feat(okf): resource-URL https allowlist reject-gate (T3, TDD, +10)
This commit is contained in:
parent
ec121f3259
commit
f9a89938b4
2 changed files with 92 additions and 0 deletions
|
|
@ -21,8 +21,10 @@ from llm_ingestion_guard.okf import (
|
|||
parse_frontmatter,
|
||||
scan_concept,
|
||||
validate_concept_path,
|
||||
validate_resource_url,
|
||||
OKFFrontmatterError,
|
||||
OKFPathError,
|
||||
OKFResourceError,
|
||||
)
|
||||
from llm_ingestion_guard.report import Report
|
||||
|
||||
|
|
@ -200,3 +202,57 @@ def test_validate_concept_path_rejects_backslash():
|
|||
def test_validate_concept_path_rejects_non_md():
|
||||
with pytest.raises(OKFPathError):
|
||||
validate_concept_path("tables/users.txt")
|
||||
|
||||
|
||||
# --- T3: resource-URL https allowlist reject-gate ----------------------------
|
||||
# OKF imposes NO scheme constraint on `resource` (verified against SPEC.md), so
|
||||
# this default-deny allowlist is the only gate: accept https, reject all else
|
||||
# BEFORE commit — reject, not defang (that is neutralize's job, for human audit).
|
||||
|
||||
def test_validate_resource_url_accepts_https():
|
||||
assert validate_resource_url("https://example.com/asset") == "https://example.com/asset"
|
||||
|
||||
|
||||
def test_validate_resource_url_accepts_https_case_insensitive_scheme():
|
||||
assert validate_resource_url("HTTPS://example.com") == "HTTPS://example.com"
|
||||
|
||||
|
||||
def test_validate_resource_url_rejects_http():
|
||||
with pytest.raises(OKFResourceError):
|
||||
validate_resource_url("http://example.com/asset")
|
||||
|
||||
|
||||
def test_validate_resource_url_rejects_data():
|
||||
with pytest.raises(OKFResourceError):
|
||||
validate_resource_url("data:text/html,<script>alert(1)</script>")
|
||||
|
||||
|
||||
def test_validate_resource_url_rejects_javascript():
|
||||
with pytest.raises(OKFResourceError):
|
||||
validate_resource_url("javascript:alert(1)")
|
||||
|
||||
|
||||
def test_validate_resource_url_rejects_file():
|
||||
with pytest.raises(OKFResourceError):
|
||||
validate_resource_url("file:///etc/passwd")
|
||||
|
||||
|
||||
def test_validate_resource_url_rejects_ftp():
|
||||
with pytest.raises(OKFResourceError):
|
||||
validate_resource_url("ftp://host/x")
|
||||
|
||||
|
||||
def test_validate_resource_url_rejects_schemeless():
|
||||
with pytest.raises(OKFResourceError):
|
||||
validate_resource_url("example.com/asset")
|
||||
|
||||
|
||||
def test_validate_resource_url_rejects_empty():
|
||||
with pytest.raises(OKFResourceError):
|
||||
validate_resource_url("")
|
||||
|
||||
|
||||
def test_validate_resource_url_rejects_embedded_whitespace():
|
||||
# a space-split URL can smuggle a second target past a naive consumer parser
|
||||
with pytest.raises(OKFResourceError):
|
||||
validate_resource_url("https://good.example/x javascript:alert(1)")
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue