Archived
Remove documentation-only IP validation from DNS record checks
This commit is contained in:
@@ -478,13 +478,6 @@ func validateDNSRecordContentForTypeWithKnowledge(recordType string, content *st
|
|||||||
diagnostics.AddError("Invalid DNS record content", fmt.Sprintf("Record type %q requires an IPv6 address, got %q.", normalizedType, trimmedContent))
|
diagnostics.AddError("Invalid DNS record content", fmt.Sprintf("Record type %q requires an IPv6 address, got %q.", normalizedType, trimmedContent))
|
||||||
return false
|
return false
|
||||||
}
|
}
|
||||||
if isDocumentationAddress(addr) {
|
|
||||||
diagnostics.AddError(
|
|
||||||
"Unsupported documentation IP address",
|
|
||||||
fmt.Sprintf("Dynu rejects documentation-only address ranges for live DNS records. Replace %q with a real routable address under your control.", trimmedContent),
|
|
||||||
)
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
return true
|
return true
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -511,22 +504,6 @@ func validateDNSRecordContentForTypeWithKnowledge(recordType string, content *st
|
|||||||
return true
|
return true
|
||||||
}
|
}
|
||||||
|
|
||||||
func isDocumentationAddress(addr netip.Addr) bool {
|
|
||||||
if addr.Is4() {
|
|
||||||
v4 := addr.As4()
|
|
||||||
return (v4[0] == 192 && v4[1] == 0 && v4[2] == 2) ||
|
|
||||||
(v4[0] == 198 && v4[1] == 51 && v4[2] == 100) ||
|
|
||||||
(v4[0] == 203 && v4[1] == 0 && v4[2] == 113)
|
|
||||||
}
|
|
||||||
|
|
||||||
if addr.Is6() {
|
|
||||||
v6 := addr.As16()
|
|
||||||
return v6[0] == 0x20 && v6[1] == 0x01 && v6[2] == 0x0d && v6[3] == 0xb8
|
|
||||||
}
|
|
||||||
|
|
||||||
return false
|
|
||||||
}
|
|
||||||
|
|
||||||
func resolveDynamicIntent(recordType string, content types.String, dynamic types.Bool, diagnostics *diag.Diagnostics) (bool, bool) {
|
func resolveDynamicIntent(recordType string, content types.String, dynamic types.Bool, diagnostics *diag.Diagnostics) (bool, bool) {
|
||||||
normalizedType := strings.ToUpper(strings.TrimSpace(recordType))
|
normalizedType := strings.ToUpper(strings.TrimSpace(recordType))
|
||||||
contentPtr := stringPointerFromOptionalContent(content)
|
contentPtr := stringPointerFromOptionalContent(content)
|
||||||
|
|||||||
@@ -28,6 +28,11 @@ func TestParseDNSRecordIDInvalid(t *testing.T) {
|
|||||||
func TestValidateDNSRecordContentForType(t *testing.T) {
|
func TestValidateDNSRecordContentForType(t *testing.T) {
|
||||||
ipv4 := "8.8.8.8"
|
ipv4 := "8.8.8.8"
|
||||||
ipv6 := "2606:4700:4700::1111"
|
ipv6 := "2606:4700:4700::1111"
|
||||||
|
docIPv4A := "192.0.2.123"
|
||||||
|
docIPv4B := "198.51.100.123"
|
||||||
|
docIPv4C := "203.0.113.123"
|
||||||
|
docIPv6 := "2001:db8::123"
|
||||||
|
nonIP := "not-an-ip"
|
||||||
nonEmpty := "hello"
|
nonEmpty := "hello"
|
||||||
blank := ""
|
blank := ""
|
||||||
|
|
||||||
@@ -39,10 +44,16 @@ func TestValidateDNSRecordContentForType(t *testing.T) {
|
|||||||
wantValid bool
|
wantValid bool
|
||||||
}{
|
}{
|
||||||
{name: "A accepts static ipv4", recordType: "A", content: &ipv4, wantValid: true},
|
{name: "A accepts static ipv4", recordType: "A", content: &ipv4, wantValid: true},
|
||||||
|
{name: "A accepts documentation ipv4 192.0.2.0/24", recordType: "A", content: &docIPv4A, wantValid: true},
|
||||||
|
{name: "A accepts documentation ipv4 198.51.100.0/24", recordType: "A", content: &docIPv4B, wantValid: true},
|
||||||
|
{name: "A accepts documentation ipv4 203.0.113.0/24", recordType: "A", content: &docIPv4C, wantValid: true},
|
||||||
|
{name: "A rejects non-ip", recordType: "A", content: &nonIP, wantValid: false},
|
||||||
{name: "A rejects ipv6", recordType: "A", content: &ipv6, wantValid: false},
|
{name: "A rejects ipv6", recordType: "A", content: &ipv6, wantValid: false},
|
||||||
{name: "A accepts dynamic nil", recordType: "A", content: nil, dynamic: true, wantValid: true},
|
{name: "A accepts dynamic nil", recordType: "A", content: nil, dynamic: true, wantValid: true},
|
||||||
{name: "A accepts dynamic blank", recordType: "A", content: &blank, dynamic: true, wantValid: true},
|
{name: "A accepts dynamic blank", recordType: "A", content: &blank, dynamic: true, wantValid: true},
|
||||||
{name: "AAAA accepts static ipv6", recordType: "AAAA", content: &ipv6, wantValid: true},
|
{name: "AAAA accepts static ipv6", recordType: "AAAA", content: &ipv6, wantValid: true},
|
||||||
|
{name: "AAAA accepts documentation ipv6 2001:db8::/32", recordType: "AAAA", content: &docIPv6, wantValid: true},
|
||||||
|
{name: "AAAA rejects non-ip", recordType: "AAAA", content: &nonIP, wantValid: false},
|
||||||
{name: "AAAA rejects ipv4", recordType: "AAAA", content: &ipv4, wantValid: false},
|
{name: "AAAA rejects ipv4", recordType: "AAAA", content: &ipv4, wantValid: false},
|
||||||
{name: "AAAA accepts dynamic nil", recordType: "AAAA", content: nil, dynamic: true, wantValid: true},
|
{name: "AAAA accepts dynamic nil", recordType: "AAAA", content: nil, dynamic: true, wantValid: true},
|
||||||
{name: "TXT requires content", recordType: "TXT", content: nil, wantValid: false},
|
{name: "TXT requires content", recordType: "TXT", content: nil, wantValid: false},
|
||||||
|
|||||||
Reference in New Issue
Block a user