mirror of
https://github.com/truewhile/MeBox.git
synced 2026-09-28 03:06:38 +08:00
b0fe40142a
* Rebrand MMTL to MeBox across codebase and assets Rename the project display name, Go module path, environment variable prefix (MEBOX_*), Docker image references, and UI branding from MMTL/mmtl to MeBox/mebox. Replace logo assets with the new MeBox icon and keep legacy SQLite migration support for existing mmtl.db deployments. Co-authored-by: truewhile <truewhile@users.noreply.github.com> * Fix logo icons: use cube-only crop without truncated text Previous icon generation cropped too much of the source image, including partial MeBox wordmark text that was cut off in square icon containers. Regenerate logo-64/192/512, favicon, and SVG from cube-only region. Co-authored-by: truewhile <truewhile@users.noreply.github.com> --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: truewhile <truewhile@users.noreply.github.com>
38 lines
1.1 KiB
Go
38 lines
1.1 KiB
Go
package service
|
|
|
|
import (
|
|
"path/filepath"
|
|
"testing"
|
|
|
|
"github.com/truewhile/MeBox/internal/config"
|
|
)
|
|
|
|
func TestBackupFilePathRejectsTraversal(t *testing.T) {
|
|
svc := &BackupService{cfg: &config.Config{}}
|
|
svc.cfg.App.DataDir = t.TempDir()
|
|
for _, name := range []string{"../evil.db", `..\evil.db`, "nested/evil.db", "evil.sqlite"} {
|
|
if _, err := svc.backupFilePath(name); err == nil {
|
|
t.Fatalf("backupFilePath(%q) allowed traversal or non-backup file", name)
|
|
}
|
|
}
|
|
path, err := svc.backupFilePath("mebox_20260611_010203.db")
|
|
if err != nil {
|
|
t.Fatalf("backupFilePath(valid) = %v", err)
|
|
}
|
|
if filepath.Dir(path) != filepath.Join(svc.cfg.App.DataDir, "backups") {
|
|
t.Fatalf("backupFilePath(valid) dir = %q", filepath.Dir(path))
|
|
}
|
|
}
|
|
|
|
func TestSafeZipTargetRejectsZipSlip(t *testing.T) {
|
|
root := t.TempDir()
|
|
for _, name := range []string{"../evil.exe", `..\evil.exe`, "/tmp/evil.exe"} {
|
|
if _, err := safeZipTarget(root, name); err == nil {
|
|
t.Fatalf("safeZipTarget(%q) allowed zip-slip path", name)
|
|
}
|
|
}
|
|
if _, err := safeZipTarget(root, "ffmpeg/bin/ffmpeg.exe"); err != nil {
|
|
t.Fatalf("safeZipTarget(valid) = %v", err)
|
|
}
|
|
}
|