async () => {
|
||||
const { app, wrap } = buildApp();
|
||||
app.use('/api/v1', routes({ asyncHandler: wrap }));
|
||||
const res = await request(app)
|
||||
.post('/api/v1/caddycode/generate')
|
||||
.send({
|
||||
domain: 'app.example.com',
|
||||
upstream: 'localhost:8080',
|
||||
headers: { 'X-Bad': 'oops\r\nHost: evil.tld' },
|
||||
});
|
||||
check(res.status === 400, `expected 400, got ${res.status}`);
|
||||
check(res.body.errors.some((e) => /CR or LF/i.test(e)), `expected CR/LF mention: ${JSON.stringify(res.body.errors)}`);
|
||||
});
|
||||
|
||||
test('end-to-end: header value with quote + backslash round-trips through generator', async () => {
|
||||
// DC-070 round-2 polish (per GLM-5.3 review): the unit tests pin the
|
||||
// escape helper and the route reject path independently, but nothing
|
||||
// asserts the GENERATED Caddyfile is well-formed when a header value
|
||||
// contains BOTH " and \. Verify the generator escapes both so the
|
||||
// resulting line parses as a Caddyfile quoted string.
|
||||
const { app, wrap } = buildApp();
|
||||
app.use('/api/v1', routes({ asyncHandler: wrap }));
|
||||
const res = await request(app)
|
||||
.post('/api/v1/caddycode/generate')
|
||||
.send({
|
||||
domain: 'app.example.com',
|
||||
upstream: 'localhost:8080',
|
||||
headers: { 'X-Custom': 'a"b\\c' },
|
||||
});
|
||||
check(res.status === 200, `expected 200, got ${res.status}: ${JSON.stringify(res.body)}`);
|
||||
const out = res.body.caddyfile;
|
||||
check(typeof out === 'string', 'expected caddyfile string');
|
||||
// The header line should be EXACTLY: X-Custom "a\"b\\c"
|
||||
// i.e. the raw `"` and `\` in the value MUST be escaped.
|
||||
check(
|
||||
/X-Custom "a\\"b\\\\c"/.test(out),
|
||||
`expected escaped quote+backslash in generated Caddyfile, got: ${out}`
|
||||
);
|
||||
});
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,192 @@
|
||||
/**
|
||||
* DC-072: WebSocket exec scope-based authorization + containerId charset
|
||||
* hardening.
|
||||
*
|
||||
* Bug class under test:
|
||||
* 1. Pre-fix `routes/exec.js` captured `auth.scope` (line 39/46) but
|
||||
* NEVER enforced it. A JWT or API key whose scope was `['read']`
|
||||
* (a legitimate monitoring/observability scope) would be granted a
|
||||
* full PTY-backed shell inside any running container. Container
|
||||
* exec is root-equivalent inside the container's user namespace,
|
||||
* so this is a privilege escalation: a read-only key holder could
|
||||
* run arbitrary commands, exfiltrate mounted volumes, or pivot
|
||||
* to the host network.
|
||||
*
|
||||
* 2. Pre-fix `containerId` regex `/^[a-zA-Z0-9][a-zA-Z0-9_.-]{0,127}$/`
|
||||
* accepted mixed case, `_`, `-`, `.`, and any length up to 128.
|
||||
* Docker container IDs are exactly 64 lowercase hex (or 12-char
|
||||
* short form). The pre-fix validator would pass any string that
|
||||
* looked vaguely ID-shaped; Docker's inspect() would then 404.
|
||||
*
|
||||
* Post-fix: `assertExecScope(auth)` requires `admin` scope and throws a
|
||||
* 403-tagged error. `isValidContainerId(id)` accepts only 12 or 64
|
||||
* lowercase hex chars. Both helpers are exported via `__test`.
|
||||
*/
|
||||
|
||||
const { __test } = require('../../routes/exec');
|
||||
const { assertExecScope, isValidContainerId } = __test;
|
||||
|
||||
function check(cond, msg) {
|
||||
if (!cond) throw new Error('assertion failed: ' + msg);
|
||||
}
|
||||
|
||||
describe('DC-072: exec WebSocket scope-based authorization', () => {
|
||||
describe('assertExecScope — admin required', () => {
|
||||
test('admin scope passes', () => {
|
||||
// Should not throw
|
||||
assertExecScope({ type: 'jwt', scope: ['admin'] });
|
||||
assertExecScope({ type: 'apikey', scope: ['admin', 'read'] });
|
||||
});
|
||||
|
||||
test('read-only scope rejected with DC-072_INSUFFICIENT_SCOPE', () => {
|
||||
let caught = null;
|
||||
try {
|
||||
assertExecScope({ type: 'apikey', scope: ['read'] });
|
||||
} catch (e) {
|
||||
caught = e;
|
||||
}
|
||||
check(caught !== null, 'expected assertExecScope to throw on read-only scope');
|
||||
check(caught.code === 'DC-072_INSUFFICIENT_SCOPE', `expected code DC-072_INSUFFICIENT_SCOPE, got ${caught.code}`);
|
||||
check(caught.statusCode === 403, `expected statusCode 403, got ${caught.statusCode}`);
|
||||
check(caught.requiredScope === 'admin', `expected requiredScope=admin, got ${caught.requiredScope}`);
|
||||
check(Array.isArray(caught.actualScope) && caught.actualScope[0] === 'read', `expected actualScope=['read'], got ${JSON.stringify(caught.actualScope)}`);
|
||||
});
|
||||
|
||||
test('write-only scope rejected (write ≠ admin)', () => {
|
||||
let caught = null;
|
||||
try {
|
||||
assertExecScope({ type: 'jwt', scope: ['write'] });
|
||||
} catch (e) {
|
||||
caught = e;
|
||||
}
|
||||
check(caught !== null, 'expected assertExecScope to throw on write-only scope');
|
||||
check(caught.code === 'DC-072_INSUFFICIENT_SCOPE', `expected code DC-072_INSUFFICIENT_SCOPE, got ${caught.code}`);
|
||||
check(caught.statusCode === 403, `expected statusCode 403, got ${caught.statusCode}`);
|
||||
});
|
||||
|
||||
test('empty scope rejected', () => {
|
||||
let caught = null;
|
||||
try {
|
||||
assertExecScope({ type: 'apikey', scope: [] });
|
||||
} catch (e) {
|
||||
caught = e;
|
||||
}
|
||||
check(caught !== null, 'expected assertExecScope to throw on empty scope');
|
||||
check(caught.code === 'DC-072_INSUFFICIENT_SCOPE', 'expected DC-072_INSUFFICIENT_SCOPE code');
|
||||
});
|
||||
|
||||
test('undefined scope rejected (null-safety)', () => {
|
||||
let caught = null;
|
||||
try {
|
||||
assertExecScope({ type: 'jwt' }); // no scope field
|
||||
} catch (e) {
|
||||
caught = e;
|
||||
}
|
||||
check(caught !== null, 'expected assertExecScope to throw on undefined scope');
|
||||
check(caught.code === 'DC-072_INSUFFICIENT_SCOPE', 'expected DC-072_INSUFFICIENT_SCOPE code');
|
||||
});
|
||||
|
||||
test('null auth rejected', () => {
|
||||
let caught = null;
|
||||
try {
|
||||
assertExecScope(null);
|
||||
} catch (e) {
|
||||
caught = e;
|
||||
}
|
||||
check(caught !== null, 'expected assertExecScope to throw on null auth');
|
||||
check(caught.code === 'DC-072_INSUFFICIENT_SCOPE', 'expected DC-072_INSUFFICIENT_SCOPE code');
|
||||
});
|
||||
|
||||
test('non-array scope rejected (defensive)', () => {
|
||||
let caught = null;
|
||||
try {
|
||||
assertExecScope({ type: 'apikey', scope: 'admin' }); // string, not array
|
||||
} catch (e) {
|
||||
caught = e;
|
||||
}
|
||||
check(caught !== null, 'expected assertExecScope to throw on non-array scope');
|
||||
check(caught.code === 'DC-072_INSUFFICIENT_SCOPE', 'expected DC-072_INSUFFICIENT_SCOPE code');
|
||||
});
|
||||
|
||||
test('error envelope carries operator-actionable fields', () => {
|
||||
let caught = null;
|
||||
try {
|
||||
assertExecScope({ type: 'apikey', keyId: 'k_test', scope: ['read'] });
|
||||
} catch (e) {
|
||||
caught = e;
|
||||
}
|
||||
check(caught.message === 'Container exec requires admin scope', `expected canonical message, got ${caught.message}`);
|
||||
check(typeof caught.requiredScope === 'string' && caught.requiredScope === 'admin', 'requiredScope present');
|
||||
check(Array.isArray(caught.actualScope), 'actualScope is array');
|
||||
});
|
||||
});
|
||||
|
||||
describe('isValidContainerId — Docker charset (12 or 64 lowercase hex)', () => {
|
||||
test('64-char lowercase hex accepted (full Docker ID)', () => {
|
||||
// Real-world example: dashcaddy-api container ID
|
||||
check(isValidContainerId('abcdef0123456789abcdef0123456789abcdef0123456789abcdef0123456789') === true, '64-char hex should pass');
|
||||
});
|
||||
|
||||
test('12-char lowercase hex accepted (short form)', () => {
|
||||
check(isValidContainerId('abcdef012345') === true, '12-char hex should pass');
|
||||
});
|
||||
|
||||
test('uppercase hex rejected (Docker IDs are lowercase)', () => {
|
||||
check(isValidContainerId('ABCDEF0123456789ABCDEF0123456789ABCDEF0123456789ABCDEF0123456789') === false, 'uppercase 64-char should fail');
|
||||
check(isValidContainerId('ABCDEF012345') === false, 'uppercase 12-char should fail');
|
||||
});
|
||||
|
||||
test('mixed case rejected', () => {
|
||||
check(isValidContainerId('Abcdef0123456789abcdef0123456789abcdef0123456789abcdef0123456789') === false, 'mixed case 64-char should fail');
|
||||
});
|
||||
|
||||
test('non-hex chars rejected', () => {
|
||||
check(isValidContainerId('zzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzz') === false, 'g-z hex should fail');
|
||||
check(isValidContainerId('abc!@#$%^&*()_+-=[]{}|\\:;\'",.<>/?0123456789012345678901234567890123') === false, 'special chars should fail');
|
||||
});
|
||||
|
||||
test('underscore / dot / dash rejected (pre-fix allowed these)', () => {
|
||||
// Pre-fix regex accepted `_`, `-`, `.` — all are non-Docker
|
||||
check(isValidContainerId('my_container_1') === false, 'underscore should fail');
|
||||
check(isValidContainerId('my.container.1') === false, 'dot should fail');
|
||||
check(isValidContainerId('my-container-1') === false, 'dash should fail');
|
||||
});
|
||||
|
||||
test('wrong length rejected', () => {
|
||||
check(isValidContainerId('abcdef0123456') === false, '13-char should fail'); // 12 + 1
|
||||
check(isValidContainerId('abcdef01234567') === false, '14-char should fail'); // 12 + 2
|
||||
check(isValidContainerId('abcdef0123456789a') === false, '65-char should fail'); // 64 + 1
|
||||
});
|
||||
|
||||
test('empty string rejected', () => {
|
||||
check(isValidContainerId('') === false, 'empty string should fail');
|
||||
});
|
||||
|
||||
test('null / undefined / non-string rejected (defensive)', () => {
|
||||
check(isValidContainerId(null) === false, 'null should fail');
|
||||
check(isValidContainerId(undefined) === false, 'undefined should fail');
|
||||
check(isValidContainerId(12345) === false, 'number should fail');
|
||||
check(isValidContainerId({}) === false, 'object should fail');
|
||||
check(isValidContainerId([]) === false, 'array should fail');
|
||||
});
|
||||
|
||||
test('whitespace / padding rejected', () => {
|
||||
check(isValidContainerId(' abcdef012345 ') === false, 'padded should fail');
|
||||
check(isValidContainerId('\nabcdef012345\n') === false, 'CRLF-padded should fail');
|
||||
});
|
||||
|
||||
test('CRLF injection rejected (defensive against pre-fix attack class)', () => {
|
||||
// Pre-fix regex accepted 128 chars with dots; a payload like
|
||||
// `aa.bb.cc.dd\r\nSet-Cookie:...` would have passed. Post-fix
|
||||
// the LF + non-hex + wrong-length combo fails on every axis.
