|
12 | 12 | import static org.assertj.core.api.Assertions.assertThat; |
13 | 13 | import static org.mockito.Mockito.doReturn; |
14 | 14 |
|
| 15 | +import java.util.ArrayList; |
| 16 | +import java.util.Collections; |
| 17 | + |
15 | 18 | import javax.servlet.http.HttpServletRequest; |
16 | 19 |
|
17 | 20 | import org.junit.jupiter.api.AfterEach; |
@@ -100,9 +103,49 @@ public void testWithXForwarded() throws Exception { |
100 | 103 |
|
101 | 104 | // XForwarded content |
102 | 105 | doReturn("https").when(request).getHeader("X-Forwarded-Proto"); |
103 | | - doReturn("open-vsx.org").when(request).getHeader("X-Forwarded-Host"); |
| 106 | + var items = new ArrayList<String>(); |
| 107 | + items.add("open-vsx.org"); |
| 108 | + doReturn(Collections.enumeration(items)).when(request).getHeaders("X-Forwarded-Host"); |
104 | 109 | doReturn("/openvsx").when(request).getHeader("X-Forwarded-Prefix"); |
105 | 110 | assertThat(UrlUtil.getBaseUrl(request)).isEqualTo("https://open-vsx.org/openvsx/"); |
106 | | - } |
| 111 | + } |
| 112 | + |
| 113 | + // Check base URL is using array X-Forwarded-Host headers |
| 114 | + @Test |
| 115 | + public void testWithXForwardedHostArray() throws Exception { |
| 116 | + // basic request |
| 117 | + doReturn("http").when(request).getScheme(); |
| 118 | + doReturn("localhost").when(request).getServerName(); |
| 119 | + doReturn(8080).when(request).getServerPort(); |
| 120 | + doReturn("/").when(request).getContextPath(); |
| 121 | + |
| 122 | + // XForwarded content |
| 123 | + doReturn("https").when(request).getHeader("X-Forwarded-Proto"); |
| 124 | + var items = new ArrayList<String>(); |
| 125 | + items.add("open-vsx.org"); |
| 126 | + items.add("foo.com"); |
| 127 | + items.add("bar.com"); |
| 128 | + doReturn(Collections.enumeration(items)).when(request).getHeaders("X-Forwarded-Host"); |
| 129 | + doReturn("/openvsx").when(request).getHeader("X-Forwarded-Prefix"); |
| 130 | + assertThat(UrlUtil.getBaseUrl(request)).isEqualTo("https://open-vsx.org/openvsx/"); |
| 131 | + } |
| 132 | + |
| 133 | + // Check base URL is using comma separated X-Forwarded-Host headers |
| 134 | + @Test |
| 135 | + public void testWithXForwardedHostCommaSeparated() throws Exception { |
| 136 | + // basic request |
| 137 | + doReturn("http").when(request).getScheme(); |
| 138 | + doReturn("localhost").when(request).getServerName(); |
| 139 | + doReturn(8080).when(request).getServerPort(); |
| 140 | + doReturn("/").when(request).getContextPath(); |
| 141 | + |
| 142 | + // XForwarded content |
| 143 | + doReturn("https").when(request).getHeader("X-Forwarded-Proto"); |
| 144 | + var items = new ArrayList<String>(); |
| 145 | + items.add("open-vsx.org, foo.com, bar.com"); |
| 146 | + doReturn(Collections.enumeration(items)).when(request).getHeaders("X-Forwarded-Host"); |
| 147 | + doReturn("/openvsx").when(request).getHeader("X-Forwarded-Prefix"); |
| 148 | + assertThat(UrlUtil.getBaseUrl(request)).isEqualTo("https://open-vsx.org/openvsx/"); |
| 149 | + } |
107 | 150 |
|
108 | 151 | } |
0 commit comments