fix: security hardening and HTTP status code corrections

- importSTRMHandler: add URL scheme validation (blocks file://, ftp://, etc.)
- backup Delete/Restore: harden path traversal check (block backslash, require .db extension)
- HTTP 201 for create endpoints: register, subscription, download client, notify channel, library, STRM import
- Error handling: return 500 for service/infra errors in download client and notify channel handlers

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
This commit is contained in:
soldosluka857
2026-05-30 02:39:11 +00:00
committed by Shuke
parent 0572612833
commit e97891175a
7 changed files with 34 additions and 15 deletions
+3 -3
View File
@@ -34,13 +34,13 @@ func createDownloadClientHandler(svc *service.Container) gin.HandlerFunc {
}
row, err := svc.DownloadClients.Create(c.Request.Context(), in)
if err != nil {
c.JSON(http.StatusBadRequest, gin.H{"error": err.Error()})
c.JSON(http.StatusInternalServerError, gin.H{"error": err.Error()})
return
}
// 让真正发起下载的 DownloadService 立刻读到新的 qb 配置,
// 避免保存后还要重启进程才能生效。
_ = svc.Downloads.ReloadConfig(c.Request.Context())
c.JSON(http.StatusOK, row)
c.JSON(http.StatusCreated, row)
}
}
@@ -53,7 +53,7 @@ func updateDownloadClientHandler(svc *service.Container) gin.HandlerFunc {
}
row, err := svc.DownloadClients.Update(c.Request.Context(), c.Param("id"), in)
if err != nil {
c.JSON(http.StatusBadRequest, gin.H{"error": err.Error()})
c.JSON(http.StatusInternalServerError, gin.H{"error": err.Error()})
return
}
_ = svc.Downloads.ReloadConfig(c.Request.Context())