fix(socket): find a domain by the link that added it, not refuse it as a CIDR - #155
Conversation
…dd took domain.add saves example.com/page as example.com on the Bypass list through RouteManager.checkDomainInput, but parseTarget refused the same value as a malformed CIDR because it treated any slash without a scheme as a broken IP range. parseTarget now reads the value with checkDomainInput for each list it searches, so the lookup and the add follow one rule.
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: GeiserX/VPN-Bypass/.coderabbit.yaml Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (4)
Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 1 remain after this review. 📝 WalkthroughWalkthroughDomain lookups now validate raw input separately for each selected list and use each list’s accepted value as its lookup key. Tests cover host, URL, path, and CIDR inputs across lookup verbs. The usage documentation and changelog describe these rules. ChangesDomain lookup
Priority: ⬇️ Low Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to This change makes domain removal, enable and disable accept the same pasted links as domain add on the Bypass list, and it refuses malformed ranges. It has tests and documentation, and no merge-blocking risk is evident. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to Domain-management commands now follow each list’s existing acceptance rules. Same-user access checks and list-scoped selection remain intact, and no new security concern was identified in the reviewed path. Failure-recovery and deployment coverage remain limited. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
… lists Reading a link by the VPN Only add rule dropped that list from the search when no list= was given, so https://example.com acted on the Bypass entry of a domain on both lists, and missed one only on VPN Only. Without list=, a link is now looked up on VPN Only by its host too.
…e-enable # Conflicts: # docs/CHANGELOG.md
vpnb domain.add domain=example.com/pagesavesexample.comon the Bypass list. Removing, enabling or disabling it with that same value answeredinvalid_args: malformed CIDR. The cause wasClassicControl.parseTarget, which refused any/without://in front as a broken IP range, whiledomain.addgoes throughRouteManager.checkDomainInputand keeps the host.parseTargetnow runscheckDomainInputonce per list it searches, so add and lookup follow one rule:https://example.com/page,example.com/page,Example.com:8080/a?b=c) findsexample.com. An IP range is refused withthe bypass list holds domain names, not a CIDR. The old code looked it up and answerednot_found.list=vpnOnly. A value with a/must be a CIDR. Anything else is refused, asdomain.addrefuses it.list=. A link is looked up on both lists by its host. A domain on both lists still answersthat domain is on both lists; add list=bypass or list=vpnOnly, and a domain only on VPN Only is still found, as before. A range is looked up only on VPN Only. If every list refuses the value, the VPN Only reason comes back (malformed, or/0and/1).A malformed range like
10.0.0.0/33is still refused on every list and never trimmed to the host entry10.0.0.0. Nothing here writes a route, and the GUI does not change. The GUI removes and toggles by entry, so it never parses a typed value. One GUI add path does skipcheckDomainInput. In Custom mode the dropdown quick-add callsaddDomainRuleToDirect, which runs plaincleanDomain, so a typed10.0.0.0/24still becomes a domain rule for the host10.0.0.0. That was there before this PR and is left for its own fix.One change in behaviour to push back on if you disagree:
domain.rm domain=https://example.com list=vpnOnlynow returnsinvalid_args. It used to findexample.com. That is whatdomain.addsays for the same value on that list. Withoutlist=the same value behaves as it did on main.Tests. Five new cases in
ClassicControlTests: a bare host, an https link, a schemeless link with a path, and a link with a port and query, through add, disable, enable and rm on the Bypass list with and withoutlist=; links on VPN Only; a link with nolist=against a domain on both lists and one only on VPN Only; a real CIDR on each list; a malformed range through every verb on every list.origin/main'sClassicControl.swiftthey fail:testBypassLookupTakesEveryValueAddTakes,testCIDRLookupOnEachListandtestVPNOnlyLookupRefusesALinkWithASlashLikeAddgo red (example.com/page list=bypass: ... "malformed CIDR ...")..bypasssends five tests red, among themtestMalformedRangeIsRefusedByEveryVerbOnEveryListand the existingtestVPNOnlyDomainEnableDisable.list=host lookup on VPN Only sendstestLinkWithoutListSearchesBothListsByHostred:domain.disable https://example.comreturns ok instead of the both-lists answer, and with the entry only on VPN Only it returnsnot_found.Executed 1467 tests, with 10 tests skipped and 0 failures.Docs: the verb notes in
docs/usage.mdand an [Unreleased] Fixed entry indocs/CHANGELOG.md. Socket error text is English only like the rest of it, so there are no new strings and no screenshots. The MCP server'sremove_domainandset_domain_enabledpass the value through unchanged and get the new answers without a change on their side.