File system paths for build dirs and log files (deploy.go)
The HTML pattern="[a-z0-9-]+" attribute is only client-side validation
A crafted POST request bypassing the browser can submit names with spaces, special characters, path separators, etc., potentially causing:
Docker API errors with invalid container/image names
Path traversal in build directories
Log injection via app names in log messages
Suggested Fix
Add server-side validation matching the client-side pattern:
varvalidAppNameRe=regexp.MustCompile(`^[a-z0-9][a-z0-9-]*[a-z0-9]$`)funcvalidateAppName(namestring)error{iflen(name)<2||len(name)>63{returnfmt.Errorf("name must be 2-63 characters")}if!validAppNameRe.MatchString(name){returnfmt.Errorf("name must contain only lowercase letters, numbers, and hyphens")}returnnil}
Apply this in both HandleAppCreate and HandleAppUpdate.
## Severity: MEDIUM
## File: `internal/handlers/app.go` lines 44-79 (HandleAppCreate, HandleAppUpdate)
## Description
The app name is used directly in:
- Docker container names: `"upaas-" + app.Name` (deploy.go)
- Docker image tags: `"upaas-%s:%d"` (deploy.go)
- File system paths for build dirs and log files (deploy.go)
- The HTML `pattern="[a-z0-9-]+"` attribute is only client-side validation
A crafted POST request bypassing the browser can submit names with spaces, special characters, path separators, etc., potentially causing:
- Docker API errors with invalid container/image names
- Path traversal in build directories
- Log injection via app names in log messages
## Suggested Fix
Add server-side validation matching the client-side pattern:
```go
var validAppNameRe = regexp.MustCompile(`^[a-z0-9][a-z0-9-]*[a-z0-9]$`)
func validateAppName(name string) error {
if len(name) < 2 || len(name) > 63 {
return fmt.Errorf("name must be 2-63 characters")
}
if !validAppNameRe.MatchString(name) {
return fmt.Errorf("name must contain only lowercase letters, numbers, and hyphens")
}
return nil
}
```
Apply this in both `HandleAppCreate` and `HandleAppUpdate`.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Severity: MEDIUM
File:
internal/handlers/app.golines 44-79 (HandleAppCreate, HandleAppUpdate)Description
The app name is used directly in:
"upaas-" + app.Name(deploy.go)"upaas-%s:%d"(deploy.go)pattern="[a-z0-9-]+"attribute is only client-side validationA crafted POST request bypassing the browser can submit names with spaces, special characters, path separators, etc., potentially causing:
Suggested Fix
Add server-side validation matching the client-side pattern:
Apply this in both
HandleAppCreateandHandleAppUpdate.yes. give me a PR