From 8bdddafc71a88a2db516778e8212e550f05d6acd Mon Sep 17 00:00:00 2001 From: Ross Lazarus Date: Sat, 11 Aug 2012 09:21:45 +1000 Subject: [PATCH] Add - and . to re.sub exclusion list for user supplied filename at Scott's suggestion and use _ as a substitute for all other characters so 'cd \/; rm -rf' becomes 'cd_____rm_-rf' FastQC wrapper should now be reasonably hard to pervert but user filenames will be at least vaguely recognizable... --- tools/rgenetics/rgFastQC.py | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/tools/rgenetics/rgFastQC.py b/tools/rgenetics/rgFastQC.py index 3f828215cca..c2c66bcc844 100644 --- a/tools/rgenetics/rgFastQC.py +++ b/tools/rgenetics/rgFastQC.py @@ -1,4 +1,7 @@ """ +# added sanitizer for user supplied name +# removed shell and make cl a sequence for Popen call +# ross lazarus August 10 2012 in response to anon insecurity report wrapper for fastqc called as @@ -53,7 +56,7 @@ class FastQC(): cl.append('-c %s' % self.opts.contaminants) # patch suggested by bwlang https://bitbucket.org/galaxy/galaxy-central/pull-request/30 # use a symlink in a temporary directory so that the FastQC report reflects the history input file name - fastqinfilename = re.sub('[^a-zA-Z0-9_]+', '', os.path.basename(self.opts.inputfilename)) + fastqinfilename = re.sub('[^a-zA-Z0-9_\-\.]', '_', os.path.basename(self.opts.inputfilename)) link_name = os.path.join(self.opts.outputdir, fastqinfilename) os.symlink(self.opts.input, link_name) cl.append(link_name)