You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

131 lines
7.0 KiB

  1. # frozen_string_literal: true
  2. require 'rails_helper'
  3. describe EmailMxValidator do
  4. describe '#validate' do
  5. let(:user) { double(email: 'foo@example.com', errors: double(add: nil)) }
  6. it 'does not add errors if there are no DNS records for an e-mail domain that is explicitly allowed' do
  7. old_whitelist = Rails.configuration.x.email_domains_whitelist
  8. Rails.configuration.x.email_domains_whitelist = 'example.com'
  9. resolver = double
  10. allow(resolver).to receive(:getresources).with('example.com', Resolv::DNS::Resource::IN::MX).and_return([])
  11. allow(resolver).to receive(:getresources).with('example.com', Resolv::DNS::Resource::IN::A).and_return([])
  12. allow(resolver).to receive(:getresources).with('example.com', Resolv::DNS::Resource::IN::AAAA).and_return([])
  13. allow(resolver).to receive(:timeouts=).and_return(nil)
  14. allow(Resolv::DNS).to receive(:open).and_yield(resolver)
  15. subject.validate(user)
  16. expect(user.errors).to_not have_received(:add)
  17. Rails.configuration.x.email_domains_whitelist = old_whitelist
  18. end
  19. it 'adds an error if there are no DNS records for the e-mail domain' do
  20. resolver = double
  21. allow(resolver).to receive(:getresources).with('example.com', Resolv::DNS::Resource::IN::MX).and_return([])
  22. allow(resolver).to receive(:getresources).with('example.com', Resolv::DNS::Resource::IN::A).and_return([])
  23. allow(resolver).to receive(:getresources).with('example.com', Resolv::DNS::Resource::IN::AAAA).and_return([])
  24. allow(resolver).to receive(:timeouts=).and_return(nil)
  25. allow(Resolv::DNS).to receive(:open).and_yield(resolver)
  26. subject.validate(user)
  27. expect(user.errors).to have_received(:add)
  28. end
  29. it 'adds an error if a MX record exists but does not lead to an IP' do
  30. resolver = double
  31. allow(resolver).to receive(:getresources).with('example.com', Resolv::DNS::Resource::IN::MX).and_return([double(exchange: 'mail.example.com')])
  32. allow(resolver).to receive(:getresources).with('example.com', Resolv::DNS::Resource::IN::A).and_return([])
  33. allow(resolver).to receive(:getresources).with('example.com', Resolv::DNS::Resource::IN::AAAA).and_return([])
  34. allow(resolver).to receive(:getresources).with('mail.example.com', Resolv::DNS::Resource::IN::A).and_return([])
  35. allow(resolver).to receive(:getresources).with('mail.example.com', Resolv::DNS::Resource::IN::AAAA).and_return([])
  36. allow(resolver).to receive(:timeouts=).and_return(nil)
  37. allow(Resolv::DNS).to receive(:open).and_yield(resolver)
  38. subject.validate(user)
  39. expect(user.errors).to have_received(:add)
  40. end
  41. it 'adds an error if the A record is blacklisted' do
  42. EmailDomainBlock.create!(domain: '1.2.3.4')
  43. resolver = double
  44. allow(resolver).to receive(:getresources).with('example.com', Resolv::DNS::Resource::IN::MX).and_return([])
  45. allow(resolver).to receive(:getresources).with('example.com', Resolv::DNS::Resource::IN::A).and_return([double(address: '1.2.3.4')])
  46. allow(resolver).to receive(:getresources).with('example.com', Resolv::DNS::Resource::IN::AAAA).and_return([])
  47. allow(resolver).to receive(:timeouts=).and_return(nil)
  48. allow(Resolv::DNS).to receive(:open).and_yield(resolver)
  49. subject.validate(user)
  50. expect(user.errors).to have_received(:add)
  51. end
  52. it 'adds an error if the AAAA record is blacklisted' do
  53. EmailDomainBlock.create!(domain: 'fd00::1')
  54. resolver = double
