mirror of
https://github.com/fawney19/Aether.git
synced 2026-10-08 02:17:46 +08:00
feat(security): harden gateway request and runtime controls
This commit is contained in:
@@ -11,6 +11,59 @@ fn production_workspace_source(path: &Path) -> String {
|
||||
.to_string()
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn gateway_production_body_collection_stays_bounded() {
|
||||
let root = Path::new(env!("CARGO_MANIFEST_DIR")).join("src");
|
||||
let mut files = Vec::new();
|
||||
collect_rust_files(&root, &mut files);
|
||||
let forbidden = [
|
||||
"to_bytes(body, usize::MAX)",
|
||||
"to_bytes(request.into_body(), usize::MAX)",
|
||||
"to_bytes(response.into_body(), usize::MAX)",
|
||||
"into_body(),\n usize::MAX",
|
||||
];
|
||||
let violations = files
|
||||
.into_iter()
|
||||
.filter(|path| {
|
||||
!path
|
||||
.components()
|
||||
.any(|component| component.as_os_str() == "tests")
|
||||
})
|
||||
.filter_map(|path| {
|
||||
let source = production_workspace_source(&path);
|
||||
let hits = forbidden
|
||||
.iter()
|
||||
.filter(|pattern| source.contains(**pattern))
|
||||
.copied()
|
||||
.collect::<Vec<_>>();
|
||||
if hits.is_empty() {
|
||||
None
|
||||
} else {
|
||||
Some(format!("{} -> {}", path.display(), hits.join(", ")))
|
||||
}
|
||||
})
|
||||
.collect::<Vec<_>>();
|
||||
|
||||
assert!(
|
||||
violations.is_empty(),
|
||||
"production body collection must use explicit limits:\n{}",
|
||||
violations.join("\n")
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn tunnel_node_status_delivery_stays_bounded() {
|
||||
let source = read_workspace_file("apps/aether-gateway/src/tunnel/embedded/hub.rs");
|
||||
assert!(
|
||||
!source.contains("unbounded_channel::<NodeStatusEvent>"),
|
||||
"tunnel node status delivery must not use an unbounded channel"
|
||||
);
|
||||
assert!(
|
||||
source.contains("bounded_queue::<NodeStatusEvent>"),
|
||||
"tunnel node status delivery must use the tracked bounded queue"
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn gateway_small_runtime_shims_stay_deleted() {
|
||||
for path in [
|
||||
|
||||
@@ -85,6 +85,60 @@ async fn admin_security_whitelist_matches_cidr() {
|
||||
.expect("whitelist check should succeed"));
|
||||
}
|
||||
|
||||
#[tokio::test]
|
||||
async fn admin_security_blacklist_cache_tracks_local_mutations() {
|
||||
let state = AppState::new().expect("gateway should build");
|
||||
let ip_address = "203.0.113.9".parse().expect("valid ip");
|
||||
|
||||
assert!(!state
|
||||
.admin_security_ip_blacklisted(ip_address)
|
||||
.await
|
||||
.expect("initial blacklist check should succeed"));
|
||||
state
|
||||
.add_admin_security_blacklist("203.0.113.9", "manual", None)
|
||||
.await
|
||||
.expect("blacklist add should succeed");
|
||||
assert!(state
|
||||
.admin_security_ip_blacklisted(ip_address)
|
||||
.await
|
||||
.expect("cached blacklist check should succeed"));
|
||||
state
|
||||
.remove_admin_security_blacklist("203.0.113.9")
|
||||
.await
|
||||
.expect("blacklist remove should succeed");
|
||||
assert!(!state
|
||||
.admin_security_ip_blacklisted(ip_address)
|
||||
.await
|
||||
.expect("updated blacklist check should succeed"));
|
||||
}
|
||||
|
||||
#[tokio::test]
|
||||
async fn admin_security_whitelist_cache_invalidates_after_mutation() {
|
||||
let state = AppState::new().expect("gateway should build");
|
||||
let ip_address = "203.0.113.10".parse().expect("valid ip");
|
||||
|
||||
assert!(!state
|
||||
.admin_security_ip_whitelisted(ip_address)
|
||||
.await
|
||||
.expect("initial whitelist check should succeed"));
|
||||
state
|
||||
.add_admin_security_whitelist("203.0.113.0/24")
|
||||
.await
|
||||
.expect("whitelist add should succeed");
|
||||
assert!(state
|
||||
.admin_security_ip_whitelisted(ip_address)
|
||||
.await
|
||||
.expect("updated whitelist check should succeed"));
|
||||
state
|
||||
.remove_admin_security_whitelist("203.0.113.0/24")
|
||||
.await
|
||||
.expect("whitelist remove should succeed");
|
||||
assert!(!state
|
||||
.admin_security_ip_whitelisted(ip_address)
|
||||
.await
|
||||
.expect("removed whitelist check should succeed"));
|
||||
}
|
||||
|
||||
async fn send_admin_security_request(
|
||||
gateway: Router,
|
||||
method: reqwest::Method,
|
||||
|
||||
Reference in New Issue
Block a user