|
||||
check(isValidContainerId('aa\r\nbb') === false, 'CRLF payload should fail');
|
||||
});
|
||||
});
|
||||
|
||||
describe('__test exports shape', () => {
|
||||
test('exports assertExecScope and isValidContainerId', () => {
|
||||
check(typeof __test.assertExecScope === 'function', 'assertExecScope is a function');
|
||||
check(typeof __test.isValidContainerId === 'function', 'isValidContainerId is a function');
|
||||
});
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,535 @@
|
||||
/**
|
||||
* DC-074: SSRF hardening for sites.js — `/site` and `/site/external`
|
||||
* must reject upstream hosts that resolve to private/reserved ranges
|
||||
* BEFORE they reach the Caddyfile.
|
||||
*
|
||||
* Bug class: an authenticated dashboard operator could call
|
||||
* POST /api/v1/site {domain: "x.example.com", upstream: "10.0.0.1:80"}
|
||||
* POST /api/v1/site/external {subdomain: "x", externalUrl: "http://192.168.1.5"}
|
||||
* and end up with a Caddy site block that proxies PUBLIC traffic to an
|
||||
* INTERNAL host. Caddy runs on DNS2 (same network as the targets), so
|
||||
* the SSRF lands.
|
||||
*
|
||||
* Pre-fix: `/site`'s only upstream check was `^[a-z0-9.-]+:\d{1,5}$/i`,
|
||||
* which accepts 192.168.1.1:80 and 169.254.169.254:80 (the AWS
|
||||
* metadata IP) with no problem. `/site/external` used `validateURL`
|
||||
* without `blockPrivate: true` at all.
|
||||
*
|
||||
* Post-fix: a new helper `validateUpstream()` in `fleet-validation.js`
|
||||
* reuses the resolver+private-range checks fleet-validation already has
|
||||
* for DC-068, gating Caddyfile writes behind a public-IP requirement.
|
||||
* Opt-in via `SITES_ALLOW_PRIVATE_UPSTREAMS=true` for operators who
|
||||
* intentionally proxy to private targets.
|
||||
*
|
||||
* The suite covers three layers:
|
||||
* 1. Helper unit tests — validateUpstream with mocked DNS / literal IPs
|
||||
* 2. Route integration tests — POST /site and POST /site/external
|
||||
* reject each known private range, accept public IPs and hostnames
|
||||
* 3. Regression — pre-fix payload `10.0.0.1:80` is rejected (the
|
||||
* canonical SSRF regression proof)
|
||||
*/
|
||||
const express = require('express');
|
||||
const request = require('supertest');
|
||||
|
||||
const {
|
||||
validateUpstream,
|
||||
isPrivateOrReservedIPv4,
|
||||
isPrivateOrReservedIPv6,
|
||||
} = require('../../src/utilities/fleet-validation');
|
||||
|
||||
// ---------------------------------------------------------------------------
|
||||
// Test fixtures
|
||||
// ---------------------------------------------------------------------------
|
||||
|
||||
const LOG = () => ({ info: jest.fn(), warn: jest.fn(), error: jest.fn() });
|
||||
|
||||
/**
|
||||
* Build a minimal Express app that mounts /api/v1/sites with stubbed
|
||||
* caddy/dns/buildDomain/addServiceToConfig. The stubs record every call
|
||||
* so tests can assert the route does NOT mutate the Caddyfile when it
|
||||
* should reject.
|
||||
*/
|
||||
function createSitesApp({ log, caddyStub, buildDomainStub, dnsStub, addServiceToConfigStub } = {}) {
|
||||
const app = express();
|
||||
app.use(express.json({ limit: '1mb' }));
|
||||
const sites = require('../../routes/sites');
|
||||
const wrap = (fn) => (req, res, next) => Promise.resolve(fn(req, res, next)).catch(next);
|
||||
const caddy = caddyStub || {
|
||||
read: async () => '# stub caddyfile\n',
|
||||
modify: jest.fn(async () => ({ success: true })),
|
||||
adminUrl: 'http://127.0.0.1:2019',
|
||||
filePath: '/tmp/stub-Caddyfile',
|
||||
};
|
||||
const dns = dnsStub || {
|
||||
universalCreateRecord: jest.fn(async () => true),
|
||||
};
|
||||
app.use('/api/v1', sites({
|
||||
asyncHandler: wrap,
|
||||
ok: (res, data) => res.json({ ok: true, ...data }),
|
||||
successMessage: (res, msg) => res.json({ ok: true, message: msg }),
|
||||
caddy,
|
||||
dns,
|
||||
fetchT: async () => ({ ok: true, json: async () => ({}) }),
|
||||
buildDomain: buildDomainStub || ((sub) => `${sub}.example.com`),
|
||||
addServiceToConfig: addServiceToConfigStub || jest.fn(async () => true),
|
||||
siteConfig: { dnsServerIp: '127.0.0.1' },
|
||||
log: log || LOG(),
|
||||
}));
|
||||
// JSON error middleware — must mirror the shape sites.js's production
|
||||
// global error middleware emits so route tests can assert on it. Without
|
||||
// this, Express's default error handler returns an HTML stack trace and
|
||||
// res.body.error is undefined.
|
||||
// eslint-disable-next-line no-unused-vars
|
||||
app.use((err, req, res, next) => {
|
||||
const status = err.statusCode || 500;
|
||||
res.status(status).json({
|
||||
error: err.message || 'Internal Server Error',
|
||||
code: err.code || null,
|
||||
field: err.field || null,
|
||||
});
|
||||
});
|
||||
return { app, caddy };
|
||||
}
|
||||
|
||||
/** Mock dns.promises.lookup to return a specific IP for any hostname.
