2018-10-22 13:22:23 -04:00
|
|
|
require 'rails_helper'
|
|
|
|
|
|
|
|
describe ContentSecurityPolicy do
|
|
|
|
describe 'report-uri' do
|
|
|
|
it 'is enabled by SiteSetting' do
|
|
|
|
SiteSetting.content_security_policy_collect_reports = true
|
|
|
|
report_uri = parse(ContentSecurityPolicy.new.build)['report-uri'].first
|
|
|
|
expect(report_uri).to eq('/csp_reports')
|
|
|
|
|
|
|
|
SiteSetting.content_security_policy_collect_reports = false
|
|
|
|
report_uri = parse(ContentSecurityPolicy.new.build)['report-uri']
|
|
|
|
expect(report_uri).to eq(nil)
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2018-11-16 16:25:21 -05:00
|
|
|
describe 'worker-src' do
|
|
|
|
it 'always has self and blob' do
|
|
|
|
worker_srcs = parse(ContentSecurityPolicy.new.build)['worker-src']
|
|
|
|
expect(worker_srcs).to eq(%w[
|
|
|
|
'self'
|
|
|
|
blob:
|
|
|
|
])
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
describe 'script-src' do
|
|
|
|
it 'always has self, logster, sidekiq, and assets' do
|
2018-10-22 13:22:23 -04:00
|
|
|
script_srcs = parse(ContentSecurityPolicy.new.build)['script-src']
|
2018-11-15 12:14:16 -05:00
|
|
|
expect(script_srcs).to eq(%w[
|
|
|
|
'unsafe-eval'
|
|
|
|
http://test.localhost/logs/
|
|
|
|
http://test.localhost/sidekiq/
|
|
|
|
http://test.localhost/mini-profiler-resources/
|
|
|
|
http://test.localhost/assets/
|
|
|
|
http://test.localhost/brotli_asset/
|
|
|
|
http://test.localhost/extra-locales/
|
|
|
|
http://test.localhost/highlight-js/
|
|
|
|
http://test.localhost/javascripts/
|
2018-11-16 16:25:21 -05:00
|
|
|
http://test.localhost/plugins/
|
2018-11-15 12:14:16 -05:00
|
|
|
http://test.localhost/theme-javascripts/
|
|
|
|
])
|
2018-10-22 13:22:23 -04:00
|
|
|
end
|
|
|
|
|
|
|
|
it 'whitelists Google Analytics and Tag Manager when integrated' do
|
|
|
|
SiteSetting.ga_universal_tracking_code = 'UA-12345678-9'
|
|
|
|
SiteSetting.gtm_container_id = 'GTM-ABCDEF'
|
|
|
|
|
|
|
|
script_srcs = parse(ContentSecurityPolicy.new.build)['script-src']
|
2018-11-15 12:14:16 -05:00
|
|
|
expect(script_srcs).to include('https://www.google-analytics.com')
|
|
|
|
expect(script_srcs).to include('https://www.googletagmanager.com')
|
2018-10-22 13:22:23 -04:00
|
|
|
end
|
|
|
|
|
2018-11-15 12:14:16 -05:00
|
|
|
it 'whitelists CDN assets when integrated' do
|
|
|
|
set_cdn_url('https://cdn.com')
|
|
|
|
|
|
|
|
script_srcs = parse(ContentSecurityPolicy.new.build)['script-src']
|
|
|
|
expect(script_srcs).to include(*%w[
|
|
|
|
https://cdn.com/assets/
|
|
|
|
https://cdn.com/brotli_asset/
|
|
|
|
https://cdn.com/highlight-js/
|
|
|
|
https://cdn.com/javascripts/
|
2018-11-16 16:25:21 -05:00
|
|
|
https://cdn.com/plugins/
|
2018-11-15 12:14:16 -05:00
|
|
|
https://cdn.com/theme-javascripts/
|
|
|
|
http://test.localhost/extra-locales/
|
|
|
|
])
|
|
|
|
|
|
|
|
global_setting(:s3_cdn_url, 'https://s3-cdn.com')
|
2018-10-22 13:22:23 -04:00
|
|
|
|
|
|
|
script_srcs = parse(ContentSecurityPolicy.new.build)['script-src']
|
2018-11-15 12:14:16 -05:00
|
|
|
expect(script_srcs).to include(*%w[
|
|
|
|
https://s3-cdn.com/assets/
|
|
|
|
https://s3-cdn.com/brotli_asset/
|
|
|
|
https://cdn.com/highlight-js/
|
|
|
|
https://cdn.com/javascripts/
|
2018-11-16 16:25:21 -05:00
|
|
|
https://cdn.com/plugins/
|
2018-11-15 12:14:16 -05:00
|
|
|
https://cdn.com/theme-javascripts/
|
|
|
|
http://test.localhost/extra-locales/
|
|
|
|
])
|
2018-10-22 13:22:23 -04:00
|
|
|
end
|
|
|
|
|
|
|
|
it 'can be extended with more sources' do
|
|
|
|
SiteSetting.content_security_policy_script_src = 'example.com|another.com'
|
|
|
|
script_srcs = parse(ContentSecurityPolicy.new.build)['script-src']
|
|
|
|
expect(script_srcs).to include('example.com')
|
|
|
|
expect(script_srcs).to include('another.com')
|
|
|
|
expect(script_srcs).to include("'unsafe-eval'")
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
def parse(csp_string)
|
|
|
|
csp_string.split(';').map do |policy|
|
|
|
|
directive, *sources = policy.split
|
|
|
|
[directive, sources]
|
|
|
|
end.to_h
|
|
|
|
end
|
|
|
|
end
|