From d39083412b8a139669a77b83690546e260dedc57 Mon Sep 17 00:00:00 2001 From: William Harrison <87287585+wdhdev@users.noreply.github.com> Date: Tue, 8 Jul 2025 20:48:07 +0800 Subject: [PATCH] feat(ci): disallowed cnames --- tests/records.test.js | 10 ++++++++++ util/disallowed-cnames.json | 3 +++ 2 files changed, 13 insertions(+) create mode 100644 util/disallowed-cnames.json diff --git a/tests/records.test.js b/tests/records.test.js index 2452c636ad..3d802451cf 100644 --- a/tests/records.test.js +++ b/tests/records.test.js @@ -88,6 +88,8 @@ function isValidHexadecimal(value) { return /^[0-9a-fA-F]+$/.test(value); } +const disallowedCNAMEs = require("../util/disallowed-cnames.json"); + function validateRecordValues(t, data, file) { const subdomain = file.replace(/\.json$/, ""); @@ -141,6 +143,14 @@ function validateRecordValues(t, data, file) { t.true(isValidHostname(value), `${file}: Invalid hostname for ${key}`); t.true(value !== `${subdomain}.is-a.dev`, `${file}: ${key} cannot point to itself`); t.true(value !== "is-a.dev", `${file}: ${key} cannot point to is-a.dev`); + + for (const disallowed of disallowedCNAMEs) { + if (disallowed.startsWith(".")) { + t.false(value.endsWith(disallowed), `${file}: ${key} cannot end with ${disallowed}`); + } else { + t.false(value === disallowed, `${file}: ${key} cannot be ${disallowed}`); + } + } } else if (key === "URL") { t.true( value.startsWith("http://") || value.startsWith("https://"), diff --git a/util/disallowed-cnames.json b/util/disallowed-cnames.json new file mode 100644 index 0000000000..97e0fea2fc --- /dev/null +++ b/util/disallowed-cnames.json @@ -0,0 +1,3 @@ +[ + ".workers.dev" +]