123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395 |
- package lib
- import (
- "encoding/json"
- "fmt"
- "net/http"
- "net/http/httptest"
- "os"
- "strings"
- "testing"
- "github.com/TecharoHQ/anubis"
- "github.com/TecharoHQ/anubis/data"
- "github.com/TecharoHQ/anubis/internal"
- "github.com/TecharoHQ/anubis/lib/policy"
- )
- func loadPolicies(t *testing.T, fname string) *policy.ParsedConfig {
- t.Helper()
- anubisPolicy, err := LoadPoliciesOrDefault(fname, anubis.DefaultDifficulty)
- if err != nil {
- t.Fatal(err)
- }
- return anubisPolicy
- }
- func spawnAnubis(t *testing.T, opts Options) *Server {
- t.Helper()
- s, err := New(opts)
- if err != nil {
- t.Fatalf("can't construct libanubis.Server: %v", err)
- }
- return s
- }
- type challenge struct {
- Challenge string `json:"challenge"`
- }
- func makeChallenge(t *testing.T, ts *httptest.Server) challenge {
- t.Helper()
- resp, err := ts.Client().Post(ts.URL+"/.within.website/x/cmd/anubis/api/make-challenge", "", nil)
- if err != nil {
- t.Fatalf("can't request challenge: %v", err)
- }
- defer resp.Body.Close()
- var chall challenge
- if err := json.NewDecoder(resp.Body).Decode(&chall); err != nil {
- t.Fatalf("can't read challenge response body: %v", err)
- }
- return chall
- }
- func TestLoadPolicies(t *testing.T) {
- for _, fname := range []string{"botPolicies.json", "botPolicies.yaml"} {
- t.Run(fname, func(t *testing.T) {
- fin, err := data.BotPolicies.Open(fname)
- if err != nil {
- t.Fatal(err)
- }
- defer fin.Close()
- if _, err := policy.ParseConfig(fin, fname, 4); err != nil {
- t.Fatal(err)
- }
- })
- }
- }
- // Regression test for CVE-2025-24369
- func TestCVE2025_24369(t *testing.T) {
- pol := loadPolicies(t, "")
- pol.DefaultDifficulty = 4
- srv := spawnAnubis(t, Options{
- Next: http.NewServeMux(),
- Policy: pol,
- CookieDomain: "local.cetacean.club",
- CookiePartitioned: true,
- CookieName: t.Name(),
- })
- ts := httptest.NewServer(internal.RemoteXRealIP(true, "tcp", srv))
- defer ts.Close()
- chall := makeChallenge(t, ts)
- calcString := fmt.Sprintf("%s%d", chall.Challenge, 0)
- calculated := internal.SHA256sum(calcString)
- nonce := 0
- elapsedTime := 420
- redir := "/"
- cli := ts.Client()
- cli.CheckRedirect = func(req *http.Request, via []*http.Request) error {
- return http.ErrUseLastResponse
- }
- req, err := http.NewRequest(http.MethodGet, ts.URL+"/.within.website/x/cmd/anubis/api/pass-challenge", nil)
- if err != nil {
- t.Fatalf("can't make request: %v", err)
- }
- q := req.URL.Query()
- q.Set("response", calculated)
- q.Set("nonce", fmt.Sprint(nonce))
- q.Set("redir", redir)
- q.Set("elapsedTime", fmt.Sprint(elapsedTime))
- req.URL.RawQuery = q.Encode()
- resp, err := cli.Do(req)
- if err != nil {
- t.Fatalf("can't do challenge passing")
- }
- if resp.StatusCode == http.StatusFound {
- t.Log("Regression on CVE-2025-24369")
- t.Errorf("wanted HTTP status %d, got: %d", http.StatusForbidden, resp.StatusCode)
- }
- }
- func TestCookieSettings(t *testing.T) {
- pol := loadPolicies(t, "")
- pol.DefaultDifficulty = 0
- srv := spawnAnubis(t, Options{
- Next: http.NewServeMux(),
- Policy: pol,
- CookieDomain: "local.cetacean.club",
- CookiePartitioned: true,
