mirror of
https://github.com/NousResearch/hermes-agent.git
synced 2026-07-31 19:16:29 +00:00
Systematic prune per AGENTS.md test policy, one pass over every major test tree (gateway, hermes_cli, tools, agent, run_agent, plugins, cli, cron, tui_gateway, honcho/openviking, root-level): - DELETE: source-reading tests (read_text/getsource on prod files), change-detector tests (exact catalog counts, model-name snapshots, config version literals), mock-echo tests (assert a mock returns what it was told), assertion-free/trivial tests, near-duplicate parametrizations (boundaries + one representative kept), async/sync twin duplicates, cosmetic within-file variations. - KEEP (mandatory): security/redaction/approval guards, message-role alternation invariants, prompt-caching/deterministic-call-id invariants, issue-number regression tests (deduped), E2E tests. - 6 test files deleted outright (script-style/no-assert or fully redundant); conftest.py, fakes/, fixtures/ untouched. - tests/acp/conftest.py added: autouse fixture stubs the live models.dev/GitHub/Copilot/Anthropic inventory fetches that ACP server tests performed on every session create — test_server.py 147s → 3.4s, and the tests are now genuinely hermetic. - Sleep-based slowness shrunk where safe (codex_ttfb_watchdog, compression_concurrent_fork, etc.); no wall-clock assertion tightened. Verification: full hermetic suite via scripts/run_tests.sh — 2439 files, 31,130 tests passed, 0 failed, 0 flaky retries, 315s wall (baseline: 583s wall, 13,564s subprocess CPU).
179 lines
6.6 KiB
Python
179 lines
6.6 KiB
Python
"""Tests for GHSA-ppp5-vxwm-4cf7 — Host-header validation.
|
|
|
|
DNS rebinding defence: a victim browser that has the dashboard open
|
|
could be tricked into fetching from an attacker-controlled hostname
|
|
that TTL-flips to 127.0.0.1. Same-origin / CORS checks won't help —
|
|
the browser now treats the attacker origin as same-origin. Validating
|
|
the Host header at the application layer rejects the attack.
|
|
"""
|
|
|
|
from __future__ import annotations
|
|
|
|
import sys
|
|
from pathlib import Path
|
|
|
|
import pytest
|
|
|
|
_repo = str(Path(__file__).resolve().parents[1])
|
|
if _repo not in sys.path:
|
|
sys.path.insert(0, _repo)
|
|
|
|
|
|
class TestHostHeaderValidator:
|
|
"""Unit test the _is_accepted_host helper directly — cheaper and
|
|
more thorough than spinning up the full FastAPI app."""
|
|
|
|
def test_loopback_bind_accepts_loopback_names(self):
|
|
from hermes_cli.web_server import _is_accepted_host
|
|
|
|
for bound in ("127.0.0.1", "localhost", "::1"):
|
|
for host_header in (
|
|
"127.0.0.1", "127.0.0.1:9119",
|
|
"localhost", "localhost:9119",
|
|
"[::1]", "[::1]:9119",
|
|
):
|
|
assert _is_accepted_host(host_header, bound), (
|
|
f"bound={bound} must accept host={host_header}"
|
|
)
|
|
|
|
|
|
def test_zero_zero_bind_accepts_anything(self):
|
|
"""0.0.0.0 means operator explicitly opted into all-interfaces
|
|
(requires --insecure). No Host-layer defence is possible — rely
|
|
on operator network controls."""
|
|
from hermes_cli.web_server import _is_accepted_host
|
|
|
|
for host in ("10.0.0.5", "evil.example", "my-server.corp.net"):
|
|
assert _is_accepted_host(host, "0.0.0.0")
|
|
assert _is_accepted_host(host + ":9119", "0.0.0.0")
|
|
|
|
def test_explicit_non_loopback_bind_requires_exact_match(self):
|
|
"""If the operator bound to a specific non-loopback hostname,
|
|
the Host header must match exactly."""
|
|
from hermes_cli.web_server import _is_accepted_host
|
|
|
|
assert _is_accepted_host("my-server.corp.net", "my-server.corp.net")
|
|
assert _is_accepted_host("my-server.corp.net:9119", "my-server.corp.net")
|
|
# Different host — reject
|
|
assert not _is_accepted_host("evil.example", "my-server.corp.net")
|
|
# Loopback — reject (we bound to a specific non-loopback name)
|
|
assert not _is_accepted_host("localhost", "my-server.corp.net")
|
|
|
|
def test_case_insensitive_comparison(self):
|
|
"""Host headers are case-insensitive per RFC — accept variations."""
