mirror of
https://github.com/discourse/discourse.git
synced 2026-08-06 10:40:48 +08:00
Ruby 3.4 shipped support for happy eyeballs in `Socket.tcp` and `TCPSocket`. However, our `FinalDestination::HTTP` wrapper was performing a DNS lookup and passing IP addresses one at a time when opening the socket. That meant that we didn't benefit from the new Ruby feature in most Discourse features. This commit factors the strategy. Now, `FinalDestination::HTTP` encodes the DNS result and passes it to the underlying implementation as a fake hostname string. A patch to `Addrinfo` detects this fake hostname and returns the given IPs instead of performing its own lookup. For this Addrinfo patch to work, we also had to patch `TCPSocket` so that it uses the ruby-based `Socket.tcp` rather than its native C socket-opening code. The result is that we now get the benefit of the native Ruby 'Happy Eyeballs' support for concurrent ipv4 and ipv6 connections. All this patching of low-level ruby classes is not ideal, but there is no native way to control name resolution in `Net::HTTP` or its dependencies.
35 lines
1,010 B
Ruby
Vendored
35 lines
1,010 B
Ruby
Vendored
# frozen_string_literal: true
|
|
|
|
RSpec.describe FastImage do
|
|
before do
|
|
FinalDestination::SSRFDetector.allow_ip_lookups_in_test!
|
|
WebMock.enable!(except: [:final_destination])
|
|
end
|
|
|
|
after do
|
|
WebMock.enable!
|
|
FinalDestination::SSRFDetector.disallow_ip_lookups_in_test!
|
|
end
|
|
|
|
it "should filter endpoint hostname through our SSRF detector and return null object" do
|
|
stub_ip_lookup("example.com", %W[0.0.0.0])
|
|
|
|
expect(described_class.type("http://example.com")).to eq(nil)
|
|
end
|
|
|
|
it "should send the right request if endpoint hostname resolves to a public ip address" do
|
|
stub_ip_lookup("example.com", %W[52.125.123.12])
|
|
|
|
success = Class.new(StandardError)
|
|
TCPSocket
|
|
.stubs(:open)
|
|
.with do |addr|
|
|
FinalDestination::Connector.token?(addr) &&
|
|
FinalDestination::Connector.addresses(addr) == %w[52.125.123.12]
|
|
end
|
|
.once
|
|
.raises(success)
|
|
|
|
expect { described_class.type("http://example.com") }.to raise_error(success)
|
|
end
|
|
end
|