fix: resolve all 22 gosec G710 open-redirect findings
All checks were successful
Check / check (pull_request) Successful in 3m25s
All checks were successful
Check / check (pull_request) Successful in 3m25s
Route every app redirect in internal/handlers/app.go through a new redirectToApp helper that parses the app ID with ulid.ParseStrict (404 on failure), re-serializes it, and path-escapes it before building the /apps/<id> target, so no unvalidated request input can reach http.Redirect. Also converts the equivalent unflagged redirect in HandleAppCreate for consistency. make lint under golangci-lint 2.12.2 drops from 47 findings to 25 (remaining: 1 gosec G703 tracked in #177, 24 goconst tracked in #178). make test and make fmt-check pass unchanged. Closes #176
This commit is contained in:
22
TODO.md
22
TODO.md
@@ -11,20 +11,23 @@
|
||||
# Status
|
||||
|
||||
1.0+. Tagged 1.0.0 on 2026-02-26. Policy violation: main currently
|
||||
fails make check under golangci-lint >= 2.12 (47 lint issues remaining:
|
||||
23 gosec, 24 goconst), so the tree is out of compliance until fixed. CI
|
||||
(Dockerfile lint stage, pinned golangci-lint v2.10.1) is green; the pin
|
||||
bump is tracked in issue #179. The road to release 1.1.0 is tracked in
|
||||
Gitea issues #175-#182 (milestone 1.1.0).
|
||||
fails make check under golangci-lint >= 2.12 (25 lint issues remaining:
|
||||
1 gosec G703, 24 goconst), so the tree is out of compliance until
|
||||
fixed. CI (Dockerfile lint stage, pinned golangci-lint v2.10.1) is
|
||||
green; the pin bump is tracked in issue #179. The road to release
|
||||
1.1.0 is tracked in Gitea issues #175-#185 (milestone 1.1.0).
|
||||
|
||||
# Next Step
|
||||
|
||||
Fix the 22 gosec G710 open-redirect findings in
|
||||
internal/handlers/app.go (issue #176) by validating app IDs in a
|
||||
shared redirect helper.
|
||||
Fix the gosec G703 path traversal finding in the deploy log download
|
||||
handler (issue #177): canonicalize and containment-check the log path
|
||||
before http.ServeFile, with a traversal-rejection test.
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-08-07: Fixed all 22 gosec G710 open-redirect findings: app
|
||||
redirects go through a redirectToApp helper that ULID-validates the
|
||||
app ID (#176).
|
||||
- 2026-08-07: Fixed all 47 noctx lint findings: tests now use
|
||||
httptest.NewRequestWithContext with t.Context() (#175).
|
||||
- 2026-07-07 Adopted scripts-to-rule-them-all: `script/` entrypoints,
|
||||
@@ -50,8 +53,7 @@ shared redirect helper.
|
||||
# Future Steps
|
||||
|
||||
- Get main green (compliance, ordered):
|
||||
- Fix 22 gosec G710 findings (Next Step, #176).
|
||||
- Fix 1 gosec G703 finding (#177).
|
||||
- Fix 1 gosec G703 finding (Next Step, #177).
|
||||
- Fix 24 goconst findings (#178).
|
||||
- Bump Dockerfile golangci-lint pin to v2.12.x (#179).
|
||||
- Run make check clean on main and keep it green; main must always
|
||||
|
||||
Reference in New Issue
Block a user