fix: 修复 TLS ConnectionState、SPA 回退、健康检查与监听小问题
This commit is contained in:
@@ -32,3 +32,43 @@ func TestParseCIDRsAndTrustedXFF(t *testing.T) {
|
||||
t.Fatal("expected https via proxy")
|
||||
}
|
||||
}
|
||||
|
||||
func TestClientIPMultiLinePortAndIPv6(t *testing.T) {
|
||||
trusted := httpx.ParseCIDRs([]string{"10.0.0.0/8", "127.0.0.1/32"})
|
||||
|
||||
t.Run("two header lines", func(t *testing.T) {
|
||||
r := httptest.NewRequest(http.MethodGet, "/", nil)
|
||||
r.RemoteAddr = "10.1.2.3:9"
|
||||
r.Header["X-Forwarded-For"] = []string{"198.51.100.1", "203.0.113.8, 10.9.9.9"}
|
||||
if got := httpx.ClientIP(r, trusted); got != "203.0.113.8" {
|
||||
t.Fatalf("got %q", got)
|
||||
}
|
||||
})
|
||||
|
||||
t.Run("port on rightmost client", func(t *testing.T) {
|
||||
r := httptest.NewRequest(http.MethodGet, "/", nil)
|
||||
r.RemoteAddr = "10.1.2.3:9"
|
||||
r.Header.Set("X-Forwarded-For", "198.51.100.9, 203.0.113.10:1234, 10.9.9.9")
|
||||
if got := httpx.ClientIP(r, trusted); got != "203.0.113.10" {
|
||||
t.Fatalf("got %q", got)
|
||||
}
|
||||
})
|
||||
|
||||
t.Run("unparseable stops", func(t *testing.T) {
|
||||
r := httptest.NewRequest(http.MethodGet, "/", nil)
|
||||
r.RemoteAddr = "10.1.2.3:9"
|
||||
r.Header.Set("X-Forwarded-For", "198.51.100.1, not-an-ip, 10.9.9.9")
|
||||
if got := httpx.ClientIP(r, trusted); got != "10.1.2.3" {
|
||||
t.Fatalf("got %q", got)
|
||||
}
|
||||
})
|
||||
|
||||
t.Run("ipv6 brackets", func(t *testing.T) {
|
||||
r := httptest.NewRequest(http.MethodGet, "/", nil)
|
||||
r.RemoteAddr = "10.1.2.3:9"
|
||||
r.Header.Set("X-Forwarded-For", "[2001:db8::1], 10.9.9.9")
|
||||
if got := httpx.ClientIP(r, trusted); got != "2001:db8::1" {
|
||||
t.Fatalf("got %q", got)
|
||||
}
|
||||
})
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user