← Files BranchaARCHIVED FILE
skills/brancha/app/src/server/http/security.test.ts
1.08 KB · Oct 4, 2026 · 12:29 UTC
import assert from 'node:assert/strict';
import type { IncomingMessage } from 'node:http';
import test from 'node:test';
import { isAllowedHost } from './security.js';
const request = (host?: string) => ({ headers: { host } }) as IncomingMessage;
test('allows loopback hosts and rejects DNS rebinding hosts', () => {
assert.equal(isAllowedHost(request('127.0.0.1:9519')), true);
assert.equal(isAllowedHost(request('localhost:9519')), true);
assert.equal(isAllowedHost(request('[::1]:9519')), true);
assert.equal(isAllowedHost(request('attacker.example:9519')), false);
assert.equal(isAllowedHost(request()), false);
});
test('supports an explicit host allowlist', () => {
const previous = process.env.BRANCHA_ALLOWED_HOSTS;
process.env.BRANCHA_ALLOWED_HOSTS = 'brancha.local, 192.168.1.20';
try {
assert.equal(isAllowedHost(request('brancha.local:9519')), true);
assert.equal(isAllowedHost(request('192.168.1.20:9519')), true);
} finally {
if (previous === undefined) delete process.env.BRANCHA_ALLOWED_HOSTS;
else process.env.BRANCHA_ALLOWED_HOSTS = previous;
}
});
SHA-256: 827e8513bc89e63140414fc8a153c5f077c3679a8c31a91d717e5ef0ebfeb233