Spaces:
Sleeping
Sleeping
Claude
Claude Sonnet 5
Add rate limiting, tests, better extraction, and HF auto-deploy
ebab0e2 unverified Download tests/test_security.py from Almaatla/web-scraper: direct link, hf CLI and curl.
- Browser
- Download file 2.44 kB
-
https://huggingface.co/spaces/Almaatla/web-scraper/resolve/main/tests/test_security.py
- Command line
-
hf download hf://spaces/Almaatla/web-scraper/tests/test_security.py
-
curl -L -o test_security.py https://huggingface.co/spaces/Almaatla/web-scraper/resolve/main/tests/test_security.py
2.44 kB
| import pytest | |
| from app.errors import ScrapeError | |
| from app.security import assert_url_is_safe | |
| def test_blocks_private_and_loopback_targets(url): | |
| with pytest.raises(ScrapeError) as exc_info: | |
| assert_url_is_safe(url) | |
| assert exc_info.value.status_code == 400 | |
| def test_blocks_disallowed_schemes(url): | |
| with pytest.raises(ScrapeError) as exc_info: | |
| assert_url_is_safe(url) | |
| assert exc_info.value.status_code == 400 | |
| def test_blocks_explicit_blocklisted_hostname(): | |
| with pytest.raises(ScrapeError): | |
| assert_url_is_safe("http://metadata.google.internal/") | |
| def test_blocks_hostname_that_fails_to_resolve(): | |
| def fake_resolver(hostname, port): | |
| raise OSError("name resolution failed") | |
| with pytest.raises(ScrapeError) as exc_info: | |
| assert_url_is_safe("http://this-does-not-resolve.invalid/", resolver=fake_resolver) | |
| assert exc_info.value.status_code == 400 | |
| def test_blocks_hostname_that_resolves_to_a_private_address_via_injected_resolver(): | |
| # Simulates DNS rebinding / an attacker-controlled domain that resolves | |
| # to an internal address, without depending on real DNS in the test. | |
| def fake_resolver(hostname, port): | |
| return [(2, 1, 6, "", ("10.1.2.3", 0))] | |
| with pytest.raises(ScrapeError) as exc_info: | |
| assert_url_is_safe("http://evil.example.com/", resolver=fake_resolver) | |
| assert exc_info.value.status_code == 400 | |
| def test_allows_public_targets(url): | |
| def fake_resolver(hostname, port): | |
| return [(2, 1, 6, "", ("93.184.216.34", 0))] | |
| assert_url_is_safe(url, resolver=fake_resolver) | |
| def test_missing_hostname_is_rejected(): | |
| with pytest.raises(ScrapeError) as exc_info: | |
| assert_url_is_safe("http:///no-host") | |
| assert exc_info.value.status_code == 400 | |