Commit 7c69c4e
committed
fix(core): anchor the dynamic report name with \z, not $
In .NET, $ matches at the end of input AND immediately before a trailing
newline, so ^[a-zA-Z][a-zA-Z0-9_-]{0,99}$ accepted a name ending in one.
That name is remotely creatable through POST /api/reports, and this
validator is the only thing standing in front of it.
The concrete consequence is the log statements in ReportJobWorker and
InMemoryJobScheduler: in a plain-text sink the trailing newline splits
the line and lets the name forge a log entry of its own, which is what
CodeQL cs/log-forging was pointing at. Path traversal was never reachable
through it — /, \, . and : have never been in the character class — so
this is the validator not doing what its own doc comment claims rather
than a hole in the file layout. \z means end of input and nothing else.
The type had NO tests at all, which is how an under-anchored pattern
survived since it was written; it has sixteen now, including the trailing
newline, embedded control characters, the length boundary and the
path-traversal shapes the type exists to reject.
One existing assertion had to change with it: ScheduleEndpointTests
compared DynamicReportName.Pattern against the RAW response body, and the
pattern now contains a backslash, which JSON doubles on the wire. It
reads the parsed `error` field instead — stricter, since it also pins
which field carries the message.
Recorded in the backlog rather than fixed here: a code-registered name is
never validated at all, and ReportRunner interpolates it into a temp file
path. The obvious guard throws ArgumentException from ReportBuilder's
constructor, and every ReportConfigCompiler.Compile call site catches only
ConfigurationException — it would turn a bad name into a 500 on POST/PUT
and on the validate endpoint, and stop a host with such a report stored
from starting at all. That needs a design decision, and the input is the
host developer's own literal rather than anything remote.
Full suite: 1 703 green across 33 projects.1 parent 625ed15 commit 7c69c4e
5 files changed
Lines changed: 108 additions & 2 deletions
File tree
- docs
- src/NeoReports.Core/Configuration
- tests
- NeoReports.AspNetCore.IntegrationTests
- NeoReports.Core.UnitTests
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
8 | 8 | | |
9 | 9 | | |
10 | 10 | | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
11 | 23 | | |
12 | 24 | | |
13 | 25 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
135 | 135 | | |
136 | 136 | | |
137 | 137 | | |
| 138 | + | |
| 139 | + | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
| 149 | + | |
| 150 | + | |
| 151 | + | |
| 152 | + | |
138 | 153 | | |
139 | 154 | | |
140 | 155 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
11 | 11 | | |
12 | 12 | | |
13 | 13 | | |
14 | | - | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
15 | 23 | | |
16 | 24 | | |
17 | 25 | | |
| |||
Lines changed: 5 additions & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
74 | 74 | | |
75 | 75 | | |
76 | 76 | | |
77 | | - | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
78 | 82 | | |
79 | 83 | | |
80 | 84 | | |
| |||
Lines changed: 67 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
0 commit comments