mirror of
https://github.com/go-gost/gost.git
synced 2026-10-08 12:05:46 +00:00
test(e2e): regression for Gost-Target destination-policy bypass
Adds TestGostTargetPolicyBypass: a service-level bypass blacklists the echo server; verifies the control request is 403, a checksum-valid Gost-Target header naming an allowed authority cannot reach the blocked backend, and a malformed header is fail-closed. Verified to catch the bug by reverting the fix (exploit returned the backend response).
This commit is contained in:
@@ -0,0 +1,18 @@
|
||||
# Service-level destination bypass (blacklist) on an HTTP forward proxy.
|
||||
# Blocks the echo server's address ({{.ServerAddr}}). Used by
|
||||
# TestHTTPProxyGostTargetPolicyBypass to verify that a Gost-Target header
|
||||
# cannot separate the authority evaluated by the policy from the authority the
|
||||
# transport dials.
|
||||
bypasses:
|
||||
- name: bypass-0
|
||||
matchers:
|
||||
- "{{.ServerAddr}}"
|
||||
|
||||
services:
|
||||
- name: http-policy
|
||||
addr: ":8080"
|
||||
handler:
|
||||
type: http
|
||||
listener:
|
||||
type: tcp
|
||||
bypass: bypass-0
|
||||
Reference in New Issue
Block a user