Remove dialLocal
This commit is contained in:
parent
84f6867cde
commit
75511e6fbe
4 changed files with 76 additions and 86 deletions
40
acl_test.go
40
acl_test.go
|
|
@ -12,11 +12,11 @@ test blacklist refused with correct status
|
||||||
*/
|
*/
|
||||||
|
|
||||||
func TestWhitelistAllowing(t *testing.T) {
|
func TestWhitelistAllowing(t *testing.T) {
|
||||||
const useTLS, dialLocal = true, true
|
const useTLS = true
|
||||||
for _, httpProxyVer := range testHTTPProxyVersions {
|
for _, httpProxyVer := range testHTTPProxyVersions {
|
||||||
for _, resource := range testResources {
|
for _, resource := range testResources {
|
||||||
response, err := getViaProxy(caddyTestTarget.addr, resource, caddyForwardProxyWhiteListing.addr, httpProxyVer,
|
response, err := getViaProxy(caddyTestTarget.addr, resource, caddyForwardProxyWhiteListing.addr, httpProxyVer,
|
||||||
"", useTLS, dialLocal)
|
"", useTLS)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
} else if err = responseExpected(response, caddyTestTarget.contents[resource]); err != nil {
|
} else if err = responseExpected(response, caddyTestTarget.contents[resource]); err != nil {
|
||||||
|
|
@ -27,11 +27,11 @@ func TestWhitelistAllowing(t *testing.T) {
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestWhitelistBlocking(t *testing.T) {
|
func TestWhitelistBlocking(t *testing.T) {
|
||||||
const useTLS, dialLocal = true, false
|
const useTLS = true
|
||||||
for _, httpProxyVer := range testHTTPProxyVersions {
|
for _, httpProxyVer := range testHTTPProxyVersions {
|
||||||
for _, resource := range testResources {
|
for _, resource := range testResources {
|
||||||
response, err := getViaProxy(caddyHTTPTestTarget.addr, resource, caddyForwardProxyWhiteListing.addr, httpProxyVer,
|
response, err := getViaProxy(caddyHTTPTestTarget.addr, resource, caddyForwardProxyWhiteListing.addr, httpProxyVer,
|
||||||
"", useTLS, dialLocal)
|
"", useTLS)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
} else if response.StatusCode != http.StatusForbidden {
|
} else if response.StatusCode != http.StatusForbidden {
|
||||||
|
|
@ -43,7 +43,7 @@ func TestWhitelistBlocking(t *testing.T) {
|
||||||
for _, httpProxyVer := range testHTTPProxyVersions {
|
for _, httpProxyVer := range testHTTPProxyVersions {
|
||||||
for _, resource := range testResources {
|
for _, resource := range testResources {
|
||||||
response, err := getViaProxy("google.com:6451", resource, caddyForwardProxyWhiteListing.addr, httpProxyVer,
|
response, err := getViaProxy("google.com:6451", resource, caddyForwardProxyWhiteListing.addr, httpProxyVer,
|
||||||
"", useTLS, dialLocal)
|
"", useTLS)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
} else if response.StatusCode != http.StatusForbidden {
|
} else if response.StatusCode != http.StatusForbidden {
|
||||||
|
|
@ -54,11 +54,11 @@ func TestWhitelistBlocking(t *testing.T) {
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestLocalhostDefaultForbidden(t *testing.T) {
|
func TestLocalhostDefaultForbidden(t *testing.T) {
|
||||||
const useTLS, dialLocal = true, false
|
const useTLS = true
|
||||||
for _, httpProxyVer := range testHTTPProxyVersions {
|
for _, httpProxyVer := range testHTTPProxyVersions {
|
||||||
for _, resource := range testResources {
|
for _, resource := range testResources {
|
||||||
response, err := getViaProxy("localhost:6451", resource, caddyForwardProxyNoBlacklistOverride.addr, httpProxyVer,
|
response, err := getViaProxy("localhost:6451", resource, caddyForwardProxyNoBlacklistOverride.addr, httpProxyVer,
|
||||||
"", useTLS, dialLocal)
|
"", useTLS)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
} else if response.StatusCode != http.StatusForbidden {
|
} else if response.StatusCode != http.StatusForbidden {
|
||||||
|
|
@ -70,7 +70,7 @@ func TestLocalhostDefaultForbidden(t *testing.T) {
|
||||||
for _, httpProxyVer := range testHTTPProxyVersions {
|
for _, httpProxyVer := range testHTTPProxyVersions {
|
||||||
for _, resource := range testResources {
|
for _, resource := range testResources {
|
||||||
response, err := getViaProxy("127.0.0.1:808", resource, caddyForwardProxyNoBlacklistOverride.addr, httpProxyVer,
|
response, err := getViaProxy("127.0.0.1:808", resource, caddyForwardProxyNoBlacklistOverride.addr, httpProxyVer,
|
||||||
"", useTLS, dialLocal)
|
"", useTLS)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
} else if response.StatusCode != http.StatusForbidden {
|
} else if response.StatusCode != http.StatusForbidden {
|
||||||
|
|
@ -82,7 +82,7 @@ func TestLocalhostDefaultForbidden(t *testing.T) {
|
||||||
for _, httpProxyVer := range testHTTPProxyVersions {
|
for _, httpProxyVer := range testHTTPProxyVersions {
|
||||||
for _, resource := range testResources {
|
for _, resource := range testResources {
|
||||||
response, err := getViaProxy("[::1]:8080", resource, caddyForwardProxyNoBlacklistOverride.addr, httpProxyVer,
|
response, err := getViaProxy("[::1]:8080", resource, caddyForwardProxyNoBlacklistOverride.addr, httpProxyVer,
|
||||||
"", useTLS, dialLocal)
|
"", useTLS)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
} else if response.StatusCode != http.StatusForbidden {
|
} else if response.StatusCode != http.StatusForbidden {
|
||||||
|
|
@ -93,11 +93,11 @@ func TestLocalhostDefaultForbidden(t *testing.T) {
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestLocalNetworksDefaultForbidden(t *testing.T) {
|
func TestLocalNetworksDefaultForbidden(t *testing.T) {
|
||||||
const useTLS, dialLocal = true, false
|
const useTLS = true
|
||||||
for _, httpProxyVer := range testHTTPProxyVersions {
|
for _, httpProxyVer := range testHTTPProxyVersions {
|
||||||
for _, resource := range testResources {
|
for _, resource := range testResources {