  55. allow(resolver).to receive(:getresources).with('example.com', Resolv::DNS::Resource::IN::MX).and_return([])
  56. allow(resolver).to receive(:getresources).with('example.com', Resolv::DNS::Resource::IN::A).and_return([])
  57. allow(resolver).to receive(:getresources).with('example.com', Resolv::DNS::Resource::IN::AAAA).and_return([double(address: 'fd00::1')])
  58. allow(resolver).to receive(:timeouts=).and_return(nil)
  59. allow(Resolv::DNS).to receive(:open).and_yield(resolver)
  60. subject.validate(user)
  61. expect(user.errors).to have_received(:add)
  62. end
  63. it 'adds an error if the MX record is blacklisted' do
  64. EmailDomainBlock.create!(domain: '2.3.4.5')
  65. resolver = double
  66. allow(resolver).to receive(:getresources).with('example.com', Resolv::DNS::Resource::IN::MX).and_return([double(exchange: 'mail.example.com')])
  67. allow(resolver).to receive(:getresources).with('example.com', Resolv::DNS::Resource::IN::A).and_return([])
  68. allow(resolver).to receive(:getresources).with('example.com', Resolv::DNS::Resource::IN::AAAA).and_return([])
  69. allow(resolver).to receive(:getresources).with('mail.example.com', Resolv::DNS::Resource::IN::A).and_return([double(address: '2.3.4.5')])
  70. allow(resolver).to receive(:getresources).with('mail.example.com', Resolv::DNS::Resource::IN::AAAA).and_return([])
  71. allow(resolver).to receive(:timeouts=).and_return(nil)
  72. allow(Resolv::DNS).to receive(:open).and_yield(resolver)
  73. subject.validate(user)
  74. expect(user.errors).to have_received(:add)
  75. end
  76. it 'adds an error if the MX IPv6 record is blacklisted' do
  77. EmailDomainBlock.create!(domain: 'fd00::2')
  78. resolver = double
  79. allow(resolver).to receive(:getresources).with('example.com', Resolv::DNS::Resource::IN::MX).and_return([double(exchange: 'mail.example.com')])
  80. allow(resolver).to receive(:getresources).with('example.com', Resolv::DNS::Resource::IN::A).and_return([])
  81. allow(resolver).to receive(:getresources).with('example.com', Resolv::DNS::Resource::IN::AAAA).and_return([])
  82. allow(resolver).to receive(:getresources).with('mail.example.com', Resolv::DNS::Resource::IN::A).and_return([])
  83. allow(resolver).to receive(:getresources).with('mail.example.com', Resolv::DNS::Resource::IN::AAAA).and_return([double(address: 'fd00::2')])
  84. allow(resolver).to receive(:timeouts=).and_return(nil)
  85. allow(Resolv::DNS).to receive(:open).and_yield(resolver)
  86. subject.validate(user)
  87. expect(user.errors).to have_received(:add)
  88. end
  89. it 'adds an error if the MX hostname is blacklisted' do
  90. EmailDomainBlock.create!(domain: 'mail.example.com')
  91. resolver = double
  92. allow(resolver).to receive(:getresources).with('example.com', Resolv::DNS::Resource::IN::MX).and_return([double(exchange: 'mail.example.com')])
  93. allow(resolver).to receive(:getresources).with('example.com', Resolv::DNS::Resource::IN::A).and_return([])
  94. allow(resolver).to receive(:getresources).with('example.com', Resolv::DNS::Resource::IN::AAAA).and_return([])
  95. allow(resolver).to receive(:getresources).with('mail.example.com', Resolv::DNS::Resource::IN::A).and_return([double(address: '2.3.4.5')])
  96. allow(resolver).to receive(:getresources).with('mail.example.com', Resolv::DNS::Resource::IN::AAAA).and_return([double(address: 'fd00::2')])
  97. allow(resolver).to receive(:timeouts=).and_return(nil)
  98. allow(Resolv::DNS).to receive(:open).and_yield(resolver)
  99. subject.validate(user)
  100. expect(user.errors).to have_received(:add)
  101. end
  102. end
  103. end