While Docker's API likely handles invalid values gracefully, the parameter should be validated as a positive integer to ensure predictable behavior and prevent potential edge cases (e.g., passing "all" to dump the entire log history, which could be a DoS vector for containers with large log files).
## Bug
**File:** `internal/handlers/app.go`, `HandleAppLogs()`
**Severity:** LOW
### Description
The `tail` query parameter is read from user input and passed directly to the Docker API without validation:
```go
tail := request.URL.Query().Get("tail")
if tail == "" {
tail = defaultLogTail
}
logs, logsErr := h.docker.ContainerLogs(request.Context(), containerInfo.ID, tail)
```
While Docker's API likely handles invalid values gracefully, the parameter should be validated as a positive integer to ensure predictable behavior and prevent potential edge cases (e.g., passing `"all"` to dump the entire log history, which could be a DoS vector for containers with large log files).
### Suggested Fix
```go
tail := request.URL.Query().Get("tail")
if tail == "" {
tail = defaultLogTail
} else if _, err := strconv.Atoi(tail); err != nil {
tail = defaultLogTail
}
```
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Bug
File:
internal/handlers/app.go,HandleAppLogs()Severity: LOW
Description
The
tailquery parameter is read from user input and passed directly to the Docker API without validation:While Docker's API likely handles invalid values gracefully, the parameter should be validated as a positive integer to ensure predictable behavior and prevent potential edge cases (e.g., passing
"all"to dump the entire log history, which could be a DoS vector for containers with large log files).Suggested Fix
do it. also clamp it to max 500.