|
||||||
response, err := getViaProxy("10.0.0.0:80", resource, caddyForwardProxyNoBlacklistOverride.addr, httpProxyVer,
|
response, err := getViaProxy("10.0.0.0:80", resource, caddyForwardProxyNoBlacklistOverride.addr, httpProxyVer,
|
||||||
"", useTLS, dialLocal)
|
"", useTLS)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
} else if response.StatusCode != http.StatusForbidden {
|
} else if response.StatusCode != http.StatusForbidden {
|
||||||
|
|
@ -109,7 +109,7 @@ func TestLocalNetworksDefaultForbidden(t *testing.T) {
|
||||||
for _, httpProxyVer := range testHTTPProxyVersions {
|
for _, httpProxyVer := range testHTTPProxyVersions {
|
||||||
for _, resource := range testResources {
|
for _, resource := range testResources {
|
||||||
response, err := getViaProxy("127.222.34.1:443", resource, caddyForwardProxyNoBlacklistOverride.addr, httpProxyVer,
|
response, err := getViaProxy("127.222.34.1:443", resource, caddyForwardProxyNoBlacklistOverride.addr, httpProxyVer,
|
||||||
"", useTLS, dialLocal)
|
"", useTLS)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
} else if response.StatusCode != http.StatusForbidden {
|
} else if response.StatusCode != http.StatusForbidden {
|
||||||
|
|
@ -121,7 +121,7 @@ func TestLocalNetworksDefaultForbidden(t *testing.T) {
|
||||||
for _, httpProxyVer := range testHTTPProxyVersions {
|
for _, httpProxyVer := range testHTTPProxyVersions {
|
||||||
for _, resource := range testResources {
|
for _, resource := range testResources {
|
||||||
response, err := getViaProxy("172.16.0.1:8080", resource, caddyForwardProxyNoBlacklistOverride.addr, httpProxyVer,
|
response, err := getViaProxy("172.16.0.1:8080", resource, caddyForwardProxyNoBlacklistOverride.addr, httpProxyVer,
|
||||||
"", useTLS, dialLocal)
|
"", useTLS)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
} else if response.StatusCode != http.StatusForbidden {
|
} else if response.StatusCode != http.StatusForbidden {
|
||||||
|
|
@ -133,7 +133,7 @@ func TestLocalNetworksDefaultForbidden(t *testing.T) {
|
||||||
for _, httpProxyVer := range testHTTPProxyVersions {
|
for _, httpProxyVer := range testHTTPProxyVersions {
|
||||||
for _, resource := range testResources {
|
for _, resource := range testResources {
|
||||||
response, err := getViaProxy("192.168.192.168:888", resource, caddyForwardProxyNoBlacklistOverride.addr, httpProxyVer,
|
response, err := getViaProxy("192.168.192.168:888", resource, caddyForwardProxyNoBlacklistOverride.addr, httpProxyVer,
|
||||||
"", useTLS, dialLocal)
|
"", useTLS)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
} else if response.StatusCode != http.StatusForbidden {
|
} else if response.StatusCode != http.StatusForbidden {
|
||||||
|
|
@ -144,11 +144,11 @@ func TestLocalNetworksDefaultForbidden(t *testing.T) {
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestBlacklistBlocking(t *testing.T) {
|
func TestBlacklistBlocking(t *testing.T) {
|
||||||
const useTLS, dialLocal = true, false
|
const useTLS = true
|
||||||
for _, httpProxyVer := range testHTTPProxyVersions {
|
for _, httpProxyVer := range testHTTPProxyVersions {
|
||||||
for _, resource := range testResources {
|
for _, resource := range testResources {
|
||||||
response, err := getViaProxy(blacklistedDomain, resource, caddyForwardProxyBlackListing.addr, httpProxyVer,
|
response, err := getViaProxy(blacklistedDomain, resource, caddyForwardProxyBlackListing.addr, httpProxyVer,
|
||||||
"", useTLS, dialLocal)
|
"", useTLS)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
} else if response.StatusCode != http.StatusForbidden {
|
} else if response.StatusCode != http.StatusForbidden {
|
||||||
|
|
@ -160,7 +160,7 @@ func TestBlacklistBlocking(t *testing.T) {
|
||||||
for _, httpProxyVer := range testHTTPProxyVersions {
|
for _, httpProxyVer := range testHTTPProxyVersions {
|
||||||
for _, resource := range testResources {
|
for _, resource := range testResources {
|
||||||
response, err := getViaProxy(blacklistedIPv4, resource, caddyForwardProxyBlackListing.addr, httpProxyVer,
|
response, err := getViaProxy(blacklistedIPv4, resource, caddyForwardProxyBlackListing.addr, httpProxyVer,
|
||||||
"", useTLS, dialLocal)
|
"", useTLS)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
} else if response.StatusCode != http.StatusForbidden {
|
} else if response.StatusCode != http.StatusForbidden {
|
||||||
|
|
@ -172,7 +172,7 @@ func TestBlacklistBlocking(t *testing.T) {
|
||||||
for _, httpProxyVer := range testHTTPProxyVersions {
|
for _, httpProxyVer := range testHTTPProxyVersions {
|
||||||
for _, resource := range testResources {
|
for _, resource := range testResources {
|
||||||
response, err := getViaProxy("["+blacklistedIPv6+"]:80", resource, caddyForwardProxyBlackListing.addr, httpProxyVer,
|
response, err := getViaProxy("["+blacklistedIPv6+"]:80", resource, caddyForwardProxyBlackListing.addr, httpProxyVer,
|
||||||
"", useTLS, dialLocal)
|
"", useTLS)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
} else if response.StatusCode != http.StatusForbidden {
|
} else if response.StatusCode != http.StatusForbidden {
|
||||||
|
|
@ -183,11 +183,11 @@ func TestBlacklistBlocking(t *testing.T) {
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestBlacklistAllowing(t *testing.T) {
|
func TestBlacklistAllowing(t *testing.T) {
|
||||||
const useTLS, dialLocal = true, true
|
const useTLS = true
|
||||||
for _, httpProxyVer := range testHTTPProxyVersions {
|
for _, httpProxyVer := range testHTTPProxyVersions {
|
||||||
for _, resource := range testResources {
|
for _, resource := range testResources {
|
||||||
response, err := getViaProxy(caddyTestTarget.addr, resource, caddyForwardProxyBlackListing.addr, httpProxyVer,
|
