CI & Build / Python lint (push) Successful in 2s
CI & Build / Build now, or wait for Android? (push) Successful in 2s
Android / Build, or is the channel already serving this? (push) Successful in 3s
Desktop (Tauri) / Build, or is the channel already serving this? (push) Successful in 2s
CI & Build / TypeScript typecheck (push) Successful in 7s
CI & Build / Python tests (push) Successful in 15s
CI & Build / integration (push) Successful in 45s
CI & Build / Build & push image (push) Skipped
Desktop (Tauri) / Windows installer (cross-compiled) (push) Successful in 4m17s
Desktop (Tauri) / Tauri desktop (Linux) (push) Successful in 7m33s
Desktop (Tauri) / Update manifest (push) Successful in 7s
Android / Kotlin + Rust (APK) (push) Successful in 11m25s
Step 2 of milestone 481. The operator chose a full rename (Scribe note 5071), so this goes past the display strings into the identities: - src/thoughtsync → src/inkwell; every import, the Dockerfile and both compose commands, alembic env, pyproject - THOUGHTSYNC_* → INKWELL_* (database URL, secret key, log level, tag/port/bind) - container data dir /var/thoughtsync → /var/inkwell - image git.fabledsword.com/bvandeusen/inkwell; Postgres user/db default inkwell; CI's integration service follows - the files the image serves are inkwell.*. fetch-clients.sh still fetches the thoughtsync-named release assets, because the lanes that publish them are renamed in steps 3 and 4 - exports are written with app "inkwell" Two deliberate exceptions, both because data rides on them: - compose volumes are now named explicitly and overridable (INKWELL_DB_VOLUME, INKWELL_DATA_VOLUME), so a deployment installed as ThoughtSync points at the volumes and DB identity it already has. .env.example says exactly what to set - import still accepts app "thoughtsync", because exports written before the rename are backups. Tested both ways Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
74 lines
3.1 KiB
Python
74 lines
3.1 KiB
Python
"""The proxy trust boundary.
|
|
|
|
The whole security property is "a caller cannot forge their own address", and it rests
|
|
on counting in from the RIGHT of the header rather than the left. These are the cases
|
|
that tell the two apart — pure functions, no request context, no database.
|
|
"""
|
|
from inkwell.proxy import forwarded_for, trusted_entry
|
|
from inkwell.settings import live
|
|
|
|
PEER = "10.0.0.1" # the socket address: our own proxy, or the caller when unproxied
|
|
|
|
|
|
def test_default_is_one_hop():
|
|
# One reverse proxy terminating TLS — this deployment, and the only shape that is
|
|
# safe to assume. A wrong default here is a silent security bug, not a preference.
|
|
#
|
|
# Read through live() rather than the registry: live() is what proxy.py actually
|
|
# calls, and it is seeded from the defaults at import time so the value is right
|
|
# before the first database read. A boot that never reached the DB must still
|
|
# count one hop, not zero.
|
|
assert live("trusted_proxy_hops") == 1
|
|
|
|
|
|
def test_no_proxy_ignores_the_header_entirely():
|
|
# hops=0 says nothing in front of us appends anything, so the header can only be
|
|
# something a caller invented.
|
|
assert forwarded_for("1.2.3.4", PEER, 0) == PEER
|
|
|
|
|
|
def test_one_hop_reads_what_our_proxy_wrote():
|
|
assert forwarded_for("203.0.113.7", PEER, 1) == "203.0.113.7"
|
|
|
|
|
|
def test_a_forged_prefix_is_never_selected():
|
|
# THE test. A caller sends `X-Forwarded-For: 1.2.3.4`; our proxy appends the
|
|
# address it actually saw. Reading from the left would hand the caller a fresh
|
|
# rate-limit bucket for every value they invent.
|
|
assert forwarded_for("1.2.3.4, 203.0.113.7", PEER, 1) == "203.0.113.7"
|
|
# …and padding it doesn't help either.
|
|
assert forwarded_for("a, b, c, d, 203.0.113.7", PEER, 1) == "203.0.113.7"
|
|
|
|
|
|
def test_two_hops_sees_past_a_cdn():
|
|
# Cloudflare appended the real client; our proxy appended Cloudflare.
|
|
assert forwarded_for("203.0.113.7, 172.16.0.5", PEER, 2) == "203.0.113.7"
|
|
assert forwarded_for("1.2.3.4, 203.0.113.7, 172.16.0.5", PEER, 2) == "203.0.113.7"
|
|
|
|
|
|
def test_a_short_header_falls_back_rather_than_reaching_left():
|
|
# Fewer proxies than configured. Reaching further left would start believing
|
|
# entries no proxy of ours wrote, so the safe direction is the socket address —
|
|
# at worst several callers share one bucket.
|
|
assert forwarded_for("203.0.113.7", PEER, 2) == PEER
|
|
assert forwarded_for("", PEER, 1) == PEER
|
|
|
|
|
|
def test_malformed_headers_do_not_crash_or_leak_empties():
|
|
assert forwarded_for(",,,", PEER, 1) == PEER
|
|
assert forwarded_for(" , 203.0.113.7 , ", PEER, 1) == "203.0.113.7"
|
|
|
|
|
|
def test_the_key_is_length_bounded():
|
|
# It becomes a dict key in the limiter; an unbounded header must not become an
|
|
# unbounded allocation.
|
|
assert len(forwarded_for("x" * 5000, PEER, 1)) <= 64
|
|
|
|
|
|
def test_trusted_entry_reports_absence_rather_than_guessing():
|
|
# `is_https` needs to tell "no trusted entry" apart from "an entry saying http",
|
|
# which is why this returns None rather than a default.
|
|
assert trusted_entry("", 1) is None
|
|
assert trusted_entry("https", 0) is None
|
|
assert trusted_entry("http, https", 1) == "https"
|