[Search] Fix CodeQL warnings (#101364)

* Fix CodeQL warnings

* Also validate if path is a file above the safe dir

* Lint

* [REVIEW] reduce possibility of exploits

* Comment

* Remove test scenario
This commit is contained in:
Leonor Oliveira
2025-03-26 15:38:58 +01:00
committed by GitHub
parent 3264067e63
commit 51bbfa2d08
2 changed files with 142 additions and 2 deletions
+102
View File
@@ -4,6 +4,7 @@ import (
"context"
"encoding/json"
"fmt"
"math"
"os"
"path/filepath"
"testing"
@@ -596,3 +597,104 @@ func (nc StubAccessClient) Write(ctx context.Context, req *authzextv1.WriteReque
func (nc StubAccessClient) BatchCheck(ctx context.Context, req *authzextv1.BatchCheckRequest) (*authzextv1.BatchCheckResponse, error) {
return nil, nil
}
func TestSafeInt64ToInt(t *testing.T) {
tests := []struct {
name string
input int64
want int
wantErr bool
}{
{
name: "Valid int64 within int range",
input: 42,
want: 42,
},
{
name: "Overflow int64 value",
input: math.MaxInt64,
want: 0,
wantErr: true,
},
{
name: "Underflow int64 value",
input: math.MinInt64,
want: 0,
wantErr: true,
},
}
for _, tt := range tests {
t.Run(tt.name, func(t *testing.T) {
got, err := safeInt64ToInt(tt.input)
if tt.wantErr {
require.Error(t, err)
return
}
require.Equal(t, tt.want, got)
})
}
}
func Test_isValidPath(t *testing.T) {
tests := []struct {
name string
dir string
safeDir string
want bool
}{
{
name: "valid path",
dir: "/path/to/my-file/",
safeDir: "/path/to/",
want: true,
},
{
name: "valid path without trailing slash",
dir: "/path/to/my-file",
safeDir: "/path/to",
want: true,
},
{
name: "path with double slashes",
dir: "/path//to//my-file/",
safeDir: "/path/to/",
want: true,
},
{
name: "invalid path: ..",
dir: "/path/../above/",
safeDir: "/path/to/",
},
{
name: "invalid path: \\",
dir: "\\path/to",
safeDir: "/path/to/",
},
{
name: "invalid path: not under safe dir",
dir: "/path/to.txt",
safeDir: "/path/to/",
},
{
name: "invalid path: empty paths",
dir: "",
safeDir: "/path/to/",
},
{
name: "invalid path: different path",
dir: "/other/path/to/my-file/",
safeDir: "/Some/other/path",
},
{
name: "invalid path: empty safe path",
dir: "/path/to/",
safeDir: "",
},
}
for _, tt := range tests {
t.Run(tt.name, func(t *testing.T) {
require.Equal(t, tt.want, isValidPath(tt.dir, tt.safeDir))
})
}
}