Published source
Download source ZIP
CH-J Server Manager
Browse directories and files for a specific application release.
Source is provided under the CH-J Proprietary Software License 1.14. Its availability does not change the license terms or grant additional rights.
1
"use strict";3
const test = require("node:test");4
const assert = require("node:assert/strict");5
const fs = require("node:fs");6
const path = require("node:path");7
const { createTestHttpsFetch } = require("../src/main/security/testHttpsFetch");9
test("test HTTPS transport rejects HTTP and foreign HTTPS origins before connecting", async () => {10
const testFetch = createTestHttpsFetch({ allowedBaseUrls: ["https://sm.ch-j.de/"] });11
await assert.rejects(() => testFetch("http://sm.ch-j.de/api/releases.php"), /outside/);12
await assert.rejects(() => testFetch("https://example.com/api/releases.php"), /outside/);13
});15
test("test HTTPS transport refuses automatic redirects", async () => {16
const testFetch = createTestHttpsFetch({ allowedBaseUrls: ["https://sm.ch-j.de/"] });17
await assert.rejects(18
() => testFetch("https://sm.ch-j.de/api/releases.php", { redirect: "follow" }),19
/must not follow redirects/20
);21
});23
test("the temporary CA exception is restricted to the single configured HTTPS domain", () => {24
const source = fs.readFileSync(path.join(__dirname, "..", "src", "main", "security", "testHttpsFetch.js"), "utf8");25
const bootstrap = fs.readFileSync(path.join(__dirname, "..", "src", "main", "index.js"), "utf8");26
const config = fs.readFileSync(path.join(__dirname, "..", "src", "main", "config", "configStore.js"), "utf8");27
assert.match(source, /rejectUnauthorized:\s*!insecureOrigins\.has\(url\.origin\)/);28
assert.match(source, /insecure test origin must also be explicitly allowed/i);29
assert.match(source, /minVersion:\s*"TLSv1\.2"/);30
assert.match(source, /maxVersion:\s*"TLSv1\.3"/);31
assert.match(bootstrap, /insecureBaseUrls:\s*\["https:\/\/sm\.ch-j\.de\/"\]/);32
assert.match(config, /https:\/\/www\.sm\.ch-j\.de\//);33
assert.match(config, /https:\/\/sm\.ch-j\.de\//);34
assert.doesNotMatch(config, /192\.168\.10\.154/);35
assert.throws(() => createTestHttpsFetch({36
allowedBaseUrls: ["https://sm.ch-j.de/"],37
insecureBaseUrls: ["https://example.com/"]38
}), /must also be explicitly allowed/);39
});SHA-256: 5d099ddf13f4420cad7e1dd2935eaacf7779f70f522f53e62dc3c1fbc733fa83
Archive SHA-256: 5ac91caf4fa32a6fdb114f2430deed486fbe7489d5eea343d1f034169fafb5e0