response, err := getViaProxy(caddyTestTarget.addr, resource, caddyForwardProxyBlackListing.addr, httpProxyVer,
|
||||||
"", useTLS, dialLocal)
|
"", useTLS)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
} else if err = responseExpected(response, caddyTestTarget.contents[resource]); err != nil {
|
} else if err = responseExpected(response, caddyTestTarget.contents[resource]); err != nil {
|
||||||
|
|
|
||||||
|
|
@ -52,16 +52,16 @@ func dial(proxyAddr, httpProxyVer string, useTLS bool) (net.Conn, error) {
|
||||||
return net.Dial("tcp", dialAddr)
|
return net.Dial("tcp", dialAddr)
|
||||||
}
|
}
|
||||||
|
|
||||||
func getViaProxy(targetHost, resource, proxyAddr, httpProxyVer, proxyCredentials string, useTLS, dialLocal bool) (*http.Response, error) {
|
func getViaProxy(targetHost, resource, proxyAddr, httpProxyVer, proxyCredentials string, useTLS bool) (*http.Response, error) {
|
||||||
proxyConn, err := dial(proxyAddr, httpProxyVer, useTLS)
|
proxyConn, err := dial(proxyAddr, httpProxyVer, useTLS)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
return getResourceViaProxyConn(proxyConn, targetHost, resource, httpProxyVer, proxyCredentials, dialLocal)
|
return getResourceViaProxyConn(proxyConn, targetHost, resource, httpProxyVer, proxyCredentials)
|
||||||
}
|
}
|
||||||
|
|
||||||
// if connect is not successful - that response is returned, otherwise the requested resource
|
// if connect is not successful - that response is returned, otherwise the requested resource
|
||||||
func connectAndGetViaProxy(targetHost, resource, proxyAddr, httpTargetVer, proxyCredentials, httpProxyVer string, useTLS, dialLocal bool) (*http.Response, error) {
|
func connectAndGetViaProxy(targetHost, resource, proxyAddr, httpTargetVer, proxyCredentials, httpProxyVer string, useTLS bool) (*http.Response, error) {
|
||||||
proxyConn, err := dial(proxyAddr, httpProxyVer, useTLS)
|
proxyConn, err := dial(proxyAddr, httpProxyVer, useTLS)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
|
|
@ -71,11 +71,7 @@ func connectAndGetViaProxy(targetHost, resource, proxyAddr, httpTargetVer, proxy
|
||||||
if len(proxyCredentials) > 0 {
|
if len(proxyCredentials) > 0 {
|
||||||
req.Header.Set("Proxy-Authorization", proxyCredentials)
|
req.Header.Set("Proxy-Authorization", proxyCredentials)
|
||||||
}
|
}
|
||||||
if dialLocal {
|
req.Host = targetHost
|
||||||
req.Host = localDialAddr(targetHost)
|
|
||||||
} else {
|
|
||||||
req.Host = targetHost
|
|
||||||
}
|
|
||||||
req.URL, err = url.Parse("https://" + req.Host + "/") // TODO: appending "/" causes file server to NOT issue redirect...
|
req.URL, err = url.Parse("https://" + req.Host + "/") // TODO: appending "/" causes file server to NOT issue redirect...
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
|
|
@ -120,21 +116,17 @@ func connectAndGetViaProxy(targetHost, resource, proxyAddr, httpTargetVer, proxy
|
||||||
return resp, err
|
return resp, err
|
||||||
}
|
}
|
||||||
|
|
||||||
return getResourceViaProxyConn(proxyConn, targetHost, resource, httpTargetVer, proxyCredentials, dialLocal)
|
return getResourceViaProxyConn(proxyConn, targetHost, resource, httpTargetVer, proxyCredentials)
|
||||||
}
|
}
|
||||||
|
|
||||||
func getResourceViaProxyConn(proxyConn net.Conn, targetHost, resource, httpTargetVer, proxyCredentials string, dialLocal bool) (*http.Response, error) {
|
func getResourceViaProxyConn(proxyConn net.Conn, targetHost, resource, httpTargetVer, proxyCredentials string) (*http.Response, error) {
|
||||||
var err error
|
var err error
|
||||||
|
|
||||||
req := &http.Request{Header: make(http.Header)}
|
req := &http.Request{Header: make(http.Header)}
|
||||||
if len(proxyCredentials) > 0 {
|
if len(proxyCredentials) > 0 {
|
||||||
req.Header.Set("Proxy-Authorization", proxyCredentials)
|
req.Header.Set("Proxy-Authorization", proxyCredentials)
|
||||||
}
|
}
|
||||||
if dialLocal {
|
req.Host = targetHost
|
||||||
req.Host = localDialAddr(targetHost)
|
|
||||||
} else {
|
|
||||||
req.Host = targetHost
|
|
||||||
}
|
|
||||||
req.URL, err = url.Parse("http://" + targetHost + resource)
|
req.URL, err = url.Parse("http://" + targetHost + resource)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
|
|
@ -223,10 +215,10 @@ func TestPassthrough(t *testing.T) {
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestGETNoAuth(t *testing.T) {
|
func TestGETNoAuth(t *testing.T) {
|
||||||
const useTLS, dialLocal = true, false
|
const useTLS = true
|
||||||
for _, httpProxyVer := range testHTTPProxyVersions {
|
for _, httpProxyVer := range testHTTPProxyVersions {
|
||||||
for _, resource := range testResources {
|
for _, resource := range testResources {
|
||||||
response, err := getViaProxy(caddyHTTPTestTarget.addr, resource, caddyForwardProxy.addr, httpProxyVer, credentialsEmpty, useTLS, dialLocal)
|
response, err := getViaProxy(caddyHTTPTestTarget.addr, resource, caddyForwardProxy.addr, httpProxyVer, credentialsEmpty, useTLS)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
} else if err = responseExpected(response, caddyHTTPTestTarget.contents[resource]); err != nil {
|
} else if err = responseExpected(response, caddyHTTPTestTarget.contents[resource]); err != nil {
|
||||||
|
|
@ -237,10 +229,10 @@ func TestGETNoAuth(t *testing.T) {
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestGETAuthCorrect(t *testing.T) {
|
func TestGETAuthCorrect(t *testing.T) {
|
||||||
const useTLS, dialLocal = true, false
|
const useTLS = true
|
||||||
for _, httpProxyVer := range testHTTPProxyVersions {
|
for _, httpProxyVer := range testHTTPProxyVersions {
|
||||||
for _, resource := range testResources {
|
for _, resource := range testResources {
|
||||||
response, err := getViaProxy(caddyHTTPTestTarget.addr, resource, caddyForwardProxyAuth.addr, httpProxyVer, credentialsCorrect, useTLS, dialLocal)
