Reject path traversal in deploy log download handler (closes #177)
Check / check (pull_request) Skipped
Check / check (pull_request) Skipped
gosec flagged G703 (path traversal via taint analysis) on the log download handler because the served path derives from a URL parameter. Open the log file through an os.Root confined to the deploy log directory instead of passing the path to http.ServeFile; Root.Open rejects any path that escapes the root, so traversal attempts return 404. Serve the opened file with http.ServeContent. Adds GetLogDir on the deploy service. The traversal regression test plants a sentinel file at the location a traversal-shaped app name resolves to (outside the log directory) and asserts the handler returns 404 without leaking the sentinel, so it fails if the os.Root guard is removed. Keeps the legitimate-download test. Model: opus-4-8
This commit is contained in:
@@ -22,6 +22,9 @@ main cannot regress.
|
||||
|
||||
- 2026-09-22: Added `.prettierignore` so `make fmt` no longer rewrites
|
||||
the vendored `static/js/alpine.min.js` bundle (#185).
|
||||
- 2026-09-22: Fixed the gosec G703 path-traversal finding in the deploy
|
||||
log download handler by verifying the resolved path stays within the
|
||||
deploy log directory before serving, returning 404 on escape (#177).
|
||||
- 2026-09-09: Fixed four deployability blockers found by QA: CSRF origin
|
||||
check over plain HTTP (`UPAAS_PLAINTEXT_HTTP`, #189), pulling the git
|
||||
image when absent (#190), the env-var editor CSRF token lookup (#191),
|
||||
|
||||
Reference in New Issue
Block a user