From 0425acfa10e6a4e21d22fbc8981ee42408f9d6f5 Mon Sep 17 00:00:00 2001 From: wizardchen Date: Wed, 26 Nov 2025 22:02:33 +0800 Subject: [PATCH] refactor: Sanitize log inputs in message and tag handlers to enhance security --- internal/handler/message.go | 2 +- internal/handler/tag.go | 12 +++++++----- 2 files changed, 8 insertions(+), 6 deletions(-) diff --git a/internal/handler/message.go b/internal/handler/message.go index 76122fdab..78544757d 100644 --- a/internal/handler/message.go +++ b/internal/handler/message.go @@ -39,7 +39,7 @@ func (h *MessageHandler) LoadMessages(c *gin.Context) { logger.Info(ctx, "Start loading messages") // Get path parameters and query parameters - sessionID := c.Param("session_id") + sessionID := secutils.SanitizeForLog(c.Param("session_id")) limit := secutils.SanitizeForLog(c.DefaultQuery("limit", "20")) beforeTimeStr := secutils.SanitizeForLog(c.DefaultQuery("before_time", "")) diff --git a/internal/handler/tag.go b/internal/handler/tag.go index 49f89c7fb..7b2209b80 100644 --- a/internal/handler/tag.go +++ b/internal/handler/tag.go @@ -8,6 +8,7 @@ import ( "github.com/Tencent/WeKnora/internal/errors" "github.com/Tencent/WeKnora/internal/logger" "github.com/Tencent/WeKnora/internal/types/interfaces" + secutils "github.com/Tencent/WeKnora/internal/utils" ) // TagHandler handles knowledge base tag operations. @@ -23,7 +24,7 @@ func NewTagHandler(tagService interfaces.KnowledgeTagService) *TagHandler { // ListTags returns all tags under a knowledge base with statistics. func (h *TagHandler) ListTags(c *gin.Context) { ctx := c.Request.Context() - kbID := c.Param("id") + kbID := secutils.SanitizeForLog(c.Param("id")) tags, err := h.tagService.ListTags(ctx, kbID) if err != nil { @@ -47,7 +48,7 @@ type createTagRequest struct { // CreateTag creates a new tag. func (h *TagHandler) CreateTag(c *gin.Context) { ctx := c.Request.Context() - kbID := c.Param("id") + kbID := secutils.SanitizeForLog(c.Param("id")) var req createTagRequest if err := c.ShouldBindJSON(&req); err != nil { @@ -56,7 +57,8 @@ func (h *TagHandler) CreateTag(c *gin.Context) { return } - tag, err := h.tagService.CreateTag(ctx, kbID, req.Name, req.Color, req.SortOrder) + tag, err := h.tagService.CreateTag(ctx, kbID, + secutils.SanitizeForLog(req.Name), secutils.SanitizeForLog(req.Color), req.SortOrder) if err != nil { logger.ErrorWithFields(ctx, err, map[string]interface{}{ "kb_id": kbID, @@ -81,7 +83,7 @@ type updateTagRequest struct { func (h *TagHandler) UpdateTag(c *gin.Context) { ctx := c.Request.Context() - tagID := c.Param("tag_id") + tagID := secutils.SanitizeForLog(c.Param("tag_id")) var req updateTagRequest if err := c.ShouldBindJSON(&req); err != nil { logger.Error(ctx, "Failed to bind update tag payload", err) @@ -107,7 +109,7 @@ func (h *TagHandler) UpdateTag(c *gin.Context) { // DeleteTag deletes a tag. Use query param force=true to force delete even if referenced. func (h *TagHandler) DeleteTag(c *gin.Context) { ctx := c.Request.Context() - tagID := c.Param("tag_id") + tagID := secutils.SanitizeForLog(c.Param("tag_id")) force := c.Query("force") == "true"