mirror of
https://github.com/dbeaver/cloudbeaver.git
synced 2026-09-24 16:04:36 +08:00
CB-3704. Validate file name (#2065)
* CB-3704. Validate file name * CB-3704. Revert imports * CB-3704. Refactor after review * CB-3704. Fixed error message if files not created. * CB-3074. Remove constant to Servlet
This commit is contained in:
+7
-4
@@ -25,6 +25,7 @@ import org.jkiss.dbeaver.model.websocket.event.WSEventDeleteTempFile;
|
||||
import org.jkiss.utils.IOUtils;
|
||||
|
||||
import java.io.IOException;
|
||||
import java.nio.file.Files;
|
||||
import java.nio.file.Path;
|
||||
|
||||
public class WSDeleteTempFileHandler implements WSEventHandler<WSEventDeleteTempFile> {
|
||||
@@ -36,10 +37,12 @@ public class WSDeleteTempFileHandler implements WSEventHandler<WSEventDeleteTemp
|
||||
Path path = CBPlatform.getInstance()
|
||||
.getTempFolder(new VoidProgressMonitor(), TEMP_FILE_FOLDER)
|
||||
.resolve(sessionId);
|
||||
try {
|
||||
IOUtils.deleteDirectory(path);
|
||||
} catch (IOException e) {
|
||||
log.error("Error deleting temp path", e);
|
||||
if (Files.exists(path)) {
|
||||
try {
|
||||
IOUtils.deleteDirectory(path);
|
||||
} catch (IOException e) {
|
||||
log.error("Error deleting temp path", e);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
+7
-1
@@ -53,6 +53,8 @@ public class WebSQLFileLoaderServlet extends WebServiceServletBase {
|
||||
|
||||
private static final String FILE_ID = "fileId";
|
||||
|
||||
private static final String FORBIDDEN_CHARACTERS_FILE_REGEX = "(?U)[\\w.$()@ -]+";
|
||||
|
||||
private static final Gson gson = new GsonBuilder()
|
||||
.serializeNulls()
|
||||
.setPrettyPrinting()
|
||||
@@ -88,7 +90,7 @@ public class WebSQLFileLoaderServlet extends WebServiceServletBase {
|
||||
|
||||
String fileId = JSONUtils.getString(variables, FILE_ID);
|
||||
|
||||
if (fileId != null) {
|
||||
if (fileId != null && !fileId.matches(FORBIDDEN_CHARACTERS_FILE_REGEX)) {
|
||||
Path file = tempFolder.resolve(fileId);
|
||||
try {
|
||||
Files.write(file, request.getPart("fileData").getInputStream().readAllBytes());
|
||||
@@ -96,6 +98,10 @@ public class WebSQLFileLoaderServlet extends WebServiceServletBase {
|
||||
log.error(e.getMessage());
|
||||
throw new DBWebException(e.getMessage());
|
||||
}
|
||||
} else {
|
||||
String illegalCharacters = fileId != null ?
|
||||
fileId.replaceAll(FORBIDDEN_CHARACTERS_FILE_REGEX, " ").strip() : null;
|
||||
throw new DBException("Resource path '" + fileId + "' contains illegal characters: " + illegalCharacters);
|
||||
}
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user