|
||||
* Returns an array of `{address, family}` records since fleet-validation
|
||||
* calls `dns.lookup(name, {all: true})`. */
|
||||
function mockDnsLookup(map) {
|
||||
const dns = require('dns');
|
||||
const original = dns.promises.lookup;
|
||||
dns.promises.lookup = async (hostname, opts) => {
|
||||
for (const [pattern, ip] of Object.entries(map)) {
|
||||
if (hostname === pattern || (pattern instanceof RegExp && pattern.test(hostname))) {
|
||||
const family = ip.includes(':') ? 6 : 4;
|
||||
return [{ address: ip, family }];
|
||||
}
|
||||
}
|
||||
// Default: throw ENOTFOUND
|
||||
const err = new Error('ENOTFOUND');
|
||||
err.code = 'ENOTFOUND';
|
||||
throw err;
|
||||
};
|
||||
return () => {
|
||||
dns.promises.lookup = original;
|
||||
};
|
||||
}
|
||||
|
||||
// ---------------------------------------------------------------------------
|
||||
// 1. Helper unit tests
|
||||
// ---------------------------------------------------------------------------
|
||||
|
||||
describe('DC-074: validateUpstream (helper)', () => {
|
||||
let restoreDns;
|
||||
|
||||
beforeEach(() => {
|
||||
delete process.env.SITES_ALLOW_PRIVATE_UPSTREAMS;
|
||||
});
|
||||
|
||||
afterEach(() => {
|
||||
if (restoreDns) restoreDns();
|
||||
delete process.env.SITES_ALLOW_PRIVATE_UPSTREAMS;
|
||||
});
|
||||
|
||||
describe('format validation', () => {
|
||||
test('rejects empty / non-string with INVALID_UPSTREAM', async () => {
|
||||
expect(await validateUpstream('')).toMatchObject({ ok: false, code: 'INVALID_UPSTREAM' });
|
||||
expect(await validateUpstream(null)).toMatchObject({ ok: false, code: 'INVALID_UPSTREAM' });
|
||||
expect(await validateUpstream(undefined)).toMatchObject({ ok: false, code: 'INVALID_UPSTREAM' });
|
||||
expect(await validateUpstream(42)).toMatchObject({ ok: false, code: 'INVALID_UPSTREAM' });
|
||||
});
|
||||
|
||||
test('rejects missing port with INVALID_UPSTREAM', async () => {
|
||||
expect(await validateUpstream('hostonly')).toMatchObject({ ok: false, code: 'INVALID_UPSTREAM' });
|
||||
});
|
||||
|
||||
test('rejects non-integer port with INVALID_PORT', async () => {
|
||||
expect(await validateUpstream('host:abc')).toMatchObject({ ok: false, code: 'INVALID_PORT' });
|
||||
expect(await validateUpstream('host:80.5')).toMatchObject({ ok: false, code: 'INVALID_PORT' });
|
||||
});
|
||||
|
||||
test('rejects out-of-range port with INVALID_PORT', async () => {
|
||||
expect(await validateUpstream('host:0')).toMatchObject({ ok: false, code: 'INVALID_PORT' });
|
||||
expect(await validateUpstream('host:65536')).toMatchObject({ ok: false, code: 'INVALID_PORT' });
|
||||
expect(await validateUpstream('host:99999999')).toMatchObject({ ok: false, code: 'INVALID_PORT' });
|
||||
expect(await validateUpstream('host:-1')).toMatchObject({ ok: false, code: 'INVALID_PORT' });
|
||||
});
|
||||
});
|
||||
|
||||
describe('private IPv4 reject (literal)', () => {
|
||||
const PRIVATE_V4 = [
|
||||
['127.0.0.1', 'loopback'],
|
||||
['127.255.255.1', 'loopback'],
|
||||
['10.0.0.1', 'RFC 1918'],
|
||||
['172.16.0.1', 'RFC 1918'],
|
||||
['192.168.1.1', 'RFC 1918'],
|
||||
['169.254.169.254', 'link-local'], // AWS IMDS
|
||||
['100.64.0.1', 'CGNAT'],
|
||||
['224.0.0.1', 'multicast'],
|
||||
['255.255.255.255', 'broadcast'],
|
||||
['0.0.0.0', 'reserved'],
|
||||
];
|
||||
for (const [ip, wantLabel] of PRIVATE_V4) {
|
||||
test(`rejects ${ip} (${wantLabel})`, async () => {
|
||||
const r = await validateUpstream(`${ip}:80`);
|
||||
expect(r.ok).toBe(false);
|
||||
expect(r.code).toBe('PRIVATE_IPV4');
|
||||
expect(r.message).toMatch(new RegExp(wantLabel, 'i'));
|
||||
});
|
||||
}
|
||||
});
|
||||
|
||||
describe('private IPv6 reject (literal)', () => {
|
||||
test('rejects ::1 (loopback)', async () => {
|
||||
const r = await validateUpstream('[::1]:80');
|
||||
expect(r.ok).toBe(false);
|
||||
expect(r.code).toBe('PRIVATE_IPV6');
|
||||
});
|
||||
|
||||
test('rejects fe80::1 (link-local)', async () => {
|
||||
const r = await validateUpstream('[fe80::1]:80');
|
||||
expect(r.ok).toBe(false);
|
||||
expect(r.code).toBe('PRIVATE_IPV6');
|
||||
});
|
||||
|
||||
test('rejects fc00::1 (ULA)', async () => {
|
||||
const r = await validateUpstream('[fc00::1]:80');
|
||||
expect(r.ok).toBe(false);
|
||||
expect(r.code).toBe('PRIVATE_IPV6');
|
||||
});
|
||||
});
|
||||
|
||||
describe('public IPs accepted (literal)', () => {
|
||||
test('accepts 8.8.8.8', async () => {
|
||||
const r = await validateUpstream('8.8.8.8:53');
|
||||
expect(r.ok).toBe(true);
|
||||
expect(r.host).toBe('8.8.8.8');
|
||||
expect(r.port).toBe(53);
|
||||
expect(r.family).toBe(4);
|
||||
});
|
||||
|
||||
test('accepts 1.1.1.1', async () => {
|
||||
const r = await validateUpstream('1.1.1.1:443');
|
||||
expect(r.ok).toBe(true);
|
||||
expect(r.port).toBe(443);
|
||||
});
|
||||
});
|
||||
|
||||
describe('hostname resolve', () => {
|
||||
test('accepts hostname that resolves to public IP', async () => {
|
||||
restoreDns = mockDnsLookup({ 'public.example.com': '8.8.8.8' });
|
||||
const r = await validateUpstream('public.example.com:443');
|
||||
expect(r.ok).toBe(true);
|
||||
expect(r.resolvedIp).toBe('8.8.8.8');
|
||||
expect(r.family).toBe(4);
|
||||
});
|
||||
|
||||
test('rejects hostname that resolves to private IP (DNS rebinding defense)', async () => {
|
||||
restoreDns = mockDnsLookup({ 'evil.example.com': '10.0.0.5' });
|
||||
const r = await validateUpstream('evil.example.com:80');
|
||||
expect(r.ok).toBe(false);
|
||||
expect(r.code).toBe('PRIVATE_IPV4');
|
||||
expect(r.message).toMatch(/evil\.example\.com.*10\.0\.0\.5/);
|
||||
});
|
||||
|
||||
test('rejects hostname that fails to resolve', async () => {
|
||||
// mockDnsLookup default throws ENOTFOUND
|
||||
const r = await validateUpstream('does-not-exist.invalid:80');
|
||||
expect(r.ok).toBe(false);
|
||||
expect(r.code).toMatch(/DNS_/);
|
||||
});
|
||||
|
||||
test('rejects hostname with invalid charset pre-DNS', async () => {
|
||||
const r = await validateUpstream('host with spaces:80');
|
||||
expect(r.ok).toBe(false);
|
||||
expect(r.code).toBe('INVALID_HOST');
|
||||
});
|
||||
});
|
||||
|
||||
describe('SITES_ALLOW_PRIVATE_UPSTREAMS opt-in', () => {
|
||||
test('default rejects private IPs', async () => {
|
||||
const r = await validateUpstream('10.0.0.1:80');
|
||||
expect(r.ok).toBe(false);
|
||||
});
|
||||
|
||||
test('opt-in accepts private literal IP', async () => {
|
||||
process.env.SITES_ALLOW_PRIVATE_UPSTREAMS = 'true';
|
||||
const r = await validateUpstream('10.0.0.1:80');
|
||||
expect(r.ok).toBe(true);
|
||||
});
|
||||
|
||||
test('opt-in accepts private DNS-resolved host', async () => {
|
||||
process.env.SITES_ALLOW_PRIVATE_UPSTREAMS = 'true';
|
||||
restoreDns = mockDnsLookup({ 'internal.example.com': '10.0.0.5' });
|
||||
const r = await validateUpstream('internal.example.com:80');
|
||||
expect(r.ok).toBe(true);
|
||||
});
|
||||
|
||||
test('explicit allowPrivate:false overrides env opt-in (programmatic guard)', async () => {
|
||||
process.env.SITES_ALLOW_PRIVATE_UPSTREAMS = 'true';
|
||||
const r = await validateUpstream('10.0.0.1:80', { allowPrivate: false });
|
||||
expect(r.ok).toBe(false);
|
||||
expect(r.code).toBe('PRIVATE_IPV4');
|
||||
});
|
||||
});
|
||||
});
|
||||
|
||||
// ---------------------------------------------------------------------------
|
||||
// 2. Route integration tests — POST /site
|
||||
// ---------------------------------------------------------------------------
|
||||
|
||||
describe('DC-074: POST /api/v1/site — SSRF hardening', () => {
|
||||
let restoreDns;
|
||||
let caddyStub;
|
||||
|
||||
beforeEach(() => {
|
||||
delete process.env.SITES_ALLOW_PRIVATE_UPSTREAMS;
|
||||
caddyStub = {
|
||||
read: async () => '# stub caddyfile\n',
|
||||
modify: jest.fn(async () => ({ success: true })),
|
||||
adminUrl: 'http://127.0.0.1:2019',
|
||||
filePath: '/tmp/stub-Caddyfile',
|
||||
};
|
||||
});
|
||||
|
||||
afterEach(() => {
|
||||
if (restoreDns) restoreDns();
|
||||
delete process.env.SITES_ALLOW_PRIVATE_UPSTREAMS;
|
||||
});
|
||||
|
||||
const REGRESSION_CASES = [
|
||||
['10.0.0.1:80', 'PRIVATE_IPV4'],
|
||||
['172.16.0.1:80', 'PRIVATE_IPV4'],
|
||||
['192.168.1.1:80', 'PRIVATE_IPV4'],
|
||||
['127.0.0.1:80', 'PRIVATE_IPV4'],
|
||||
['169.254.169.254:80', 'PRIVATE_IPV4'], // AWS IMDS
|
||||
['100.64.0.1:80', 'PRIVATE_IPV4'], // CGNAT
|
||||
['224.0.0.1:80', 'PRIVATE_IPV4'], // multicast
|
||||
['0.0.0.0:80', 'PRIVATE_IPV4'], // reserved
