continuous-integration/drone/push Build encountered an error
Input handling: - uploadLogo: client file name reduced to a safe base name with an image extension (path traversal and arbitrary-extension writes closed). - extractZIP: zip-slip guard; entries that resolve outside the target are refused. Per-entry closes no longer pile up as defers. - ffmpeg.path / vlc.path must be an existing regular file named ffmpeg, vlc or cvlc, checked both when saved and right before exec. - Stream URLs passed to the external buffer must use a network scheme (http, https, rtsp, rtmp, rtp, udp, mms); file:, concat:, pipe: are refused. - /download/ (backups with settings.json and authentication.json) requires the web session when web authentication is enabled. - settings.json is written 0600; the Plex token is masked in every payload sent to the UI and the mask round-trips as "unchanged" on save. Authentication: - Passwords are stored with bcrypt. Existing HMAC-SHA256 records still verify (constant time) and are re-hashed on the first successful login. Username lookups compare in constant time. - URL (?username=&password=) and HTTP Basic authentication verify the credentials per request via AuthenticateUser and no longer create a session token, which removes the unbounded token growth under Plex polling. Expired sessions are evicted whenever a new one is created. - createFirstUserForAuthentication and checkAuthorizationLevel now return real errors instead of calling no-op closures. Tests: src/security_test.go and src/internal/authentication/ authentication_test.go cover each of the above.
36 lines
644 B
Go
36 lines
644 B
Go
package src
|
|
|
|
import (
|
|
b64 "encoding/base64"
|
|
"fmt"
|
|
"strings"
|
|
)
|
|
|
|
func uploadLogo(input, filename string) (logoURL string, err error) {
|
|
|
|
filename, err = sanitizeUploadFilename(filename)
|
|
if err != nil {
|
|
return
|
|
}
|
|
|
|
b64data := input[strings.IndexByte(input, ',')+1:]
|
|
|
|
// BAse64 in bytes umwandeln un speichern
|
|
sDec, err := b64.StdEncoding.DecodeString(b64data)
|
|
if err != nil {
|
|
return
|
|
}
|
|
|
|
var file = fmt.Sprintf("%s%s", System.Folder.ImagesUpload, filename)
|
|
|
|
err = writeByteToFile(file, sDec)
|
|
if err != nil {
|
|
return
|
|
}
|
|
|
|
logoURL = fmt.Sprintf("%s://%s/data_images/%s", System.ServerProtocol.XML, System.Domain, filename)
|
|
|
|
return
|
|
|
|
}
|