]> source.dussan.org Git - nextcloud-server.git/commitdiff
feat: add switch to disable dns pinning 40162/head
authorDaniel Kesselberg <mail@danielkesselberg.de>
Tue, 29 Aug 2023 15:20:16 +0000 (17:20 +0200)
committerbackportbot-nextcloud[bot] <backportbot-nextcloud[bot]@users.noreply.github.com>
Wed, 30 Aug 2023 13:07:55 +0000 (13:07 +0000)
Signed-off-by: Daniel Kesselberg <mail@danielkesselberg.de>
lib/private/Http/Client/ClientService.php
tests/lib/Http/Client/ClientServiceTest.php

index 532aa7f566ab5053410151355eb9c53f358d05a7..66f84e14c574087ba45a153b7291708d3e9c7348 100644 (file)
@@ -27,8 +27,8 @@ declare(strict_types=1);
 namespace OC\Http\Client;
 
 use GuzzleHttp\Client as GuzzleClient;
-use GuzzleHttp\HandlerStack;
 use GuzzleHttp\Handler\CurlHandler;
+use GuzzleHttp\HandlerStack;
 use GuzzleHttp\Middleware;
 use OCP\Diagnostics\IEventLogger;
 use OCP\Http\Client\IClient;
@@ -75,7 +75,9 @@ class ClientService implements IClientService {
        public function newClient(): IClient {
                $handler = new CurlHandler();
                $stack = HandlerStack::create($handler);
-               $stack->push($this->dnsPinMiddleware->addDnsPinning());
+               if ($this->config->getSystemValueBool('dns_pinning', true)) {
+                       $stack->push($this->dnsPinMiddleware->addDnsPinning());
+               }
                $stack->push(Middleware::tap(function (RequestInterface $request) {
                        $this->eventLogger->start('http:request', $request->getMethod() . " request to " . $request->getRequestTarget());
                }, function () {
index 40da0a2111c77895a42bae755a4d914494f17d42..3aae7ceae2555759cc18538e11189e60792f75bd 100644 (file)
@@ -12,8 +12,8 @@ declare(strict_types=1);
 namespace Test\Http\Client;
 
 use GuzzleHttp\Client as GuzzleClient;
-use GuzzleHttp\HandlerStack;
 use GuzzleHttp\Handler\CurlHandler;
+use GuzzleHttp\HandlerStack;
 use GuzzleHttp\Middleware;
 use OC\Http\Client\Client;
 use OC\Http\Client\ClientService;
@@ -32,6 +32,9 @@ class ClientServiceTest extends \Test\TestCase {
        public function testNewClient(): void {
                /** @var IConfig $config */
                $config = $this->createMock(IConfig::class);
+               $config->method('getSystemValueBool')
+                       ->with('dns_pinning', true)
+                       ->willReturn(true);
                /** @var ICertificateManager $certificateManager */
                $certificateManager = $this->createMock(ICertificateManager::class);
                $dnsPinMiddleware = $this->createMock(DnsPinMiddleware::class);
@@ -74,4 +77,52 @@ class ClientServiceTest extends \Test\TestCase {
                        $clientService->newClient()
                );
        }
+
+       public function testDisableDnsPinning(): void {
+               /** @var IConfig $config */
+               $config = $this->createMock(IConfig::class);
+               $config->method('getSystemValueBool')
+                       ->with('dns_pinning', true)
+                       ->willReturn(false);
+               /** @var ICertificateManager $certificateManager */
+               $certificateManager = $this->createMock(ICertificateManager::class);
+               $dnsPinMiddleware = $this->createMock(DnsPinMiddleware::class);
+               $dnsPinMiddleware
+                       ->expects($this->never())
+                       ->method('addDnsPinning')
+                       ->willReturn(function () {
+                       });
+               $remoteHostValidator = $this->createMock(IRemoteHostValidator::class);
+               $eventLogger = $this->createMock(IEventLogger::class);
+               $logger = $this->createMock(LoggerInterface::class);
+
+               $clientService = new ClientService(
+                       $config,
+                       $certificateManager,
+                       $dnsPinMiddleware,
+                       $remoteHostValidator,
+                       $eventLogger,
+                       $logger,
+               );
+
+               $handler = new CurlHandler();
+               $stack = HandlerStack::create($handler);
+               $stack->push(Middleware::tap(function (RequestInterface $request) use ($eventLogger) {
+                       $eventLogger->start('http:request', $request->getMethod() . " request to " . $request->getRequestTarget());
+               }, function () use ($eventLogger) {
+                       $eventLogger->end('http:request');
+               }), 'event logger');
+               $guzzleClient = new GuzzleClient(['handler' => $stack]);
+
+               $this->assertEquals(
+                       new Client(
+                               $config,
+                               $certificateManager,
+                               $guzzleClient,
+                               $remoteHostValidator,
+                               $logger,
+                       ),
+                       $clientService->newClient()
+               );
+       }
 }