|
||||
['[::1]:80', 'PRIVATE_IPV6'],
|
||||
['[fc00::1]:80', 'PRIVATE_IPV6'],
|
||||
];
|
||||
|
||||
for (const [upstream, wantCode] of REGRESSION_CASES) {
|
||||
test(`rejects upstream="${upstream}" with code=${wantCode}`, async () => {
|
||||
const { app } = createSitesApp({ caddyStub });
|
||||
const res = await request(app)
|
||||
.post('/api/v1/site')
|
||||
.send({ domain: 'evil.example.com', upstream });
|
||||
expect(res.status).toBe(400);
|
||||
expect(res.body.error).toMatch(/\[DC-074\]/);
|
||||
expect(res.body.error).toMatch(/SITES_ALLOW_PRIVATE_UPSTREAMS/);
|
||||
// caddy.modify() must NOT have been called (gate happens before write)
|
||||
expect(caddyStub.modify).not.toHaveBeenCalled();
|
||||
});
|
||||
}
|
||||
|
||||
test('rejects DNS-resolved private IP (rebinding defense)', async () => {
|
||||
restoreDns = mockDnsLookup({ 'looks-public.example.com': '10.0.0.5' });
|
||||
const { app } = createSitesApp({ caddyStub });
|
||||
const res = await request(app)
|
||||
.post('/api/v1/site')
|
||||
.send({ domain: 'evil.example.com', upstream: 'looks-public.example.com:80' });
|
||||
expect(res.status).toBe(400);
|
||||
expect(res.body.error).toMatch(/10\.0\.0\.5/);
|
||||
expect(caddyStub.modify).not.toHaveBeenCalled();
|
||||
});
|
||||
|
||||
test('accepts public literal IP', async () => {
|
||||
const { app } = createSitesApp({ caddyStub });
|
||||
const res = await request(app)
|
||||
.post('/api/v1/site')
|
||||
.send({ domain: 'new.example.com', upstream: '8.8.8.8:80' });
|
||||
expect(res.status).toBe(200);
|
||||
expect(caddyStub.modify).toHaveBeenCalledTimes(1);
|
||||
});
|
||||
|
||||
test('accepts hostname resolving to public IP', async () => {
|
||||
restoreDns = mockDnsLookup({ 'real.example.com': '8.8.8.8' });
|
||||
const { app } = createSitesApp({ caddyStub });
|
||||
const res = await request(app)
|
||||
.post('/api/v1/site')
|
||||
.send({ domain: 'new.example.com', upstream: 'real.example.com:80' });
|
||||
expect(res.status).toBe(200);
|
||||
expect(caddyStub.modify).toHaveBeenCalledTimes(1);
|
||||
});
|
||||
|
||||
test('SITES_ALLOW_PRIVATE_UPSTREAMS=true opts in for private literal', async () => {
|
||||
process.env.SITES_ALLOW_PRIVATE_UPSTREAMS = 'true';
|
||||
const { app } = createSitesApp({ caddyStub });
|
||||
const res = await request(app)
|
||||
.post('/api/v1/site')
|
||||
.send({ domain: 'lab.example.com', upstream: '10.0.0.1:80' });
|
||||
expect(res.status).toBe(200);
|
||||
expect(caddyStub.modify).toHaveBeenCalledTimes(1);
|
||||
});
|
||||
|
||||
test('SITES_ALLOW_PRIVATE_UPSTREAMS=true opts in for private-resolved hostname', async () => {
|
||||
process.env.SITES_ALLOW_PRIVATE_UPSTREAMS = 'true';
|
||||
restoreDns = mockDnsLookup({ 'internal.lan': '10.0.0.5' });
|
||||
const { app } = createSitesApp({ caddyStub });
|
||||
const res = await request(app)
|
||||
.post('/api/v1/site')
|
||||
.send({ domain: 'lab.example.com', upstream: 'internal.lan:80' });
|
||||
expect(res.status).toBe(200);
|
||||
});
|
||||
|
||||
test('rejects out-of-range port without invoking private-IP check', async () => {
|
||||
const { app } = createSitesApp({ caddyStub });
|
||||
const res = await request(app)
|
||||
.post('/api/v1/site')
|
||||
.send({ domain: 'new.example.com', upstream: '8.8.8.8:99999' });
|
||||
expect(res.status).toBe(400);
|
||||
expect(res.body.error).toMatch(/INVALID_PORT|\[DC-074\]/);
|
||||
expect(caddyStub.modify).not.toHaveBeenCalled();
|
||||
});
|
||||
|
||||
test('rejects upstream with spaces (charset) without invoking private-IP check', async () => {
|
||||
const { app } = createSitesApp({ caddyStub });
|
||||
const res = await request(app)
|
||||
.post('/api/v1/site')
|
||||
.send({ domain: 'new.example.com', upstream: 'not a host:80' });
|
||||
expect(res.status).toBe(400);
|
||||
expect(caddyStub.modify).not.toHaveBeenCalled();
|
||||
});
|
||||
});
|
||||
|
||||
// ---------------------------------------------------------------------------
|
||||
// 3. Route integration tests — POST /site/external
|
||||
// ---------------------------------------------------------------------------
|
||||
|
||||
describe('DC-074: POST /api/v1/site/external — SSRF hardening', () => {
|
||||
let restoreDns;
|
||||
let caddyStub;
|
||||
|
||||
beforeEach(() => {
|
||||
delete process.env.SITES_ALLOW_PRIVATE_UPSTREAMS;
|
||||
caddyStub = {
|
||||
read: async () => '# stub caddyfile\n',
|
||||
modify: jest.fn(async () => ({ success: true })),
|
||||
adminUrl: 'http://127.0.0.1:2019',
|
||||
filePath: '/tmp/stub-Caddyfile',
|
||||
};
|
||||
});
|
||||
|
||||
afterEach(() => {
|
||||
if (restoreDns) restoreDns();
|
||||
delete process.env.SITES_ALLOW_PRIVATE_UPSTREAMS;
|
||||
});
|
||||
|
||||
const REGRESSION_CASES = [
|
||||
'http://10.0.0.1',
|
||||
'http://192.168.1.1',
|
||||
'http://127.0.0.1',
|
||||
'http://169.254.169.254', // AWS IMDS via URL form
|
||||
'http://100.64.0.1', // CGNAT — caught by validateUpstream defense-in-depth, not validateURL
|
||||
'http://0.0.0.0',
|
||||
'http://[::1]',
|
||||
'http://[fc00::1]',
|
||||
];
|
||||
|
||||
for (const externalUrl of REGRESSION_CASES) {
|
||||
test(`rejects externalUrl="${externalUrl}"`, async () => {
|
||||
const { app } = createSitesApp({ caddyStub });
|
||||
const res = await request(app)
|
||||
.post('/api/v1/site/external')
|
||||
.send({ subdomain: 'ext', externalUrl });
|
||||
// 400 from validateURL OR from validateUpstream — either path closes the gate.
|
||||
expect(res.status).toBe(400);
|
||||
expect(caddyStub.modify).not.toHaveBeenCalled();
|
||||
});
|
||||
}
|
||||
|
||||
test('rejects DNS-resolved private IP', async () => {
|
||||
restoreDns = mockDnsLookup({ 'looks-public.example.com': '10.0.0.5' });
|
||||
const { app } = createSitesApp({ caddyStub });
|
||||
const res = await request(app)
|
||||
.post('/api/v1/site/external')
|
||||
.send({ subdomain: 'ext', externalUrl: 'http://looks-public.example.com' });
|
||||
expect(res.status).toBe(400);
|
||||
expect(res.body.error).toMatch(/\[DC-074\]|Private URLs/);
|
||||
expect(caddyStub.modify).not.toHaveBeenCalled();
|
||||
});
|
||||
|
||||
test('accepts externalUrl with public hostname', async () => {
|
||||
restoreDns = mockDnsLookup({ 'api.example.com': '8.8.8.8' });
|
||||
const { app } = createSitesApp({ caddyStub });
|
||||
const res = await request(app)
|
||||
.post('/api/v1/site/external')
|
||||
.send({ subdomain: 'ext', externalUrl: 'http://api.example.com' });
|
||||
expect(res.status).toBe(200);
|
||||
expect(caddyStub.modify).toHaveBeenCalledTimes(1);
|
||||
});
|
||||
|
||||
test('accepts externalUrl with public literal IP', async () => {
|
||||
const { app } = createSitesApp({ caddyStub });
|
||||
const res = await request(app)
|
||||
.post('/api/v1/site/external')
|
||||
.send({ subdomain: 'ext', externalUrl: 'http://8.8.8.8' });
|
||||
expect(res.status).toBe(200);
|
||||
});
|
||||
|
||||
test('SITES_ALLOW_PRIVATE_UPSTREAMS=true opts in for private externalUrl', async () => {
|
||||
process.env.SITES_ALLOW_PRIVATE_UPSTREAMS = 'true';
|
||||
const { app } = createSitesApp({ caddyStub });
|
||||
const res = await request(app)
|
||||
.post('/api/v1/site/external')
|
||||
.send({ subdomain: 'ext', externalUrl: 'http://10.0.0.5' });
|
||||
expect(res.status).toBe(200);
|
||||
});
|
||||
});
|
||||
|
||||
// ---------------------------------------------------------------------------
|
||||
// 4. Regression — pre-fix payload (the canonical SSRF regression proof)
|
||||
// ---------------------------------------------------------------------------
|
||||
|
||||
describe('DC-074: regression — pre-fix payloads are now rejected', () => {
|
||||
test('the canonical SSRF payload `10.0.0.1:80` is rejected at the route layer', async () => {
|
||||
const caddyStub = {
|
||||
read: async () => '',
|
||||
modify: jest.fn(async () => ({ success: true })),
|
||||
adminUrl: 'http://127.0.0.1:2019',
|
||||
filePath: '/tmp/stub-Caddyfile',
|
||||
};
|
||||
const { app } = createSitesApp({ caddyStub });
|
||||
const res = await request(app)
|
||||
.post('/api/v1/site')
|
||||
.send({ domain: 'evil.attacker.com', upstream: '10.0.0.1:80' });
|
||||
expect(res.status).toBe(400);
|
||||
// Pre-fix this payload would have been accepted, the regex happily
|
||||
// matches `[a-z0-9.-]+:\d{1,5}` against `10.0.0.1:80`, and a Caddy
|
||||
// site block would have been written that proxied public HTTPS
|
||||
// traffic at `evil.attacker.com` to the internal 10.0.0.1:80.
