fix: 限制管理接口请求体大小与读取时间
This commit is contained in:
@@ -0,0 +1,53 @@
|
||||
package admin_test
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"io"
|
||||
"net/http"
|
||||
"strings"
|
||||
"testing"
|
||||
)
|
||||
|
||||
func TestLoginRejectsOversizeBody(t *testing.T) {
|
||||
_, srv, client, _ := setup(t)
|
||||
body := `{"username":"admin","password":"` + strings.Repeat("a", 1<<20) + `"}`
|
||||
req, err := http.NewRequest(http.MethodPost, srv.URL+"/api/admin/login", strings.NewReader(body))
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
req.Header.Set("Content-Type", "application/json")
|
||||
res, err := client.Do(req)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
env := decodeEnv(t, res)
|
||||
if res.StatusCode != http.StatusRequestEntityTooLarge {
|
||||
t.Fatalf("want 413 got %d env=%+v", res.StatusCode, env)
|
||||
}
|
||||
if env.Error == nil || env.Error.Code != "payload_too_large" {
|
||||
t.Fatalf("want payload_too_large got %+v", env.Error)
|
||||
}
|
||||
}
|
||||
|
||||
func TestImportRejectsOversizeCSV(t *testing.T) {
|
||||
_, srv, client, _, _ := setupEndpoints(t)
|
||||
payload := bytes.Repeat([]byte("x"), 8<<20+1)
|
||||
req, err := http.NewRequest(http.MethodPost, srv.URL+"/api/admin/endpoints/import", bytes.NewReader(payload))
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
req.Header.Set("Content-Type", "text/csv")
|
||||
req.Header.Set("X-Nixmsg-Request", "1")
|
||||
res, err := client.Do(req)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
raw, _ := io.ReadAll(res.Body)
|
||||
_ = res.Body.Close()
|
||||
if res.StatusCode != http.StatusRequestEntityTooLarge {
|
||||
t.Fatalf("want 413 got %d body=%s", res.StatusCode, raw)
|
||||
}
|
||||
if !strings.Contains(string(raw), "payload_too_large") {
|
||||
t.Fatalf("want payload_too_large in body: %s", raw)
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user