Merged from STRUTS_2_3_15_X

WW-4136 - Demonstrate proper input sanitizing for file download showcase example
- added demo code to prevent input paths containing "WEB-INF" [from revision 1500082]

git-svn-id: https://svn.apache.org/repos/asf/struts/struts2/trunk@1500083 13f79535-47bb-0310-9956-ffa450edef68
This commit is contained in:
René Gielen
2013-07-05 17:47:42 +00:00
parent eb41dc6ea6
commit 43d067f52b
2 changed files with 59 additions and 1 deletions
@@ -39,7 +39,23 @@ public class FileDownloadAction implements Action {
}
public void setInputPath(String value) {
inputPath = value;
inputPath = sanitizeInputPath(value);
}
/**
* As the user modifiable parameter inputPath will be used to access server side resources, we want the path to be
* sanitized - in this case it is demonstrated to disallow inputPath parameter values containing "WEB-INF". Consider to
* use even stricter rules in production environments.
*
* @param value the raw parameter input value to sanitize
*
* @return the sanitized value; <tt>null</tt> if value contains an invalid path segment like WEB-INF
*/
String sanitizeInputPath( String value ) {
if (value != null && value.toUpperCase().contains("WEB-INF")) {
return null;
}
return value;
}
public InputStream getInputStream() throws Exception {
@@ -0,0 +1,42 @@
package org.apache.struts2.showcase.filedownload;
import org.junit.Before;
import org.junit.Test;
import static junit.framework.Assert.assertEquals;
import static junit.framework.Assert.assertNull;
public class FileDownloadActionTest {
private FileDownloadAction fileDownloadAction;
@Before
public void setUp() {
this.fileDownloadAction = new FileDownloadAction();
}
@Test
public void testSanitizeInputPathShouldAllowSimpleParameter() throws Exception {
assertEquals("foo", fileDownloadAction.sanitizeInputPath("foo"));
}
@Test
public void testSanitizeInputPathShouldReturnNullForNullInput() throws Exception {
assertNull(fileDownloadAction.sanitizeInputPath(null));
}
@Test
public void testSanitizeInputPathShouldReturnNullForLeadingWebInf() throws Exception {
assertNull(fileDownloadAction.sanitizeInputPath("WEB-INF/foo"));
}
@Test
public void testSanitizeInputPathShouldReturnNullForNonLeadingWebInf() throws Exception {
assertNull(fileDownloadAction.sanitizeInputPath("./WEB-INF/foo"));
}
@Test
public void testSanitizeInputPathShouldReturnNullForNonUppercaseWebInf() throws Exception {
assertNull(fileDownloadAction.sanitizeInputPath("./wEB-Inf/foo"));
}
}