From 09642445ded60d4e0da6a785b8e88529ece4cd71 Mon Sep 17 00:00:00 2001 From: wizardchen Date: Wed, 26 Nov 2025 10:50:53 +0800 Subject: [PATCH] refactor: Sanitize log inputs in user, auth, knowledge, and model handlers to enhance security --- internal/application/service/user.go | 3 ++- internal/handler/auth.go | 5 ++++- internal/handler/knowledge.go | 12 +++++++----- internal/handler/mcp_service.go | 6 +++++- internal/handler/model.go | 5 ++--- 5 files changed, 20 insertions(+), 11 deletions(-) diff --git a/internal/application/service/user.go b/internal/application/service/user.go index 5c2887fea..0c7c9f546 100644 --- a/internal/application/service/user.go +++ b/internal/application/service/user.go @@ -18,6 +18,7 @@ import ( "github.com/Tencent/WeKnora/internal/logger" "github.com/Tencent/WeKnora/internal/types" "github.com/Tencent/WeKnora/internal/types/interfaces" + secutils "github.com/Tencent/WeKnora/internal/utils" ) var ( @@ -126,7 +127,7 @@ func (s *userService) Register(ctx context.Context, req *types.RegisterRequest) // Create default tenant for the user tenant := &types.Tenant{ - Name: fmt.Sprintf("%s's Workspace", req.Username), + Name: fmt.Sprintf("%s's Workspace", secutils.SanitizeForLog(req.Username)), Description: "Default workspace", Status: "active", RetrieverEngines: types.RetrieverEngines{Engines: egs}, diff --git a/internal/handler/auth.go b/internal/handler/auth.go index b3173d0e6..f0b6a5be2 100644 --- a/internal/handler/auth.go +++ b/internal/handler/auth.go @@ -51,6 +51,9 @@ func (h *AuthHandler) Register(c *gin.Context) { c.Error(appErr) return } + req.Username = secutils.SanitizeForLog(req.Username) + req.Email = secutils.SanitizeForLog(req.Email) + req.Password = secutils.SanitizeForLog(req.Password) // Validate required fields if req.Username == "" || req.Email == "" || req.Password == "" { @@ -77,7 +80,7 @@ func (h *AuthHandler) Register(c *gin.Context) { User: user, } - logger.Infof(ctx, "User registered successfully: %s", user.Email) + logger.Infof(ctx, "User registered successfully: %s", secutils.SanitizeForLog(user.Email)) c.JSON(http.StatusCreated, response) } diff --git a/internal/handler/knowledge.go b/internal/handler/knowledge.go index cf245fc62..b2dd6a6a1 100644 --- a/internal/handler/knowledge.go +++ b/internal/handler/knowledge.go @@ -35,7 +35,7 @@ func (h *KnowledgeHandler) validateKnowledgeBaseAccess(c *gin.Context) (*types.K ctx := c.Request.Context() // Get knowledge base ID from URL path parameter - kbID := c.Param("id") + kbID := secutils.SanitizeForLog(c.Param("id")) if kbID == "" { logger.Error(ctx, "Knowledge base ID is empty") return nil, "", errors.NewBadRequestError("Knowledge base ID cannot be empty") @@ -104,14 +104,16 @@ func (h *KnowledgeHandler) CreateKnowledgeFromFile(c *gin.Context) { // Get custom filename if provided (for folder uploads with path) customFileName := c.PostForm("fileName") + customFileName = secutils.SanitizeForLog(customFileName) displayFileName := file.Filename + displayFileName = secutils.SanitizeForLog(displayFileName) if customFileName != "" { displayFileName = customFileName - logger.Infof(ctx, "Using custom filename: %s (original: %s)", secutils.SanitizeForLog(customFileName), secutils.SanitizeForLog(file.Filename)) + logger.Infof(ctx, "Using custom filename: %s (original: %s)", customFileName, displayFileName) } - logger.Infof(ctx, "File upload successful, filename: %s, size: %.2f KB", secutils.SanitizeForLog(displayFileName), float64(file.Size)/1024) - logger.Infof(ctx, "Creating knowledge, knowledge base ID: %s, filename: %s", secutils.SanitizeForLog(kbID), secutils.SanitizeForLog(displayFileName)) + logger.Infof(ctx, "File upload successful, filename: %s, size: %.2f KB", displayFileName, float64(file.Size)/1024) + logger.Infof(ctx, "Creating knowledge, knowledge base ID: %s, filename: %s", kbID, displayFileName) // Parse metadata if provided var metadata map[string]string @@ -572,7 +574,7 @@ func (h *KnowledgeHandler) UpdateImageInfo(c *gin.Context) { // Update chunk properties logger.Infof(ctx, "Updating knowledge chunk, knowledge ID: %s, chunk ID: %s", id, chunkID) - err := h.kgService.UpdateImageInfo(ctx, id, chunkID, request.ImageInfo) + err := h.kgService.UpdateImageInfo(ctx, id, chunkID, secutils.SanitizeForLog(request.ImageInfo)) if err != nil { logger.ErrorWithFields(ctx, err, nil) c.Error(errors.NewInternalServerError(err.Error())) diff --git a/internal/handler/mcp_service.go b/internal/handler/mcp_service.go index 747a1ceea..2555b00a3 100644 --- a/internal/handler/mcp_service.go +++ b/internal/handler/mcp_service.go @@ -145,7 +145,11 @@ func (h *MCPServiceHandler) UpdateMCPService(c *gin.Context) { updateFields["description"] = true } if enabled, ok := updateData["enabled"].(bool); ok { - service.Enabled = enabled + if enabled { + service.Enabled = true + } else { + service.Enabled = false + } updateFields["enabled"] = true } if transportType, ok := updateData["transport_type"].(string); ok { diff --git a/internal/handler/model.go b/internal/handler/model.go index 16e3d9ebf..1bbf0899c 100644 --- a/internal/handler/model.go +++ b/internal/handler/model.go @@ -84,7 +84,6 @@ func (h *ModelHandler) CreateModel(c *gin.Context) { c.Error(errors.NewBadRequestError(err.Error())) return } - req.Name = secutils.SanitizeForLog(req.Name) tenantID := c.GetUint64(types.TenantIDContextKey.String()) if tenantID == 0 { logger.Error(ctx, "Tenant ID is empty") @@ -97,10 +96,10 @@ func (h *ModelHandler) CreateModel(c *gin.Context) { model := &types.Model{ TenantID: tenantID, - Name: req.Name, + Name: secutils.SanitizeForLog(req.Name), Type: req.Type, Source: req.Source, - Description: req.Description, + Description: secutils.SanitizeForLog(req.Description), Parameters: req.Parameters, }