mirror of
https://github.com/Tencent/WeKnora.git
synced 2026-09-24 16:29:01 +08:00
refactor: Sanitize log inputs in user, auth, knowledge, and model handlers to enhance security
This commit is contained in:
@@ -18,6 +18,7 @@ import (
|
||||
"github.com/Tencent/WeKnora/internal/logger"
|
||||
"github.com/Tencent/WeKnora/internal/types"
|
||||
"github.com/Tencent/WeKnora/internal/types/interfaces"
|
||||
secutils "github.com/Tencent/WeKnora/internal/utils"
|
||||
)
|
||||
|
||||
var (
|
||||
@@ -126,7 +127,7 @@ func (s *userService) Register(ctx context.Context, req *types.RegisterRequest)
|
||||
|
||||
// Create default tenant for the user
|
||||
tenant := &types.Tenant{
|
||||
Name: fmt.Sprintf("%s's Workspace", req.Username),
|
||||
Name: fmt.Sprintf("%s's Workspace", secutils.SanitizeForLog(req.Username)),
|
||||
Description: "Default workspace",
|
||||
Status: "active",
|
||||
RetrieverEngines: types.RetrieverEngines{Engines: egs},
|
||||
|
||||
@@ -51,6 +51,9 @@ func (h *AuthHandler) Register(c *gin.Context) {
|
||||
c.Error(appErr)
|
||||
return
|
||||
}
|
||||
req.Username = secutils.SanitizeForLog(req.Username)
|
||||
req.Email = secutils.SanitizeForLog(req.Email)
|
||||
req.Password = secutils.SanitizeForLog(req.Password)
|
||||
|
||||
// Validate required fields
|
||||
if req.Username == "" || req.Email == "" || req.Password == "" {
|
||||
@@ -77,7 +80,7 @@ func (h *AuthHandler) Register(c *gin.Context) {
|
||||
User: user,
|
||||
}
|
||||
|
||||
logger.Infof(ctx, "User registered successfully: %s", user.Email)
|
||||
logger.Infof(ctx, "User registered successfully: %s", secutils.SanitizeForLog(user.Email))
|
||||
c.JSON(http.StatusCreated, response)
|
||||
}
|
||||
|
||||
|
||||
@@ -35,7 +35,7 @@ func (h *KnowledgeHandler) validateKnowledgeBaseAccess(c *gin.Context) (*types.K
|
||||
ctx := c.Request.Context()
|
||||
|
||||
// Get knowledge base ID from URL path parameter
|
||||
kbID := c.Param("id")
|
||||
kbID := secutils.SanitizeForLog(c.Param("id"))
|
||||
if kbID == "" {
|
||||
logger.Error(ctx, "Knowledge base ID is empty")
|
||||
return nil, "", errors.NewBadRequestError("Knowledge base ID cannot be empty")
|
||||
@@ -104,14 +104,16 @@ func (h *KnowledgeHandler) CreateKnowledgeFromFile(c *gin.Context) {
|
||||
|
||||
// Get custom filename if provided (for folder uploads with path)
|
||||
customFileName := c.PostForm("fileName")
|
||||
customFileName = secutils.SanitizeForLog(customFileName)
|
||||
displayFileName := file.Filename
|
||||
displayFileName = secutils.SanitizeForLog(displayFileName)
|
||||
if customFileName != "" {
|
||||
displayFileName = customFileName
|
||||
logger.Infof(ctx, "Using custom filename: %s (original: %s)", secutils.SanitizeForLog(customFileName), secutils.SanitizeForLog(file.Filename))
|
||||
logger.Infof(ctx, "Using custom filename: %s (original: %s)", customFileName, displayFileName)
|
||||
}
|
||||
|
||||
logger.Infof(ctx, "File upload successful, filename: %s, size: %.2f KB", secutils.SanitizeForLog(displayFileName), float64(file.Size)/1024)
|
||||
logger.Infof(ctx, "Creating knowledge, knowledge base ID: %s, filename: %s", secutils.SanitizeForLog(kbID), secutils.SanitizeForLog(displayFileName))
|
||||
logger.Infof(ctx, "File upload successful, filename: %s, size: %.2f KB", displayFileName, float64(file.Size)/1024)
|
||||
logger.Infof(ctx, "Creating knowledge, knowledge base ID: %s, filename: %s", kbID, displayFileName)
|
||||
|
||||
// Parse metadata if provided
|
||||
var metadata map[string]string
|
||||
@@ -572,7 +574,7 @@ func (h *KnowledgeHandler) UpdateImageInfo(c *gin.Context) {
|
||||
|
||||
// Update chunk properties
|
||||
logger.Infof(ctx, "Updating knowledge chunk, knowledge ID: %s, chunk ID: %s", id, chunkID)
|
||||
err := h.kgService.UpdateImageInfo(ctx, id, chunkID, request.ImageInfo)
|
||||
err := h.kgService.UpdateImageInfo(ctx, id, chunkID, secutils.SanitizeForLog(request.ImageInfo))
|
||||
if err != nil {
|
||||
logger.ErrorWithFields(ctx, err, nil)
|
||||
c.Error(errors.NewInternalServerError(err.Error()))
|
||||
|
||||
@@ -145,7 +145,11 @@ func (h *MCPServiceHandler) UpdateMCPService(c *gin.Context) {
|
||||
updateFields["description"] = true
|
||||
}
|
||||
if enabled, ok := updateData["enabled"].(bool); ok {
|
||||
service.Enabled = enabled
|
||||
if enabled {
|
||||
service.Enabled = true
|
||||
} else {
|
||||
service.Enabled = false
|
||||
}
|
||||
updateFields["enabled"] = true
|
||||
}
|
||||
if transportType, ok := updateData["transport_type"].(string); ok {
|
||||
|
||||
@@ -84,7 +84,6 @@ func (h *ModelHandler) CreateModel(c *gin.Context) {
|
||||
c.Error(errors.NewBadRequestError(err.Error()))
|
||||
return
|
||||
}
|
||||
req.Name = secutils.SanitizeForLog(req.Name)
|
||||
tenantID := c.GetUint64(types.TenantIDContextKey.String())
|
||||
if tenantID == 0 {
|
||||
logger.Error(ctx, "Tenant ID is empty")
|
||||
@@ -97,10 +96,10 @@ func (h *ModelHandler) CreateModel(c *gin.Context) {
|
||||
|
||||
model := &types.Model{
|
||||
TenantID: tenantID,
|
||||
Name: req.Name,
|
||||
Name: secutils.SanitizeForLog(req.Name),
|
||||
Type: req.Type,
|
||||
Source: req.Source,
|
||||
Description: req.Description,
|
||||
Description: secutils.SanitizeForLog(req.Description),
|
||||
Parameters: req.Parameters,
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user