|
229 | 229 | expect($hosts2)->not->toBeEmpty(); |
230 | 230 | }); |
231 | 231 |
|
232 | | -it('skips host validation for terminal auth routes', function () { |
233 | | - // These routes should be accessible with any Host header (for internal container communication) |
| 232 | +it('allows terminal auth requests from the local terminal server', function () { |
234 | 233 | $response = $this->postJson('/terminal/auth', [], [ |
235 | | - 'Host' => 'coolify:8080', // Internal Docker host |
| 234 | + 'Host' => '127.0.0.1:8080', |
236 | 235 | ]); |
237 | 236 |
|
238 | | - // Should not get 400 Bad Host (might get 401 Unauthorized instead) |
239 | 237 | expect($response->status())->not->toBe(400); |
240 | 238 | }); |
241 | 239 |
|
242 | | -it('skips host validation for terminal auth ips route', function () { |
243 | | - // These routes should be accessible with any Host header (for internal container communication) |
| 240 | +it('enforces host validation for terminal auth routes', function () { |
| 241 | + InstanceSettings::updateOrCreate( |
| 242 | + ['id' => 0], |
| 243 | + ['fqdn' => 'https://coolify.example.com'] |
| 244 | + ); |
| 245 | + Cache::forget('instance_settings_fqdn_host'); |
| 246 | + |
244 | 247 | $response = $this->postJson('/terminal/auth/ips', [], [ |
245 | | - 'Host' => 'soketi:6002', // Another internal Docker host |
| 248 | + 'Host' => 'evil.com', |
246 | 249 | ]); |
247 | 250 |
|
248 | | - // Should not get 400 Bad Host (might get 401 Unauthorized instead) |
249 | | - expect($response->status())->not->toBe(400); |
| 251 | + expect($response->status())->toBe(400); |
250 | 252 | }); |
251 | 253 |
|
252 | 254 | it('still enforces host validation for non-terminal routes', function () { |
|
0 commit comments