ec74559ca5
kagane serves cover images from behind the same Cloudflare challenge as
its pages and with cross-origin-resource-policy: same-origin. The second
header is the decisive one: no <img> on the web UI's origin can load a
kagane cover even from a browser that already holds the clearance cookie,
verified 2026-08-08 by loading one from a foreign origin with and without
a referrer. Hot-linking cannot be made to work, so every kagane series
rendered the monogram placeholder.
Bookmark.CoverURL rewrites a stored kagane og:image to /img/kagane/{id}
and returns every other cover untouched; the templates render .CoverURL
in place of .Cover. The endpoint is session-gated like every other UI
route, and hands the id to the shared headless browser, whose fetch is
same-origin with kagane and therefore satisfies both the challenge and
the CORP header. Results are memoised in-process, so a cover costs one
navigation per deployment lifetime.
The id is matched against a UUID regex before it reaches the browser.
That gate is load-bearing rather than tidiness: the cover is a stored
client-supplied string, so an unvalidated one turns the endpoint into an
SSRF primitive aimed at the deployment's own network. ServeMux
path-cleans a traversal into a redirect before the handler runs, but the
handler does not rely on that, and a test pins it.
With BROWSER_WS_URL unset there is no browser and the endpoint answers
404 rather than reaching for a nil fetcher - the same degrade-to-
userscript behaviour the poller already has for these sites.
156 lines
4.6 KiB
Go
156 lines
4.6 KiB
Go
package main
|
|
|
|
import (
|
|
"context"
|
|
"errors"
|
|
"net/http"
|
|
"net/http/httptest"
|
|
"sync/atomic"
|
|
"testing"
|
|
)
|
|
|
|
// fakeCovers stands in for the headless browser. It counts calls so the test
|
|
// can prove the cache spares the browser a second navigation.
|
|
type fakeCovers struct {
|
|
body []byte
|
|
contentType string
|
|
err error
|
|
calls atomic.Int32
|
|
lastID atomic.Value
|
|
}
|
|
|
|
func (f *fakeCovers) Image(_ context.Context, imageID string) ([]byte, string, error) {
|
|
f.calls.Add(1)
|
|
f.lastID.Store(imageID)
|
|
if f.err != nil {
|
|
return nil, "", f.err
|
|
}
|
|
return f.body, f.contentType, nil
|
|
}
|
|
|
|
const testCoverID = "019fe11a-84c3-7fc3-a84b-88787374b617"
|
|
|
|
func getCover(t *testing.T, srv http.Handler, path string, cookie *http.Cookie) *httptest.ResponseRecorder {
|
|
t.Helper()
|
|
req := httptest.NewRequest(http.MethodGet, path, nil)
|
|
if cookie != nil {
|
|
req.AddCookie(cookie)
|
|
}
|
|
rr := httptest.NewRecorder()
|
|
srv.ServeHTTP(rr, req)
|
|
return rr
|
|
}
|
|
|
|
// kagane serves its covers behind a Cloudflare challenge and with
|
|
// cross-origin-resource-policy: same-origin, so the UI can only show one by
|
|
// re-serving the bytes from its own origin.
|
|
func TestKaganeCoverProxiesAndCaches(t *testing.T) {
|
|
cf := &fakeCovers{body: []byte("\x00webp-bytes"), contentType: "image/webp"}
|
|
cfg := testConfig()
|
|
cfg.Covers = cf
|
|
srv, st := newWebTestServer(t, cfg)
|
|
cookie := sessionCookie(t, st)
|
|
|
|
for i := range 2 {
|
|
rr := getCover(t, srv, "/img/kagane/"+testCoverID, cookie)
|
|
if rr.Code != http.StatusOK {
|
|
t.Fatalf("request %d: status = %d, want 200", i, rr.Code)
|
|
}
|
|
if got := rr.Body.String(); got != string(cf.body) {
|
|
t.Fatalf("request %d: body = %q, want %q", i, got, cf.body)
|
|
}
|
|
if got := rr.Header().Get("Content-Type"); got != "image/webp" {
|
|
t.Fatalf("request %d: Content-Type = %q, want image/webp", i, got)
|
|
}
|
|
}
|
|
if got := cf.calls.Load(); got != 1 {
|
|
t.Fatalf("fetcher called %d times, want 1 — the second read must come from the cache", got)
|
|
}
|
|
if got := cf.lastID.Load(); got != testCoverID {
|
|
t.Fatalf("fetched image id = %v, want %s", got, testCoverID)
|
|
}
|
|
}
|
|
|
|
// The proxy reaches a headless browser, so it is not open to the internet.
