mirror of
https://github.com/opencloud-eu/opencloud.git
synced 2026-10-07 11:21:56 -04:00
Limit body size on unauthenticated redeem endpoint
This commit is contained in:
1 parent
e8c78f496d
commit
934232e838
2 files changed
+17
No files matched your search
@@ -12,6 +12,10 @@ import (
|
||||
"github.com/opencloud-eu/opencloud/services/auth-guest/pkg/service/authguest"
|
||||
)
|
||||
|
||||
// maxRedeemBodySize limits the body of the unauthenticated redeem request. A
|
||||
// token is about 90 bytes, so this leaves plenty of room for the JSON wrapping.
|
||||
const maxRedeemBodySize = 4 << 10
|
||||
|
||||
// RedeemRequest is the request body for token redemption.
|
||||
type RedeemRequest struct {
|
||||
Token string `json:"token"`
|
||||
@@ -24,6 +28,8 @@ type redeemResponse struct {
|
||||
// RedeemHandler validates the token submitted to the redeem endpoint.
|
||||
func RedeemHandler(log log.Logger, s authguest.AuthGuest, cfg *config.Config) func(w http.ResponseWriter, r *http.Request) {
|
||||
return func(w http.ResponseWriter, r *http.Request) {
|
||||
r.Body = http.MaxBytesReader(w, r.Body, maxRedeemBodySize)
|
||||
|
||||
var req RedeemRequest
|
||||
if err := json.NewDecoder(r.Body).Decode(&req); err != nil {
|
||||
log.Debug().Err(err).Msg("request body is malformed")
|
||||
|
||||
@@ -123,6 +123,17 @@ func TestRedeemHandlerErrorMapping(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
func TestRedeemHandlerBodyTooLarge(t *testing.T) {
|
||||
svcMock := mocks.NewAuthGuest(t)
|
||||
|
||||
body := `{"token":"` + strings.Repeat("a", maxRedeemBodySize) + `"}`
|
||||
rr := httptest.NewRecorder()
|
||||
newRedeemHandler(t, svcMock)(rr, httptest.NewRequest(http.MethodPost, "/", strings.NewReader(body)))
|
||||
|
||||
assert.Equal(t, http.StatusBadRequest, rr.Code)
|
||||
svcMock.AssertNotCalled(t, "Redeem", mock.Anything, mock.Anything)
|
||||
}
|
||||
|
||||
func TestRedeemHandlerMalformedBody(t *testing.T) {
|
||||
svcMock := mocks.NewAuthGuest(t)
|
||||
|
||||
|
||||
Reference in new issue
Block a user