diff options
| author | Jeff Halter <868228+jhalter@users.noreply.github.com> | 2022-01-30 20:56:04 -0800 |
|---|---|---|
| committer | Jeff Halter <jeff.d.halter@gmail.com> | 2022-01-30 20:56:04 -0800 |
| commit | 92a7e455a347e5be7fb69b6846b9f27ca698ae12 (patch) | |
| tree | cf7d2063123434adfa14f4f781ec4f7966a3adf1 /hotline/file_path_test.go | |
| parent | 154adcc6b47b3cb278f655a9580311e14de7444d (diff) | |
Sanitize file path input to prevent directory traversal
Diffstat (limited to 'hotline/file_path_test.go')
| -rw-r--r-- | hotline/file_path_test.go | 104 |
1 files changed, 100 insertions, 4 deletions
diff --git a/hotline/file_path_test.go b/hotline/file_path_test.go index a8ab2ce..4c2f6db 100644 --- a/hotline/file_path_test.go +++ b/hotline/file_path_test.go @@ -6,10 +6,6 @@ import ( ) func TestFilePath_UnmarshalBinary(t *testing.T) { - type fields struct { - ItemCount []byte - Items []FilePathItem - } type args struct { b []byte } @@ -58,3 +54,103 @@ func TestFilePath_UnmarshalBinary(t *testing.T) { }) } } + +func Test_readPath(t *testing.T) { + type args struct { + fileRoot string + filePath []byte + fileName []byte + } + tests := []struct { + name string + args args + want string + wantErr bool + }{ + { + name: "when filePath is invalid", + args: args{ + fileRoot: "/usr/local/var/mobius/Files", + filePath: []byte{ + 0x61, + }, + fileName: []byte{ + 0x61, 0x61, 0x61, + }, + }, + want: "", + wantErr: true, + }, + { + name: "when filePath is nil", + args: args{ + fileRoot: "/usr/local/var/mobius/Files", + filePath: nil, + fileName: []byte("foo"), + + }, + want: "/usr/local/var/mobius/Files/foo", + }, + { + name: "when fileName contains .. ", + args: args{ + fileRoot: "/usr/local/var/mobius/Files", + filePath: nil, + fileName: []byte("../../../foo"), + }, + want: "/usr/local/var/mobius/Files/foo", + }, + { + name: "when filePath contains .. ", + args: args{ + fileRoot: "/usr/local/var/mobius/Files", + filePath: []byte{ + 0x00, 0x02, + 0x00, 0x00, + 0x03, + 0x2e, 0x2e, 0x2f, + 0x00, 0x00, + 0x08, + 0x41, 0x20, 0x53, 0x75, 0x62, 0x44, 0x69, 0x72, + }, + fileName: []byte("foo"), + }, + want: "/usr/local/var/mobius/Files/A SubDir/foo", + }, + { + name: "when a filePath entry contains .. ", + args: args{ + fileRoot: "/usr/local/var/mobius/Files", + filePath: []byte{ + 0x00, 0x01, + 0x00, 0x00, + 0x0b, + 0x2e, 0x2e, 0x2f, 0x41, 0x20, 0x53, 0x75, 0x62, 0x44, 0x69, 0x72, + }, + fileName: []byte("foo"), + }, + want: "/usr/local/var/mobius/Files/A SubDir/foo", + }, + { + name: "when filePath and fileName are nil", + args: args{ + fileRoot: "/usr/local/var/mobius/Files", + filePath: nil, + fileName: nil, + }, + want: "/usr/local/var/mobius/Files", + }, + } + for _, tt := range tests { + t.Run(tt.name, func(t *testing.T) { + got, err := readPath(tt.args.fileRoot, tt.args.filePath, tt.args.fileName) + if (err != nil) != tt.wantErr { + t.Errorf("readPath() error = %v, wantErr %v", err, tt.wantErr) + return + } + if got != tt.want { + t.Errorf("readPath() got = %v, want %v", got, tt.want) + } + }) + } +}
\ No newline at end of file |