- CookieName: t.Name(),
- })
- ts := httptest.NewServer(internal.RemoteXRealIP(true, "tcp", srv))
- defer ts.Close()
- cli := &http.Client{
- CheckRedirect: func(req *http.Request, via []*http.Request) error {
- return http.ErrUseLastResponse
- },
- }
- resp, err := cli.Post(ts.URL+"/.within.website/x/cmd/anubis/api/make-challenge", "", nil)
- if err != nil {
- t.Fatalf("can't request challenge: %v", err)
- }
- defer resp.Body.Close()
- var chall = struct {
- Challenge string `json:"challenge"`
- }{}
- if err := json.NewDecoder(resp.Body).Decode(&chall); err != nil {
- t.Fatalf("can't read challenge response body: %v", err)
- }
- nonce := 0
- elapsedTime := 420
- redir := "/"
- calculated := ""
- calcString := fmt.Sprintf("%s%d", chall.Challenge, nonce)
- calculated = internal.SHA256sum(calcString)
- req, err := http.NewRequest(http.MethodGet, ts.URL+"/.within.website/x/cmd/anubis/api/pass-challenge", nil)
- if err != nil {
- t.Fatalf("can't make request: %v", err)
- }
- q := req.URL.Query()
- q.Set("response", calculated)
- q.Set("nonce", fmt.Sprint(nonce))
- q.Set("redir", redir)
- q.Set("elapsedTime", fmt.Sprint(elapsedTime))
- req.URL.RawQuery = q.Encode()
- resp, err = cli.Do(req)
- if err != nil {
- t.Fatalf("can't do challenge passing")
- }
- if resp.StatusCode != http.StatusFound {
- resp.Write(os.Stderr)
- t.Errorf("wanted %d, got: %d", http.StatusFound, resp.StatusCode)
- }
- var ckie *http.Cookie
- for _, cookie := range resp.Cookies() {
- t.Logf("%#v", cookie)
- if cookie.Name == anubis.CookieName {
- ckie = cookie
- break
- }
- }
- if ckie == nil {
- t.Errorf("Cookie %q not found", anubis.CookieName)
- return
- }
- if ckie.Domain != "local.cetacean.club" {
- t.Errorf("cookie domain is wrong, wanted local.cetacean.club, got: %s", ckie.Domain)
- }
- if ckie.Partitioned != srv.opts.CookiePartitioned {
- t.Errorf("wanted partitioned flag %v, got: %v", srv.opts.CookiePartitioned, ckie.Partitioned)
- }
- }
- func TestCheckDefaultDifficultyMatchesPolicy(t *testing.T) {
- h := http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
- fmt.Fprintln(w, "OK")
- })
- for i := 1; i < 10; i++ {
- t.Run(fmt.Sprint(i), func(t *testing.T) {
- anubisPolicy, err := LoadPoliciesOrDefault("", i)
- if err != nil {
- t.Fatal(err)
- }
- s, err := New(Options{
- Next: h,
- Policy: anubisPolicy,
- ServeRobotsTXT: true,
- })
- if err != nil {
- t.Fatalf("can't construct libanubis.Server: %v", err)
- }
- req, err := http.NewRequest(http.MethodGet, "/", nil)
- if err != nil {
- t.Fatal(err)
- }
- req.Header.Add("X-Real-Ip", "127.0.0.1")
- _, bot, err := s.check(req)
- if err != nil {
- t.Fatal(err)
- }
- if bot.Challenge.Difficulty != i {
- t.Errorf("Challenge.Difficulty is wrong, wanted %d, got: %d", i, bot.Challenge.Difficulty)
- }
- if bot.Challenge.ReportAs != i {
- t.Errorf("Challenge.ReportAs is wrong, wanted %d, got: %d", i, bot.Challenge.ReportAs)
- }
- })
- }
- }
- func TestBasePrefix(t *testing.T) {
- h := http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
- fmt.Fprintln(w, "OK")
- })
- testCases := []struct {
- name string
- basePrefix string
- path string
- expected string
- }{
- {
- name: "no prefix",
- basePrefix: "",
- path: "/.within.website/x/cmd/anubis/api/make-challenge",