|
response, err := getViaProxy(caddyHTTPTestTarget.addr, resource, caddyForwardProxyAuth.addr, httpProxyVer, credentialsCorrect, useTLS)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
} else if err = responseExpected(response, caddyHTTPTestTarget.contents[resource]); err != nil {
|
} else if err = responseExpected(response, caddyHTTPTestTarget.contents[resource]); err != nil {
|
||||||
|
|
@ -251,11 +243,11 @@ func TestGETAuthCorrect(t *testing.T) {
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestGETAuthWrong(t *testing.T) {
|
func TestGETAuthWrong(t *testing.T) {
|
||||||
const useTLS, dialLocal = true, false
|
const useTLS = true
|
||||||
for _, wrongCreds := range credentialsWrong {
|
for _, wrongCreds := range credentialsWrong {
|
||||||
for _, httpProxyVer := range testHTTPProxyVersions {
|
for _, httpProxyVer := range testHTTPProxyVersions {
|
||||||
for _, resource := range testResources {
|
for _, resource := range testResources {
|
||||||
response, err := getViaProxy(caddyHTTPTestTarget.addr, resource, caddyForwardProxyAuth.addr, httpProxyVer, wrongCreds, useTLS, dialLocal)
|
response, err := getViaProxy(caddyHTTPTestTarget.addr, resource, caddyForwardProxyAuth.addr, httpProxyVer, wrongCreds, useTLS)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
|
|
@ -269,11 +261,11 @@ func TestGETAuthWrong(t *testing.T) {
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestProxySelfGet(t *testing.T) {
|
func TestProxySelfGet(t *testing.T) {
|
||||||
const useTLS, dialLocal = true, false
|
const useTLS = true
|
||||||
// GETNoAuth to self
|
// GETNoAuth to self
|
||||||
for _, httpTargetVer := range testHTTPTargetVersions {
|
for _, httpTargetVer := range testHTTPTargetVersions {
|
||||||
for _, resource := range testResources {
|
for _, resource := range testResources {
|
||||||
response, err := getViaProxy(caddyForwardProxy.addr, resource, caddyForwardProxy.addr, httpTargetVer, credentialsEmpty, useTLS, dialLocal)
|
response, err := getViaProxy(caddyForwardProxy.addr, resource, caddyForwardProxy.addr, httpTargetVer, credentialsEmpty, useTLS)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
} else if err = responseExpected(response, caddyForwardProxy.contents[resource]); err != nil {
|
} else if err = responseExpected(response, caddyForwardProxy.contents[resource]); err != nil {
|
||||||
|
|
@ -285,7 +277,7 @@ func TestProxySelfGet(t *testing.T) {
|
||||||
// GETAuthCorrect to self
|
// GETAuthCorrect to self
|
||||||
for _, httpTargetVer := range testHTTPTargetVersions {
|
for _, httpTargetVer := range testHTTPTargetVersions {
|
||||||
for _, resource := range testResources {
|
for _, resource := range testResources {
|
||||||
response, err := getViaProxy(caddyForwardProxyAuth.addr, resource, caddyForwardProxyAuth.addr, httpTargetVer, credentialsCorrect, useTLS, dialLocal)
|
response, err := getViaProxy(caddyForwardProxyAuth.addr, resource, caddyForwardProxyAuth.addr, httpTargetVer, credentialsCorrect, useTLS)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
} else if err = responseExpected(response, caddyForwardProxyAuth.contents[resource]); err != nil {
|
} else if err = responseExpected(response, caddyForwardProxyAuth.contents[resource]); err != nil {
|
||||||
|
|
@ -300,11 +292,11 @@ func TestProxySelfGet(t *testing.T) {
|
||||||
// Low priority since this is a functionality issue, not security, and it would be easily caught in the wild.
|
// Low priority since this is a functionality issue, not security, and it would be easily caught in the wild.
|
||||||
|
|
||||||
func TestConnectNoAuth(t *testing.T) {
|
func TestConnectNoAuth(t *testing.T) {
|
||||||
const useTLS, dialLocal = true, true
|
const useTLS = true
|
||||||
for _, httpProxyVer := range testHTTPProxyVersions {
|
for _, httpProxyVer := range testHTTPProxyVersions {
|
||||||
for _, httpTargetVer := range testHTTPTargetVersions {
|
for _, httpTargetVer := range testHTTPTargetVersions {
|
||||||
for _, resource := range testResources {
|
for _, resource := range testResources {
|
||||||
response, err := connectAndGetViaProxy(caddyTestTarget.addr, resource, caddyForwardProxy.addr, httpTargetVer, credentialsEmpty, httpProxyVer, useTLS, dialLocal)
|
response, err := connectAndGetViaProxy(caddyTestTarget.addr, resource, caddyForwardProxy.addr, httpTargetVer, credentialsEmpty, httpProxyVer, useTLS)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
} else if err = responseExpected(response, caddyTestTarget.contents[resource]); err != nil {
|
} else if err = responseExpected(response, caddyTestTarget.contents[resource]); err != nil {
|
||||||
|
|
@ -316,11 +308,11 @@ func TestConnectNoAuth(t *testing.T) {
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestConnectAuthCorrect(t *testing.T) {
|
func TestConnectAuthCorrect(t *testing.T) {
|
||||||
const useTLS, dialLocal = true, true
|
const useTLS = true
|
||||||
for _, httpProxyVer := range testHTTPProxyVersions {
|
for _, httpProxyVer := range testHTTPProxyVersions {
|
||||||
for _, httpTargetVer := range testHTTPTargetVersions {
|
for _, httpTargetVer := range testHTTPTargetVersions {
|
||||||
for _, resource := range testResources {
|
for _, resource := range testResources {
|
||||||
response, err := connectAndGetViaProxy(caddyTestTarget.addr, resource, caddyForwardProxyAuth.addr, httpTargetVer, credentialsCorrect, httpProxyVer, useTLS, dialLocal)
|
response, err := connectAndGetViaProxy(caddyTestTarget.addr, resource, caddyForwardProxyAuth.addr, httpTargetVer, credentialsCorrect, httpProxyVer, useTLS)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(httpProxyVer, httpTargetVer, err)
|
t.Fatal(httpProxyVer, httpTargetVer, err)
|
||||||
