|
1 | 1 | import * as assert from 'node:assert/strict'; |
2 | 2 | import { after, before, describe, it } from 'node:test'; |
3 | 3 | import nodejs from '../dist/index.js'; |
4 | | -import { loadFixture } from './test-utils.js'; |
| 4 | +import { createRequestAndResponse, loadFixture } from './test-utils.js'; |
5 | 5 |
|
6 | 6 | describe('test URIs beginning with a dot', () => { |
7 | 7 | /** @type {import('./test-utils').Fixture} */ |
@@ -43,4 +43,42 @@ describe('test URIs beginning with a dot', () => { |
43 | 43 | assert.equal(res.status, 404); |
44 | 44 | }); |
45 | 45 | }); |
| 46 | + |
| 47 | + describe('dotfile access via unnormalized paths', async () => { |
| 48 | + it('denies dotfile access when path contains .well-known/../ traversal', async () => { |
| 49 | + const { handler } = await import('./fixtures/well-known-locations/dist/server/entry.mjs'); |
| 50 | + const { req, res, done } = createRequestAndResponse({ |
| 51 | + method: 'GET', |
| 52 | + url: '/.well-known/../.hidden-file', |
| 53 | + }); |
| 54 | + |
| 55 | + handler(req, res); |
| 56 | + req.send(); |
| 57 | + |
| 58 | + await done; |
| 59 | + assert.notEqual( |
| 60 | + res.statusCode, |
| 61 | + 200, |
| 62 | + 'dotfile should not be served via .well-known path traversal', |
| 63 | + ); |
| 64 | + }); |
| 65 | + |
| 66 | + it('denies dotfolder file access when path contains .well-known/../ traversal', async () => { |
| 67 | + const { handler } = await import('./fixtures/well-known-locations/dist/server/entry.mjs'); |
| 68 | + const { req, res, done } = createRequestAndResponse({ |
| 69 | + method: 'GET', |
| 70 | + url: '/.well-known/../.hidden/file.json', |
| 71 | + }); |
| 72 | + |
| 73 | + handler(req, res); |
| 74 | + req.send(); |
| 75 | + |
| 76 | + await done; |
| 77 | + assert.notEqual( |
| 78 | + res.statusCode, |
| 79 | + 200, |
| 80 | + 'dotfolder file should not be served via .well-known path traversal', |
| 81 | + ); |
| 82 | + }); |
| 83 | + }); |
46 | 84 | }); |
0 commit comments