mirror of
https://github.com/appwrite/appwrite.git
synced 2026-05-26 13:51:13 +00:00
Support empty CAA records
This commit is contained in:
@@ -8,10 +8,10 @@ use Utopia\Validator;
|
||||
|
||||
class DNS extends Validator
|
||||
{
|
||||
public const RECORD_A = 'a';
|
||||
public const RECORD_AAAA = 'aaaa';
|
||||
public const RECORD_CNAME = 'cname';
|
||||
public const RECORD_CAA = 'caa'; // You can provide domain only (as $target) for CAA validation
|
||||
public const RECORD_A = 'A';
|
||||
public const RECORD_AAAA = 'AAAA';
|
||||
public const RECORD_CNAME = 'CNAME';
|
||||
public const RECORD_CAA = 'CAA'; // You can provide domain only (as $target) for CAA validation
|
||||
|
||||
/**
|
||||
* @var mixed
|
||||
@@ -57,7 +57,7 @@ class DNS extends Validator
|
||||
$dns = new Client($dnsServer);
|
||||
|
||||
try {
|
||||
$query = $dns->query($value, strtoupper($this->type));
|
||||
$query = $dns->query($value, $this->type);
|
||||
$this->logs = $query;
|
||||
} catch (\Exception $e) {
|
||||
$this->logs = ['error' => $e->getMessage()];
|
||||
@@ -65,10 +65,21 @@ class DNS extends Validator
|
||||
}
|
||||
|
||||
if (empty($query)) {
|
||||
// No CAA records means anyone can issue certificate
|
||||
if ($this->type === self::RECORD_CAA) {
|
||||
return true;
|
||||
}
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
$caaCount = 0;
|
||||
|
||||
foreach ($query as $record) {
|
||||
if ($record->getTypeName() === self::RECORD_CAA) {
|
||||
$caaCount++;
|
||||
}
|
||||
|
||||
// CAA validation only needs to ensure domain
|
||||
if ($this->type === self::RECORD_CAA) {
|
||||
// Extract domain; comments showcase extraction steps in most complex scenario
|
||||
@@ -87,6 +98,11 @@ class DNS extends Validator
|
||||
}
|
||||
}
|
||||
|
||||
if ($this->type === self::RECORD_CAA && $caaCount === 0) {
|
||||
// No CAA records, means anyone can issue certificate
|
||||
return true;
|
||||
}
|
||||
|
||||
return false;
|
||||
}
|
||||
|
||||
|
||||
@@ -52,10 +52,7 @@ class DNSTest extends TestCase
|
||||
{
|
||||
$validator = new DNS('digicert.com', DNS::RECORD_CAA);
|
||||
$this->assertEquals($validator->isValid('github.com'), true);
|
||||
$this->assertEquals($validator->isValid(''), false);
|
||||
$this->assertEquals($validator->isValid(null), false);
|
||||
$this->assertEquals($validator->isValid(false), false);
|
||||
$this->assertEquals($validator->isValid('test1.appwrite.org'), false);
|
||||
$this->assertEquals($validator->isValid('test1.appwrite.org'), true);
|
||||
|
||||
$validator = new DNS('0 issue "digicert.com"', DNS::RECORD_CAA);
|
||||
$this->assertEquals($validator->isValid('github.com'), true);
|
||||
@@ -67,6 +64,14 @@ class DNSTest extends TestCase
|
||||
$this->assertEquals($validator->isValid('github.com'), false);
|
||||
|
||||
$validator = new DNS('letsencrypt.org', DNS::RECORD_CAA);
|
||||
$this->assertEquals($validator->isValid('test2.appwrite.org'), false);
|
||||
$this->assertEquals($validator->isValid('github.com'), false);
|
||||
|
||||
// Valid becasue no CAA record configured
|
||||
$validator = new DNS('anything.com', DNS::RECORD_CAA);
|
||||
$this->assertEquals($validator->isValid('cloud.appwrite.io'), true);
|
||||
|
||||
// Valid becasue no CAA record configured
|
||||
$validator = new DNS('something.org', DNS::RECORD_CAA);
|
||||
$this->assertEquals($validator->isValid('cloud.appwrite.io'), true);
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user