fix(05): WR-04 restrict thumb mode and ext to [a-z0-9]+ before building blob keys
This commit is contained in:
@@ -9,14 +9,28 @@ import (
|
||||
_ "image/png"
|
||||
"io"
|
||||
"path"
|
||||
"regexp"
|
||||
"strings"
|
||||
|
||||
"github.com/disintegration/imaging"
|
||||
"gocloud.dev/blob"
|
||||
)
|
||||
|
||||
// thumbToken is the alphabet allowed for the mode and extension segments of a
|
||||
// thumb filename. Both are interpolated into a blob key, which fileblob maps
|
||||
// to a filesystem path, so separators and dots must never reach it.
|
||||
var thumbToken = regexp.MustCompile(`^[a-z0-9]+$`)
|
||||
|
||||
// ThumbFilename is Winter File::getThumbFilename: thumb_<id>_<w>_<h>_<ox>_<oy>_<mode>.<ext>.
|
||||
// A mode or ext outside [a-z0-9]+ is coerced to "auto" / "jpg" so the result
|
||||
// is always a single safe path element; File.Thumb rejects such input instead.
|
||||
func ThumbFilename(id uint, w, h int, offsetX, offsetY int, mode, ext string) string {
|
||||
if !thumbToken.MatchString(mode) {
|
||||
mode = "auto"
|
||||
}
|
||||
if !thumbToken.MatchString(ext) {
|
||||
ext = "jpg"
|
||||
}
|
||||
return fmt.Sprintf("thumb_%d_%d_%d_%d_%d_%s.%s", id, w, h, offsetX, offsetY, mode, ext)
|
||||
}
|
||||
|
||||
@@ -92,7 +106,14 @@ func (f *File) Thumb(ctx context.Context, bucket *blob.Bucket, w, h int, mode st
|
||||
if mode == "" {
|
||||
mode = "auto"
|
||||
}
|
||||
mode = strings.ToLower(mode)
|
||||
if !thumbToken.MatchString(mode) {
|
||||
return "", fmt.Errorf("attach: invalid thumb mode %q", mode)
|
||||
}
|
||||
ext := fileExt(f.DiskName)
|
||||
if !thumbToken.MatchString(ext) {
|
||||
return "", fmt.Errorf("attach: invalid thumb extension %q", ext)
|
||||
}
|
||||
thumbName := ThumbFilename(f.ID, w, h, 0, 0, mode, ext)
|
||||
part := PartitionDirectory(f.DiskName)
|
||||
thumbKey := part + thumbName
|
||||
|
||||
Reference in New Issue
Block a user