|
|
from hermes_cli.web_server import _is_accepted_host
|
|
|
|
assert _is_accepted_host("LOCALHOST", "127.0.0.1")
|
|
assert _is_accepted_host("LocalHost:9119", "127.0.0.1")
|
|
|
|
|
|
class TestHostHeaderMiddleware:
|
|
"""End-to-end test via the FastAPI app — verify the middleware
|
|
rejects bad Host headers with 400."""
|
|
|
|
def test_rebinding_request_rejected(self):
|
|
from fastapi.testclient import TestClient
|
|
from hermes_cli.web_server import app
|
|
|
|
# Simulate start_server having set the bound_host
|
|
app.state.bound_host = "127.0.0.1"
|
|
try:
|
|
client = TestClient(app)
|
|
# The TestClient sends Host: testserver by default — which is
|
|
# NOT a loopback alias, so the middleware must reject it.
|
|
resp = client.get(
|
|
"/api/status",
|
|
headers={"Host": "evil.example"},
|
|
)
|
|
assert resp.status_code == 400
|
|
assert "Invalid Host header" in resp.json()["detail"]
|
|
finally:
|
|
# Clean up so other tests don't inherit the bound_host
|
|
if hasattr(app.state, "bound_host"):
|
|
del app.state.bound_host
|
|
|
|
|
|
def test_no_bound_host_skips_validation(self):
|
|
"""If app.state.bound_host isn't set (e.g. running under test
|
|
infra without calling start_server), middleware must pass through
|
|
rather than crash."""
|
|
from fastapi.testclient import TestClient
|
|
from hermes_cli.web_server import app
|
|
|
|
# Make sure bound_host isn't set
|
|
if hasattr(app.state, "bound_host"):
|
|
del app.state.bound_host
|
|
|
|
client = TestClient(app)
|
|
resp = client.get("/api/status")
|
|
# Should get through to the status endpoint, not a 400
|
|
assert resp.status_code != 400
|
|
|
|
|
|
class TestWebSocketHostOriginGuard:
|
|
"""WebSocket upgrades must enforce the same dashboard boundary as HTTP."""
|
|
|
|
def test_rebinding_websocket_host_is_rejected(self, monkeypatch):
|
|
from fastapi.testclient import TestClient
|
|
from starlette.websockets import WebSocketDisconnect
|
|
|
|
import hermes_cli.web_server as ws
|
|
|
|
monkeypatch.setattr(ws.app.state, "bound_host", "127.0.0.1", raising=False)
|
|
monkeypatch.setattr(ws, "_DASHBOARD_EMBEDDED_CHAT_ENABLED", True)
|
|
|
|
client = TestClient(ws.app)
|
|
url = f"/api/events?token={ws._SESSION_TOKEN}&channel=security-test"
|
|
with pytest.raises(WebSocketDisconnect) as exc:
|
|
with client.websocket_connect(
|
|
url,
|
|
headers={
|
|
"Host": "evil.example",
|
|
"Origin": "http://evil.example",
|
|
},
|
|
):
|
|
pass
|
|
|
|
assert exc.value.code == 4403
|
|
|
|
def test_rebinding_websocket_origin_is_rejected(self, monkeypatch):
|
|
from fastapi.testclient import TestClient
|
|
from starlette.websockets import WebSocketDisconnect
|
|
|
|
import hermes_cli.web_server as ws
|
|
|
|
monkeypatch.setattr(ws.app.state, "bound_host", "127.0.0.1", raising=False)
|
|
monkeypatch.setattr(ws, "_DASHBOARD_EMBEDDED_CHAT_ENABLED", True)
|
|
|
|
client = TestClient(ws.app)
|
|
url = f"/api/events?token={ws._SESSION_TOKEN}&channel=security-test"
|
|
with pytest.raises(WebSocketDisconnect) as exc:
|
|
with client.websocket_connect(
|
|
url,
|
|
headers={
|
|
"Host": "localhost:9119",
|
|
"Origin": "http://evil.example",
|
|
},
|
|
):
|
|
pass
|
|
|
|
assert exc.value.code == 4403
|
|
|
|
def test_loopback_websocket_host_and_origin_are_accepted(self, monkeypatch):
|
|
from fastapi.testclient import TestClient
|
|
|
|
import hermes_cli.web_server as ws
|
|
|
|
monkeypatch.setattr(ws.app.state, "bound_host", "127.0.0.1", raising=False)
|
|
monkeypatch.setattr(ws, "_DASHBOARD_EMBEDDED_CHAT_ENABLED", True)
|
|
|
|
client = TestClient(ws.app)
|
|
url = f"/api/events?token={ws._SESSION_TOKEN}&channel=security-test"
|
|
with client.websocket_connect(
|
|
url,
|
|
headers={
|
|
"Host": "localhost:9119",
|
|
"Origin": "http://localhost:9119",
|
|
},
|
|
):
|
|
pass
|