test(backend): add phone injection-security tests
Verify ValidateUKPhoneNumber rejects SQLi, XSS, command injection, and control character payloads. Also verifies mixed injection-wrapped numbers are rejected (libphonenumber doesn't extract digits from noise). Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-openagent) Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
This commit is contained in:
@@ -1469,5 +1469,59 @@ func TestLoginInProgress_Cap(t *testing.T) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// ValidateUKPhoneNumber Security Tests
|
||||||
|
//
|
||||||
|
// These tests verify that ValidateUKPhoneNumber rejects or sanitises
|
||||||
|
// injection payloads (SQLi, XSS, command injection, control characters).
|
||||||
|
|
||||||
|
func TestValidateUKPhoneNumber_RejectsPureInjectionPayloads(t *testing.T) {
|
||||||
|
payloads := []string{
|
||||||
|
// SQL injection
|
||||||
|
"' OR '1'='1",
|
||||||
|
"admin'--",
|
||||||
|
`" OR 1=1 --`,
|
||||||
|
"'; DROP TABLE users;--",
|
||||||
|
// XSS
|
||||||
|
"<script>alert(1)</script>",
|
||||||
|
"<img src=x onerror=alert(1)>",
|
||||||
|
"\"><script>alert(1)</script>",
|
||||||
|
"javascript:alert(1)",
|
||||||
|
// Command injection
|
||||||
|
"; rm -rf /",
|
||||||
|
"| cat /etc/passwd",
|
||||||
|
"`id`",
|
||||||
|
"$(cat /etc/passwd)",
|
||||||
|
// Control characters
|
||||||
|
"\n",
|
||||||
|
"\r\n",
|
||||||
|
"\x00",
|
||||||
|
}
|
||||||
|
for _, p := range payloads {
|
||||||
|
result, err := ValidateUKPhoneNumber(p)
|
||||||
|
if err == nil {
|
||||||
|
t.Errorf("expected injection payload %q to be rejected, got result %q", p, result)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestValidateUKPhoneNumber_RejectsMixedInjectionPayloads(t *testing.T) {
|
||||||
|
// When injection characters are interleaved with a valid UK phone number,
|
||||||
|
// libphonenumber rejects the entire input — it does NOT try to extract
|
||||||
|
// digits from non-numeric characters. This is MORE secure than naive
|
||||||
|
// digit-stripping approaches.
|
||||||
|
payloads := []string{
|
||||||
|
"' OR '1'='1 OR '+447700900000",
|
||||||
|
"><script>+447700900000</script>",
|
||||||
|
"'; rm -rf /; +447700900000",
|
||||||
|
"\x00\n+447700900000",
|
||||||
|
}
|
||||||
|
for _, p := range payloads {
|
||||||
|
result, err := ValidateUKPhoneNumber(p)
|
||||||
|
if err == nil {
|
||||||
|
t.Errorf("expected mixed payload %q to be rejected, got result %q", p, result)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
// Ensure test compilation - import pgxpool to avoid unused import
|
// Ensure test compilation - import pgxpool to avoid unused import
|
||||||
var _ = func() *pgxpool.Pool { return nil }
|
var _ = func() *pgxpool.Pool { return nil }
|
||||||
|
|||||||
Reference in New Issue
Block a user