mirror of
https://github.com/tiennm99/coolify.git
synced 2026-10-03 07:12:33 +00:00
fix: enhance validation for database names and filenames to prevent command injection
This commit is contained in:
1 parent
0073d045fb
commit
281a706231
2 files changed
+17
-2
No files matched your search
@@ -25,6 +25,11 @@ class DynamicConfigurationNavbar extends Component
|
||||
$this->authorize('update', $this->server);
|
||||
$proxy_path = $this->server->proxyPath();
|
||||
$proxy_type = $this->server->proxyType();
|
||||
|
||||
// Decode filename: pipes are used to encode dots for Livewire property binding
|
||||
// (e.g., 'my|service.yaml' -> 'my.service.yaml')
|
||||
// This must happen BEFORE validation because validateShellSafePath() correctly
|
||||
// rejects pipe characters as dangerous shell metacharacters
|
||||
$file = str_replace('|', '.', $fileName);
|
||||
|
||||
// Validate filename to prevent command injection
|
||||
|
||||
Reference in new issue
Block a user