|
||||
expect(caddyStub.modify).not.toHaveBeenCalled();
|
||||
});
|
||||
|
||||
test('the canonical SSRF payload `http://192.168.1.5` is rejected at the external endpoint', async () => {
|
||||
const caddyStub = {
|
||||
read: async () => '',
|
||||
modify: jest.fn(async () => ({ success: true })),
|
||||
adminUrl: 'http://127.0.0.1:2019',
|
||||
filePath: '/tmp/stub-Caddyfile',
|
||||
};
|
||||
const { app } = createSitesApp({ caddyStub });
|
||||
const res = await request(app)
|
||||
.post('/api/v1/site/external')
|
||||
.send({ subdomain: 'ext', externalUrl: 'http://192.168.1.5' });
|
||||
expect(res.status).toBe(400);
|
||||
expect(caddyStub.modify).not.toHaveBeenCalled();
|
||||
});
|
||||
});
|
||||
|
||||
// ---------------------------------------------------------------------------
|
||||
// 5. Sanity — fleet-validation helper exports still work as before
|
||||
// ---------------------------------------------------------------------------
|
||||
|
||||
describe('DC-074: fleet-validation helpers still exported and unchanged behavior', () => {
|
||||
test('isPrivateOrReservedIPv4 still detects the same set as before', () => {
|
||||
expect(isPrivateOrReservedIPv4('10.0.0.1').isPrivate).toBe(true);
|
||||
expect(isPrivateOrReservedIPv4('8.8.8.8').isPrivate).toBe(false);
|
||||
});
|
||||
|
||||
test('isPrivateOrReservedIPv6 still detects the same set as before', () => {
|
||||
expect(isPrivateOrReservedIPv6('::1').isPrivate).toBe(true);
|
||||
expect(isPrivateOrReservedIPv6('2001:4860:4860::8888').isPrivate).toBe(false);
|
||||
});
|
||||
});
|
||||
@@ -4,7 +4,9 @@
|
||||
* Exposes:
|
||||
* GET /api/v1/caddy/upstreams — full snapshot
|
||||
* GET /api/v1/caddy/upstreams/incidents — open dead-upstream incidents (via healthChecker)
|
||||
* POST /api/v1/caddy/upstreams/:host/mute — body { muted: true|false } (also via query ?muted=true)
|
||||
* POST /api/v1/caddy/upstreams/mute — body { host, muted: true|false }
|
||||
* POST /api/v1/caddy/upstreams/:host/mute — body { muted: true|false } OR query ?muted=true
|
||||
* POST /api/v1/caddy/upstreams/:host/unmute — clears the mute
|
||||
*
|
||||
* Auth: same as the rest of /api/v1 — handled by the global middleware
|
||||
* (the router is mounted under the auth-gated apiRouter in app.js).
|
||||
@@ -16,6 +18,48 @@ const express = require('express');
|
||||
const { success, errorResponse } = require('../src/utils/responses');
|
||||
const { ValidationError } = require('../src/utilities/errors');
|
||||
|
||||
/**
|
||||
* DC-073: shared mute helper — used by all three mute endpoints so the
|
||||
* host-validation logic can't drift.
|
||||
*
|
||||
* Pre-fix, only the bare `/caddy/upstreams/mute` body-style endpoint
|
||||
* rejected unknown hosts (with a "not a known upstream" 400). The
|
||||
* path-style `/:host/mute` and `/:host/unmute` endpoints skipped that
|
||||
* check entirely, so an authenticated operator could POST
|
||||
* `/caddy/upstreams/phantom.test:12345/mute` and the watcher would
|
||||
* silently add `phantom.test:12345` to its muted Set and `_saveState()`
|
||||
* would persist it to disk. The phantom entry then survives container
|
||||
* restarts, pollutes the snapshot view (the muted Set is iterated in
|
||||
* places like the dashboard's "muted upstreams" badge), and would
|
||||
* silently disable any future probe that happened to resolve to the
|
||||
* same string.
|
||||
*
|
||||
* Post-fix, every mute path runs through this helper so:
|
||||
* (1) host format is well-formed (rejects injection / `:` / `?` / etc.)
|
||||
* (2) host is in `caddyUpstreamWatcher.upstreams` (the live registry
|
||||
* populated by `scanSites()` reading every `reverse_proxy` from
|
||||
* /etc/caddy/sites/*. A phantom host cannot reach setMuted.)
|
||||
* (3) the muted Set never holds entries the scanner doesn't know.
|
||||
*
|
||||
* @param {Object} watcher caddyUpstreamWatcher instance
|
||||
* @param {string} host raw host string from the request
|
||||
* @param {boolean} wantMuted true to mute, false to unmute
|
||||
* @returns {{host: string, muted: boolean}} the result of setMuted
|
||||
* @throws {ValidationError} on invalid format or unknown host
|
||||
*/
|
||||
function validateAndMuteHost(watcher, host, wantMuted) {
|
||||
if (typeof host !== 'string' || host.length === 0 || host.length > 253) {
|
||||
throw new ValidationError('host must be a non-empty string up to 253 chars');
|
||||
}
|
||||
if (!/^[a-z0-9._:-]+$/i.test(host)) {
|
||||
throw new ValidationError('host must be a valid host[:port] string');
|
||||
}
|
||||
if (!watcher || !watcher.upstreams || !watcher.upstreams.has(host)) {
|
||||
throw new ValidationError(`host ${host} is not a known upstream (run scan first)`);
|
||||
}
|
||||
return watcher.setMuted(host, wantMuted);
|
||||
}
|
||||
|
||||
module.exports = function({ asyncHandler, caddyUpstreamWatcher, healthChecker }) {
|
||||
const router = express.Router();
|
||||
|
||||
@@ -55,62 +99,48 @@ module.exports = function({ asyncHandler, caddyUpstreamWatcher, healthChecker })
|
||||
success(res, { incidents: open });
|
||||
}, 'caddy-upstreams-incidents'));
|
||||
|
||||
// POST /caddy/upstreams/mute body { host, muted }
|
||||
// POST /caddy/upstreams/:host/mute body { muted: true } OR query ?muted=true
|
||||
// Both shapes supported because the dashboard code is small and either is
|
||||
// ergonomic depending on caller.
|
||||
const handleMute = asyncHandler(async (req, res) => {
|
||||
if (!caddyUpstreamWatcher) {
|
||||
return errorResponse(res, 503, 'Caddy upstream watcher not initialized');
|
||||
}
|
||||
const host = req.params.host || req.body?.host;
|
||||
if (!host || typeof host !== 'string' || !/^[a-z0-9._:-]+$/i.test(host)) {
|
||||
throw new ValidationError('host must be a valid host[:port] string');
|
||||
}
|
||||
// Accept muted as boolean body field OR ?muted=true|false query OR
|
||||
// a { muted: true|false } JSON body. Default to toggling on bare POST
|
||||
// without a muted value (this is the "mute it" path).
|
||||
let muted;
|
||||
if (typeof req.body?.muted === 'boolean') muted = req.body.muted;
|
||||
else if (typeof req.query.muted === 'string') muted = req.query.muted === 'true';
|
||||
else muted = true; // POST with no body = mute
|
||||
|
||||
const result = caddyUpstreamWatcher.setMuted(host, muted);
|
||||
success(res, result);
|
||||
}, 'caddy-upstreams-mute');
|
||||
|
||||
// Bare /mute with JSON body {host, muted}. Default mutes when muted is
|
||||
// absent or unparseable; require muted === false explicitly to unmute.
|
||||
// DC-073: now routes through validateAndMuteHost so the unknown-host
|
||||
// check applies (was already correct here pre-fix, but path-style
|
||||
// was missing it — see validateAndMuteHost docblock).
|
||||
router.post('/caddy/upstreams/mute', asyncHandler(async (req, res) => {
|
||||
if (!caddyUpstreamWatcher) {
|
||||
return errorResponse(res, 503, 'Caddy upstream watcher not initialized');
|
||||
}
|
||||
const { host, muted } = req.body || {};
|
||||
if (!host || typeof host !== 'string' || !/^[a-z0-9._:-]+$/i.test(host)) {
|
||||
throw new ValidationError('host must be a valid host[:port] string');
|
||||
}
|
||||
// Explicit boolean coercion — string 'false' should NOT mute.
|
||||
const wantMuted = muted === undefined ? true : muted === true;
|
||||
if (caddyUpstreamWatcher.upstreams && !caddyUpstreamWatcher.upstreams.has(host)) {
|
||||
throw new ValidationError(`host ${host} is not a known upstream (run scan first)`);
|
||||
}
|
||||
const result = caddyUpstreamWatcher.setMuted(host, wantMuted);
|
||||
const result = validateAndMuteHost(caddyUpstreamWatcher, host, wantMuted);
|
||||
success(res, result);
|
||||
}, 'caddy-upstreams-mute-bare'));
|
||||
|
||||
// /:host/mute and /:host/unmute for path-style toggles
|
||||
router.post('/caddy/upstreams/:host/mute', handleMute);
|
||||
// Path-style /:host/mute — body { muted: true|false } OR query ?muted=true|false.
|
||||
// DC-073: now also rejects unknown hosts (was the bug — see docblock).
|
||||
router.post('/caddy/upstreams/:host/mute', asyncHandler(async (req, res) => {
|
||||
if (!caddyUpstreamWatcher) {
|
||||
return errorResponse(res, 503, 'Caddy upstream watcher not initialized');
|
||||
}
|
||||
let wantMuted;
|
||||
if (typeof req.body?.muted === 'boolean') wantMuted = req.body.muted;
|
||||
else if (typeof req.query.muted === 'string') wantMuted = req.query.muted === 'true';
|
||||
else wantMuted = true; // bare POST = mute
|
||||
const result = validateAndMuteHost(caddyUpstreamWatcher, req.params.host, wantMuted);
|
||||
success(res, result);
|
||||
}, 'caddy-upstreams-mute'));
|
||||
|
||||
// DC-073: path-style /:host/unmute now also rejects unknown hosts.
|
||||
router.post('/caddy/upstreams/:host/unmute', asyncHandler(async (req, res) => {
|
||||
if (!caddyUpstreamWatcher) {
|
||||
return errorResponse(res, 503, 'Caddy upstream watcher not initialized');
|
||||
}
|
||||
const host = req.params.host;
|
||||
if (!host || !/^[a-z0-9._:-]+$/i.test(host)) {
|
||||
throw new ValidationError('host must be a valid host[:port] string');
|
||||
}
|
||||
const result = caddyUpstreamWatcher.setMuted(host, false);
|
||||
const result = validateAndMuteHost(caddyUpstreamWatcher, req.params.host, false);
|
||||
success(res, result);
|
||||
}, 'caddy-upstreams-unmute'));
|
||||
|
||||
return router;
|
||||
};
|
||||
};
|
||||
|
||||
// Export the helper for unit tests so the validation surface can be
|
||||
// exercised without spinning up a full Express app.
|
||||
module.exports.__test = { validateAndMuteHost };
|
||||
@@ -11,10 +11,138 @@
|
||||
*/
|
||||
const express = require('express');
|
||||
const { ok, errorResponse } = require('../src/utils/responses');
|
||||
const { REGEX } = require('../src/utilities/constants');
|
||||
|
||||
/**
|
||||
* DC-070: Validate the structural config that flows into generateSiteBlock.