} else if err = responseExpected(response, caddyTestTarget.contents[resource]); err != nil {
|
} else if err = responseExpected(response, caddyTestTarget.contents[resource]); err != nil {
|
||||||
|
|
@ -332,12 +324,12 @@ func TestConnectAuthCorrect(t *testing.T) {
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestConnectAuthWrong(t *testing.T) {
|
func TestConnectAuthWrong(t *testing.T) {
|
||||||
const useTLS, dialLocal = true, false
|
const useTLS = true
|
||||||
for _, wrongCreds := range credentialsWrong {
|
for _, wrongCreds := range credentialsWrong {
|
||||||
for _, httpProxyVer := range testHTTPProxyVersions {
|
for _, httpProxyVer := range testHTTPProxyVersions {
|
||||||
for _, httpTargetVer := range testHTTPTargetVersions {
|
for _, httpTargetVer := range testHTTPTargetVersions {
|
||||||
for _, resource := range testResources {
|
for _, resource := range testResources {
|
||||||
response, err := connectAndGetViaProxy(caddyTestTarget.addr, resource, caddyForwardProxyAuth.addr, httpTargetVer, wrongCreds, httpProxyVer, useTLS, dialLocal)
|
response, err := connectAndGetViaProxy(caddyTestTarget.addr, resource, caddyForwardProxyAuth.addr, httpTargetVer, wrongCreds, httpProxyVer, useTLS)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
|
|
@ -371,13 +363,13 @@ func TestPAC(t *testing.T) {
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestCONNECTViaUpstream(t *testing.T) {
|
func TestCONNECTViaUpstream(t *testing.T) {
|
||||||
const useTLS, dialLocal = true, true
|
const useTLS = true
|
||||||
for range make([]byte, 5) { // do several times to test http2 connection reuse
|
for range make([]byte, 5) { // do several times to test http2 connection reuse
|
||||||
for _, httpProxyVer := range testHTTPProxyVersions {
|
for _, httpProxyVer := range testHTTPProxyVersions {
|
||||||
for _, httpTargetVer := range testHTTPTargetVersions {
|
for _, httpTargetVer := range testHTTPTargetVersions {
|
||||||
for _, resource := range testResources {
|
for _, resource := range testResources {
|
||||||
response, err := connectAndGetViaProxy(caddyTestTarget.addr, resource, caddyAuthedUpstreamEnter.addr,
|
response, err := connectAndGetViaProxy(caddyTestTarget.addr, resource, caddyAuthedUpstreamEnter.addr,
|
||||||
httpTargetVer, credentialsUpstreamCorrect, httpProxyVer, useTLS, dialLocal)
|
httpTargetVer, credentialsUpstreamCorrect, httpProxyVer, useTLS)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
} else if err = responseExpected(response, caddyTestTarget.contents[resource]); err != nil {
|
} else if err = responseExpected(response, caddyTestTarget.contents[resource]); err != nil {
|
||||||
|
|
@ -390,12 +382,12 @@ func TestCONNECTViaUpstream(t *testing.T) {
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestGETViaUpstream(t *testing.T) {
|
func TestGETViaUpstream(t *testing.T) {
|
||||||
const useTLS, dialLocal = true, true
|
const useTLS = true
|
||||||
for range make([]byte, 5) { // do several times to test http2 connection reuse
|
for range make([]byte, 5) { // do several times to test http2 connection reuse
|
||||||
for _, httpProxyVer := range testHTTPProxyVersions {
|
for _, httpProxyVer := range testHTTPProxyVersions {
|
||||||
for _, resource := range testResources {
|
for _, resource := range testResources {
|
||||||
response, err := getViaProxy(caddyHTTPTestTarget.addr, resource, caddyAuthedUpstreamEnter.addr, httpProxyVer,
|
response, err := getViaProxy(caddyHTTPTestTarget.addr, resource, caddyAuthedUpstreamEnter.addr, httpProxyVer,
|
||||||
credentialsUpstreamCorrect, useTLS, dialLocal)
|
credentialsUpstreamCorrect, useTLS)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
} else if err = responseExpected(response, caddyHTTPTestTarget.contents[resource]); err != nil {
|
} else if err = responseExpected(response, caddyHTTPTestTarget.contents[resource]); err != nil {
|
||||||
|
|
|
||||||
|
|
@ -13,7 +13,6 @@ import (
|
||||||
)
|
)
|
||||||
|
|
||||||
func TestHttpClient(t *testing.T) {
|
func TestHttpClient(t *testing.T) {
|
||||||
const dialLocal = false
|
|
||||||
_test := func(urlSchemeAndCreds, urlAddress string) {
|
_test := func(urlSchemeAndCreds, urlAddress string) {
|
||||||
for _, httpProxyVer := range testHTTPProxyVersions {
|
for _, httpProxyVer := range testHTTPProxyVersions {
|
||||||
for _, httpTargetVer := range testHTTPTargetVersions {
|
for _, httpTargetVer := range testHTTPTargetVersions {
|
||||||
|
|
@ -42,7 +41,7 @@ func TestHttpClient(t *testing.T) {
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
response, err := getResourceViaProxyConn(conn, caddyTestTarget.addr, resource, httpTargetVer, credentialsCorrect, dialLocal)
|
response, err := getResourceViaProxyConn(conn, caddyTestTarget.addr, resource, httpTargetVer, credentialsCorrect)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(httpProxyVer, httpTargetVer, err)
|
t.Fatal(httpProxyVer, httpTargetVer, err)
|
||||||
} else if err = responseExpected(response, caddyTestTarget.contents[resource]); err != nil {
|
} else if err = responseExpected(response, caddyTestTarget.contents[resource]); err != nil {
|
||||||
|
|
@ -62,7 +61,6 @@ func TestHttpClientH2Multiplexing(t *testing.T) {
|
||||||
// but it was manually inspected in Wireshark when this code was committed
|
// but it was manually inspected in Wireshark when this code was committed
|
||||||
httpProxyVer := "HTTP/2.0"
|
httpProxyVer := "HTTP/2.0"
|
||||||
httpTargetVer := "HTTP/1.1"
|
httpTargetVer := "HTTP/1.1"
|
||||||
const dialLocal = false
|
|
||||||
|
|
||||||
dialer, err := httpclient.NewHTTPConnectDialer("https://" + credentialsCorrectPlain + "@" + caddyForwardProxyAuth.addr)
|
dialer, err := httpclient.NewHTTPConnectDialer("https://" + credentialsCorrectPlain + "@" + caddyForwardProxyAuth.addr)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
