Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Capture environment variables πŸ’―πŸŽ‰ #41

Merged
merged 2 commits into from
Mar 8, 2018
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions src/Pidget.AspNet/RequestDataProvider.cs
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,7 @@ public RequestData GetRequestData(HttpRequest request)
Cookies = GetCookies(request),
Headers = GetHeaders(request),
QueryString = GetQueryString(request),
Environment = GetEnvironmentVariables()
};

public string GetUrl(HttpRequest request)
Expand Down Expand Up @@ -57,6 +58,9 @@ public IDictionary<string, string> GetForm(HttpRequest request)
? _sanitizer.SanitizeForm(request)
: null;

public IDictionary<string, string> GetEnvironmentVariables()
=> _sanitizer.GetSanitizedEnvironmentVairables();

private bool IsUrlEncodedForm(string contentType)
=> contentType != null && contentType.Equals(
value: "application/x-www-form-urlencoded",
Expand Down
9 changes: 9 additions & 0 deletions src/Pidget.AspNet/Sanitizing/RequestSanitizer.cs
Original file line number Diff line number Diff line change
Expand Up @@ -30,6 +30,15 @@ public IDictionary<string, string> SanitizeCookies(HttpRequest request)
public IDictionary<string, string> SanitizeQuery(HttpRequest request)
=> request.Query.ToDictionary(k => k.Key, SanitizeHeaderValue);

public IDictionary<string, string> GetSanitizedEnvironmentVairables()
{
var envVars = Environment.GetEnvironmentVariables();

return envVars.Keys.Cast<string>()
.ToDictionary(k => k, k
=> SanitizeValue(k, (string)envVars[k]));
}

private string SanitizeCookieValue(
KeyValuePair<string, string> kvp)
=> IsAuth(kvp.Key) || IsSession(kvp.Key)
Expand Down
15 changes: 15 additions & 0 deletions test/Pidget.AspNet.Test/RequestDataProviderTests.cs
Original file line number Diff line number Diff line change
Expand Up @@ -190,6 +190,17 @@ public void NullForm_ReturnsNull()
Assert.Null(form);
}

[Theory, InlineData("ASPNET_ENVIRONMENT", "Development")]
public void SetsEnvironmentVariables(string name, string value)
{
Environment.SetEnvironmentVariable(name, value);

var envVars = RequestData.GetEnvironmentVariables();

Assert.Contains(name, envVars.Keys);
Assert.Contains(value, envVars.Values);
}

public void GetData()
{
var requestMock = new Mock<HttpRequest>();
Expand Down Expand Up @@ -229,6 +240,8 @@ public void GetData()
PairsToDictionary(new[] { "foo=bar" }, s => new StringValues(s))))
.Verifiable();

Environment.SetEnvironmentVariable("foo", "bar");

var request = RequestData.GetRequestData(requestMock.Object);

requestMock.Verify();
Expand All @@ -239,6 +252,8 @@ public void GetData()
Assert.NotNull(request.Headers);
Assert.NotNull(request.Cookies);
Assert.NotNull(request.Data);
Assert.True(request.Environment
.Contains(new KeyValuePair<string, string>("foo", "bar")));
}

private static Dictionary<string, TValue> PairsToDictionary<TValue>(
Expand Down
14 changes: 14 additions & 0 deletions test/Pidget.AspNet.Test/RequestSanitizerTests.cs
Original file line number Diff line number Diff line change
Expand Up @@ -119,5 +119,19 @@ public void GetQuery_ReturnsProvidedQuery(string query, string expectedQuery)
Assert.Equal(expectedQuery,
actual: QueryString.Create(sanitizedParams).ToUriComponent());
}

[Theory, InlineData("password", "foo", "OMITTED")]
public void SanitizesEnvironmentVariables(string name,
string value,
string expectedValue)
{
Environment.SetEnvironmentVariable(name, value);

var sanitizedParams = RequestSanitizer.Default
.GetSanitizedEnvironmentVairables();

Assert.Equal(expectedValue,
actual: sanitizedParams[name]);
}
}
}