fix(sharing): enforce base path boundaries

* fix: replace strings.HasPrefix with utils.IsSubPath for path validation

Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>

* fix: re-validate shared paths to ensure they remain within the creator's base path

Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>

---------

Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
Co-authored-by: MadDogOwner <xiaoran@xrgzs.top>
This commit is contained in:
ShenLin
2026-07-09 12:28:51 +08:00
committed by jyxjjj
parent 757f9d383d
commit 59bd343140
3 changed files with 13 additions and 4 deletions
+1 -2
View File
@@ -2,7 +2,6 @@ package handles
import (
"path"
"strings"
"github.com/OpenListTeam/OpenList/v4/internal/conf"
"github.com/OpenListTeam/OpenList/v4/internal/errs"
@@ -51,7 +50,7 @@ func Search(c *gin.Context) {
}
var filteredNodes []model.SearchNode
for _, node := range nodes {
if !strings.HasPrefix(node.Parent, user.BasePath) {
if !utils.IsSubPath(user.BasePath, node.Parent) {
continue
}
meta, err := op.GetNearestMeta(node.Parent)
+2 -2
View File
@@ -461,7 +461,7 @@ func UpdateSharing(c *gin.Context) {
for i, s := range req.Files {
s = utils.FixAndCleanPath(s)
req.Files[i] = s
if !reqUser.IsAdmin() && !strings.HasPrefix(s, user.BasePath) {
if !reqUser.IsAdmin() && !utils.IsSubPath(user.BasePath, s) {
common.ErrorStrResp(c, fmt.Sprintf("permission denied to share path [%s]", s), 500)
return
}
@@ -545,7 +545,7 @@ func CreateSharing(c *gin.Context) {
for i, s := range req.Files {
s = utils.FixAndCleanPath(s)
req.Files[i] = s
if !reqUser.IsAdmin() && !strings.HasPrefix(s, user.BasePath) {
if !reqUser.IsAdmin() && !utils.IsSubPath(user.BasePath, s) {
common.ErrorStrResp(c, fmt.Sprintf("permission denied to share path [%s]", s), 500)
return
}