mirror of
https://github.com/google/nomulus
synced 2026-09-20 15:04:24 +00:00
Tighten control on Marksdb URL hostname (#3198)
this doesn't really matter but eh, a URL shouldn't be able to be like, ry.marksdb.org.attacker.com b/535251045
This commit is contained in:
@@ -64,7 +64,7 @@ public final class NordnVerifyAction implements Runnable {
|
|||||||
static final String NORDN_URL_PARAM = "nordnUrl";
|
static final String NORDN_URL_PARAM = "nordnUrl";
|
||||||
static final String NORDN_LOG_ID_PARAM = "nordnLogId";
|
static final String NORDN_LOG_ID_PARAM = "nordnLogId";
|
||||||
|
|
||||||
private static final String MARKSDB_URL_BEGINNING = "ry.marksdb.org";
|
private static final String MARKSDB_HOST_NAME = "ry.marksdb.org";
|
||||||
|
|
||||||
private static final FluentLogger logger = FluentLogger.forEnclosingClass();
|
private static final FluentLogger logger = FluentLogger.forEnclosingClass();
|
||||||
|
|
||||||
@@ -109,11 +109,7 @@ public final class NordnVerifyAction implements Runnable {
|
|||||||
@VisibleForTesting
|
@VisibleForTesting
|
||||||
LordnLog verify() throws IOException, GeneralSecurityException {
|
LordnLog verify() throws IOException, GeneralSecurityException {
|
||||||
String host = Ascii.toLowerCase(url.getHost());
|
String host = Ascii.toLowerCase(url.getHost());
|
||||||
checkArgument(
|
checkArgument(host.equals(MARKSDB_HOST_NAME), "Host %s must equal %s", host, MARKSDB_HOST_NAME);
|
||||||
host.startsWith(MARKSDB_URL_BEGINNING),
|
|
||||||
"URL %s must start with %s",
|
|
||||||
url,
|
|
||||||
MARKSDB_URL_BEGINNING);
|
|
||||||
logger.atInfo().log("LORDN verify task %s: Sending request to URL %s", actionLogId, url);
|
logger.atInfo().log("LORDN verify task %s: Sending request to URL %s", actionLogId, url);
|
||||||
HttpURLConnection connection = urlConnectionService.createConnection(url);
|
HttpURLConnection connection = urlConnectionService.createConnection(url);
|
||||||
lordnRequestInitializer.initialize(connection, tld);
|
lordnRequestInitializer.initialize(connection, tld);
|
||||||
|
|||||||
@@ -170,9 +170,7 @@ class NordnVerifyActionTest {
|
|||||||
void testFailure_badUrl() throws Exception {
|
void testFailure_badUrl() throws Exception {
|
||||||
action.url = URI.create("http://example.com/blobio").toURL();
|
action.url = URI.create("http://example.com/blobio").toURL();
|
||||||
IllegalArgumentException thrown = assertThrows(IllegalArgumentException.class, action::run);
|
IllegalArgumentException thrown = assertThrows(IllegalArgumentException.class, action::run);
|
||||||
assertThat(thrown)
|
assertThat(thrown).hasMessageThat().isEqualTo("Host example.com must equal ry.marksdb.org");
|
||||||
.hasMessageThat()
|
|
||||||
.isEqualTo("URL http://example.com/blobio must start with ry.marksdb.org");
|
|
||||||
}
|
}
|
||||||
|
|
||||||
@Test
|
@Test
|
||||||
|
|||||||
Reference in New Issue
Block a user