mirror of
https://github.com/truewhile/MeBox.git
synced 2026-10-07 13:56:37 +08:00
fix: security hardening and HTTP status code corrections
- importSTRMHandler: add URL scheme validation (blocks file://, ftp://, etc.) - backup Delete/Restore: harden path traversal check (block backslash, require .db extension) - HTTP 201 for create endpoints: register, subscription, download client, notify channel, library, STRM import - Error handling: return 500 for service/infra errors in download client and notify channel handlers Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
This commit is contained in:
@@ -106,7 +106,7 @@ func (b *BackupService) List() ([]BackupInfo, error) {
|
||||
|
||||
// Delete removes a single backup file.
|
||||
func (b *BackupService) Delete(filename string) error {
|
||||
if strings.Contains(filename, "/") || strings.Contains(filename, "..") {
|
||||
if !isValidBackupFilename(filename) {
|
||||
return errors.New("invalid filename")
|
||||
}
|
||||
path := filepath.Join(b.backupDir(), filename)
|
||||
@@ -117,7 +117,7 @@ func (b *BackupService) Delete(filename string) error {
|
||||
// reverse. WARNING: this is destructive — the live DB will be replaced.
|
||||
// Callers should shut down the server after this call.
|
||||
func (b *BackupService) Restore(ctx context.Context, filename string) error {
|
||||
if strings.Contains(filename, "/") || strings.Contains(filename, "..") {
|
||||
if !isValidBackupFilename(filename) {
|
||||
return errors.New("invalid filename")
|
||||
}
|
||||
src := filepath.Join(b.backupDir(), filename)
|
||||
@@ -148,3 +148,17 @@ func (b *BackupService) Restore(ctx context.Context, filename string) error {
|
||||
zap.String("backup", filename))
|
||||
return nil
|
||||
}
|
||||
|
||||
// isValidBackupFilename rejects path traversal attempts and non-.db files.
|
||||
func isValidBackupFilename(name string) bool {
|
||||
if name == "" {
|
||||
return false
|
||||
}
|
||||
if strings.ContainsAny(name, "/\\") || strings.Contains(name, "..") {
|
||||
return false
|
||||
}
|
||||
if !strings.HasSuffix(name, ".db") {
|
||||
return false
|
||||
}
|
||||
return true
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user