From 92a7e455a347e5be7fb69b6846b9f27ca698ae12 Mon Sep 17 00:00:00 2001 From: Jeff Halter <868228+jhalter@users.noreply.github.com> Date: Sun, 30 Jan 2022 20:56:04 -0800 Subject: Sanitize file path input to prevent directory traversal --- hotline/file_path.go | 21 +++++++++++++++++++++ 1 file changed, 21 insertions(+) (limited to 'hotline/file_path.go') diff --git a/hotline/file_path.go b/hotline/file_path.go index d6c05bc..2e2e085 100644 --- a/hotline/file_path.go +++ b/hotline/file_path.go @@ -32,6 +32,9 @@ type FilePath struct { const minFilePathLen = 2 func (fp *FilePath) UnmarshalBinary(b []byte) error { + if b == nil { + return nil + } if len(b) < minFilePathLen { return errors.New("insufficient bytes") } @@ -71,3 +74,21 @@ func ReadFilePath(filePathFieldData []byte) string { } return fp.String() } + +func readPath(fileRoot string, filePath, fileName []byte) (fullPath string, err error) { + var fp FilePath + if filePath != nil { + if err = fp.UnmarshalBinary(filePath); err != nil { + return "", err + } + } + + fullPath = path.Join( + "/", + fileRoot, + fp.String(), + path.Join("/", string(fileName)), + ) + + return fullPath, nil +} -- cgit