- expected: "/.within.website/x/cmd/anubis/api/make-challenge",
- },
- {
- name: "with prefix",
- basePrefix: "/myapp",
- path: "/myapp/.within.website/x/cmd/anubis/api/make-challenge",
- expected: "/myapp/.within.website/x/cmd/anubis/api/make-challenge",
- },
- {
- name: "with prefix and trailing slash",
- basePrefix: "/myapp/",
- path: "/myapp/.within.website/x/cmd/anubis/api/make-challenge",
- expected: "/myapp/.within.website/x/cmd/anubis/api/make-challenge",
- },
- }
- for _, tc := range testCases {
- t.Run(tc.name, func(t *testing.T) {
- // Reset the global BasePrefix before each test
- anubis.BasePrefix = ""
- pol := loadPolicies(t, "")
- pol.DefaultDifficulty = 4
- srv := spawnAnubis(t, Options{
- Next: h,
- Policy: pol,
- BasePrefix: tc.basePrefix,
- })
- ts := httptest.NewServer(internal.RemoteXRealIP(true, "tcp", srv))
- defer ts.Close()
- // Test API endpoint with prefix
- resp, err := ts.Client().Post(ts.URL+tc.path, "", nil)
- if err != nil {
- t.Fatalf("can't request challenge: %v", err)
- }
- defer resp.Body.Close()
- if resp.StatusCode != http.StatusOK {
- t.Errorf("expected status code %d, got: %d", http.StatusOK, resp.StatusCode)
- }
- var chall challenge
- if err := json.NewDecoder(resp.Body).Decode(&chall); err != nil {
- t.Fatalf("can't read challenge response body: %v", err)
- }
- if chall.Challenge == "" {
- t.Errorf("expected non-empty challenge")
- }
- // Test cookie path when passing challenge
- // Find a nonce that produces a hash with the required number of leading zeros
- nonce := 0
- var calculated string
- for {
- calcString := fmt.Sprintf("%s%d", chall.Challenge, nonce)
- calculated = internal.SHA256sum(calcString)
- if strings.HasPrefix(calculated, strings.Repeat("0", pol.DefaultDifficulty)) {
- break
- }
- nonce++
- }
- elapsedTime := 420
- redir := "/"
- cli := ts.Client()
- cli.CheckRedirect = func(req *http.Request, via []*http.Request) error {
- return http.ErrUseLastResponse
- }
- // Construct the correct path for pass-challenge
- passChallengePath := tc.path
- passChallengePath = passChallengePath[:strings.LastIndex(passChallengePath, "/")+1] + "pass-challenge"
- req, err := http.NewRequest(http.MethodGet, ts.URL+passChallengePath, nil)
- if err != nil {
- t.Fatalf("can't make request: %v", err)
- }
- q := req.URL.Query()
- q.Set("response", calculated)
- q.Set("nonce", fmt.Sprint(nonce))
- q.Set("redir", redir)
- q.Set("elapsedTime", fmt.Sprint(elapsedTime))
- req.URL.RawQuery = q.Encode()
- resp, err = cli.Do(req)
- if err != nil {
- t.Fatalf("can't do challenge passing: %v", err)
- }
- if resp.StatusCode != http.StatusFound {
- t.Errorf("wanted %d, got: %d", http.StatusFound, resp.StatusCode)
- }
- // Check cookie path
- var ckie *http.Cookie
- for _, cookie := range resp.Cookies() {
- if cookie.Name == anubis.CookieName {
- ckie = cookie
- break
- }
- }
- if ckie == nil {
- t.Errorf("Cookie %q not found", anubis.CookieName)
- return
- }
- expectedPath := "/"
- if tc.basePrefix != "" {
- expectedPath = strings.TrimSuffix(tc.basePrefix, "/") + "/"
- }
- if ckie.Path != expectedPath {
- t.Errorf("cookie path is wrong, wanted %s, got: %s", expectedPath, ckie.Path)
- }
- })
- }
- }
|