diff options
| author | Jeff Halter <868228+jhalter@users.noreply.github.com> | 2022-01-30 20:56:04 -0800 |
|---|---|---|
| committer | Jeff Halter <jeff.d.halter@gmail.com> | 2022-01-30 20:56:04 -0800 |
| commit | 92a7e455a347e5be7fb69b6846b9f27ca698ae12 (patch) | |
| tree | cf7d2063123434adfa14f4f781ec4f7966a3adf1 /hotline/file_path.go | |
| parent | 154adcc6b47b3cb278f655a9580311e14de7444d (diff) | |
Sanitize file path input to prevent directory traversal
Diffstat (limited to 'hotline/file_path.go')
| -rw-r--r-- | hotline/file_path.go | 21 |
1 files changed, 21 insertions, 0 deletions
diff --git a/hotline/file_path.go b/hotline/file_path.go index d6c05bc..2e2e085 100644 --- a/hotline/file_path.go +++ b/hotline/file_path.go @@ -32,6 +32,9 @@ type FilePath struct { const minFilePathLen = 2 func (fp *FilePath) UnmarshalBinary(b []byte) error { + if b == nil { + return nil + } if len(b) < minFilePathLen { return errors.New("insufficient bytes") } @@ -71,3 +74,21 @@ func ReadFilePath(filePathFieldData []byte) string { } return fp.String() } + +func readPath(fileRoot string, filePath, fileName []byte) (fullPath string, err error) { + var fp FilePath + if filePath != nil { + if err = fp.UnmarshalBinary(filePath); err != nil { + return "", err + } + } + + fullPath = path.Join( + "/", + fileRoot, + fp.String(), + path.Join("/", string(fileName)), + ) + + return fullPath, nil +} |