TestSecretTokenAuth verifies that the fileserver running at localhost cannot be accessed directly without the correct secret token. This matters because if a victim can be induced to visit the localhost URL and access a malicious file on their own share, it could allow a Mark-of-the-Web bypass attac
(t *testing.T)
| 203 | // if a victim can be induced to visit the localhost URL and access a malicious |
| 204 | // file on their own share, it could allow a Mark-of-the-Web bypass attack. |
| 205 | func TestSecretTokenAuth(t *testing.T) { |
| 206 | s := newSystem(t) |
| 207 | |
| 208 | fileserverAddr := s.addRemote(remote1) |
| 209 | s.addShare(remote1, share11, drive.PermissionReadWrite) |
| 210 | s.writeFile("writing file to read/write remote should succeed", remote1, share11, file111, "hello world", true) |
| 211 | |
| 212 | client := &http.Client{ |
| 213 | Transport: &http.Transport{DisableKeepAlives: true}, |
| 214 | } |
| 215 | addr := strings.Split(fileserverAddr, "|")[1] |
| 216 | wrongSecret, err := generateSecretToken() |
| 217 | if err != nil { |
| 218 | t.Fatal(err) |
| 219 | } |
| 220 | u := fmt.Sprintf("http://%s/%s/%s", addr, wrongSecret, url.PathEscape(file111)) |
| 221 | resp, err := client.Get(u) |
| 222 | if err != nil { |
| 223 | t.Fatal(err) |
| 224 | } |
| 225 | if resp.StatusCode != http.StatusForbidden { |
| 226 | t.Errorf("expected %d for incorrect secret token, but got %d", http.StatusForbidden, resp.StatusCode) |
| 227 | } |
| 228 | } |
| 229 | |
| 230 | func TestLOCK(t *testing.T) { |
| 231 | s := newSystem(t) |
nothing calls this directly
no test coverage detected
searching dependent graphs…