|
|
func TestKaganeCoverRequiresSession(t *testing.T) {
|
|
cf := &fakeCovers{body: []byte("x"), contentType: "image/webp"}
|
|
cfg := testConfig()
|
|
cfg.Covers = cf
|
|
srv, _ := newWebTestServer(t, cfg)
|
|
|
|
rr := getCover(t, srv, "/img/kagane/"+testCoverID, nil)
|
|
if rr.Code != http.StatusUnauthorized {
|
|
t.Fatalf("status = %d, want 401", rr.Code)
|
|
}
|
|
if got := cf.calls.Load(); got != 0 {
|
|
t.Fatalf("fetcher called %d times for an unauthenticated request, want 0", got)
|
|
}
|
|
}
|
|
|
|
func TestKaganeCoverRejectsBadInput(t *testing.T) {
|
|
cases := []struct {
|
|
name string
|
|
id string
|
|
fetch *fakeCovers
|
|
}{
|
|
{
|
|
"an id that is not a uuid never reaches the browser",
|
|
"solo-leveling",
|
|
&fakeCovers{body: []byte("x"), contentType: "image/webp"},
|
|
},
|
|
{
|
|
"a uuid-shaped id with a trailing segment is rejected whole",
|
|
testCoverID + "x",
|
|
&fakeCovers{body: []byte("x"), contentType: "image/webp"},
|
|
},
|
|
{
|
|
"a challenged fetch is a missing cover",
|
|
testCoverID,
|
|
&fakeCovers{err: errors.New("challenge held")},
|
|
},
|
|
{
|
|
"a content type outside the image set is not echoed back",
|
|
testCoverID,
|
|
&fakeCovers{body: []byte("<script>"), contentType: "text/html"},
|
|
},
|
|
}
|
|
for _, tc := range cases {
|
|
t.Run(tc.name, func(t *testing.T) {
|
|
cfg := testConfig()
|
|
cfg.Covers = tc.fetch
|
|
srv, st := newWebTestServer(t, cfg)
|
|
rr := getCover(t, srv, "/img/kagane/"+tc.id, sessionCookie(t, st))
|
|
if rr.Code != http.StatusNotFound {
|
|
t.Fatalf("status = %d, want 404", rr.Code)
|
|
}
|
|
})
|
|
}
|
|
}
|
|
|
|
// ServeMux path-cleans a traversal into a redirect before the handler runs, so
|
|
// the guarantee to pin down is that no request shaped like one ever gets bytes.
|
|
func TestKaganeCoverTraversalServesNothing(t *testing.T) {
|
|
cf := &fakeCovers{body: []byte("secret"), contentType: "image/webp"}
|
|
cfg := testConfig()
|
|
cfg.Covers = cf
|
|
srv, st := newWebTestServer(t, cfg)
|
|
|
|
rr := getCover(t, srv, "/img/kagane/../../etc/passwd", sessionCookie(t, st))
|
|
if rr.Code == http.StatusOK {
|
|
t.Fatalf("status = 200, want anything but a served body")
|
|
}
|
|
if got := cf.calls.Load(); got != 0 {
|
|
t.Fatalf("fetcher called %d times for a traversal, want 0", got)
|
|
}
|
|
}
|
|
|
|
// Without BROWSER_WS_URL there is no fetcher, and the endpoint must answer
|
|
// rather than reach for a nil one.
|
|
func TestKaganeCoverWithoutFetcher(t *testing.T) {
|
|
srv, st := newWebTestServer(t, testConfig())
|
|
rr := getCover(t, srv, "/img/kagane/"+testCoverID, sessionCookie(t, st))
|
|
if rr.Code != http.StatusNotFound {
|
|
t.Fatalf("status = %d, want 404", rr.Code)
|
|
}
|
|
}
|