Reject backslashes in confined file paths
This commit is contained in:
@@ -19,7 +19,7 @@ func SafePath(root, name string) (string, error) {
|
|||||||
if name == "" {
|
if name == "" {
|
||||||
return "", fmt.Errorf("artifact name must not be empty")
|
return "", fmt.Errorf("artifact name must not be empty")
|
||||||
}
|
}
|
||||||
if strings.Contains(name, `\\`) {
|
if strings.ContainsRune(name, '\\') {
|
||||||
return "", fmt.Errorf("artifact name %q must use slash-separated relative paths", name)
|
return "", fmt.Errorf("artifact name %q must use slash-separated relative paths", name)
|
||||||
}
|
}
|
||||||
if path.IsAbs(name) || filepath.IsAbs(name) {
|
if path.IsAbs(name) || filepath.IsAbs(name) {
|
||||||
|
|||||||
@@ -8,7 +8,7 @@ import (
|
|||||||
)
|
)
|
||||||
|
|
||||||
func TestSafePathRejectsUnsafeNames(t *testing.T) {
|
func TestSafePathRejectsUnsafeNames(t *testing.T) {
|
||||||
for _, name := range []string{"/tmp/x", "a/../x", "a//x", `a\\x`} {
|
for _, name := range []string{"/tmp/x", "a/../x", "a//x", `a\x`, `a\\x`} {
|
||||||
if _, err := SafePath(t.TempDir(), name); err == nil {
|
if _, err := SafePath(t.TempDir(), name); err == nil {
|
||||||
t.Fatalf("SafePath(%q) accepted unsafe path", name)
|
t.Fatalf("SafePath(%q) accepted unsafe path", name)
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user