CI & Build / Python lint (push) Successful in 2s
CI & Build / Build now, or wait for Android? (push) Successful in 2s
Android / Build, or is the channel already serving this? (push) Successful in 3s
Desktop (Tauri) / Build, or is the channel already serving this? (push) Successful in 2s
CI & Build / Web typecheck and unit tests (push) Successful in 8s
CI & Build / Python tests (push) Successful in 10s
CI & Build / integration (push) Failing after 1m21s
CI & Build / Build & push image (push) Skipped
Desktop (Tauri) / Web tests, clippy, Rust tests and rustfmt (push) Successful in 2m47s
Desktop (Tauri) / Windows installer (cross-compiled) (push) Successful in 2m48s
Desktop (Tauri) / Tauri desktop (Linux) (push) Successful in 3m39s
Desktop (Tauri) / Update manifest (push) Successful in 3s
Android / Kotlin + Rust (APK) (push) Successful in 8m37s
From the audit (#5178). Each was unreachable from every client: - Checklist add-item and delete-item: REST POST /items and DELETE /items/<id>, the Tauri commands, the store, rest and local adapters, the core's add_item/delete_item, set_item_text and remove_item, and the FFI exports. Adding, rewording and removing an item are body edits in every editor. The checked toggle stays, and its rewriter is simpler without the drop branch. - Manual unfurl: POST /unfurl and its adapters. Previews arrive in the background after a save (unfurl_queue). - The /api/config `android_client` key, android_release() and the APK_NAME/MANIFEST_NAME aliases. Phones poll /api/client/android. - users.email_verified and users.avatar_path (migration 0037). Nothing set the first or read the second; the SMTP reset never checked verification. - derive::extract_tags (only tests used it; the shared fixture now runs through extract_tag_spans), the unused check and link icons, and the unused editor_add_item string. - The blob scheme is renamed tsblob -> inkblob. URLs are built as notes are read, so nothing stored carries the old one. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
67 lines
2.7 KiB
Python
67 lines
2.7 KiB
Python
import ipaddress
|
|
|
|
import pytest
|
|
|
|
from inkwell.app import create_app
|
|
from inkwell.unfurl import UnfurlError, extract_preview, is_public_ip, validate_url
|
|
|
|
|
|
@pytest.fixture
|
|
def app():
|
|
return create_app()
|
|
|
|
|
|
def test_is_public_ip_blocks_internal_ranges():
|
|
assert is_public_ip(ipaddress.ip_address("8.8.8.8"))
|
|
assert is_public_ip(ipaddress.ip_address("2606:4700:4700::1111"))
|
|
# everything internal / special is rejected (the SSRF core)
|
|
assert not is_public_ip(ipaddress.ip_address("10.0.0.1")) # private
|
|
assert not is_public_ip(ipaddress.ip_address("192.168.1.1")) # private
|
|
assert not is_public_ip(ipaddress.ip_address("127.0.0.1")) # loopback
|
|
assert not is_public_ip(ipaddress.ip_address("169.254.169.254")) # link-local (cloud metadata)
|
|
assert not is_public_ip(ipaddress.ip_address("0.0.0.0")) # unspecified
|
|
assert not is_public_ip(ipaddress.ip_address("::1")) # loopback v6
|
|
assert not is_public_ip(ipaddress.ip_address("fc00::1")) # unique-local v6
|
|
|
|
|
|
def test_validate_url_scheme_and_parts():
|
|
assert validate_url("https://example.com/a?b=c") == ("https", "example.com", 443, "/a?b=c")
|
|
assert validate_url("http://x.io")[3] == "/" # default path
|
|
assert validate_url("http://x.io:8080/p")[2] == 8080 # explicit port
|
|
for bad in ("file:///etc/passwd", "ftp://x", "gopher://x", "not a url", ""):
|
|
with pytest.raises(UnfurlError):
|
|
validate_url(bad)
|
|
|
|
|
|
def test_extract_preview_opengraph():
|
|
html = (
|
|
b"<html><head>"
|
|
b'<meta property="og:title" content="Hello & World">'
|
|
b'<meta property="og:description" content="A page">'
|
|
b'<meta property="og:image" content="/img.png">'
|
|
b'<meta property="og:site_name" content="Example">'
|
|
b"</head></html>"
|
|
)
|
|
p = extract_preview("https://example.com/page", html)
|
|
assert p["title"] == "Hello & World" # entities decoded
|
|
assert p["description"] == "A page"
|
|
assert p["image_url"] == "https://example.com/img.png" # relative resolved to absolute
|
|
assert p["site_name"] == "Example"
|
|
|
|
|
|
def test_extract_preview_title_fallback_and_host_defaults():
|
|
html = b"<html><head><title> Just a Title </title></head></html>"
|
|
p = extract_preview("https://example.com", html)
|
|
assert p["title"] == "Just a Title" # whitespace collapsed
|
|
assert p["description"] is None
|
|
assert p["image_url"] is None
|
|
assert p["site_name"] == "example.com" # falls back to host
|
|
|
|
|
|
async def test_delete_preview_requires_auth(app):
|
|
client = app.test_client()
|
|
resp = await client.delete(
|
|
"/api/notes/00000000-0000-0000-0000-000000000000/previews/00000000-0000-0000-0000-000000000001"
|
|
)
|
|
assert resp.status_code == 401
|