|
||||
*
|
||||
* Threat model: `generateSiteBlock` interpolates user-controlled fields
|
||||
* (domain, tls, authService, headers.*, stripPrefix, upstream) DIRECTLY into
|
||||
* a Caddyfile text block that is later fed to `caddy.modify()` and the
|
||||
* Caddy admin /load endpoint. The /caddycode/generate endpoint is
|
||||
* authenticated (forward_auth gated), but the bug class is "compromised
|
||||
* middleware / pivot" — a JSON-only payload can be smuggled past any
|
||||
* UI-side input checks.
|
||||
*
|
||||
* Pre-fix, every field was trusted: `lines.push(`${domain} {`)` accepted any
|
||||
* string (including newlines that close the block and inject a new site),
|
||||
* `headers[key] = "${value}"` accepted arbitrary quotes (which would break
|
||||
* the surrounding `"..."` Caddy quoted-string context and inject directives),
|
||||
* and `tls`, `authService`, `stripPrefix`, `upstream` had no charset
|
||||
* restrictions at all (spaces, braces, semicolons would land verbatim).
|
||||
*
|
||||
* Post-fix: every field is constrained to a known-safe character class
|
||||
* BEFORE interpolation, and CRLF is rejected outright. Quoted-string
|
||||
* injection in header values is closed by escaping `\` and `"` per the
|
||||
* Caddy quoted-string spec (backslash escapes the next character).
|
||||
*/
|
||||
function validateGenerationConfig(config) {
|
||||
const errors = [];
|
||||
const {
|
||||
domain,
|
||||
upstream,
|
||||
upstreamProtocol = 'http',
|
||||
tls = 'auto',
|
||||
auth = false,
|
||||
authService = null,
|
||||
headers = {},
|
||||
stripPrefix = null,
|
||||
} = config;
|
||||
|
||||
// 1. domain — RFC 1123 hostname. Reject anything with whitespace, brace,
|
||||
// semicolon, newline, or non-printable. REGEX.DOMAIN is
|
||||
// /^[a-z0-9]([a-z0-9.-]{0,251}[a-z0-9])?$/i in constants.js.
|
||||
if (typeof domain !== 'string' || !REGEX.DOMAIN.test(domain)) {
|
||||
errors.push('domain must be a valid hostname (letters, digits, dots, hyphens)');
|
||||
}
|
||||
|
||||
// 2. upstream — `host:port` form (the only shape Caddy's reverse_proxy
|
||||
// directive takes for non-URL upstreams). Reject `://`, whitespace,
|
||||
// braces. Allow optional IPv6 bracket form `[::1]:5000`. Must
|
||||
// include an explicit :port segment — a bare `localhost` would
|
||||
// produce a Caddyfile that fails to reload (port required for
|
||||
// reverse_proxy upstreams). Two regex branches: (a) bare host with
|
||||
// required :port, (b) bracketed IPv6 literal with required :port.
|
||||
if (typeof upstream !== 'string'
|
||||
|| !/^[a-z0-9.\-]+:\d{1,5}$/i.test(upstream)
|
||||
&& !/^\[[a-z0-9.\-:.]+\]:\d{1,5}$/i.test(upstream)
|
||||
) {
|
||||
errors.push('upstream must be host:port (host letters/digits/dots/hyphens, port 1-65535, optional IPv6 brackets)');
|
||||
}
|
||||
|
||||
// 3. tls — either the literal strings 'auto' / 'internal' (handled
|
||||
// specially below) OR a CA name like 'letsencrypt' / 'internal' that
|
||||
// must match /^[a-z0-9._-]+$/i. Reject whitespace + braces + quotes.
|
||||
if (typeof tls !== 'string' || !/^[a-z0-9._-]+$/i.test(tls)) {
|
||||
errors.push('tls must be one of: auto, internal, or a CA name (letters, digits, dots, underscores, hyphens)');
|
||||
}
|
||||
|
||||
// 4. authService — only meaningful when auth=true; otherwise ignore. Must
|
||||
// match the existing SSO service-id charset (REGEX.SUBDOMAIN).
|
||||
if (auth) {
|
||||
if (typeof authService !== 'string' || !REGEX.SUBDOMAIN.test(authService)) {
|
||||
errors.push('authService must be a valid subdomain (lowercase, alphanumeric, hyphens)');
|
||||
}
|
||||
}
|
||||
|
||||
// 5. upstreamProtocol — only 'http' or 'https'. Anything else gets coerced
|
||||
// to 'http' but only after we explicitly accept it; reject obvious
|
||||
// injection vectors here.
|
||||
if (upstreamProtocol !== 'http' && upstreamProtocol !== 'https') {
|
||||
errors.push('upstreamProtocol must be "http" or "https"');
|
||||
}
|
||||
|
||||
// 6. headers — each key must be a valid HTTP header name ([A-Za-z0-9-]+),
|
||||
// each value must be a string with no CR/LF and no unescaped quotes.
|
||||
if (headers && typeof headers === 'object') {
|
||||
for (const [key, value] of Object.entries(headers)) {
|
||||
if (typeof key !== 'string' || !/^[A-Za-z0-9-]+$/.test(key)) {
|
||||
errors.push(`header key "${String(key)}" must be HTTP-token chars only ([A-Za-z0-9-])`);
|
||||
}
|
||||
if (typeof value !== 'string') {
|
||||
errors.push(`header "${key}" value must be a string`);
|
||||
continue;
|
||||
}
|
||||
if (/[\r\n]/.test(value)) {
|
||||
errors.push(`header "${key}" value must not contain CR or LF`);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// 7. stripPrefix — must be a leading-slash path with safe chars. Reject
|
||||
// braces, quotes, whitespace, and { } which would let the attacker
|
||||
// open a new Caddyfile block.
|
||||
if (stripPrefix != null) {
|
||||
if (typeof stripPrefix !== 'string' || !/^\/[A-Za-z0-9._\-/]*$/.test(stripPrefix)) {
|
||||
errors.push('stripPrefix must be an absolute path (letters, digits, dots, hyphens, slashes)');
|
||||
}
|
||||
}
|
||||
|
||||
return { valid: errors.length === 0, errors };
|
||||
}
|
||||
|
||||
/**
|
||||
* Escape a string for safe interpolation inside a Caddyfile quoted-string
|
||||
* context. Caddy uses the same backslash-escape semantics as JSON-ish
|
||||
* contexts — `\` and `"` MUST be escaped, otherwise the attacker breaks out
|
||||
* of the quoted string and injects arbitrary directives.
|
||||
*
|
||||
* @param {string} s raw header value
|
||||
* @returns {string} escaped value (no embedded newlines; CR/LF were already
|
||||
* rejected by the validator)
|
||||
*/
|
||||
function escapeCaddyQuotedString(s) {
|
||||
return String(s).replace(/\\/g, '\\\\').replace(/"/g, '\\"');
|
||||
}
|
||||
|
||||
/**
|
||||
* Generate a Caddyfile site block from a structured config.
|
||||
* @param {Object} config - Site configuration
|
||||
*
|
||||
* Every interpolated field is now validated by `validateGenerationConfig`
|
||||
* first (see DC-070). Quoted-string values are escaped via
|
||||
* `escapeCaddyQuotedString` so a `"` in a header value cannot break out.
|
||||
*
|
||||
* @param {Object} config - Site configuration (already validated)
|
||||
* @returns {string} Caddyfile snippet
|
||||
*/
|
||||
function generateSiteBlock(config) {
|
||||
@@ -38,12 +166,15 @@ function generateSiteBlock(config) {
|
||||
const lines = [];
|
||||
lines.push(`${domain} {`);
|
||||
|
||||
// TLS
|
||||
// TLS — only emit a tls directive when explicitly 'internal' or a CA
|
||||
// name; 'auto' means Caddy's default behaviour (no directive needed).
|
||||
if (tls === 'internal') {
|
||||
lines.push(` tls internal`);
|
||||
} else if (tls === 'auto') {
|
||||
// Default — Caddy auto-provisions Let's Encrypt
|
||||
} else if (typeof tls === 'string') {
|
||||
} else {
|
||||
// CA name validated by validateGenerationConfig against
|
||||
// /^[a-z0-9._-]+$/i — safe to interpolate verbatim.
|
||||
lines.push(` tls ${tls}`);
|
||||
}
|
||||
|
||||
@@ -52,7 +183,8 @@ function generateSiteBlock(config) {
|
||||
lines.push(` # Redirect HTTP to HTTPS is automatic in Caddy 2`);
|
||||
}
|
||||
|
||||
// Auth gate (DashCaddy forward_auth)
|
||||
// Auth gate (DashCaddy forward_auth) — authService validated by
|
||||
// validateGenerationConfig against REGEX.SUBDOMAIN — safe to interpolate.
|
||||
if (auth && authService) {
|
||||
lines.push(` import dashcaddy_auth ${authService}`);
|
||||
}
|
||||
@@ -66,16 +198,17 @@ function generateSiteBlock(config) {
|
||||
lines.push(` }`);
|
||||
}
|
||||
|
||||
// Custom headers
|
||||
if (Object.keys(headers).length > 0) {
|
||||
// Custom headers — keys validated against /^[A-Za-z0-9-]+$/, values
|
||||
// escaped via escapeCaddyQuotedString before being placed inside "..."
|
||||
if (headers && typeof headers === 'object' && Object.keys(headers).length > 0) {
|
||||
lines.push(` header {`);
|
||||
for (const [key, value] of Object.entries(headers)) {
|
||||
lines.push(` ${key} "${value}"`);
|
||||
lines.push(` ${key} "${escapeCaddyQuotedString(value)}"`);
|
||||
}
|
||||
lines.push(` }`);
|
||||
}
|
||||
|
||||
// Strip prefix
|
||||
// Strip prefix — validated to /^\/[A-Za-z0-9._\-/]*$/ — safe.
