WW-4136 - Demonstrate proper input sanitizing for file download showcase example

- added demo code to prevent input paths containing "WEB-INF"

git-svn-id: https://svn.apache.org/repos/asf/struts/struts2/branches/STRUTS_2_3_15_X@1500082 13f79535-47bb-0310-9956-ffa450edef68
This commit is contained in:
René Gielen
2013-07-05 17:44:09 +00:00
parent ba2d9b7400
commit 42c615c826
2 changed files with 59 additions and 1 deletions
@@ -39,7 +39,23 @@ public class FileDownloadAction implements Action {
}
public void setInputPath(String value) {
inputPath = value;
inputPath = sanitizeInputPath(value);
}
/**
* As the user modifiable parameter inputPath will be used to access server side resources, we want the path to be
* sanitized - in this case it is demonstrated to disallow inputPath parameter values containing "WEB-INF". Consider to
* use even stricter rules in production environments.
*
* @param value the raw parameter input value to sanitize
*
* @return the sanitized value; <tt>null</tt> if value contains an invalid path segment like WEB-INF
*/
String sanitizeInputPath( String value ) {
if (value != null && value.toUpperCase().contains("WEB-INF")) {
return null;
}
return value;
}
public InputStream getInputStream() throws Exception {
@@ -0,0 +1,42 @@
package org.apache.struts2.showcase.filedownload;
import org.junit.Before;
import org.junit.Test;
import static junit.framework.Assert.assertEquals;
import static junit.framework.Assert.assertNull;
public class FileDownloadActionTest {
private FileDownloadAction fileDownloadAction;
@Before
public void setUp() {
this.fileDownloadAction = new FileDownloadAction();
}
@Test
public void testSanitizeInputPathShouldAllowSimpleParameter() throws Exception {
assertEquals("foo", fileDownloadAction.sanitizeInputPath("foo"));
}
@Test
public void testSanitizeInputPathShouldReturnNullForNullInput() throws Exception {
assertNull(fileDownloadAction.sanitizeInputPath(null));
}
@Test
public void testSanitizeInputPathShouldReturnNullForLeadingWebInf() throws Exception {
assertNull(fileDownloadAction.sanitizeInputPath("WEB-INF/foo"));
}
@Test
public void testSanitizeInputPathShouldReturnNullForNonLeadingWebInf() throws Exception {
assertNull(fileDownloadAction.sanitizeInputPath("./WEB-INF/foo"));
}
@Test
public void testSanitizeInputPathShouldReturnNullForNonUppercaseWebInf() throws Exception {
assertNull(fileDownloadAction.sanitizeInputPath("./wEB-Inf/foo"));
}
}