← Files BranchaARCHIVED FILE

skills/brancha/app/src/server/http/security.test.ts

1.08 KB · Oct 3, 2026 · 06:30 UTC

↓ Download file

import assert from 'node:assert/strict';
import type { IncomingMessage } from 'node:http';
import test from 'node:test';
import { isAllowedHost } from './security.js';

const request = (host?: string) => ({ headers: { host } }) as IncomingMessage;

test('allows loopback hosts and rejects DNS rebinding hosts', () => {
  assert.equal(isAllowedHost(request('127.0.0.1:9519')), true);
  assert.equal(isAllowedHost(request('localhost:9519')), true);
  assert.equal(isAllowedHost(request('[::1]:9519')), true);
  assert.equal(isAllowedHost(request('attacker.example:9519')), false);
  assert.equal(isAllowedHost(request()), false);
});

test('supports an explicit host allowlist', () => {
  const previous = process.env.BRANCHA_ALLOWED_HOSTS;
  process.env.BRANCHA_ALLOWED_HOSTS = 'brancha.local, 192.168.1.20';
  try {
    assert.equal(isAllowedHost(request('brancha.local:9519')), true);
    assert.equal(isAllowedHost(request('192.168.1.20:9519')), true);
  } finally {
    if (previous === undefined) delete process.env.BRANCHA_ALLOWED_HOSTS;
    else process.env.BRANCHA_ALLOWED_HOSTS = previous;
  }
});

SHA-256: 827e8513bc89e63140414fc8a153c5f077c3679a8c31a91d717e5ef0ebfeb233