|
||||
if (stripPrefix) {
|
||||
lines.push(` uri strip_prefix ${stripPrefix}`);
|
||||
}
|
||||
@@ -118,6 +251,19 @@ module.exports = function({ asyncHandler }) {
|
||||
return errorResponse(res, 400, 'upstream is required (e.g. localhost:8080)');
|
||||
}
|
||||
|
||||
// DC-070: structural validation BEFORE interpolation. Every field that
|
||||
// flows into the Caddyfile text must satisfy a known-safe charset rule,
|
||||
// and CRLF is rejected outright. Run this BEFORE generateSiteBlock so
|
||||
// the bad input is rejected with a clean 400 + enumerable error list,
|
||||
// not a generated-Caddyfile + 500.
|
||||
const validation = validateGenerationConfig(config);
|
||||
if (!validation.valid) {
|
||||
return errorResponse(res, 400, 'Invalid configuration', {
|
||||
code: 'DC-CCD-700',
|
||||
errors: validation.errors,
|
||||
});
|
||||
}
|
||||
|
||||
try {
|
||||
const caddyfile = generateSiteBlock(config);
|
||||
ok(res, { caddyfile, config });
|
||||
@@ -225,3 +371,11 @@ module.exports = function({ asyncHandler }) {
|
||||
|
||||
return router;
|
||||
};
|
||||
|
||||
// DC-070: export helpers for unit-testing the sanitization surface
|
||||
// independently of the route handler.
|
||||
module.exports.__test = {
|
||||
validateGenerationConfig,
|
||||
escapeCaddyQuotedString,
|
||||
generateSiteBlock,
|
||||
};
|
||||
|
||||
@@ -4,6 +4,50 @@ const url = require('url');
|
||||
|
||||
const docker = new Docker();
|
||||
|
||||
/**
|
||||
* DC-072: WebSocket scope authorization — admin-only by default.
|
||||
*
|
||||
* Container exec is full root-equivalent access inside the target
|
||||
* container. Granting it to a key whose scope is `['read']` violates
|
||||
* least privilege. The validScopes list (`['read','write','admin']`)
|
||||
* is defined in routes/auth/keys.js; exec requires `admin`.
|
||||
*
|
||||
* Defensive: the scope field is coerced via `Array.isArray(...) ? ... : []`
|
||||
* so a malformed payload (string, object, null, undefined) cannot reach
|
||||
* `.includes('admin')` and accidentally grant access. Every malformed
|
||||
* shape falls into the rejection branch with the same 403 envelope.
|
||||
*
|
||||
* Tests should call `__test.assertExecScope(auth)` directly rather
|
||||
* than spinning up a WebSocket server.
|
||||
*/
|
||||
function assertExecScope(auth) {
|
||||
const scope = Array.isArray(auth && auth.scope) ? auth.scope : [];
|
||||
if (!scope.includes('admin')) {
|
||||
const err = new Error('Container exec requires admin scope');
|
||||
err.code = 'DC-072_INSUFFICIENT_SCOPE';
|
||||
err.statusCode = 403;
|
||||
err.requiredScope = 'admin';
|
||||
err.actualScope = scope;
|
||||
throw err;
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* DC-072: Tighten containerId validation.
|
||||
*
|
||||
* Docker container IDs are exactly 64 lowercase hex chars (or 12-char
|
||||
* short form). The pre-fix regex accepted `_`, `-`, `.`, mixed case,
|
||||
* and up to 128 chars — Docker would then 404 the inspect call and
|
||||
* the rejection would surface as a generic 500 in the WS error
|
||||
* envelope. Pre-validate at the upgrade layer so the rejection is
|
||||
* fast and the log line discriminates "malformed" from "unknown".
|
||||
*/
|
||||
function isValidContainerId(id) {
|
||||
if (typeof id !== 'string') return false;
|
||||
// Full 64-char hex, or 12-char short hex
|
||||
return /^[0-9a-f]{64}$/.test(id) || /^[0-9a-f]{12}$/.test(id);
|
||||
}
|
||||
|
||||
/**
|
||||
* Attach WebSocket server for container exec/shell
|
||||
* Route: ws://host/ws/exec/:containerId
|
||||
@@ -21,8 +65,8 @@ module.exports = function attachExecWS(server, log, authManager) {
|
||||
|
||||
const containerId = decodeURIComponent(match[1]);
|
||||
|
||||
// Validate container ID format to prevent injection
|
||||
if (!/^[a-zA-Z0-9][a-zA-Z0-9_.-]{0,127}$/.test(containerId)) {
|
||||
// DC-072: Tighten containerId charset (64-char / 12-char lowercase hex)
|
||||
if (!isValidContainerId(containerId)) {
|
||||
log.warn('exec', 'Invalid container ID in WebSocket path', { containerId });
|
||||
socket.write('HTTP/1.1 400 Bad Request\r\n\r\n');
|
||||
socket.destroy();
|
||||
@@ -55,6 +99,35 @@ module.exports = function attachExecWS(server, log, authManager) {
|
||||
return;
|
||||
}
|
||||
|
||||
// DC-072: Container exec is root-equivalent — require admin scope.
|
||||
// Pre-fix, a key issued with scope `['read']` (e.g., for monitoring)
|
||||
// would get a full PTY shell inside any running container. The
|
||||
// `auth.scope` was captured at lines 39/46 but never checked.
|
||||
try {
|
||||
assertExecScope(auth);
|
||||
} catch (err) {
|
||||
log.warn('exec', 'Insufficient scope for exec attempt', {
|
||||
containerId,
|
||||
authType: auth.type,
|
||||
authId: auth.type === 'jwt' ? auth.userId : auth.keyId,
|
||||
actualScope: err.actualScope,
|
||||
requiredScope: err.requiredScope,
|
||||
ip: req.socket.remoteAddress,
|
||||
});
|
||||
// 403 with a JSON error envelope over the upgrade socket so the
|
||||
// dashboard can display "admin required" instead of guessing.
|
||||
socket.write('HTTP/1.1 403 Forbidden\r\n');
|
||||
socket.write('Content-Type: application/json\r\n');
|
||||
socket.write('\r\n');
|
||||
socket.end(JSON.stringify({
|
||||
error: err.message,
|
||||
code: err.code,
|
||||
requiredScope: err.requiredScope,
|
||||
actualScope: err.actualScope,
|
||||
}));
|
||||
return;
|
||||
}
|
||||
|
||||
// Auth passed — proceed with WebSocket upgrade
|
||||
wss.handleUpgrade(req, socket, head, (ws) => {
|
||||
handleExec(ws, containerId, log, auth);
|
||||
@@ -67,6 +140,7 @@ module.exports = function attachExecWS(server, log, authManager) {
|
||||
async function handleExec(ws, containerId, log, auth) {
|
||||
let execStream = null;
|
||||
let execInstance = null;
|
||||
const sessionStart = Date.now();
|
||||
|
||||
try {
|
||||
const container = docker.getContainer(containerId);
|
||||
@@ -78,10 +152,13 @@ async function handleExec(ws, containerId, log, auth) {
|
||||
return;
|
||||
}
|
||||
|
||||
// DC-072: Audit-log the exec session start. Pairs with the end-log
|
||||
// below so the operator can correlate who opened which shell.
|
||||
log.info('exec', 'Authenticated exec session started', {
|
||||
containerId,
|
||||
authType: auth.type,
|
||||
authId: auth.type === 'jwt' ? auth.userId : auth.keyId
|
||||
authId: auth.type === 'jwt' ? auth.userId : auth.keyId,
|
||||
containerName: info.Name,
|
||||
});
|
||||
|
||||
// Detect available shell
|
||||
@@ -120,7 +197,28 @@ async function handleExec(ws, containerId, log, auth) {
|
||||
}
|
||||
});
|
||||
|
||||
// DC-072: Track whether the end-log has fired so we don't double-log
|
||||
// when both execStream 'end' and ws 'close' fire (Docker stream end
|
||||
// closes the WS, which then fires 'close' too — without the flag
|
||||
// we'd emit the same audit line twice with the same durationMs).
|
||||
let ended = false;
|
||||
const logSessionEnd = (reason) => {
|
||||
if (ended) return;
|
||||
ended = true;
|
||||
log.info('exec', 'Exec session ended', {
|
||||
containerId,
|
||||
authType: auth.type,
|
||||
authId: auth.type === 'jwt' ? auth.userId : auth.keyId,
|
||||
durationMs: Date.now() - sessionStart,
|
||||
reason,
|
||||
});
|
||||
};
|
||||
|
||||
execStream.on('end', () => {
|
||||
// DC-072: Audit-log the session end (duration + container) so a
|
||||
// long-running session is observable in the error log. Normal
|
||||
// shutdown path: Docker exec stream closes → log + tell client.
|
||||
logSessionEnd('exec-stream-end');
|
||||
if (ws.readyState === ws.OPEN) {
|
||||
ws.send(JSON.stringify({ type: 'exit' }));
|
||||
ws.close();
|
||||
@@ -148,6 +246,11 @@ async function handleExec(ws, containerId, log, auth) {
|
||||
});
|
||||
|
||||
ws.on('close', () => {
|
||||
// DC-072: Fallback audit-log for abnormal close (browser tab
|
||||
// closed, network drop, container killed mid-session) where the
|
||||
// execStream 'end' event never fires. The ended-flag guard makes
|
||||
// this idempotent with the normal path above.
|
||||
logSessionEnd('ws-close');
|
||||
if (execStream) {
|
||||
try { execStream.destroy(); } catch (_) {
|
||||
// Ignore stream teardown errors on socket close
|
||||
@@ -172,3 +275,11 @@ async function handleExec(ws, containerId, log, auth) {
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// Internal-only export for unit tests. Stripped from the public
|
||||
// surface; tests import this via the destructure form
|
||||
// `const { __test } = require('./routes/exec')`.
|
||||
module.exports.__test = {
|
||||
assertExecScope,
|
||||
isValidContainerId,
|
||||
};
|
||||
|
||||
@@ -4,6 +4,9 @@ const { CADDY, REGEX, LIMITS } = require('../src/utilities/constants');
|
||||
const { ValidationError, ConflictError, NotFoundError } = require('../src/utilities/errors');
|
||||
const { validateURL } = require('../src/security/input-validator');
|
||||
const { ok, successMessage } = require('../src/utils/responses');
|
||||
// DC-074: SSRF defense — reject upstream hosts that resolve to
|
||||
// private/reserved ranges before they reach the Caddyfile.
