mirror of
https://github.com/whyour/qinglong.git
synced 2026-08-13 12:23:29 +08:00
Add comprehensive security validation to prevent malicious code injection
Co-authored-by: whyour <22700758+whyour@users.noreply.github.com>
This commit is contained in:
co-authored by
whyour
parent
a030e19fc0
commit
ac8090d937
+43
-1
@@ -64,7 +64,44 @@ export default (app: Router) => {
|
||||
celebrate({
|
||||
body: Joi.object({
|
||||
name: Joi.string().required(),
|
||||
content: Joi.string().allow('').optional(),
|
||||
content: Joi.string().allow('').optional().custom((value, helpers) => {
|
||||
if (!value) return value;
|
||||
|
||||
// Security validation for configuration file content
|
||||
const dangerousPatterns = [
|
||||
// Command substitution that could download/execute malware
|
||||
{ pattern: /\$\([^)]*curl[^)]*\)/gi, desc: '命令替换中的下载操作' },
|
||||
{ pattern: /\$\([^)]*wget[^)]*\)/gi, desc: '命令替换中的下载操作' },
|
||||
{ pattern: /`[^`]*curl[^`]*`/gi, desc: '反引号命令替换中的下载操作' },
|
||||
{ pattern: /`[^`]*wget[^`]*`/gi, desc: '反引号命令替换中的下载操作' },
|
||||
|
||||
// Suspicious file downloads followed by execution
|
||||
{ pattern: /(curl|wget)[^;]*\|\s*bash/gi, desc: '下载并直接执行的危险模式' },
|
||||
{ pattern: /(curl|wget)[^;]*&&\s*chmod\s*\+x/gi, desc: '下载并赋予执行权限的可疑模式' },
|
||||
|
||||
// External URLs downloading executables with suspicious names
|
||||
{ pattern: /https?:\/\/[^\s]+\/(fullgc|\.[\w-]+)[\s;"']/gi, desc: '可疑的外部可执行文件下载' },
|
||||
|
||||
// Background execution of hidden files
|
||||
{ pattern: /nohup\s+["']?[^"'\s]*\/\.\w+["']?\s*>/gi, desc: '后台执行隐藏文件' },
|
||||
];
|
||||
|
||||
for (const { pattern, desc } of dangerousPatterns) {
|
||||
if (pattern.test(value)) {
|
||||
return helpers.error('string.unsafe', { description: desc });
|
||||
}
|
||||
}
|
||||
|
||||
// Check for excessive length
|
||||
if (value.length > 1000000) {
|
||||
return helpers.error('string.max', { limit: 1000000 });
|
||||
}
|
||||
|
||||
return value;
|
||||
}).messages({
|
||||
'string.unsafe': '配置文件内容包含潜在危险的模式 ({#description}),已被安全系统拦截',
|
||||
'string.max': '配置文件内容过长,已被安全系统拦截',
|
||||
}),
|
||||
}),
|
||||
}),
|
||||
async (req: Request, res: Response, next: NextFunction) => {
|
||||
@@ -73,11 +110,16 @@ export default (app: Router) => {
|
||||
const { name, content } = req.body;
|
||||
if (config.blackFileList.includes(name)) {
|
||||
res.send({ code: 403, message: '文件无法访问' });
|
||||
return;
|
||||
}
|
||||
let path = join(config.configPath, name);
|
||||
if (name.startsWith('data/scripts/')) {
|
||||
path = join(config.rootPath, name);
|
||||
}
|
||||
|
||||
// Log security-relevant file modifications
|
||||
logger.info(`配置文件写入: ${name}, 大小: ${content?.length || 0} 字节`);
|
||||
|
||||
await writeFileWithLock(path, content);
|
||||
res.send({ code: 200, message: '保存成功' });
|
||||
} catch (e) {
|
||||
|
||||
Reference in New Issue
Block a user