- Implemented CrowdSec configuration page with import/export capabilities. - Added API endpoints for exporting, importing, listing, reading, and writing CrowdSec configuration files. - Enhanced security handler to support runtime overrides for CrowdSec mode and API URL. - Updated frontend components to include CrowdSec settings in the UI. - Added tests for CrowdSec configuration management and security handler behavior. - Improved user experience with toast notifications for successful operations and error handling.
31 lines
584 B
Go
31 lines
584 B
Go
package handlers
|
|
|
|
import (
|
|
"path/filepath"
|
|
"testing"
|
|
)
|
|
|
|
func TestIsSafePathUnderBase(t *testing.T) {
|
|
base := filepath.FromSlash("/tmp/session")
|
|
cases := []struct {
|
|
name string
|
|
want bool
|
|
}{
|
|
{"Caddyfile", true},
|
|
{"site/site.conf", true},
|
|
{"../etc/passwd", false},
|
|
{"../../escape", false},
|
|
{"/absolute/path", false},
|
|
{"", false},
|
|
{".", false},
|
|
{"sub/../ok.txt", true},
|
|
}
|
|
|
|
for _, tc := range cases {
|
|
got := isSafePathUnderBase(base, tc.name)
|
|
if got != tc.want {
|
|
t.Fatalf("isSafePathUnderBase(%q, %q) = %v; want %v", base, tc.name, got, tc.want)
|
|
}
|
|
}
|
|
}
|