First Commit
ci / go (push) Waiting to run
ci / go-db (agent) (push) Waiting to run
ci / go-db (config) (push) Waiting to run
ci / go-db (db) (push) Waiting to run
ci / go-db (evidence) (push) Waiting to run
ci / go-db (llmrec) (push) Waiting to run
ci / go-db (server) (push) Waiting to run
web / web (push) Waiting to run
docs / links (push) Canceled after 0s
detections / detections (push) Canceled after 0s
ci / go (push) Waiting to run
ci / go-db (agent) (push) Waiting to run
ci / go-db (config) (push) Waiting to run
ci / go-db (db) (push) Waiting to run
ci / go-db (evidence) (push) Waiting to run
ci / go-db (llmrec) (push) Waiting to run
ci / go-db (server) (push) Waiting to run
web / web (push) Waiting to run
docs / links (push) Canceled after 0s
detections / detections (push) Canceled after 0s
This commit is contained in:
@@ -0,0 +1,46 @@
|
||||
package db
|
||||
|
||||
import (
|
||||
"regexp"
|
||||
"testing"
|
||||
)
|
||||
|
||||
// 内置「删除类接口路径」规则匹配的是整个 tool_input JSON 串,因此用例直接以
|
||||
// JSON 形态给出,与 Interceptor 实际拿到的 subject 一致。
|
||||
func TestDeleteEndpointPathPattern(t *testing.T) {
|
||||
re := regexp.MustCompile(deleteEndpointPathPattern)
|
||||
|
||||
hit := []string{
|
||||
`{"command":"curl -s 'http://t.com/api/user/delete?id=1'"}`, // GET 打删除接口
|
||||
`{"command":"curl -X POST http://t.com/admin/delete -d id=1"}`, // POST 打删除接口
|
||||
`{"command":"curl 'http://t.com/api/deleteAll'"}`,
|
||||
`{"command":"curl 'http://t.com/api/delete_user?id=1'"}`,
|
||||
`{"command":"curl 'http://t.com/api/delete-user?id=1'"}`,
|
||||
`{"url":"http://t.com/api/remove?id=1"}`,
|
||||
`{"command":"curl http://t.com/files/unlink/3"}`,
|
||||
`{"command":"curl http://t.com/api/del?id=2"}`,
|
||||
`{"command":"curl -X POST http://t/v1/erase"}`,
|
||||
`{"command":"curl http://t/admin/destroyAll"}`, // v1 的路径规则不允许后缀,这里补上
|
||||
}
|
||||
for _, s := range hit {
|
||||
if !re.MatchString(s) {
|
||||
t.Errorf("应命中却放行: %s", s)
|
||||
}
|
||||
}
|
||||
|
||||
// 动词后必须跟分隔符,避免 /delivery、/details 这类只读路径被误拦。
|
||||
miss := []string{
|
||||
`{"command":"curl 'http://t.com/api/delivery?id=1'"}`,
|
||||
`{"command":"curl 'http://t.com/order/details'"}`,
|
||||
`{"command":"curl 'http://t.com/api/delta/sync'"}`,
|
||||
`{"command":"curl 'http://t.com/user/delegate'"}`,
|
||||
`{"command":"curl 'http://delete.example.com/'"}`, // 删除动词出现在域名而非路径
|
||||
`{"command":"curl 'http://t.com/remote/status'"}`,
|
||||
`{"command":"nmap -p80 10.0.0.1"}`,
|
||||
}
|
||||
for _, s := range miss {
|
||||
if re.MatchString(s) {
|
||||
t.Errorf("误拦: %s", s)
|
||||
}
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user