From b43236d70b74d854a2317c23552d5fc856658b8c Mon Sep 17 00:00:00 2001 From: Dannon Baker Date: Thu, 20 Feb 2020 16:44:37 -0500 Subject: [PATCH 1/2] Fix shed image resolution to actually test base-path images as intended (and then fail through to static/images) --- .../galaxy/controllers/shed_tool_static.py | 40 +++++++++++++------ 1 file changed, 27 insertions(+), 13 deletions(-) diff --git a/lib/galaxy/webapps/galaxy/controllers/shed_tool_static.py b/lib/galaxy/webapps/galaxy/controllers/shed_tool_static.py index d938f86c958..bcc722f81db 100644 --- a/lib/galaxy/webapps/galaxy/controllers/shed_tool_static.py +++ b/lib/galaxy/webapps/galaxy/controllers/shed_tool_static.py @@ -9,6 +9,12 @@ from galaxy.webapps.base.controller import BaseUIController log = logging.getLogger(__name__) +def _asset_exists_and_is_safe(repo_path, asset_path): + if not safe_contains(repo_path, asset_path): + raise RequestParameterInvalidException() + return os.path.exists(asset_path) + + class ShedToolStatic(BaseUIController): @web.expose @@ -26,17 +32,25 @@ class ShedToolStatic(BaseUIController): """ guid = '/'.join([shed, 'repos', owner, repo, tool, version]) tool = trans.app.toolbox.get_tool(guid) - repo_path = tool._repository_dir - if 'static/images' not in image_file: - path = join(repo_path, 'static', 'images', image_file) + repo_path = os.path.abspath(tool._repository_dir) + asset_path = os.path.abspath(join(repo_path, image_file)) + + # test specified image_file path exactly first, then fail through to + # other locations. + # Might want to swap this around and check for static/images first if + # that's the new(?) standard. + if not _asset_exists_and_is_safe(repo_path, asset_path): + if 'static/images' not in image_file: + asset_path = join(repo_path, 'static', 'images', image_file) + if not _asset_exists_and_is_safe(repo_path, asset_path): + asset_path = None + + if asset_path: + ext = os.path.splitext(image_file)[-1].lstrip('.') + if ext: + mime = trans.app.datatypes_registry.get_mimetype_by_extension(ext) + if mime: + trans.response.set_content_type(mime) + return open(asset_path, 'rb') else: - path = join(repo_path, image_file) - if not safe_contains(os.path.abspath(repo_path), os.path.abspath(path)): - raise RequestParameterInvalidException() - ext = os.path.splitext(image_file)[-1].lstrip('.') - if ext: - mime = trans.app.datatypes_registry.get_mimetype_by_extension(ext) - if mime: - trans.response.set_content_type(mime) - if os.path.exists(path): - return open(path, 'rb') + return None From 6ed152d9763a076fb87e3e36df0a19d95cfd0f79 Mon Sep 17 00:00:00 2001 From: Dannon Baker Date: Thu, 20 Feb 2020 17:50:46 -0500 Subject: [PATCH 2/2] Throw exception for invalid requested image instead of just returning nothing, so we can catch these in sentry. --- lib/galaxy/webapps/galaxy/controllers/shed_tool_static.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/lib/galaxy/webapps/galaxy/controllers/shed_tool_static.py b/lib/galaxy/webapps/galaxy/controllers/shed_tool_static.py index bcc722f81db..042e8184f9c 100644 --- a/lib/galaxy/webapps/galaxy/controllers/shed_tool_static.py +++ b/lib/galaxy/webapps/galaxy/controllers/shed_tool_static.py @@ -53,4 +53,4 @@ class ShedToolStatic(BaseUIController): trans.response.set_content_type(mime) return open(asset_path, 'rb') else: - return None + raise RequestParameterInvalidException()