CB-3704. Validate file name (#2065)

* CB-3704. Validate file name

* CB-3704. Revert imports

* CB-3704. Refactor after review

* CB-3704. Fixed error message if files not created.

* CB-3074. Remove constant to Servlet
This commit is contained in:
DenisSinelnikov
2023-10-18 15:42:29 +03:00
committed by GitHub
parent 245d49b892
commit d87115d753
2 changed files with 14 additions and 5 deletions
@@ -25,6 +25,7 @@ import org.jkiss.dbeaver.model.websocket.event.WSEventDeleteTempFile;
import org.jkiss.utils.IOUtils;
import java.io.IOException;
import java.nio.file.Files;
import java.nio.file.Path;
public class WSDeleteTempFileHandler implements WSEventHandler<WSEventDeleteTempFile> {
@@ -36,10 +37,12 @@ public class WSDeleteTempFileHandler implements WSEventHandler<WSEventDeleteTemp
Path path = CBPlatform.getInstance()
.getTempFolder(new VoidProgressMonitor(), TEMP_FILE_FOLDER)
.resolve(sessionId);
try {
IOUtils.deleteDirectory(path);
} catch (IOException e) {
log.error("Error deleting temp path", e);
if (Files.exists(path)) {
try {
IOUtils.deleteDirectory(path);
} catch (IOException e) {
log.error("Error deleting temp path", e);
}
}
}
@@ -53,6 +53,8 @@ public class WebSQLFileLoaderServlet extends WebServiceServletBase {
private static final String FILE_ID = "fileId";
private static final String FORBIDDEN_CHARACTERS_FILE_REGEX = "(?U)[\\w.$()@ -]+";
private static final Gson gson = new GsonBuilder()
.serializeNulls()
.setPrettyPrinting()
@@ -88,7 +90,7 @@ public class WebSQLFileLoaderServlet extends WebServiceServletBase {
String fileId = JSONUtils.getString(variables, FILE_ID);
if (fileId != null) {
if (fileId != null && !fileId.matches(FORBIDDEN_CHARACTERS_FILE_REGEX)) {
Path file = tempFolder.resolve(fileId);
try {
Files.write(file, request.getPart("fileData").getInputStream().readAllBytes());
@@ -96,6 +98,10 @@ public class WebSQLFileLoaderServlet extends WebServiceServletBase {
log.error(e.getMessage());
throw new DBWebException(e.getMessage());
}
} else {
String illegalCharacters = fileId != null ?
fileId.replaceAll(FORBIDDEN_CHARACTERS_FILE_REGEX, " ").strip() : null;
throw new DBException("Resource path '" + fileId + "' contains illegal characters: " + illegalCharacters);
}
}
}