diff --git a/gitnexus/test/unit/git-clone.test.ts b/gitnexus/test/unit/git-clone.test.ts index 637ff5932..2df5a0a5e 100644 --- a/gitnexus/test/unit/git-clone.test.ts +++ b/gitnexus/test/unit/git-clone.test.ts @@ -1,5 +1,5 @@ import { describe, it, expect } from 'vitest'; -import { extractRepoName, getCloneDir } from '../../src/server/git-clone.js'; +import { extractRepoName, getCloneDir, validateGitUrl } from '../../src/server/git-clone.js'; describe('git-clone', () => { describe('extractRepoName', () => { @@ -32,4 +32,86 @@ describe('git-clone', () => { expect(dir).toContain('my-repo'); }); }); + + describe('validateGitUrl', () => { + it('allows valid HTTPS GitHub URLs', () => { + expect(() => validateGitUrl('https://github.com/user/repo.git')).not.toThrow(); + expect(() => validateGitUrl('https://github.com/user/repo')).not.toThrow(); + }); + + it('allows valid HTTP URLs', () => { + expect(() => validateGitUrl('http://gitlab.com/user/repo.git')).not.toThrow(); + }); + + it('blocks SSH protocol', () => { + expect(() => validateGitUrl('ssh://git@github.com/user/repo.git')).toThrow( + 'Only https:// and http://', + ); + }); + + it('blocks file:// protocol', () => { + expect(() => validateGitUrl('file:///etc/passwd')).toThrow( + 'Only https:// and http://', + ); + }); + + it('blocks IPv4 loopback', () => { + expect(() => validateGitUrl('http://127.0.0.1/repo.git')).toThrow('private/internal'); + expect(() => validateGitUrl('http://127.255.0.1/repo.git')).toThrow('private/internal'); + }); + + it('blocks IPv6 loopback ::1', () => { + // Node URL parser strips brackets: hostname is "::1" not "[::1]" + expect(() => validateGitUrl('http://[::1]/repo.git')).toThrow('private/internal'); + }); + + it('blocks IPv4 private ranges (10.x, 172.16-31.x, 192.168.x)', () => { + expect(() => validateGitUrl('http://10.0.0.1/repo.git')).toThrow('private/internal'); + expect(() => validateGitUrl('http://172.16.0.1/repo.git')).toThrow('private/internal'); + expect(() => validateGitUrl('http://172.31.255.255/repo.git')).toThrow('private/internal'); + expect(() => validateGitUrl('http://192.168.1.1/repo.git')).toThrow('private/internal'); + }); + + it('blocks link-local addresses', () => { + expect(() => validateGitUrl('http://169.254.1.1/repo.git')).toThrow('private/internal'); + }); + + it('blocks cloud metadata hostname', () => { + expect(() => validateGitUrl('http://metadata.google.internal/repo')).toThrow( + 'private/internal', + ); + expect(() => validateGitUrl('http://metadata.azure.com/repo')).toThrow( + 'private/internal', + ); + }); + + it('blocks IPv6 ULA (fc/fd)', () => { + expect(() => validateGitUrl('http://[fc00::1]/repo.git')).toThrow('private/internal'); + expect(() => validateGitUrl('http://[fd12::1]/repo.git')).toThrow('private/internal'); + }); + + it('blocks IPv6 link-local (fe80)', () => { + expect(() => validateGitUrl('http://[fe80::1]/repo.git')).toThrow('private/internal'); + }); + + it('blocks IPv4-mapped IPv6', () => { + expect(() => validateGitUrl('http://[::ffff:127.0.0.1]/repo.git')).toThrow( + 'private/internal', + ); + }); + + it('does not block valid public IPs', () => { + expect(() => validateGitUrl('https://140.82.121.4/repo.git')).not.toThrow(); + }); + + it('blocks CGN range (100.64.0.0/10)', () => { + expect(() => validateGitUrl('http://100.64.0.1/repo.git')).toThrow('private/internal'); + expect(() => validateGitUrl('http://100.127.255.255/repo.git')).toThrow('private/internal'); + }); + + it('blocks benchmarking range (198.18.0.0/15)', () => { + expect(() => validateGitUrl('http://198.18.0.1/repo.git')).toThrow('private/internal'); + expect(() => validateGitUrl('http://198.19.255.255/repo.git')).toThrow('private/internal'); + }); + }); });