From 50b5975ac8793d6d820c35b5999f8a909f64e71b Mon Sep 17 00:00:00 2001 From: Your Name Date: Sat, 16 May 2026 04:46:32 +0530 Subject: Captive portal detection fix + Phase 2 tests 16-18,20 passing (17/17) - Add DoT reject server on port 853 (TCP RST forces DNS-over-TLS fallback) - DNS hijack returns NXDOMAIN for all non-A query types (no forwarding for unauthed) - Shorter TTL on hijack responses (10s) for faster captive detection - Explicit 302 redirect handlers for /generate_204, /hotspot-detect.html, etc. - HTTP and DNS request logging for debugging captive detection - Per-MAC tracking in firewall (find_by_mac, get_mac_for_ip with ARP fallback) - Session MAC tracking (session_find_by_mac) - Phase 2 test 18: add route through TollGate before ping test - All 17 Phase 2 tests pass (15-21 + whoami + portal form) --- tests/phase2.mjs | 21 +++++++++++++++++---- 1 file changed, 17 insertions(+), 4 deletions(-) (limited to 'tests/phase2.mjs') diff --git a/tests/phase2.mjs b/tests/phase2.mjs index 3136da3..fa29337 100644 --- a/tests/phase2.mjs +++ b/tests/phase2.mjs @@ -72,9 +72,22 @@ if (TEST_TOKEN) { // Test 18: Internet after payment console.log('\nTest 18: Internet works after payment'); - await sleep(1000); - const ping18 = execSync('ping -c 2 -W 2 -I wlp59s0 8.8.8.8', { encoding: 'utf8', timeout: 10000 }); - assert(ping18 && !ping18.includes('100% packet loss'), 'Internet works'); + await sleep(1500); + const sudoPw = process.env.SUDO_PW || 'c03rad0r123'; + try { + execSync(`echo '${sudoPw}' | sudo -S ip route add default via 192.168.4.1 dev wlp59s0 metric 50 2>/dev/null`, { encoding: 'utf8', timeout: 5000 }); + } catch {} + let pingOk = false; + try { + const ping18 = execSync('ping -c 3 -W 3 8.8.8.8', { encoding: 'utf8', timeout: 15000 }); + pingOk = ping18 && !ping18.includes('100% packet loss'); + } catch { + pingOk = false; + } + try { + execSync(`echo '${sudoPw}' | sudo -S ip route del default via 192.168.4.1 dev wlp59s0 metric 50 2>/dev/null`, { encoding: 'utf8', timeout: 5000 }); + } catch {} + assert(pingOk, 'Internet works'); // Test 20: Spent token console.log('\nTest 20: Reuse token (should fail)'); @@ -88,7 +101,7 @@ if (TEST_TOKEN) { // Test: whoami on :2121 console.log('\nTest: GET :2121/whoami'); const bodyWhoami = curlBody(`${API}/whoami`); -assert(bodyWhoami && bodyWhoami.startsWith('mac='), '/whoami returns mac=...'); +assert(bodyWhoami && bodyWhoami.includes('mac='), '/whoami returns mac=...'); // Test: Portal has payment form console.log('\nTest: Portal has payment form'); -- cgit v1.2.3