mirror of
https://github.com/Wei-Shaw/sub2api.git
synced 2026-10-06 14:33:10 +08:00
PR #5423 relaxed the email suffix whitelist: once a whitelist is configured, non-whitelisted registrable domains are each allowed to register one account. That behavior activated unconditionally. Add registration_email_domain_quota_enabled (default false) to gate it: - Off (default): restore pre-#5423 strict whitelist semantics — with a non-empty whitelist, non-whitelisted domains are rejected with EMAIL_SUFFIX_NOT_ALLOWED; the register/verify views restore the client-side whitelist pre-check and allowed-domain hint. - On: keep #5423 behavior — one account per non-whitelisted registrable domain (EMAIL_DOMAIN_REGISTRATION_LIMIT). - Empty whitelist keeps allowing all domains in both states. Gating lives in validateRegistrationEmailQuota and (as a race-safety backstop) createUserWithRegistrationEmailGuard; the repository-level domain lock + in-tx recheck is unchanged. The admin update field is *bool (omitted = keep current) so stale full-payload saves cannot silently flip the switch. Email binding and OAuth auto-signup keep their strict policy, and pending-OAuth bind-login for existing accounts is unaffected because the handler resolves existing emails before the quota check. Frontend adds the toggle to admin settings (zh/en copy; whitelist hint restored to strict wording, quota wording moved to the new toggle) and exposes the flag via public settings + SSR injection payload. Tests: #5423 quota tests now enable the switch explicitly; new default-off regression tests cover register/send-code/async/pending OAuth/OIDC create-account plus both register views; API contract JSON and the injection drift guard are updated.
75 lines
3.5 KiB
Go
75 lines
3.5 KiB
Go
//go:build unit
|
|
|
|
package service
|
|
|
|
import (
|
|
"context"
|
|
"testing"
|
|
|
|
"github.com/stretchr/testify/require"
|
|
)
|
|
|
|
func TestNormalizeRegistrationEmailSuffixWhitelist(t *testing.T) {
|
|
got, err := NormalizeRegistrationEmailSuffixWhitelist([]string{"example.com", "@EXAMPLE.COM", " @foo.bar ", "*.EDU.CN"})
|
|
require.NoError(t, err)
|
|
require.Equal(t, []string{"@example.com", "@foo.bar", "*.edu.cn"}, got)
|
|
}
|
|
|
|
func TestNormalizeRegistrationEmailSuffixWhitelist_Invalid(t *testing.T) {
|
|
for _, item := range []string{"@invalid_domain", "*.", "*", "*.@", "*.foo"} {
|
|
t.Run(item, func(t *testing.T) {
|
|
_, err := NormalizeRegistrationEmailSuffixWhitelist([]string{item})
|
|
require.Error(t, err)
|
|
})
|
|
}
|
|
}
|
|
|
|
func TestParseRegistrationEmailSuffixWhitelist(t *testing.T) {
|
|
got := ParseRegistrationEmailSuffixWhitelist(`["example.com","@foo.bar","*.EDU.CN","@invalid_domain","*.foo"]`)
|
|
require.Equal(t, []string{"@example.com", "@foo.bar", "*.edu.cn"}, got)
|
|
}
|
|
|
|
func TestIsRegistrationEmailSuffixAllowed(t *testing.T) {
|
|
require.True(t, IsRegistrationEmailSuffixAllowed("user@example.com", []string{"@example.com"}))
|
|
require.True(t, IsRegistrationEmailSuffixAllowed("user@example.com.", []string{"@example.com"}))
|
|
require.False(t, IsRegistrationEmailSuffixAllowed("user@sub.example.com", []string{"@example.com"}))
|
|
require.True(t, IsRegistrationEmailSuffixAllowed("user@qq.com", []string{"@qq.com"}))
|
|
require.False(t, IsRegistrationEmailSuffixAllowed("user@sub.qq.com", []string{"@qq.com"}))
|
|
require.True(t, IsRegistrationEmailSuffixAllowed("student@cs.edu.cn", []string{"*.edu.cn"}))
|
|
require.True(t, IsRegistrationEmailSuffixAllowed("student@edu.cn", []string{"*.edu.cn"}))
|
|
require.False(t, IsRegistrationEmailSuffixAllowed("student@foo.cn", []string{"*.edu.cn"}))
|
|
require.True(t, IsRegistrationEmailSuffixAllowed("user@a.com", []string{"@a.com", "*.b.cn"}))
|
|
require.True(t, IsRegistrationEmailSuffixAllowed("user@school.b.cn", []string{"@a.com", "*.b.cn"}))
|
|
require.True(t, IsRegistrationEmailSuffixAllowed("user@b.cn", []string{"@a.com", "*.b.cn"}))
|
|
require.False(t, IsRegistrationEmailSuffixAllowed("user@c.cn", []string{"@a.com", "*.b.cn"}))
|
|
require.True(t, IsRegistrationEmailSuffixAllowed("user@any.com", []string{}))
|
|
}
|
|
|
|
func TestRegistrationEmailQuotaRejectsMalformedDomainWhenWhitelistConfigured(t *testing.T) {
|
|
repo := &userRepoStub{}
|
|
svc := newAuthService(repo, map[string]string{
|
|
SettingKeyRegistrationEnabled: "true",
|
|
SettingKeyRegistrationEmailSuffixWhitelist: `["@example.com"]`,
|
|
SettingKeyRegistrationEmailDomainQuotaEnabled: "true",
|
|
}, nil, nil)
|
|
|
|
_, _, err := svc.Register(context.Background(), "malformed-email", "password")
|
|
|
|
require.ErrorIs(t, err, ErrEmailSuffixNotAllowed)
|
|
require.Empty(t, repo.created)
|
|
}
|
|
|
|
func TestIsRegistrationEmailSuffixLimited(t *testing.T) {
|
|
require.False(t, IsRegistrationEmailSuffixLimited("user@custom.example", nil))
|
|
require.False(t, IsRegistrationEmailSuffixLimited("user@example.com", []string{"@example.com"}))
|
|
require.True(t, IsRegistrationEmailSuffixLimited("user@custom.example", []string{"@example.com"}))
|
|
}
|
|
|
|
func TestRegistrationEmailDomainUsesRegistrableDomain(t *testing.T) {
|
|
require.Equal(t, "abc.com", RegistrationEmailDomain("user@abc.com"))
|
|
require.Equal(t, "abc.com", RegistrationEmailDomain("user@abcd.abc.com"))
|
|
require.Equal(t, "example.co.uk", RegistrationEmailDomain("user@team.example.co.uk"))
|
|
require.Equal(t, "example.com", RegistrationEmailDomain("user@example.com."))
|
|
require.Equal(t, "example.com", RegistrationEmailDomain("user@team.example.com."))
|
|
}
|