From 902f4328c6a2d910c1d9d537b045ad309eefcb13 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" Date: Tue, 18 Feb 2025 21:02:44 +0000 Subject: [PATCH] apply security patch: release-11.2.7/320-202502130525.patch commit ece53167dc7986fd76fee19d161144026fb90646 Author: AgnesToulet <35176601+AgnesToulet@users.noreply.github.com> Date: Tue Feb 11 10:57:05 2025 +0100 Dashboards: Prevent title longer than 5 000 characters (cherry picked from commit f9e0789210004b0bd7902255644ef348ae7b3aa8) --- pkg/services/dashboards/errors.go | 5 +++++ pkg/services/dashboards/service/dashboard_service.go | 4 ++++ 2 files changed, 9 insertions(+) diff --git a/pkg/services/dashboards/errors.go b/pkg/services/dashboards/errors.go index 6e1528124cf..77e5ea1cc37 100644 --- a/pkg/services/dashboards/errors.go +++ b/pkg/services/dashboards/errors.go @@ -47,6 +47,11 @@ var ( StatusCode: 400, Status: "empty-name", } + ErrDashboardTitleTooLong = DashboardErr{ + Reason: "Dashboard title cannot contain more than 5 000 characters", + StatusCode: 400, + Status: "title-too-long", + } ErrDashboardFolderCannotHaveParent = DashboardErr{ Reason: "A Dashboard Folder cannot be added to another folder", StatusCode: 400, diff --git a/pkg/services/dashboards/service/dashboard_service.go b/pkg/services/dashboards/service/dashboard_service.go index c67298ee085..75141fb5dc5 100644 --- a/pkg/services/dashboards/service/dashboard_service.go +++ b/pkg/services/dashboards/service/dashboard_service.go @@ -113,6 +113,10 @@ func (dr *DashboardServiceImpl) BuildSaveDashboardCommand(ctx context.Context, d return nil, dashboards.ErrDashboardTitleEmpty } + if len(dash.Title) > 5000 { + return nil, dashboards.ErrDashboardTitleTooLong + } + metrics.MFolderIDsServiceCount.WithLabelValues(metrics.Dashboard).Inc() // nolint:staticcheck if dash.IsFolder && dash.FolderID > 0 {