|
|
@ -93,7 +91,7 @@ func TestHttpClientH2Multiplexing(t *testing.T) {
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
response, err := getResourceViaProxyConn(conn, caddyTestTarget.addr, resource, httpTargetVer, credentialsCorrect, dialLocal)
|
response, err := getResourceViaProxyConn(conn, caddyTestTarget.addr, resource, httpTargetVer, credentialsCorrect)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(httpProxyVer, httpTargetVer, err)
|
t.Fatal(httpProxyVer, httpTargetVer, err)
|
||||||
} else if err = responseExpected(response, caddyTestTarget.contents[resource]); err != nil {
|
} else if err = responseExpected(response, caddyTestTarget.contents[resource]); err != nil {
|
||||||
|
|
|
||||||
|
|
@ -12,10 +12,10 @@ import (
|
||||||
)
|
)
|
||||||
|
|
||||||
func TestGETAuthCorrectProbeResist(t *testing.T) {
|
func TestGETAuthCorrectProbeResist(t *testing.T) {
|
||||||
const useTLS, dialLocal = true, true
|
const useTLS = true
|
||||||
for _, httpProxyVer := range testHTTPProxyVersions {
|
for _, httpProxyVer := range testHTTPProxyVersions {
|
||||||
for _, resource := range testResources {
|
for _, resource := range testResources {
|
||||||
response, err := getViaProxy(caddyTestTarget.addr, resource, caddyForwardProxyProbeResist.addr, httpProxyVer, credentialsCorrect, useTLS, dialLocal)
|
response, err := getViaProxy(caddyTestTarget.addr, resource, caddyForwardProxyProbeResist.addr, httpProxyVer, credentialsCorrect, useTLS)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
} else if err = responseExpected(response, caddyTestTarget.contents[resource]); err != nil {
|
} else if err = responseExpected(response, caddyTestTarget.contents[resource]); err != nil {
|
||||||
|
|
@ -26,21 +26,21 @@ func TestGETAuthCorrectProbeResist(t *testing.T) {
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestGETAuthWrongProbeResist(t *testing.T) {
|
func TestGETAuthWrongProbeResist(t *testing.T) {
|
||||||
const useTLS, dialLocal = true, false
|
const useTLS = true
|
||||||
for _, wrongCreds := range credentialsWrong {
|
for _, wrongCreds := range credentialsWrong {
|
||||||
for _, httpProxyVer := range testHTTPProxyVersions {
|
for _, httpProxyVer := range testHTTPProxyVersions {
|
||||||
for _, resource := range testResources {
|
for _, resource := range testResources {
|
||||||
responseProbeResist, err := getViaProxy(caddyTestTarget.addr, resource, caddyForwardProxyProbeResist.addr, httpProxyVer, wrongCreds, useTLS, dialLocal)
|
responseProbeResist, err := getViaProxy(caddyTestTarget.addr, resource, caddyForwardProxyProbeResist.addr, httpProxyVer, wrongCreds, useTLS)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
// get response from reference server without forwardproxy and compare them
|
// get response from reference server without forwardproxy and compare them
|
||||||
responseReference, err := getViaProxy(caddyTestTarget.addr, resource, caddyDummyProbeResist.addr, httpProxyVer, wrongCreds, useTLS, dialLocal)
|
responseReference, err := getViaProxy(caddyTestTarget.addr, resource, caddyDummyProbeResist.addr, httpProxyVer, wrongCreds, useTLS)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
// as a sanity check, get 407 from simple authenticated forwardproxy
|
// as a sanity check, get 407 from simple authenticated forwardproxy
|
||||||
responseForwardProxy, err := getViaProxy(caddyTestTarget.addr, resource, caddyForwardProxyAuth.addr, httpProxyVer, wrongCreds, useTLS, dialLocal)
|
responseForwardProxy, err := getViaProxy(caddyTestTarget.addr, resource, caddyForwardProxyAuth.addr, httpProxyVer, wrongCreds, useTLS)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
|
|
@ -58,17 +58,17 @@ func TestGETAuthWrongProbeResist(t *testing.T) {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
for _, resource := range testResources {
|
for _, resource := range testResources {
|
||||||
responseProbeResist, err := getViaProxy(caddyForwardProxyProbeResist.addr, resource, caddyForwardProxyProbeResist.addr, httpProxyVer, wrongCreds, useTLS, dialLocal)
|
responseProbeResist, err := getViaProxy(caddyForwardProxyProbeResist.addr, resource, caddyForwardProxyProbeResist.addr, httpProxyVer, wrongCreds, useTLS)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
// get response from reference server without forwardproxy and compare them
|
// get response from reference server without forwardproxy and compare them
|
||||||
responseReference, err := getViaProxy(caddyDummyProbeResist.addr, resource, caddyDummyProbeResist.addr, httpProxyVer, wrongCreds, useTLS, dialLocal)
|
responseReference, err := getViaProxy(caddyDummyProbeResist.addr, resource, caddyDummyProbeResist.addr, httpProxyVer, wrongCreds, useTLS)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
// as a sanity check, get 407 from simple authenticated forwardproxy
|
// as a sanity check, get 407 from simple authenticated forwardproxy
|
||||||
responseForwardProxy, err := getViaProxy(caddyForwardProxyAuth.addr, resource, caddyForwardProxyAuth.addr, httpProxyVer, wrongCreds, useTLS, dialLocal)
|
responseForwardProxy, err := getViaProxy(caddyForwardProxyAuth.addr, resource, caddyForwardProxyAuth.addr, httpProxyVer, wrongCreds, useTLS)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
|
|
@ -91,14 +91,14 @@ func TestGETAuthWrongProbeResist(t *testing.T) {
|
||||||
|
|
||||||
// test that responses on http redirect port are same
|
// test that responses on http redirect port are same
|
||||||
func TestGETAuthWrongProbeResistRedir(t *testing.T) {
|
func TestGETAuthWrongProbeResistRedir(t *testing.T) {
|
||||||
const useTLS, dialLocal = false, false
|
const useTLS = false
|
||||||
httpProxyVer := "HTTP/1.1"
|
httpProxyVer := "HTTP/1.1"
