Skip to content

Commit

Permalink
Revert "Mocked network calls made in SSRFVulnerabilityTest. (#447)"
Browse files Browse the repository at this point in the history
This reverts commit 98cecd1.
  • Loading branch information
zhraa1992 authored Dec 3, 2023
1 parent 2916763 commit 8d3aea0
Show file tree
Hide file tree
Showing 2 changed files with 9 additions and 29 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -68,24 +68,20 @@ private ResponseEntity<GenericVulnerabilityResponseBean<String>> invalidUrlRespo
MetaDataServiceMock.getResponse(u), true),
HttpStatus.OK);
} else {
return new ResponseEntity<>(
new GenericVulnerabilityResponseBean<>(
getResponseForURLConnection(u), true),
HttpStatus.OK);
URLConnection urlConnection = u.openConnection();
try (BufferedReader reader =
new BufferedReader(new InputStreamReader(urlConnection.getInputStream()))) {
return new ResponseEntity<>(
new GenericVulnerabilityResponseBean<>(
reader.lines().collect(Collectors.joining()), true),
HttpStatus.OK);
}
}
} else {
return invalidUrlResponse();
}
}

String getResponseForURLConnection(URL u) throws IOException {
URLConnection urlConnection = u.openConnection();
try (BufferedReader reader =
new BufferedReader(new InputStreamReader(urlConnection.getInputStream()))) {
return reader.lines().collect(Collectors.joining());
}
}

@AttackVector(
vulnerabilityExposed = VulnerabilityType.SIMPLE_SSRF,
description = "SSRF_VULNERABILITY_URL_WITHOUT_CHECK",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -3,18 +3,13 @@
import static org.junit.jupiter.api.Assertions.assertEquals;
import static org.junit.jupiter.api.Assertions.assertNotNull;
import static org.junit.jupiter.api.Assertions.assertTrue;
import static org.mockito.ArgumentMatchers.eq;
import static org.mockito.Mockito.doReturn;
import static org.mockito.Mockito.spy;

import java.io.File;
import java.io.IOException;
import java.net.URL;
import java.nio.file.Files;
import java.util.Collections;
import java.util.stream.Stream;
import org.junit.jupiter.api.BeforeAll;
import org.junit.jupiter.api.BeforeEach;
import org.junit.jupiter.api.io.TempDir;
import org.junit.jupiter.params.ParameterizedTest;
import org.junit.jupiter.params.provider.Arguments;
Expand All @@ -41,18 +36,7 @@ class SSRFVulnerabilityTest {

private static String tempFileUrl;

private SSRFVulnerability ssrfVulnerability;

@BeforeEach
void each() throws IOException {
SSRFVulnerability ssrfSpy = spy(new SSRFVulnerability(GIST_ID));
// mocks network calls
doReturn(GIST_URL_CONTENT).when(ssrfSpy).getResponseForURLConnection(eq(new URL(GIST_URL)));
doReturn(OTHER_URL_CONTENT)
.when(ssrfSpy)
.getResponseForURLConnection(eq(new URL(OTHER_URL)));
ssrfVulnerability = ssrfSpy;
}
private final SSRFVulnerability ssrfVulnerability = new SSRFVulnerability(GIST_ID);

@BeforeAll
static void setUp() throws IOException {
Expand Down

0 comments on commit 8d3aea0

Please sign in to comment.