|
||||
const { validateUpstream } = require('../src/utilities/fleet-validation');
|
||||
|
||||
/**
|
||||
* Sites route factory
|
||||
@@ -166,8 +169,25 @@ module.exports = function({ asyncHandler, ok, caddy, dns, fetchT, buildDomain, a
|
||||
if (!domain || !upstream) throw new ValidationError('Domain and upstream are required');
|
||||
if (!REGEX.DOMAIN.test(domain)) throw new ValidationError('[DC-301] Invalid domain format');
|
||||
|
||||
const upstreamRegex = /^[a-z0-9.-]+:\d{1,5}$/i;
|
||||
if (!upstreamRegex.test(upstream)) throw new ValidationError('Invalid upstream format. Use host:port');
|
||||
// DC-074: SSRF defense — reject upstreams that resolve to private/
|
||||
// reserved ranges BEFORE we write them into the Caddyfile. Without
|
||||
// this, an authenticated dashboard operator can call POST /api/v1/site
|
||||
// with `upstream: '10.0.0.1:80'` and end up with a Caddy site block
|
||||
// that proxies public traffic to an internal host. Caddy runs on
|
||||
// DNS2 (same network as the targets), so the SSRF lands.
|
||||
//
|
||||
// The existing upstreamRegex /^[a-z0-9.-]+:\d{1,5}$/i only checks
|
||||
// charset — it happily accepts 192.168.1.1:80 and 169.254.169.254:80
|
||||
// (the AWS metadata IP). validateUpstream() also does a DNS lookup
|
||||
// for hostnames so a malicious operator can't sneak a public-looking
|
||||
// domain past the gate and have it resolve to a private IP later.
|
||||
const upstreamCheck = await validateUpstream(upstream);
|
||||
if (!upstreamCheck.ok) {
|
||||
// Don't echo attacker-supplied hostnames in the audit log; keep the
|
||||
// canonical code + message but never write the raw value.
|
||||
log?.warn?.('site', 'POST /site rejected by SSRF gate', { code: upstreamCheck.code });
|
||||
throw new ValidationError(`[DC-074] ${upstreamCheck.message} (set SITES_ALLOW_PRIVATE_UPSTREAMS=true to opt in)`);
|
||||
}
|
||||
|
||||
const content = await caddy.read();
|
||||
const escapedDomain = domain.replace(/[.*+?^${}()|[\]\\]/g, '\\$&');
|
||||
@@ -199,12 +219,40 @@ module.exports = function({ asyncHandler, ok, caddy, dns, fetchT, buildDomain, a
|
||||
throw new ValidationError('[DC-301] Invalid subdomain format');
|
||||
}
|
||||
|
||||
// DC-074: SSRF defense — validate the URL syntax via validateURL() (catches
|
||||
// non-http(s) schemes, malformed URLs) AND validateUpstream() (catches
|
||||
// every private/reserved range including CGNAT, multicast, TEST-NET
|
||||
// ranges that validateURL's isPrivateIP() regex misses).
|
||||
//
|
||||
// We intentionally do NOT pass `blockPrivate: true` to validateURL()
|
||||
// here — that's handled by validateUpstream() below, which honors the
|
||||
// SITES_ALLOW_PRIVATE_UPSTREAMS opt-in. validateURL's blockPrivate path
|
||||
// is a hard reject with no escape hatch, which would force operators
|
||||
// who intentionally proxy to a private target to remove validation
|
||||
// entirely.
|
||||
try {
|
||||
validateURL(externalUrl);
|
||||
} catch (validationErr) {
|
||||
throw new ValidationError(validationErr.message);
|
||||
}
|
||||
|
||||
// DC-074: validateUpstream() does the same rigorous private-IP check
|
||||
// fleet-validation shipped for DC-068, with full CGNAT / multicast /
|
||||
// broadcast / 0.0.0.0 / TEST-NET / benchmark range coverage and a DNS
|
||||
// resolution step for hostnames (rebinding defense).
|
||||
let parsedExternalUrl;
|
||||
try {
|
||||
parsedExternalUrl = new URL(externalUrl);
|
||||
} catch (_) {
|
||||
// validateURL() above already gates URL syntax — unreachable.
|
||||
throw new ValidationError('Invalid external URL');
|
||||
}
|
||||
const externalCheck = await validateUpstream(`${parsedExternalUrl.hostname}:${parsedExternalUrl.port || (parsedExternalUrl.protocol === 'https:' ? '443' : '80')}`);
|
||||
if (!externalCheck.ok) {
|
||||
log?.warn?.('site', 'POST /site/external rejected by SSRF gate', { code: externalCheck.code });
|
||||
throw new ValidationError(`[DC-074] ${externalCheck.message} (set SITES_ALLOW_PRIVATE_UPSTREAMS=true to opt in)`);
|
||||
}
|
||||
|
||||
const domain = buildDomain(subdomain);
|
||||
let dnsWarning = null;
|
||||
|
||||
|
||||
@@ -415,10 +415,91 @@ function validateFleetHost(input) {
|
||||
};
|
||||
}
|
||||
|
||||
/**
|
||||
* Validate a `host:port` upstream string for use in Caddy's `reverse_proxy`.
|
||||
*
|
||||
* DC-074 SSRF hardening: an authenticated dashboard operator can call
|
||||
* POST /api/v1/site with `upstream: '10.0.0.1:80'` and end up with a
|
||||
* Caddyfile entry that proxies public traffic (https://attacker.example.com)
|
||||
* to an INTERNAL host (10.0.0.1:80). Caddy runs on DNS2 — same network
|
||||
* as the targets — so the proxy lands the request on the private host.
|
||||
* The operator doesn't even need DNS-rebinding tricks: a literal IPv4
|
||||
* like 192.168.1.1 is accepted by the existing `[a-z0-9.-]+:\d{1,5}`
|
||||
* upstream regex.
|
||||
*
|
||||
* Reuses `resolveAndCheckAddress()` to:
|
||||
* - reject literal private IPv4 / IPv6
|
||||
* - resolve DNS names and reject any private-IP answer
|
||||
* (rebinding defense — the actual address Caddy connects to is
|
||||
* the resolved IP at registration time; Caddy itself resolves
|
||||
* the name per-request, so a malicious operator could flip the
|
||||
* A record between registration and connection. Acceptable
|
||||
* residual risk — the registration check is the main gate.)
|
||||
* - cap port to 1..65535 (defense vs. `host:99999999` integer
|
||||
* overflow / Caddy parser-bomb)
|
||||
*
|
||||
* Opt-in via SITES_ALLOW_PRIVATE_UPSTREAMS=true for operators who
|
||||
* intentionally proxy to private targets (faster than a public DNS
|
||||
* round-trip + central control plane).
|
||||
*
|
||||
* @param {string} upstream - "host:port" string (e.g. "10.0.0.1:80")
|
||||
* @param {object} [opts]
|
||||
* @param {boolean} [opts.allowPrivate] - override the env-var default
|
||||
* @returns {Promise<{ok: true, host: string, port: number, resolvedIp?: string, family?: number} | {ok: false, code: string, message: string}>}
|
||||
*/
|
||||
async function validateUpstream(upstream, opts = {}) {
|
||||
if (typeof upstream !== 'string' || upstream.length === 0) {
|
||||
return { ok: false, code: 'INVALID_UPSTREAM', message: 'upstream is required' };
|
||||
}
|
||||
|
||||
// Split on the LAST colon so IPv6 literals like `[::1]:80` parse
|
||||
// correctly (and a malformed `[::1]` without port is rejected with
|
||||
// a clean code, not a confusing TypeError from Number()).
|
||||
const lastColon = upstream.lastIndexOf(':');
|
||||
if (lastColon < 0) {
|
||||
return { ok: false, code: 'INVALID_UPSTREAM', message: 'upstream must be host:port' };
|
||||
}
|
||||
const host = upstream.slice(0, lastColon);
|
||||
const portStr = upstream.slice(lastColon + 1);
|
||||
|
||||
const portNum = Number(portStr);
|
||||
if (!Number.isInteger(portNum) || portNum < 1 || portNum > 65535) {
|
||||
return { ok: false, code: 'INVALID_PORT', message: 'upstream port must be an integer 1..65535' };
|
||||
}
|
||||
|
||||
// Allow-list the host charset BEFORE the DNS lookup so attacker
|
||||
// payloads can't make the resolver do work. Matches the fleet
|
||||
// isValidHostnameSyntax check; sites.js's own `[a-z0-9.-]+` regex
|
||||
// is more restrictive (only letters/digits/dots/hyphens) so
|
||||
// we widen here to also accept bracketed IPv6. Anything else gets
|
||||
// rejected pre-DNS.
|
||||
const isBracketedIPv6 = host.startsWith('[') && host.endsWith(']');
|
||||
const hostToCheck = isBracketedIPv6 ? host.slice(1, -1) : host;
|
||||
if (!isValidHostnameSyntax(hostToCheck) && require('net').isIP(hostToCheck) === 0) {
|
||||
return { ok: false, code: 'INVALID_HOST', message: `upstream host "${host}" is not a valid DNS name or IP address` };
|
||||
}
|
||||
|
||||
const allowPrivate = typeof opts.allowPrivate === 'boolean'
|
||||
? opts.allowPrivate
|
||||
: process.env.SITES_ALLOW_PRIVATE_UPSTREAMS === 'true';
|
||||
|
||||
const r = await resolveAndCheckAddress(hostToCheck, { allowPrivate });
|
||||
if (!r.ok) return r; // bubbles up PRIVATE_IPV4 / PRIVATE_IPV6 / INVALID_HOSTNAME / DNS_*
|
||||
|
||||
return {
|
||||
ok: true,
|
||||
host,
|
||||
port: portNum,
|
||||
resolvedIp: r.ip,
|
||||
family: r.family,
|
||||
};
|
||||
}
|
||||
|
||||
module.exports = {
|
||||
validateFleetHost,
|
||||
resolveAndCheckAddress,
|
||||
isPrivateOrReservedIPv4,
|
||||
isPrivateOrReservedIPv6,
|
||||
isValidHostnameSyntax,
|
||||
validateUpstream,
|
||||
};
|
||||
|
||||
Reference in New Issue
Block a user