mirror of
https://github.com/truewhile/MeBox.git
synced 2026-10-04 12:36:37 +08:00
fix: security hardening and HTTP status code corrections
- importSTRMHandler: add URL scheme validation (blocks file://, ftp://, etc.) - backup Delete/Restore: harden path traversal check (block backslash, require .db extension) - HTTP 201 for create endpoints: register, subscription, download client, notify channel, library, STRM import - Error handling: return 500 for service/infra errors in download client and notify channel handlers Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
This commit is contained in:
@@ -77,17 +77,22 @@ func importSTRMHandler(svc *service.Container) gin.HandlerFunc {
|
||||
c.JSON(http.StatusBadRequest, gin.H{"error": err.Error()})
|
||||
return
|
||||
}
|
||||
url := strings.TrimSpace(req.URL)
|
||||
if !strings.HasPrefix(url, "http://") && !strings.HasPrefix(url, "https://") {
|
||||
c.JSON(http.StatusBadRequest, gin.H{"error": "url must start with http:// or https://"})
|
||||
return
|
||||
}
|
||||
m := &model.Media{
|
||||
LibraryID: req.LibraryID,
|
||||
Title: req.Title,
|
||||
Path: req.URL, // unique-index target — keep it identical to the URL
|
||||
STRMURL: req.URL,
|
||||
Path: url,
|
||||
STRMURL: url,
|
||||
Container: "strm",
|
||||
}
|
||||
if err := svc.Repo.Media.Upsert(c.Request.Context(), m); err != nil {
|
||||
c.JSON(http.StatusBadRequest, gin.H{"error": err.Error()})
|
||||
c.JSON(http.StatusInternalServerError, gin.H{"error": err.Error()})
|
||||
return
|
||||
}
|
||||
c.JSON(http.StatusOK, m)
|
||||
c.JSON(http.StatusCreated, m)
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user