|
||||||
for _, wrongCreds := range credentialsWrong {
|
for _, wrongCreds := range credentialsWrong {
|
||||||
// request test target
|
// request test target
|
||||||
for _, resource := range testResources {
|
for _, resource := range testResources {
|
||||||
responseProbeResist, rPRerr := getViaProxy(caddyTestTarget.addr, resource, changePort(caddyForwardProxyProbeResist.addr, caddyForwardProxyProbeResist.httpRedirPort), httpProxyVer, wrongCreds, useTLS, dialLocal)
|
responseProbeResist, rPRerr := getViaProxy(caddyTestTarget.addr, resource, changePort(caddyForwardProxyProbeResist.addr, caddyForwardProxyProbeResist.httpRedirPort), httpProxyVer, wrongCreds, useTLS)
|
||||||
// get response from reference server without forwardproxy and compare them
|
// get response from reference server without forwardproxy and compare them
|
||||||
responseReference, rRerr := getViaProxy(caddyTestTarget.addr, resource, changePort(caddyDummyProbeResist.addr, caddyDummyProbeResist.httpRedirPort), httpProxyVer, wrongCreds, useTLS, dialLocal)
|
responseReference, rRerr := getViaProxy(caddyTestTarget.addr, resource, changePort(caddyDummyProbeResist.addr, caddyDummyProbeResist.httpRedirPort), httpProxyVer, wrongCreds, useTLS)
|
||||||
if (rPRerr == nil && rRerr != nil) || (rPRerr != nil && rRerr == nil) {
|
if (rPRerr == nil && rRerr != nil) || (rPRerr != nil && rRerr == nil) {
|
||||||
t.Fatalf("Reference error: %s. Probe resist error: %s", rRerr, rPRerr)
|
t.Fatalf("Reference error: %s. Probe resist error: %s", rRerr, rPRerr)
|
||||||
}
|
}
|
||||||
|
|
@ -112,12 +112,12 @@ func TestGETAuthWrongProbeResistRedir(t *testing.T) {
|
||||||
}
|
}
|
||||||
// request self
|
// request self
|
||||||
for _, resource := range testResources {
|
for _, resource := range testResources {
|
||||||
responseProbeResist, err := getViaProxy(caddyForwardProxyProbeResist.addr, resource, changePort(caddyForwardProxyProbeResist.addr, caddyForwardProxyProbeResist.httpRedirPort), httpProxyVer, wrongCreds, useTLS, dialLocal)
|
responseProbeResist, err := getViaProxy(caddyForwardProxyProbeResist.addr, resource, changePort(caddyForwardProxyProbeResist.addr, caddyForwardProxyProbeResist.httpRedirPort), httpProxyVer, wrongCreds, useTLS)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
// get response from reference server without forwardproxy and compare them
|
// get response from reference server without forwardproxy and compare them
|
||||||
responseReference, err := getViaProxy(caddyDummyProbeResist.addr, resource, changePort(caddyDummyProbeResist.addr, caddyDummyProbeResist.httpRedirPort), httpProxyVer, wrongCreds, useTLS, dialLocal)
|
responseReference, err := getViaProxy(caddyDummyProbeResist.addr, resource, changePort(caddyDummyProbeResist.addr, caddyDummyProbeResist.httpRedirPort), httpProxyVer, wrongCreds, useTLS)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
|
|
@ -133,11 +133,11 @@ func TestGETAuthWrongProbeResistRedir(t *testing.T) {
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestConnectAuthCorrectProbeResist(t *testing.T) {
|
func TestConnectAuthCorrectProbeResist(t *testing.T) {
|
||||||
const useTLS, dialLocal = true, true
|
const useTLS = true
|
||||||
for _, httpProxyVer := range testHTTPProxyVersions {
|
for _, httpProxyVer := range testHTTPProxyVersions {
|
||||||
for _, httpTargetVer := range testHTTPTargetVersions {
|
for _, httpTargetVer := range testHTTPTargetVersions {
|
||||||
for _, resource := range testResources {
|
for _, resource := range testResources {
|
||||||
response, err := connectAndGetViaProxy(caddyTestTarget.addr, resource, caddyForwardProxyProbeResist.addr, httpTargetVer, credentialsCorrect, httpProxyVer, useTLS, dialLocal)
|
response, err := connectAndGetViaProxy(caddyTestTarget.addr, resource, caddyForwardProxyProbeResist.addr, httpTargetVer, credentialsCorrect, httpProxyVer, useTLS)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
} else if err = responseExpected(response, caddyTestTarget.contents[resource]); err != nil {
|
} else if err = responseExpected(response, caddyTestTarget.contents[resource]); err != nil {
|
||||||
|
|
@ -149,22 +149,22 @@ func TestConnectAuthCorrectProbeResist(t *testing.T) {
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestConnectAuthWrongProbeResist(t *testing.T) {
|
func TestConnectAuthWrongProbeResist(t *testing.T) {
|
||||||
const useTLS, dialLocal = true, false
|
const useTLS = true
|
||||||
for _, wrongCreds := range credentialsWrong {
|
for _, wrongCreds := range credentialsWrong {
|
||||||
for _, httpProxyVer := range testHTTPProxyVersions {
|
for _, httpProxyVer := range testHTTPProxyVersions {
|
||||||
for _, httpTargetVer := range testHTTPTargetVersions {
|
for _, httpTargetVer := range testHTTPTargetVersions {
|
||||||
for _, resource := range testResources {
|
for _, resource := range testResources {
|
||||||
responseProbeResist, err := connectAndGetViaProxy(caddyTestTarget.addr, resource, caddyForwardProxyProbeResist.addr, httpTargetVer, wrongCreds, httpProxyVer, useTLS, dialLocal)
|
responseProbeResist, err := connectAndGetViaProxy(caddyTestTarget.addr, resource, caddyForwardProxyProbeResist.addr, httpTargetVer, wrongCreds, httpProxyVer, useTLS)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
// get response from reference server without forwardproxy and compare them
|
// get response from reference server without forwardproxy and compare them
|
||||||
responseReference, err := connectAndGetViaProxy(caddyTestTarget.addr, resource, caddyDummyProbeResist.addr, httpTargetVer, wrongCreds, httpProxyVer, useTLS, dialLocal)
|
responseReference, err := connectAndGetViaProxy(caddyTestTarget.addr, resource, caddyDummyProbeResist.addr, httpTargetVer, wrongCreds, httpProxyVer, useTLS)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
