aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
-rw-r--r--hotline/access.go11
-rw-r--r--hotline/access_test.go10
-rw-r--r--hotline/server.go6
3 files changed, 24 insertions, 3 deletions
diff --git a/hotline/access.go b/hotline/access.go
index 370f8c2..927e0a9 100644
--- a/hotline/access.go
+++ b/hotline/access.go
@@ -67,8 +67,15 @@ func (bits *AccessBitmap) UnmarshalYAML(unmarshal func(interface{}) error) error
// Mobius versions < v0.17.0 store the user access bitmap as an array of int values like:
// [96, 112, 12, 32, 3, 128, 0, 0]
// This case supports reading of user config files using this format.
- for i, v := range flags.([]interface{}) {
- bits[i] = byte(v.(int))
+ for i, elem := range v {
+ if i >= len(bits) {
+ return fmt.Errorf("unmarshal access bitmap: too many elements (%d, max %d)", len(v), len(bits))
+ }
+ n, ok := elem.(int)
+ if !ok {
+ return fmt.Errorf("unmarshal access bitmap: element %d is %T, want int", i, elem)
+ }
+ bits[i] = byte(n)
}
case map[string]interface{}:
// Mobius versions >= v0.17.0 store the user access bitmap as map[string]bool to provide a human-readable view of
diff --git a/hotline/access_test.go b/hotline/access_test.go
index 2c5b8f4..65d29be 100644
--- a/hotline/access_test.go
+++ b/hotline/access_test.go
@@ -75,6 +75,16 @@ func Test_accessBitmap_UnmarshalYAML(t *testing.T) {
wantErr: false,
},
{
+ name: "legacy array with non-int element returns error",
+ yamlData: `access: [96, "nope", 12, 32, 3, 128, 0, 0]`,
+ wantErr: true,
+ },
+ {
+ name: "legacy array with too many elements returns error",
+ yamlData: "access: [1, 2, 3, 4, 5, 6, 7, 8, 9]",
+ wantErr: true,
+ },
+ {
name: "unmarshal map format with true values",
yamlData: `access:
DownloadFile: true
diff --git a/hotline/server.go b/hotline/server.go
index d757062..7bc6a4a 100644
--- a/hotline/server.go
+++ b/hotline/server.go
@@ -690,8 +690,12 @@ func (s *Server) handleFileTransfer(ctx context.Context, rwc io.ReadWriter) erro
time.Sleep(3 * time.Second)
}()
+ var remoteAddr string
+ if rc, ok := ctx.Value(contextKeyReq).(requestCtx); ok {
+ remoteAddr = rc.remoteAddr
+ }
rLogger := s.Logger.With(
- "remoteAddr", ctx.Value(contextKeyReq).(requestCtx).remoteAddr,
+ "remoteAddr", remoteAddr,
"login", fileTransfer.ClientConn.Account.Login,
"Name", string(fileTransfer.ClientConn.UserName),
)