refactor: Sanitize log inputs in user, auth, knowledge, and model handlers to enhance security

This commit is contained in:
wizardchen
2025-11-26 10:50:53 +08:00
parent 8e3c2d8547
commit 09642445de
5 changed files with 20 additions and 11 deletions
+2 -1
View File
@@ -18,6 +18,7 @@ import (
"github.com/Tencent/WeKnora/internal/logger"
"github.com/Tencent/WeKnora/internal/types"
"github.com/Tencent/WeKnora/internal/types/interfaces"
secutils "github.com/Tencent/WeKnora/internal/utils"
)
var (
@@ -126,7 +127,7 @@ func (s *userService) Register(ctx context.Context, req *types.RegisterRequest)
// Create default tenant for the user
tenant := &types.Tenant{
Name: fmt.Sprintf("%s's Workspace", req.Username),
Name: fmt.Sprintf("%s's Workspace", secutils.SanitizeForLog(req.Username)),
Description: "Default workspace",
Status: "active",
RetrieverEngines: types.RetrieverEngines{Engines: egs},
+4 -1
View File
@@ -51,6 +51,9 @@ func (h *AuthHandler) Register(c *gin.Context) {
c.Error(appErr)
return
}
req.Username = secutils.SanitizeForLog(req.Username)
req.Email = secutils.SanitizeForLog(req.Email)
req.Password = secutils.SanitizeForLog(req.Password)
// Validate required fields
if req.Username == "" || req.Email == "" || req.Password == "" {
@@ -77,7 +80,7 @@ func (h *AuthHandler) Register(c *gin.Context) {
User: user,
}
logger.Infof(ctx, "User registered successfully: %s", user.Email)
logger.Infof(ctx, "User registered successfully: %s", secutils.SanitizeForLog(user.Email))
c.JSON(http.StatusCreated, response)
}
+7 -5
View File
@@ -35,7 +35,7 @@ func (h *KnowledgeHandler) validateKnowledgeBaseAccess(c *gin.Context) (*types.K
ctx := c.Request.Context()
// Get knowledge base ID from URL path parameter
kbID := c.Param("id")
kbID := secutils.SanitizeForLog(c.Param("id"))
if kbID == "" {
logger.Error(ctx, "Knowledge base ID is empty")
return nil, "", errors.NewBadRequestError("Knowledge base ID cannot be empty")
@@ -104,14 +104,16 @@ func (h *KnowledgeHandler) CreateKnowledgeFromFile(c *gin.Context) {
// Get custom filename if provided (for folder uploads with path)
customFileName := c.PostForm("fileName")
customFileName = secutils.SanitizeForLog(customFileName)
displayFileName := file.Filename
displayFileName = secutils.SanitizeForLog(displayFileName)
if customFileName != "" {
displayFileName = customFileName
logger.Infof(ctx, "Using custom filename: %s (original: %s)", secutils.SanitizeForLog(customFileName), secutils.SanitizeForLog(file.Filename))
logger.Infof(ctx, "Using custom filename: %s (original: %s)", customFileName, displayFileName)
}
logger.Infof(ctx, "File upload successful, filename: %s, size: %.2f KB", secutils.SanitizeForLog(displayFileName), float64(file.Size)/1024)
logger.Infof(ctx, "Creating knowledge, knowledge base ID: %s, filename: %s", secutils.SanitizeForLog(kbID), secutils.SanitizeForLog(displayFileName))
logger.Infof(ctx, "File upload successful, filename: %s, size: %.2f KB", displayFileName, float64(file.Size)/1024)
logger.Infof(ctx, "Creating knowledge, knowledge base ID: %s, filename: %s", kbID, displayFileName)
// Parse metadata if provided
var metadata map[string]string
@@ -572,7 +574,7 @@ func (h *KnowledgeHandler) UpdateImageInfo(c *gin.Context) {
// Update chunk properties
logger.Infof(ctx, "Updating knowledge chunk, knowledge ID: %s, chunk ID: %s", id, chunkID)
err := h.kgService.UpdateImageInfo(ctx, id, chunkID, request.ImageInfo)
err := h.kgService.UpdateImageInfo(ctx, id, chunkID, secutils.SanitizeForLog(request.ImageInfo))
if err != nil {
logger.ErrorWithFields(ctx, err, nil)
c.Error(errors.NewInternalServerError(err.Error()))
+5 -1
View File
@@ -145,7 +145,11 @@ func (h *MCPServiceHandler) UpdateMCPService(c *gin.Context) {
updateFields["description"] = true
}
if enabled, ok := updateData["enabled"].(bool); ok {
service.Enabled = enabled
if enabled {
service.Enabled = true
} else {
service.Enabled = false
}
updateFields["enabled"] = true
}
if transportType, ok := updateData["transport_type"].(string); ok {
+2 -3
View File
@@ -84,7 +84,6 @@ func (h *ModelHandler) CreateModel(c *gin.Context) {
c.Error(errors.NewBadRequestError(err.Error()))
return
}
req.Name = secutils.SanitizeForLog(req.Name)
tenantID := c.GetUint64(types.TenantIDContextKey.String())
if tenantID == 0 {
logger.Error(ctx, "Tenant ID is empty")
@@ -97,10 +96,10 @@ func (h *ModelHandler) CreateModel(c *gin.Context) {
model := &types.Model{
TenantID: tenantID,
Name: req.Name,
Name: secutils.SanitizeForLog(req.Name),
Type: req.Type,
Source: req.Source,
Description: req.Description,
Description: secutils.SanitizeForLog(req.Description),
Parameters: req.Parameters,
}