mirror of
https://github.com/go-gost/gost.git
synced 2026-10-08 03:55:45 +00:00
Adds TestGostTargetPolicyBypass: a service-level bypass blacklists the echo server; verifies the control request is 403, a checksum-valid Gost-Target header naming an allowed authority cannot reach the blocked backend, and a malformed header is fail-closed. Verified to catch the bug by reverting the fix (exploit returned the backend response).
19 lines
508 B
YAML
19 lines
508 B
YAML
# Service-level destination bypass (blacklist) on an HTTP forward proxy.
|
|
# Blocks the echo server's address ({{.ServerAddr}}). Used by
|
|
# TestHTTPProxyGostTargetPolicyBypass to verify that a Gost-Target header
|
|
# cannot separate the authority evaluated by the policy from the authority the
|
|
# transport dials.
|
|
bypasses:
|
|
- name: bypass-0
|
|
matchers:
|
|
- "{{.ServerAddr}}"
|
|
|
|
services:
|
|
- name: http-policy
|
|
addr: ":8080"
|
|
handler:
|
|
type: http
|
|
listener:
|
|
type: tcp
|
|
bypass: bypass-0
|