Files
gost/tests/e2e/testdata/http/server_policy_bypass.yaml
ginuerzh 76467efc59 test(e2e): regression for Gost-Target destination-policy bypass
Adds TestGostTargetPolicyBypass: a service-level bypass blacklists the
echo server; verifies the control request is 403, a checksum-valid
Gost-Target header naming an allowed authority cannot reach the blocked
backend, and a malformed header is fail-closed. Verified to catch the bug
by reverting the fix (exploit returned the backend response).
2026-08-27 20:16:34 +08:00

19 lines
508 B
YAML

# Service-level destination bypass (blacklist) on an HTTP forward proxy.
# Blocks the echo server's address ({{.ServerAddr}}). Used by
# TestHTTPProxyGostTargetPolicyBypass to verify that a Gost-Target header
# cannot separate the authority evaluated by the policy from the authority the
# transport dials.
bypasses:
- name: bypass-0
matchers:
- "{{.ServerAddr}}"
services:
- name: http-policy
addr: ":8080"
handler:
type: http
listener:
type: tcp
bypass: bypass-0