@@ -119,6 +119,60 @@ func TestValidateURLDomain(t *testing.T) {
119119 input : "https://example.stackit.cloud" ,
120120 isValid : true ,
121121 },
122+ {
123+ name : "apex domain" ,
124+ allowedUrlDomain : "stackit.cloud" ,
125+ input : "https://stackit.cloud/path" ,
126+ isValid : true ,
127+ },
128+ {
129+ name : "multiple subdomains" ,
130+ allowedUrlDomain : "stackit.cloud" ,
131+ input : "https://dns.api.stackit.cloud/v1" ,
132+ isValid : true ,
133+ },
134+ {
135+ name : "hostname suffix without label boundary" ,
136+ allowedUrlDomain : "stackit.cloud" ,
137+ input : "https://suspiciousstackit.cloud" ,
138+ isValid : false ,
139+ },
140+ {
141+ name : "lookalike subdomain" ,
142+ allowedUrlDomain : "stackit.cloud" ,
143+ input : "https://api.suspiciousstackit.cloud" ,
144+ isValid : false ,
145+ },
146+ {
147+ name : "domain followed by extra labels" ,
148+ allowedUrlDomain : "stackit.cloud" ,
149+ input : "https://api.stackit.cloud.evil.example" ,
150+ isValid : false ,
151+ },
152+ {
153+ name : "port is not hostname" ,
154+ allowedUrlDomain : "stackit.cloud" ,
155+ input : "https://stackit.cloud:443/v1" ,
156+ isValid : true ,
157+ },
158+ {
159+ name : "userinfo does not affect hostname" ,
160+ allowedUrlDomain : "stackit.cloud" ,
161+ input : "https://stackit.cloud@evil.example/path" ,
162+ isValid : false ,
163+ },
164+ {
165+ name : "path does not affect hostname" ,
166+ allowedUrlDomain : "stackit.cloud" ,
167+ input : "https://evil.example/path/stackit.cloud" ,
168+ isValid : false ,
169+ },
170+ {
171+ name : "hostname is case insensitive" ,
172+ allowedUrlDomain : "stackit.cloud" ,
173+ input : "https://API.STACKIT.CLOUD/path" ,
174+ isValid : true ,
175+ },
122176 {
123177 name : "STACKIT URL invalid" ,
124178 allowedUrlDomain : "example.com" ,
@@ -137,6 +191,12 @@ func TestValidateURLDomain(t *testing.T) {
137191 input : "https://www.test.example.com/" ,
138192 isValid : true ,
139193 },
194+ {
195+ name : "custom domain boundary rejected" ,
196+ allowedUrlDomain : "example.com" ,
197+ input : "https://badexample.com" ,
198+ isValid : false ,
199+ },
140200 {
141201 name : "every URL valid" ,
142202 allowedUrlDomain : "" ,
@@ -153,6 +213,24 @@ func TestValidateURLDomain(t *testing.T) {
153213 input : "http://example.stackit.cloud" ,
154214 isValid : false ,
155215 },
216+ {
217+ name : "invalid protocol with allowed domain" ,
218+ allowedUrlDomain : "stackit.cloud" ,
219+ input : "http://api.stackit.cloud" ,
220+ isValid : false ,
221+ },
222+ {
223+ name : "missing host" ,
224+ allowedUrlDomain : "stackit.cloud" ,
225+ input : "https:///path" ,
226+ isValid : false ,
227+ },
228+ {
229+ name : "malformed URL" ,
230+ allowedUrlDomain : "stackit.cloud" ,
231+ input : "https://%zz" ,
232+ isValid : false ,
233+ },
156234 {
157235 name : "no protocol" ,
158236 input : "example.stackit.cloud" ,
0 commit comments