mirror of
https://github.com/tiennm99/coolify.git
synced 2026-10-03 05:19:37 +00:00
refactor(volumes): validate input and escape shell args
Tighten validation on volume name and host path inputs across Livewire + API storage endpoints and escape shell arguments in volume clone and compose preview cleanup paths.
This commit is contained in:
1 parent
a1b2ab124a
commit
410a9a6195
8 files changed
+148
-29
No files matched your search
@@ -2,6 +2,7 @@
|
||||
|
||||
namespace App\Models;
|
||||
|
||||
use App\Support\ValidationPatterns;
|
||||
use Illuminate\Database\Eloquent\SoftDeletes;
|
||||
use Spatie\Url\Url;
|
||||
use Visus\Cuid2\Cuid2;
|
||||
@@ -42,11 +43,18 @@ class ApplicationPreview extends BaseModel
|
||||
$networkKeys = collect($networks)->keys();
|
||||
$volumeKeys = collect($volumes)->keys();
|
||||
$volumeKeys->each(function ($key) use ($server) {
|
||||
instant_remote_process(["docker volume rm -f $key"], $server, false);
|
||||
if (! preg_match(ValidationPatterns::VOLUME_NAME_PATTERN, $key)) {
|
||||
return;
|
||||
}
|
||||
instant_remote_process(['docker volume rm -f '.escapeshellarg($key)], $server, false);
|
||||
});
|
||||
$networkKeys->each(function ($key) use ($server) {
|
||||
instant_remote_process(["docker network disconnect $key coolify-proxy"], $server, false);
|
||||
instant_remote_process(["docker network rm $key"], $server, false);
|
||||
if (! preg_match(ValidationPatterns::DOCKER_NETWORK_PATTERN, $key)) {
|
||||
return;
|
||||
}
|
||||
$k = escapeshellarg($key);
|
||||
instant_remote_process(["docker network disconnect {$k} coolify-proxy"], $server, false);
|
||||
instant_remote_process(["docker network rm {$k}"], $server, false);
|
||||
});
|
||||
} else {
|
||||
// Regular application volume cleanup
|
||||
|
||||
Reference in new issue
Block a user