srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/internal/scope/scope_test.go
blob: fee5d4490662426e6c45efb8b5a650d18c081766 (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
package scope

import "testing"

func TestInScopeEmptyRulesMeansEverything(t *testing.T) {
	if !InScope(nil, "example.com") {
		t.Error("empty rule set should mean everything is in scope")
	}
	if !InScope([]Rule{}, "anything.at.all") {
		t.Error("empty rule set should mean everything is in scope")
	}
}

func TestInScopeAllDisabledMeansEverything(t *testing.T) {
	rules := []Rule{{Enabled: false, Pattern: "example.com"}}
	if !InScope(rules, "unrelated.org") {
		t.Error("no enabled rules should mean everything is in scope")
	}
}

func TestInScopeSubstringMatch(t *testing.T) {
	rules := []Rule{{Enabled: true, Pattern: "example.com"}}
	tests := []struct {
		host string
		want bool
	}{
		{"example.com", true},
		{"www.example.com", true},
		{"api.example.com", true},
		{"example.com.evil.org", true}, // substring containment, deliberately simple
		{"other.org", false},
	}
	for _, tt := range tests {
		if got := InScope(rules, tt.host); got != tt.want {
			t.Errorf("InScope(%q) = %v, want %v", tt.host, got, tt.want)
		}
	}
}

func TestInScopeCaseInsensitive(t *testing.T) {
	rules := []Rule{{Enabled: true, Pattern: "Example.COM"}}
	if !InScope(rules, "www.EXAMPLE.com") {
		t.Error("substring match should be case-insensitive")
	}
}

func TestInScopeRegex(t *testing.T) {
	rules := []Rule{{Enabled: true, Pattern: `(^|\.)example\.com$`, IsRegex: true}}
	tests := []struct {
		host string
		want bool
	}{
		{"example.com", true},
		{"api.example.com", true},
		{"notexample.com", false},
		{"example.com.evil.org", false},
	}
	for _, tt := range tests {
		if got := InScope(rules, tt.host); got != tt.want {
			t.Errorf("InScope(%q) = %v, want %v", tt.host, got, tt.want)
		}
	}
}

func TestInScopeInvalidRegexNeverMatches(t *testing.T) {
	rules := []Rule{{Enabled: true, Pattern: "(unclosed", IsRegex: true}}
	if InScope(rules, "example.com") {
		t.Error("an invalid regex rule should never match, not panic or false-positive")
	}
}

func TestInScopeMultipleRulesAnyMatch(t *testing.T) {
	rules := []Rule{
		{Enabled: true, Pattern: "example.com"},
		{Enabled: true, Pattern: "other.org"},
	}
	if !InScope(rules, "other.org") {
		t.Error("should match the second rule")
	}
	if InScope(rules, "unrelated.net") {
		t.Error("should not match either rule")
	}
}

func TestInScopeDisabledRuleIgnored(t *testing.T) {
	rules := []Rule{
		{Enabled: false, Pattern: "example.com"},
		{Enabled: true, Pattern: "other.org"},
	}
	if InScope(rules, "example.com") {
		t.Error("a disabled rule should not match")
	}
	if !InScope(rules, "other.org") {
		t.Error("the enabled rule should still match")
	}
}