1
0
mirror of https://github.com/verdaccio/verdaccio.git synced 2024-11-13 03:35:52 +01:00
verdaccio/test/functional/sanity/security.js

73 lines
2.1 KiB
JavaScript
Raw Normal View History

2017-04-19 21:15:28 +02:00
'use strict';
const assert = require('assert');
2013-12-19 16:11:54 +01:00
module.exports = function () {
2017-04-19 21:15:28 +02:00
let server = process.server;
2013-12-29 07:40:47 +01:00
describe('Security', function () {
before(function () {
return server.addPackage('testpkg-sec');
2017-04-19 21:15:28 +02:00
});
2013-12-19 16:11:54 +01:00
it('bad pkg #1', function () {
return server.getPackage('package.json')
.status(403)
.body_error(/invalid package/);
2017-04-19 21:15:28 +02:00
});
2013-12-19 16:11:54 +01:00
it('bad pkg #2', function () {
return server.getPackage('__proto__')
.status(403)
.body_error(/invalid package/);
2017-04-19 21:15:28 +02:00
});
it('__proto__, connect stuff', function () {
2017-04-19 21:15:28 +02:00
return server.request({uri: '/testpkg-sec?__proto__=1'})
.then(function (body) {
// test for NOT outputting stack trace
2017-04-19 21:15:28 +02:00
assert(!body || typeof(body) === 'object' || body.indexOf('node_modules') === -1);
2013-12-19 16:11:54 +01:00
// test for NOT crashing
2017-04-19 21:15:28 +02:00
return server.request({uri: '/testpkg-sec'}).status(200);
});
});
2013-12-19 16:11:54 +01:00
it('do not return package.json as an attachment', function () {
2017-04-19 21:15:28 +02:00
return server.request({uri: '/testpkg-sec/-/package.json'})
.status(403)
.body_error(/invalid filename/);
2017-04-19 21:15:28 +02:00
});
2013-12-19 16:11:54 +01:00
it('silly things - reading #1', function () {
2017-04-19 21:15:28 +02:00
return server.request({uri: '/testpkg-sec/-/../../../../../../../../etc/passwd'})
.status(404);
2017-04-19 21:15:28 +02:00
});
2013-12-19 16:11:54 +01:00
it('silly things - reading #2', function () {
2017-04-19 21:15:28 +02:00
return server.request({uri: '/testpkg-sec/-/%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fetc%2fpasswd'})
.status(403)
.body_error(/invalid filename/);
2017-04-19 21:15:28 +02:00
});
2013-12-19 16:11:54 +01:00
it('silly things - writing #1', function () {
return server.putTarball('testpkg-sec', 'package.json', '{}')
.status(403)
.body_error(/invalid filename/);
2017-04-19 21:15:28 +02:00
});
2013-12-19 16:11:54 +01:00
it('silly things - writing #3', function () {
return server.putTarball('testpkg-sec', 'node_modules', '{}')
.status(403)
.body_error(/invalid filename/);
2017-04-19 21:15:28 +02:00
});
2013-12-19 16:11:54 +01:00
it('silly things - writing #4', function () {
return server.putTarball('testpkg-sec', '../testpkg.tgz', '{}')
.status(403)
.body_error(/invalid filename/);
2017-04-19 21:15:28 +02:00
});
});
};
2013-12-19 16:11:54 +01:00