mirror of
https://github.com/windmill-labs/windmill.git
synced 2026-10-04 08:02:23 +00:00
fix: validate app and trigger paths, refuse traversal in workspace export (#11311)
* fix: enforce proper_id paths on apps and triggers, refuse traversal in export Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix: skip proper_id on tables already holding non-conforming paths Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * test: pin archive entry path traversal guard Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix: refuse windows-normalized traversal in export, check raw app path early Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix: only treat a colon in the first archive segment as a drive prefix Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * test: accept a colon past the first archive segment Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * revert: drop proper_id migration, keep path validation in the API Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix: validate paths in bulk http trigger creation Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5.5
parent
1de54eeea4
commit
7593597617
@@ -22,7 +22,7 @@ use windmill_common::{
|
||||
fetch_draft_only_list_rows, overlay_or_draft_only, UserDraftItemKind, WithDraftOverlay,
|
||||
WithDraftQuery,
|
||||
},
|
||||
utils::{paginate, Pagination, StripPath},
|
||||
utils::{check_proper_path, paginate, Pagination, StripPath},
|
||||
worker::CLOUD_HOSTED,
|
||||
DB,
|
||||
};
|
||||
@@ -547,6 +547,7 @@ async fn create_trigger<T: TriggerCrud>(
|
||||
&new_trigger.base.path
|
||||
)
|
||||
})?;
|
||||
check_proper_path(&new_trigger.base.path)?;
|
||||
|
||||
if *CLOUD_HOSTED && !T::IS_ALLOWED_ON_CLOUD {
|
||||
return Err(Error::BadRequest(format!(
|
||||
@@ -817,6 +818,9 @@ async fn update_trigger<T: TriggerCrud>(
|
||||
&edit_trigger.base.path
|
||||
)
|
||||
})?;
|
||||
if edit_trigger.base.path != path {
|
||||
check_proper_path(&edit_trigger.base.path)?;
|
||||
}
|
||||
|
||||
edit_trigger.error_handling.validate()?;
|
||||
|
||||
|
||||
Reference in New Issue
Block a user