security: add slug validation, username validation, and template escaping
- Enforce SLUG_REGEX (alphanumeric + dot/dash/underscore only) in creation_error to prevent path traversal (C-1) and stored XSS (C-3). - Add File.expand_path containment check in default_path_for as defense-in-depth. - Escape slug in form action attributes (list, form views). - Validate username in change_username using the same regex as create_user (C-4). - Escape username in settings form action attributes. - Treat submitting the current username as a no-op success instead of 'taken'.
This commit is contained in:
@@ -49,4 +49,10 @@ class StoreTest < Minitest::Test
|
||||
assert store.find("global", lang: "cs")
|
||||
assert store.find("global", lang: "en")
|
||||
end
|
||||
|
||||
def test_save_rejects_path_traversal_slug
|
||||
store = Volumen::Store.new(@dir)
|
||||
post = Volumen::Post.new(metadata: { "slug" => "../../etc/passwd" }, body: "x")
|
||||
assert_raises(ArgumentError, "slug escapes content directory") { store.save(post) }
|
||||
end
|
||||
end
|
||||
|
||||
Reference in New Issue
Block a user