summaryrefslogtreecommitdiffstats
path: root/tests/test_htmlbuilder.cpp
diff options
context:
space:
mode:
Diffstat (limited to 'tests/test_htmlbuilder.cpp')
-rw-r--r--tests/test_htmlbuilder.cpp56
1 files changed, 56 insertions, 0 deletions
diff --git a/tests/test_htmlbuilder.cpp b/tests/test_htmlbuilder.cpp
index 38699f4..86a40cd 100644
--- a/tests/test_htmlbuilder.cpp
+++ b/tests/test_htmlbuilder.cpp
@@ -1,4 +1,6 @@
+#include <QSet>
#include <QtTest>
+#include "cidschemehandler.h"
#include "htmlbuilder.h"
class TestHtmlBuilder : public QObject
@@ -21,6 +23,7 @@ private slots:
void namespacesCidInStyleBlock();
void namespacesMultipleCidRefsOnOneLine();
void namespacesWhitespaceAroundEquals();
+ void namespacedKeyRejectsPrefixContainingSeparator();
};
void TestHtmlBuilder::escapesPlainText()
@@ -202,5 +205,58 @@ void TestHtmlBuilder::namespacesWhitespaceAroundEquals()
QVERIFY(html.contains(QStringLiteral("cid:m0!logo@example.org")));
}
+void TestHtmlBuilder::namespacedKeyRejectsPrefixContainingSeparator()
+{
+ // The property that actually matters, and holds even in release builds
+ // where Q_ASSERT is compiled out: distinct (prefix, id) pairs, drawn from
+ // the documented "m<index>" generator form plus hostile Content-IDs
+ // (including ones containing '!', a percent-encoded '!', and several
+ // '!'s), always produce distinct keys, and the key always splits at its
+ // FIRST '!' back to exactly the original prefix. That only holds because
+ // prefixes generated in the "m<index>" form are themselves '!'-free; the
+ // attacker only ever controls the id half, which sits after the first
+ // (and only guaranteed-separator) '!'.
+ const QStringList prefixes = { QStringLiteral("m0"), QStringLiteral("m1"),
+ QStringLiteral("m2"), QStringLiteral("m10") };
+ const QStringList hostileIds = {
+ QStringLiteral("logo@example.org"),
+ QStringLiteral("a!b@x"),
+ QStringLiteral("a!b!c@x"),
+ QStringLiteral("%21encoded@x"),
+ QStringLiteral(""),
+ QStringLiteral("!leading@x"),
+ QStringLiteral("trailing!@x"),
+ };
+
+ QSet<QString> seenKeys;
+ for (const QString &prefix : prefixes) {
+ for (const QString &id : hostileIds) {
+ const QString key = CidSchemeHandler::namespacedKey(prefix, id);
+
+ // Distinctness: no other (prefix, id) pair already produced this
+ // exact key.
+ QVERIFY2(!seenKeys.contains(key),
+ qPrintable(QStringLiteral("collision for key '%1'").arg(key)));
+ seenKeys.insert(key);
+
+ // Splitting at the FIRST '!' always recovers the original
+ // prefix, regardless of how many '!' the hostile id contributes.
+ const qsizetype sep = key.indexOf(QLatin1Char('!'));
+ QVERIFY(sep != -1);
+ QCOMPARE(key.left(sep), prefix);
+ QCOMPARE(key.mid(sep + 1), id);
+ }
+ }
+
+ // Same property, exercised through HtmlBuilder::namespaceCids, which
+ // performs the identical concatenation independently: the resulting URL
+ // must contain the CidSchemeHandler-computed key verbatim.
+ const QString html = HtmlBuilder::namespaceCids(
+ QStringLiteral("<img src=\"cid:a!b@x\">"), QStringLiteral("m0"));
+ const QString expectedKey = CidSchemeHandler::namespacedKey(
+ QStringLiteral("m0"), QStringLiteral("a!b@x"));
+ QVERIFY(html.contains(QStringLiteral("cid:%1").arg(expectedKey)));
+}
+
QTEST_MAIN(TestHtmlBuilder)
#include "test_htmlbuilder.moc"