consider IP address protected only if it is used for the chosen host (#1895)

* consider IP address protected only if it is used for the chosen host

* simplify

* simplify

* simplify

---------

Co-authored-by: Evgeny @ SimpleX Chat <259188159+evgeny-simplex@users.noreply.github.com>
This commit is contained in:
Evgeny
2026-10-03 22:45:44 +01:00
committed by GitHub
co-authored by Evgeny @ SimpleX Chat
parent 76248dd767
commit e11dfb985d
2 changed files with 23 additions and 3 deletions
+5 -2
View File
@@ -1261,9 +1261,12 @@ sendOrProxySMPCommand c nm userId destSrv@ProtocolServer {host = destHosts} conn
Left e -> throwE e
ipAddressProtected :: NetworkConfig -> ProtocolServer p -> Bool
ipAddressProtected NetworkConfig {socksProxy, hostMode} (ProtocolServer _ hosts _ _) = do
isJust socksProxy || (hostMode == HMOnion && any isOnionHost hosts)
ipAddressProtected NetworkConfig {socksProxy, socksMode, hostMode} (ProtocolServer _ hosts _ _)
| isJust socksProxy = socksMode == SMAlways || if hostMode == HMPublic then allOnion else anyOnion
| otherwise = hostMode == HMOnion && anyOnion
where
anyOnion = any isOnionHost hosts
allOnion = all isOnionHost hosts
isOnionHost = \case THOnionHost _ -> True; _ -> False
withNtfClient :: AgentClient -> NetworkRequestMode -> NtfServer -> EntityId -> ByteString -> (NtfClient -> ExceptT NtfClientError IO a) -> AM a
+18 -1
View File
@@ -2,15 +2,18 @@
{-# LANGUAGE NamedFieldPuns #-}
{-# LANGUAGE OverloadedLists #-}
{-# LANGUAGE OverloadedStrings #-}
{-# LANGUAGE PatternSynonyms #-}
{-# LANGUAGE TypeApplications #-}
{-# OPTIONS_GHC -fno-warn-ambiguous-fields #-}
module CoreTests.SOCKSSettings where
import Network.Socket (SockAddr (..), tupleToHostAddress)
import Simplex.Messaging.Agent.Client (ipAddressProtected)
import Simplex.Messaging.Client
import qualified Simplex.Messaging.Crypto as C
import Simplex.Messaging.Encoding.String
import Simplex.Messaging.Protocol (ErrorType)
import Simplex.Messaging.Protocol (ErrorType, pattern SMPServer)
import Simplex.Messaging.Transport.Client
import Test.Hspec hiding (fit, it)
import Util
@@ -19,6 +22,7 @@ socksSettingsTests :: Spec
socksSettingsTests = do
describe "hostMode and requiredHostMode settings" testHostMode
describe "socksMode setting, independent of hostMode setting" testSocksMode
describe "ipAddressProtected, consistent with chosen host and socksMode" testIPAddressProtected
describe "socks proxy address encoding" testSocksProxyEncoding
testPublicHost :: TransportHost
@@ -94,6 +98,19 @@ testSocksMode = do
let TransportClientConfig {socksProxy} = transportClientConfig cfg NRMInteractive host False Nothing
in socksProxy
testIPAddressProtected :: Spec
testIPAddressProtected = do
it "should be protected if SOCKS proxy is used for the chosen host" $ do
protected SMAlways HMOnionViaSocks [testPublicHost] `shouldBe` True
protected SMOnion HMOnionViaSocks [testPublicHost, testOnionHost] `shouldBe` True
protected SMOnion HMPublic [testOnionHost] `shouldBe` True
it "should not be protected if SOCKS proxy is not used for the chosen host" $ do
protected SMOnion HMOnionViaSocks [testPublicHost] `shouldBe` False
protected SMOnion HMPublic [testPublicHost, testOnionHost] `shouldBe` False
where
protected socksMode hostMode hosts =
ipAddressProtected defaultNetworkConfig {socksProxy = Just defaultSocksProxyWithAuth, socksMode, hostMode} (SMPServer hosts "" (C.KeyHash ""))
testSocksProxyEncoding :: Spec
testSocksProxyEncoding = do
it "should decode SOCKS proxy with isolate-by-auth mode" $ do