apply security patch: release-11.2.9/368-202504020742.patch
commit 14c7fa5311814148bbf24967cd3094480f9d21ab Author: Andres Martinez Gotor <andres.martinez@grafana.com> Date: Wed Apr 2 09:41:11 2025 +0200 Sanitize paths before evaluating access to route
This commit is contained in:
@@ -257,6 +257,14 @@ func TestDataSourceProxy_routeRule(t *testing.T) {
|
||||
err = proxy.validateRequest()
|
||||
require.NoError(t, err)
|
||||
})
|
||||
|
||||
t.Run("path with slashes and user is editor", func(t *testing.T) {
|
||||
ctx, _ := setUp()
|
||||
proxy, err := setupDSProxyTest(t, ctx, ds, routes, "//api//admin")
|
||||
require.NoError(t, err)
|
||||
err = proxy.validateRequest()
|
||||
require.Error(t, err)
|
||||
})
|
||||
})
|
||||
|
||||
t.Run("plugin route with RBAC protection user is allowed", func(t *testing.T) {
|
||||
|
||||
Reference in New Issue
Block a user