// as a sanity check, get 407 from simple authenticated forwardproxy
|
// as a sanity check, get 407 from simple authenticated forwardproxy
|
||||||
responseForwardProxy, err := connectAndGetViaProxy(caddyTestTarget.addr, resource, caddyForwardProxyAuth.addr, httpTargetVer, wrongCreds, httpProxyVer, useTLS, dialLocal)
|
responseForwardProxy, err := connectAndGetViaProxy(caddyTestTarget.addr, resource, caddyForwardProxyAuth.addr, httpTargetVer, wrongCreds, httpProxyVer, useTLS)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
|
|
@ -186,17 +186,17 @@ func TestConnectAuthWrongProbeResist(t *testing.T) {
|
||||||
if httpTargetVer != httpProxyVer {
|
if httpTargetVer != httpProxyVer {
|
||||||
continue
|
continue
|
||||||
}
|
}
|
||||||
responseProbeResist, err := connectAndGetViaProxy(caddyForwardProxyProbeResist.addr, resource, caddyForwardProxyProbeResist.addr, httpTargetVer, wrongCreds, httpProxyVer, useTLS, dialLocal)
|
responseProbeResist, err := connectAndGetViaProxy(caddyForwardProxyProbeResist.addr, resource, caddyForwardProxyProbeResist.addr, httpTargetVer, wrongCreds, httpProxyVer, useTLS)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
// get response from reference server without forwardproxy and compare them
|
// get response from reference server without forwardproxy and compare them
|
||||||
responseReference, err := connectAndGetViaProxy(caddyDummyProbeResist.addr, resource, caddyDummyProbeResist.addr, httpTargetVer, wrongCreds, httpProxyVer, useTLS, dialLocal)
|
responseReference, err := connectAndGetViaProxy(caddyDummyProbeResist.addr, resource, caddyDummyProbeResist.addr, httpTargetVer, wrongCreds, httpProxyVer, useTLS)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
// as a sanity check, get 407 from simple authenticated forwardproxy
|
// as a sanity check, get 407 from simple authenticated forwardproxy
|
||||||
responseForwardProxy, err := connectAndGetViaProxy(caddyForwardProxyAuth.addr, resource, caddyForwardProxyAuth.addr, httpTargetVer, wrongCreds, httpProxyVer, useTLS, dialLocal)
|
responseForwardProxy, err := connectAndGetViaProxy(caddyForwardProxyAuth.addr, resource, caddyForwardProxyAuth.addr, httpTargetVer, wrongCreds, httpProxyVer, useTLS)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
|
|
@ -216,18 +216,18 @@ func TestConnectAuthWrongProbeResist(t *testing.T) {
|
||||||
|
|
||||||
// test that responses on http redirect port are same
|
// test that responses on http redirect port are same
|
||||||
func TestConnectAuthWrongProbeResistRedir(t *testing.T) {
|
func TestConnectAuthWrongProbeResistRedir(t *testing.T) {
|
||||||
const useTLS, dialLocal = false, false
|
const useTLS = false
|
||||||
httpProxyVer := "HTTP/1.1"
|
httpProxyVer := "HTTP/1.1"
|
||||||
for _, wrongCreds := range credentialsWrong {
|
for _, wrongCreds := range credentialsWrong {
|
||||||
for _, httpTargetVer := range testHTTPTargetVersions {
|
for _, httpTargetVer := range testHTTPTargetVersions {
|
||||||
// request test target
|
// request test target
|
||||||
for _, resource := range testResources {
|
for _, resource := range testResources {
|
||||||
responseProbeResist, err := connectAndGetViaProxy(caddyTestTarget.addr, resource, changePort(caddyForwardProxyProbeResist.addr, caddyForwardProxyProbeResist.httpRedirPort), httpTargetVer, wrongCreds, httpProxyVer, useTLS, dialLocal)
|
responseProbeResist, err := connectAndGetViaProxy(caddyTestTarget.addr, resource, changePort(caddyForwardProxyProbeResist.addr, caddyForwardProxyProbeResist.httpRedirPort), httpTargetVer, wrongCreds, httpProxyVer, useTLS)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
// get response from reference server without forwardproxy and compare them
|
// get response from reference server without forwardproxy and compare them
|
||||||
responseReference, err := connectAndGetViaProxy(caddyTestTarget.addr, resource, changePort(caddyDummyProbeResist.addr, caddyDummyProbeResist.httpRedirPort), httpTargetVer, wrongCreds, httpProxyVer, useTLS, dialLocal)
|
responseReference, err := connectAndGetViaProxy(caddyTestTarget.addr, resource, changePort(caddyDummyProbeResist.addr, caddyDummyProbeResist.httpRedirPort), httpTargetVer, wrongCreds, httpProxyVer, useTLS)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
|
|
@ -241,12 +241,12 @@ func TestConnectAuthWrongProbeResistRedir(t *testing.T) {
|
||||||
}
|
}
|
||||||
// request self
|
// request self
|
||||||
for _, resource := range testResources {
|
for _, resource := range testResources {
|
||||||
responseProbeResist, err := connectAndGetViaProxy(caddyForwardProxyProbeResist.addr, resource, changePort(caddyForwardProxyProbeResist.addr, caddyForwardProxyProbeResist.httpRedirPort), httpTargetVer, wrongCreds, httpProxyVer, useTLS, dialLocal)
|
responseProbeResist, err := connectAndGetViaProxy(caddyForwardProxyProbeResist.addr, resource, changePort(caddyForwardProxyProbeResist.addr, caddyForwardProxyProbeResist.httpRedirPort), httpTargetVer, wrongCreds, httpProxyVer, useTLS)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
// get response from reference server without forwardproxy and compare them
|
// get response from reference server without forwardproxy and compare them
|
||||||
responseReference, err := connectAndGetViaProxy(caddyDummyProbeResist.addr, resource, changePort(caddyDummyProbeResist.addr, caddyDummyProbeResist.httpRedirPort), httpTargetVer, wrongCreds, httpProxyVer, useTLS, dialLocal)
|
responseReference, err := connectAndGetViaProxy(caddyDummyProbeResist.addr, resource, changePort(caddyDummyProbeResist.addr, caddyDummyProbeResist.httpRedirPort), httpTargetVer, wrongCreds, httpProxyVer, useTLS)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue