*/ private array $originalEnvironment = []; public function createApplication() { $this->databasePath = sys_get_temp_dir().'/nntmux-block-abusive-services-test.sqlite'; $this->originalEnvironment = [ 'APP_ENV' => getenv('APP_ENV'), 'DB_CONNECTION' => getenv('DB_CONNECTION'), 'DB_DATABASE' => getenv('DB_DATABASE'), ]; if (file_exists($this->databasePath)) { unlink($this->databasePath); } $pdo = new PDO('sqlite:'.$this->databasePath); $pdo->exec('CREATE TABLE settings (name VARCHAR PRIMARY KEY, value TEXT NULL)'); $pdo->exec("INSERT INTO settings (name, value) VALUES ('categorizeforeign', '0'), ('catwebdl', '0'), ('innerfileblacklist', '')"); $this->setEnvironmentValue('APP_ENV', 'testing'); $this->setEnvironmentValue('DB_CONNECTION', 'sqlite'); $this->setEnvironmentValue('DB_DATABASE', $this->databasePath); $app = require __DIR__.'/../../bootstrap/app.php'; $app->make(Kernel::class)->bootstrap(); return $app; } protected function tearDown(): void { if ($this->databasePath !== '' && file_exists($this->databasePath)) { unlink($this->databasePath); } parent::tearDown(); foreach ($this->originalEnvironment as $key => $value) { $this->setEnvironmentValue($key, $value === false ? null : $value); } } public function test_disabled_proxy_indexer_app_block_allows_configured_user_agent_on_indexer_endpoint(): void { config()->set('nntmux.block_proxy_indexer_apps', false); config()->set('nntmux.block_proxy_indexer_app_user_agents', 'Prowlarr/,NZBHydra2'); $response = $this->handleRequest('/api/v1/api?t=search&q=linux', 'Prowlarr/2.0.0'); $this->assertSame(Response::HTTP_OK, $response->getStatusCode()); } public function test_enabled_proxy_indexer_app_block_denies_proxied_downloads(): void { config()->set('nntmux.block_proxy_indexer_apps', true); config()->set('nntmux.block_proxy_indexer_app_user_agents', 'Prowlarr/,NZBHydra2'); foreach ([ '/api/v1/api?t=get&id=release-guid' => 'Prowlarr/2.0.0', '/api/v1/api?t=g&id=release-guid' => 'Prowlarr/2.0.0', '/api/v2/getnzb?id=release-guid' => 'NZBHydra2 8.3.0', ] as $uri => $userAgent) { $response = $this->handleRequest($uri, $userAgent); $this->assertSame(Response::HTTP_FORBIDDEN, $response->getStatusCode(), $uri); $this->assertStringContainsString('Proxying NZB downloads through indexer apps is not allowed', (string) $response->getContent()); } } public function test_enabled_proxy_indexer_app_block_allows_proxied_searches(): void { config()->set('nntmux.block_proxy_indexer_apps', true); config()->set('nntmux.block_proxy_indexer_app_user_agents', 'Prowlarr/,NZBHydra2'); foreach ([ '/api/v1/api?t=caps' => 'Prowlarr/2.0.0', '/api/v1/api?t=search&q=linux' => 'Prowlarr/2.0.0', '/api/v1/api?t=tvsearch&q=linux' => 'Prowlarr/2.0.0', '/api/v2/capabilities' => 'NZBHydra2 8.3.0', '/api/v2/search?q=linux' => 'NZBHydra2 8.3.0', ] as $uri => $userAgent) { $response = $this->handleRequest($uri, $userAgent); $this->assertSame(Response::HTTP_OK, $response->getStatusCode(), $uri); } } public function test_enabled_proxy_indexer_app_block_allows_proxied_rss_feeds(): void { config()->set('nntmux.block_proxy_indexer_apps', true); config()->set('nntmux.block_proxy_indexer_app_user_agents', 'Prowlarr/,NZBHydra2'); foreach ([ '/rss/full-feed?api_token=token', '/rss/category?api_token=token&t=2000', ] as $uri) { $response = $this->handleRequest($uri, 'Prowlarr/2.0.0'); $this->assertSame(Response::HTTP_OK, $response->getStatusCode(), $uri); } } public function test_enabled_proxy_indexer_app_block_allows_redirected_downloader_user_agent_on_same_download_url(): void { config()->set('nntmux.block_proxy_indexer_apps', true); config()->set('nntmux.block_proxy_indexer_app_user_agents', 'Prowlarr/,NZBHydra2'); $response = $this->handleRequest('/api/v1/api?t=get&id=release-guid', 'SABnzbd/4.3.3'); $this->assertSame(Response::HTTP_OK, $response->getStatusCode()); } public function test_behavioral_detection_blocks_spoofed_ua_direct_proxy_fetch(): void { $this->enableBehavioralDetection(); // A direct proxy fetch masquerading as a downloader: the strict UA fast path // (block_proxy_indexer_apps) is off and SABnzbd is not a blocked UA, so only // the behavioural signals can catch this. $spoofedUa = 'SABnzbd/4.3.3'; $ip = '203.0.113.10'; // The proxy searches first with the spoofed UA — this seeds the UA-pair // window for the api_token and the IP->UA correlation window. $searchResponse = $this->handleRequest( '/api/v1/api?t=search&q=linux&apikey=user-key', $spoofedUa, ip: $ip, ); $this->assertSame(Response::HTTP_OK, $searchResponse->getStatusCode()); // Then it downloads with the same UA, same token, same IP, and leaks the // indexer host in the Referer. Signals: referer (30) + ua_pair (25) + // ip_correlation (20) = 75 >= 50 threshold. $downloadResponse = $this->handleRequest( '/api/v1/api?t=get&id=release-guid&apikey=user-key', $spoofedUa, ['Referer' => 'http://hydra.local:5076/nzb/details'], $ip, ); $this->assertSame(Response::HTTP_FORBIDDEN, $downloadResponse->getStatusCode()); $this->assertStringContainsString( 'Proxying NZB downloads through indexer apps is not allowed', (string) $downloadResponse->getContent(), ); } public function test_search_routes_record_signals_for_later_correlation(): void { $this->enableBehavioralDetection(); $spoofedUa = 'SABnzbd/4.3.3'; $ip = '203.0.113.20'; $downloadUri = '/api/v1/api?t=get&id=release-guid&apikey=user-key'; $referer = ['Referer' => 'http://prowlarr.local:9696/download']; // Without a prior search, only the Referer signal fires (30 < 50 threshold), // so the download is allowed — the correlation windows are empty. $coldResponse = $this->handleRequest($downloadUri, $spoofedUa, $referer, $ip); $this->assertSame(Response::HTTP_OK, $coldResponse->getStatusCode()); // A search from the same token + IP + UA seeds the UA-pair and IP windows. $this->handleRequest('/api/v1/api?t=search&q=ubuntu&apikey=user-key', $spoofedUa, ip: $ip); // Now the same download correlates: referer (30) + ua_pair (25) + // ip_correlation (20) = 75, and it is blocked. $warmResponse = $this->handleRequest($downloadUri, $spoofedUa, $referer, $ip); $this->assertSame(Response::HTTP_FORBIDDEN, $warmResponse->getStatusCode()); } public function test_enabled_proxy_indexer_app_block_allows_configured_user_agent_on_unrelated_routes(): void { config()->set('nntmux.block_proxy_indexer_apps', true); config()->set('nntmux.block_proxy_indexer_app_user_agents', 'Prowlarr/,NZBHydra2'); foreach ([ '/api/inform/release', '/api/release/123/mediainfo', '/rss/health', ] as $uri) { $response = $this->handleRequest($uri, 'Prowlarr/2.0.0'); $this->assertSame(Response::HTTP_OK, $response->getStatusCode(), $uri); } } public function test_existing_abusive_user_agent_block_still_applies(): void { config()->set('nntmux.block_proxy_indexer_apps', false); $response = $this->handleRequest('/api/v1/api?t=caps', 'AIOStreams/1.0'); $this->assertSame(Response::HTTP_FORBIDDEN, $response->getStatusCode()); $this->assertStringContainsString('Streaming services are not allowed', (string) $response->getContent()); } public function test_block_logs_redact_sensitive_query_parameters(): void { Log::spy(); config()->set('nntmux.block_proxy_indexer_apps', true); config()->set('nntmux.block_proxy_indexer_app_user_agents', 'Prowlarr/,NZBHydra2'); $response = $this->handleRequest( '/api/v1/api?t=get&id=release-guid&apikey=secret-api-key&api_token=secret-token&passkey=secret-passkey', 'Prowlarr/2.0.0' ); $this->assertSame(Response::HTTP_FORBIDDEN, $response->getStatusCode()); Log::shouldHaveReceived('warning') ->with('Blocked proxied NZB download from indexer app', \Mockery::on(function (mixed $context): bool { if (! is_array($context)) { return false; } $uri = (string) ($context['uri'] ?? ''); return str_contains($uri, 'apikey=%5Bredacted%5D') && str_contains($uri, 'api_token=%5Bredacted%5D') && str_contains($uri, 'passkey=%5Bredacted%5D') && str_contains($uri, 'id=release-guid') && ! str_contains($uri, 'secret-api-key') && ! str_contains($uri, 'secret-token') && ! str_contains($uri, 'secret-passkey'); })) ->once(); } private function setEnvironmentValue(string $key, ?string $value): void { if ($value === null) { putenv($key); unset($_ENV[$key], $_SERVER[$key]); return; } putenv($key.'='.$value); $_ENV[$key] = $value; $_SERVER[$key] = $value; } /** * @param array $headers */ private function handleRequest(string $uri, string $userAgent, array $headers = [], string $ip = '127.0.0.1'): Response { $server = [ 'HTTP_USER_AGENT' => $userAgent, 'REMOTE_ADDR' => $ip, ]; foreach ($headers as $name => $value) { $server['HTTP_'.strtoupper(str_replace('-', '_', $name))] = $value; } $request = Request::create($uri, 'GET', server: $server); return app(BlockAbusiveServices::class)->handle( $request, static fn (): Response => response()->json(['ok' => true]) ); } /** * Turn on behavioural proxy detection with a deterministic in-memory cache. * * The detector resolves its CacheRepository from the container; binding an * ArrayStore-backed repository keeps per-token / per-IP windows isolated to the * test and lets a recorded search feed a later download in the same test run. * The ASN cache uses the Cache facade (a different store) and is untouched. */ private function enableBehavioralDetection(): void { config()->set('nntmux.block_proxy_indexer_apps', false); config()->set('nntmux.proxy_detection_enabled', true); config()->set('nntmux.proxy_detection_threshold', 50); config()->set('nntmux.proxy_detection_window_seconds', 3600); config()->set('nntmux.proxy_detection_ratio_min', 0.8); config()->set('nntmux.proxy_detection_min_searches', 20); config()->set('nntmux.proxy_detection_indexer_referer_patterns', 'hydra,prowlarr,jackett'); $this->app->instance( CacheRepositoryContract::class, new CacheRepository(new ArrayStore) ); } }