fix(callback): abort on invalid Upyun callback signature

pull/3472/merge
Aaron Liu 2 weeks ago
parent ade1866be5
commit ca76282963

@ -83,7 +83,8 @@ func UpyunCallbackAuth(c *gin.Context) {
if err := upyun.ValidateCallback(c, uploadSession); err != nil {
l.Error("Failed to verify callback request: %s", err)
c.JSON(401, serializer.GeneralUploadCallbackFailed{Error: "Failed to verify callback request."})
c.AbortWithStatusJSON(401, serializer.GeneralUploadCallbackFailed{Error: "Failed to verify callback request."})
return
}
c.Next()

@ -0,0 +1,37 @@
package controllers
import (
"net/http"
"net/http/httptest"
"testing"
"github.com/cloudreve/Cloudreve/v4/pkg/filemanager/fs"
"github.com/cloudreve/Cloudreve/v4/pkg/filemanager/manager"
"github.com/gin-gonic/gin"
"github.com/stretchr/testify/assert"
)
func TestUpyunCallbackAuthAbortsInvalidSignature(t *testing.T) {
gin.SetMode(gin.TestMode)
nextCalled := false
router := gin.New()
router.POST(
"/callback",
func(c *gin.Context) {
c.Set(manager.UploadSessionCtx, &fs.UploadSession{})
},
UpyunCallbackAuth,
func(c *gin.Context) {
nextCalled = true
c.Status(http.StatusNoContent)
},
)
recorder := httptest.NewRecorder()
request := httptest.NewRequest(http.MethodPost, "/callback", nil)
router.ServeHTTP(recorder, request)
assert.Equal(t, http.StatusUnauthorized, recorder.Code)
assert.False(t, nextCalled)
}
Loading…
Cancel
Save