penpot/backend/test/e2e/ldap-test-curl.sh
Andrey Antukh f38c7dd639
⬆️ Update deps (#11960)
* 🐛 Migrate openUIApi schema to Zod v4 function syntax

Zod 4 removed z.function().args(), which broke the
plugins-runtime build with implicit-any errors on every
openUIApi parameter and knock-on possibly-null errors on
the modal in plugin-manager.

Declare the inputs with z.function({ input: [...] }) so the
parameter and return types infer again; behavior is unchanged.

Add a regression spec covering delegation, optional args and
rejection of invalid theme and title values.

AI-assisted-by: muse-spark-1.3-contributor

* 📚 Fix deprecated markdown-it-anchor permalink option in docs

Migrate docs Eleventy config to the markdown-it-anchor v10 API.
Replace the deprecated boolean permalink option with
linkInsideHeader, keeping the same symbol and class.
Bump markdown-it-anchor to v10 and related docs deps.

AI-assisted-by: muse-spark-1.3-contributor

* ⬆️ Update deps

* ⬆️ Update base docker images

* 📎 Fix mcp tests
2026-09-29 09:07:34 +02:00

27 lines
1008 B
Bash

#!/bin/bash
# LDAP injection test script — run against running Penpot backend
# Usage: bash backend/test/e2e/ldap-test-curl.sh
BASE="http://localhost:3450/api/main/methods/login-with-ldap"
H1='Content-Type: application/json'
H2='Accept: application/json'
#echo "=== 1. Normal login (fry/fry) ==="
#curl -s -X POST "$BASE" -H "$H1" -H "$H2" \
# -d '{"email":"fry@planetexpress.com","password":"fry"}' | python3 -m json.tool
#echo ""
#echo "=== 2. Wildcard injection (*@planetexpress.com + amy) ==="
#curl -s -X POST "$BASE" -H "$H1" -H "$H2" \
# -d '{"email":"*@planetexpress.com","password":"amy"}' | python3 -m json.tool
echo ""
echo "=== 3. Identity swap (hubert@ + professor password) ==="
curl -s -X POST "$BASE" -H "$H1" -H "$H2" \
-d '{"email":"hubert@planetexpress.com","password":"professor"}' | python3 -m json.tool
#echo ""
#echo "=== 4. Wrong password ==="
#curl -s -X POST "$BASE" -H "$H1" -H "$H2" \
# -d '{"email":"fry@planetexpress.com","password":"wrong"}' | python3 -m json.tool