2020-09-08 13:56:45 +03:00
|
|
|
package dnsforward
|
|
|
|
|
|
|
|
import (
|
2022-10-24 16:29:44 +03:00
|
|
|
"net/netip"
|
2020-09-08 13:56:45 +03:00
|
|
|
"testing"
|
|
|
|
|
2023-02-27 16:48:32 +03:00
|
|
|
"github.com/AdguardTeam/urlfilter/rules"
|
|
|
|
"github.com/miekg/dns"
|
2020-09-08 13:56:45 +03:00
|
|
|
"github.com/stretchr/testify/assert"
|
2021-03-11 17:32:58 +03:00
|
|
|
"github.com/stretchr/testify/require"
|
2020-09-08 13:56:45 +03:00
|
|
|
)
|
|
|
|
|
2021-06-29 15:53:28 +03:00
|
|
|
func TestIsBlockedClientID(t *testing.T) {
|
|
|
|
clientID := "client-1"
|
|
|
|
clients := []string{clientID}
|
2021-03-11 17:32:58 +03:00
|
|
|
|
2021-06-29 15:53:28 +03:00
|
|
|
a, err := newAccessCtx(clients, nil, nil)
|
|
|
|
require.NoError(t, err)
|
2021-03-11 17:32:58 +03:00
|
|
|
|
2021-06-29 15:53:28 +03:00
|
|
|
assert.False(t, a.isBlockedClientID(clientID))
|
2021-03-11 17:32:58 +03:00
|
|
|
|
2021-06-29 15:53:28 +03:00
|
|
|
a, err = newAccessCtx(nil, clients, nil)
|
|
|
|
require.NoError(t, err)
|
2021-03-11 17:32:58 +03:00
|
|
|
|
2021-06-29 15:53:28 +03:00
|
|
|
assert.True(t, a.isBlockedClientID(clientID))
|
2020-09-08 13:56:45 +03:00
|
|
|
}
|
|
|
|
|
2021-06-29 15:53:28 +03:00
|
|
|
func TestIsBlockedHost(t *testing.T) {
|
|
|
|
a, err := newAccessCtx(nil, nil, []string{
|
2020-12-07 15:38:05 +03:00
|
|
|
"host1",
|
2020-09-08 13:56:45 +03:00
|
|
|
"*.host.com",
|
|
|
|
"||host3.com^",
|
2023-02-27 16:48:32 +03:00
|
|
|
"||*^$dnstype=HTTPS",
|
2021-04-20 16:26:19 +03:00
|
|
|
})
|
|
|
|
require.NoError(t, err)
|
2021-03-11 17:32:58 +03:00
|
|
|
|
|
|
|
testCases := []struct {
|
2023-02-27 16:48:32 +03:00
|
|
|
want assert.BoolAssertionFunc
|
2021-06-29 15:53:28 +03:00
|
|
|
name string
|
|
|
|
host string
|
2023-02-27 16:48:32 +03:00
|
|
|
qt rules.RRType
|
2021-03-11 17:32:58 +03:00
|
|
|
}{{
|
2023-02-27 16:48:32 +03:00
|
|
|
want: assert.True,
|
2021-06-29 15:53:28 +03:00
|
|
|
name: "plain_match",
|
|
|
|
host: "host1",
|
2023-02-27 16:48:32 +03:00
|
|
|
qt: dns.TypeA,
|
2021-03-11 17:32:58 +03:00
|
|
|
}, {
|
2023-02-27 16:48:32 +03:00
|
|
|
want: assert.False,
|
2021-06-29 15:53:28 +03:00
|
|
|
name: "plain_mismatch",
|
|
|
|
host: "host2",
|
2023-02-27 16:48:32 +03:00
|
|
|
qt: dns.TypeA,
|
2021-03-11 17:32:58 +03:00
|
|
|
}, {
|
2023-02-27 16:48:32 +03:00
|
|
|
want: assert.True,
|
2021-06-29 15:53:28 +03:00
|
|
|
name: "subdomain_match_short",
|
|
|
|
host: "asdf.host.com",
|
2023-02-27 16:48:32 +03:00
|
|
|
qt: dns.TypeA,
|
2021-03-11 17:32:58 +03:00
|
|
|
}, {
|
2023-02-27 16:48:32 +03:00
|
|
|
want: assert.True,
|
2021-06-29 15:53:28 +03:00
|
|
|
name: "subdomain_match_long",
|
|
|
|
host: "qwer.asdf.host.com",
|
2023-02-27 16:48:32 +03:00
|
|
|
qt: dns.TypeA,
|
2021-03-11 17:32:58 +03:00
|
|
|
}, {
|
2023-02-27 16:48:32 +03:00
|
|
|
want: assert.False,
|
2021-06-29 15:53:28 +03:00
|
|
|
name: "subdomain_mismatch_no_lead",
|
|
|
|
host: "host.com",
|
2023-02-27 16:48:32 +03:00
|
|
|
qt: dns.TypeA,
|
2021-03-11 17:32:58 +03:00
|
|
|
}, {
|
2023-02-27 16:48:32 +03:00
|
|
|
want: assert.False,
|
2021-06-29 15:53:28 +03:00
|
|
|
name: "subdomain_mismatch_bad_asterisk",
|
|
|
|
host: "asdf.zhost.com",
|
