48 lines
1.8 KiB
Go
48 lines
1.8 KiB
Go
package identity_test
|
|
|
|
// v2.3 task 03: on a route's dedicated listener the route is fixed, so the gate is that route's
|
|
// peers for every request, whatever path or X-Crossbar-Route header the caller sends.
|
|
|
|
import (
|
|
"net/http"
|
|
"net/http/httptest"
|
|
"testing"
|
|
|
|
"git.wntrmute.dev/kyle/crossbar/internal/identity"
|
|
)
|
|
|
|
func TestRouteMiddleware(t *testing.T) {
|
|
inner := http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { w.WriteHeader(204) })
|
|
checker := identity.NewChecker(fakeResolver{"100.64.0.5": "talos", "100.64.0.9": "titan"})
|
|
locked := identity.RouteMiddleware(checker, []string{"talos"}, inner)
|
|
open := identity.RouteMiddleware(checker, nil, inner)
|
|
for _, tc := range []struct {
|
|
name string
|
|
h http.Handler
|
|
path, hdr string
|
|
addr string
|
|
want int
|
|
}{
|
|
{"right peer", locked, "/v1/chat/completions", "", "100.64.0.5:5", 204},
|
|
{"wrong peer", locked, "/v1/chat/completions", "", "100.64.0.9:5", 403},
|
|
{"not a peer", locked, "/slots", "", "203.0.113.1:5", 403},
|
|
{"a path that looks like an open route is still this route", locked, "/open/v1/models", "", "100.64.0.9:5", 403},
|
|
{"a header naming another route does not change the gate", locked, "/v1/models", "open", "100.64.0.9:5", 403},
|
|
{"admin-looking path is gated too (no admin on this listener)", locked, "/_crossbar/hosts", "", "100.64.0.9:5", 403},
|
|
{"open route, anyone", open, "/v1/models", "", "203.0.113.1:5", 204},
|
|
} {
|
|
t.Run(tc.name, func(t *testing.T) {
|
|
req := httptest.NewRequest(http.MethodGet, tc.path, nil)
|
|
req.RemoteAddr = tc.addr
|
|
if tc.hdr != "" {
|
|
req.Header.Set("X-Crossbar-Route", tc.hdr)
|
|
}
|
|
rec := httptest.NewRecorder()
|
|
tc.h.ServeHTTP(rec, req)
|
|
if rec.Code != tc.want {
|
|
t.Errorf("%s = %d, want %d (%s)", tc.path, rec.Code, tc.want, rec.Body.String())
|
|
}
|
|
})
|
|
}
|
|
}
|