mirror of
https://github.com/tiennm99/coolify.git
synced 2026-08-13 02:22:26 +00:00
Squashed commit from 'qqrq-r9h4-x6wp-authenticated-rce'
This commit is contained in:
@@ -9,7 +9,7 @@ class ValidationPatterns
|
||||
{
|
||||
/**
|
||||
* Pattern for names excluding all dangerous characters
|
||||
*/
|
||||
*/
|
||||
public const NAME_PATTERN = '/^[\p{L}\p{M}\p{N}\s\-_.@\/&]+$/u';
|
||||
|
||||
/**
|
||||
@@ -23,6 +23,32 @@ class ValidationPatterns
|
||||
*/
|
||||
public const FILE_PATH_PATTERN = '/^\/[a-zA-Z0-9._\-\/~@+]+$/';
|
||||
|
||||
/**
|
||||
* Pattern for directory paths (base_directory, publish_directory, etc.)
|
||||
* Like FILE_PATH_PATTERN but also allows bare "/" (root directory)
|
||||
*/
|
||||
public const DIRECTORY_PATH_PATTERN = '/^\/([a-zA-Z0-9._\-\/~@+]*)?$/';
|
||||
|
||||
/**
|
||||
* Pattern for Docker build target names (multi-stage build stage names)
|
||||
* Allows alphanumeric, dots, hyphens, and underscores
|
||||
*/
|
||||
public const DOCKER_TARGET_PATTERN = '/^[a-zA-Z0-9][a-zA-Z0-9._-]*$/';
|
||||
|
||||
/**
|
||||
* Pattern for shell-safe command strings (docker compose commands, docker run options)
|
||||
* Blocks dangerous shell metacharacters: ; & | ` $ ( ) > < newlines and carriage returns
|
||||
* Also blocks backslashes, single quotes, and double quotes to prevent escape-sequence attacks
|
||||
* Uses [ \t] instead of \s to explicitly exclude \n and \r (which act as command separators)
|
||||
*/
|
||||
public const SHELL_SAFE_COMMAND_PATTERN = '/^[a-zA-Z0-9 \t._\-\/=:@,+\[\]{}#%^~]+$/';
|
||||
|
||||
/**
|
||||
* Pattern for Docker container names
|
||||
* Must start with alphanumeric, followed by alphanumeric, dots, hyphens, or underscores
|
||||
*/
|
||||
public const CONTAINER_NAME_PATTERN = '/^[a-zA-Z0-9][a-zA-Z0-9._-]*$/';
|
||||
|
||||
/**
|
||||
* Get validation rules for name fields
|
||||
*/
|
||||
@@ -70,7 +96,7 @@ class ValidationPatterns
|
||||
public static function nameMessages(): array
|
||||
{
|
||||
return [
|
||||
'name.regex' => "The name may only contain letters (including Unicode), numbers, spaces, and these characters: - _ . / @ &",
|
||||
'name.regex' => 'The name may only contain letters (including Unicode), numbers, spaces, and these characters: - _ . / @ &',
|
||||
'name.min' => 'The name must be at least :min characters.',
|
||||
'name.max' => 'The name may not be greater than :max characters.',
|
||||
];
|
||||
@@ -105,6 +131,38 @@ class ValidationPatterns
|
||||
];
|
||||
}
|
||||
|
||||
/**
|
||||
* Get validation rules for directory path fields (base_directory, publish_directory)
|
||||
*/
|
||||
public static function directoryPathRules(int $maxLength = 255): array
|
||||
{
|
||||
return ['nullable', 'string', 'max:'.$maxLength, 'regex:'.self::DIRECTORY_PATH_PATTERN];
|
||||
}
|
||||
|
||||
/**
|
||||
* Get validation rules for Docker build target fields
|
||||
*/
|
||||
public static function dockerTargetRules(int $maxLength = 128): array
|
||||
{
|
||||
return ['nullable', 'string', 'max:'.$maxLength, 'regex:'.self::DOCKER_TARGET_PATTERN];
|
||||
}
|
||||
|
||||
/**
|
||||
* Get validation rules for shell-safe command fields
|
||||
*/
|
||||
public static function shellSafeCommandRules(int $maxLength = 1000): array
|
||||
{
|
||||
return ['nullable', 'string', 'max:'.$maxLength, 'regex:'.self::SHELL_SAFE_COMMAND_PATTERN];
|
||||
}
|
||||
|
||||
/**
|
||||
* Get validation rules for container name fields
|
||||
*/
|
||||
public static function containerNameRules(int $maxLength = 255): array
|
||||
{
|
||||
return ['string', 'max:'.$maxLength, 'regex:'.self::CONTAINER_NAME_PATTERN];
|
||||
}
|
||||
|
||||
/**
|
||||
* Get combined validation messages for both name and description fields
|
||||
*/
|
||||
|
||||
Reference in New Issue
Block a user