2023-02-27 16:48:32 +03:00
|
|
|
qt: dns.TypeA,
|
2021-03-11 17:32:58 +03:00
|
|
|
}, {
|
2023-02-27 16:48:32 +03:00
|
|
|
want: assert.True,
|
2021-06-29 15:53:28 +03:00
|
|
|
name: "rule_match_simple",
|
|
|
|
host: "host3.com",
|
2023-02-27 16:48:32 +03:00
|
|
|
qt: dns.TypeA,
|
2021-03-11 17:32:58 +03:00
|
|
|
}, {
|
2023-02-27 16:48:32 +03:00
|
|
|
want: assert.True,
|
2021-06-29 15:53:28 +03:00
|
|
|
name: "rule_match_complex",
|
|
|
|
host: "asdf.host3.com",
|
2023-02-27 16:48:32 +03:00
|
|
|
qt: dns.TypeA,
|
2021-03-11 17:32:58 +03:00
|
|
|
}, {
|
2023-02-27 16:48:32 +03:00
|
|
|
want: assert.False,
|
2021-06-29 15:53:28 +03:00
|
|
|
name: "rule_mismatch",
|
|
|
|
host: ".host3.com",
|
2023-02-27 16:48:32 +03:00
|
|
|
qt: dns.TypeA,
|
|
|
|
}, {
|
|
|
|
want: assert.True,
|
|
|
|
name: "by_qtype",
|
|
|
|
host: "site-with-https-record.example",
|
|
|
|
qt: dns.TypeHTTPS,
|
|
|
|
}, {
|
|
|
|
want: assert.False,
|
|
|
|
name: "by_qtype_other",
|
|
|
|
host: "site-with-https-record.example",
|
|
|
|
qt: dns.TypeA,
|
2021-03-11 17:32:58 +03:00
|
|
|
}}
|
|
|
|
|
|
|
|
for _, tc := range testCases {
|
|
|
|
t.Run(tc.name, func(t *testing.T) {
|
2023-02-27 16:48:32 +03:00
|
|
|
tc.want(t, a.isBlockedHost(tc.host, tc.qt))
|
2021-03-11 17:32:58 +03:00
|
|
|
})
|
|
|
|
}
|
2020-09-08 13:56:45 +03:00
|
|
|
}
|
2021-06-29 15:53:28 +03:00
|
|
|
|
|
|
|
func TestIsBlockedIP(t *testing.T) {
|
|
|
|
clients := []string{
|
|
|
|
"1.2.3.4",
|
|
|
|
"5.6.7.8/24",
|
|
|
|
}
|
|
|
|
|
|
|
|
allowCtx, err := newAccessCtx(clients, nil, nil)
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
|
|
|
blockCtx, err := newAccessCtx(nil, clients, nil)
|
|
|
|
require.NoError(t, err)
|
|
|
|
|
|
|
|
testCases := []struct {
|
2023-02-27 16:48:32 +03:00
|
|
|
ip netip.Addr
|
2021-06-29 15:53:28 +03:00
|
|
|
name string
|
|
|
|
wantRule string
|
|
|
|
wantBlocked bool
|
|
|
|
}{{
|
2023-02-27 16:48:32 +03:00
|
|
|
ip: netip.MustParseAddr("1.2.3.4"),
|
2021-06-29 15:53:28 +03:00
|
|
|
name: "match_ip",
|
|
|
|
wantRule: "1.2.3.4",
|
|
|
|
wantBlocked: true,
|
|
|
|
}, {
|
2023-02-27 16:48:32 +03:00
|
|
|
ip: netip.MustParseAddr("5.6.7.100"),
|
2021-06-29 15:53:28 +03:00
|
|
|
name: "match_cidr",
|
|
|
|
wantRule: "5.6.7.8/24",
|
|
|
|
wantBlocked: true,
|
|
|
|
}, {
|
2023-02-27 16:48:32 +03:00
|
|
|
ip: netip.MustParseAddr("9.2.3.4"),
|
2021-06-29 15:53:28 +03:00
|
|
|
name: "no_match_ip",
|
|
|
|
wantRule: "",
|
|
|
|
wantBlocked: false,
|
|
|
|
}, {
|
2023-02-27 16:48:32 +03:00
|
|
|
ip: netip.MustParseAddr("9.6.7.100"),
|
2021-06-29 15:53:28 +03:00
|
|
|
name: "no_match_cidr",
|
|
|
|
wantRule: "",
|
|
|
|
wantBlocked: false,
|
|
|
|
}}
|
|
|
|
|
|
|
|
t.Run("allow", func(t *testing.T) {
|
|
|
|
for _, tc := range testCases {
|
|
|
|
blocked, rule := allowCtx.isBlockedIP(tc.ip)
|
|
|
|
assert.Equal(t, !tc.wantBlocked, blocked)
|
|
|
|
assert.Equal(t, tc.wantRule, rule)
|
|
|
|
}
|
|
|
|
})
|
|
|
|
|
|
|
|
t.Run("block", func(t *testing.T) {
|
|
|
|
for _, tc := range testCases {
|
|
|
|
blocked, rule := blockCtx.isBlockedIP(tc.ip)
|
|
|
|
assert.Equal(t, tc.wantBlocked, blocked)
|
|
|
|
assert.Equal(t, tc.wantRule, rule)
|
|
|
|
}
|
|
|
|
})
|
|
|
|
}
|