srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/cmd/mitmux/csv_test.go
diff options
context:
space:
mode:
Diffstat (limited to 'cmd/mitmux/csv_test.go')
-rw-r--r--cmd/mitmux/csv_test.go84
1 files changed, 84 insertions, 0 deletions
diff --git a/cmd/mitmux/csv_test.go b/cmd/mitmux/csv_test.go
new file mode 100644
index 0000000..b2f6074
--- /dev/null
+++ b/cmd/mitmux/csv_test.go
@@ -0,0 +1,84 @@
+package main
+
+import (
+ "encoding/csv"
+ "strings"
+ "testing"
+ "time"
+
+ "mitmux/internal/store"
+)
+
+func TestCsvFromSummariesBasic(t *testing.T) {
+ entries := []store.Summary{
+ {ID: 1, Method: "GET", Scheme: "https", Host: "example.com", Path: "/a", StatusCode: 200, ReqSize: 100, RespSize: 200, Duration: 150 * time.Millisecond, Source: "proxy"},
+ }
+ out, err := csvFromSummaries(entries)
+ if err != nil {
+ t.Fatalf("unexpected error: %v", err)
+ }
+ r := csv.NewReader(strings.NewReader(out))
+ rows, err := r.ReadAll()
+ if err != nil {
+ t.Fatalf("output is not valid CSV: %v", err)
+ }
+ if len(rows) != 2 { // header + 1 row
+ t.Fatalf("expected 2 rows (header+1), got %d: %v", len(rows), rows)
+ }
+ if rows[1][0] != "1" || rows[1][3] != "example.com" || rows[1][5] != "200" {
+ t.Errorf("unexpected row content: %v", rows[1])
+ }
+}
+
+func TestCsvFromSummariesEmpty(t *testing.T) {
+ out, err := csvFromSummaries(nil)
+ if err != nil {
+ t.Fatalf("unexpected error: %v", err)
+ }
+ r := csv.NewReader(strings.NewReader(out))
+ rows, err := r.ReadAll()
+ if err != nil {
+ t.Fatalf("output is not valid CSV: %v", err)
+ }
+ if len(rows) != 1 { // header only
+ t.Fatalf("expected header-only output, got %d rows", len(rows))
+ }
+}
+
+func TestCsvSafeNeutralizesFormulaPrefixes(t *testing.T) {
+ tests := []struct {
+ in string
+ want string
+ }{
+ {"=cmd|'/c calc'!A1", "'=cmd|'/c calc'!A1"},
+ {"+1+1", "'+1+1"},
+ {"-1", "'-1"},
+ {"@SUM(A1)", "'@SUM(A1)"},
+ {"example.com", "example.com"},
+ {"", ""},
+ }
+ for _, tt := range tests {
+ if got := csvSafe(tt.in); got != tt.want {
+ t.Errorf("csvSafe(%q) = %q, want %q", tt.in, got, tt.want)
+ }
+ }
+}
+
+func TestCsvFromSummariesNeutralizesFormulaInjection(t *testing.T) {
+ entries := []store.Summary{
+ {ID: 1, Method: "GET", Scheme: "http", Host: "=cmd|'/c calc'!A1", Path: "/", StatusCode: 200},
+ }
+ out, err := csvFromSummaries(entries)
+ if err != nil {
+ t.Fatalf("unexpected error: %v", err)
+ }
+ r := csv.NewReader(strings.NewReader(out))
+ rows, err := r.ReadAll()
+ if err != nil {
+ t.Fatalf("output is not valid CSV: %v", err)
+ }
+ host := rows[1][3]
+ if !strings.HasPrefix(host, "'") {
+ t.Errorf("expected malicious host to be neutralized with a leading quote, got %q", host)
+ }
+}