TASK22019: phase 11 harden blob/delete hash guards and negative paths

This commit is contained in:
2026-03-13 12:32:37 +00:00
parent 368ef86b74
commit 36260bb405
4 changed files with 219 additions and 14 deletions
@@ -13,6 +13,19 @@ ApiProxy.get(async (req, res) => {
var blobName = req.query.blobname;
var checkHash = req.query.hash;
if (
typeof containerName === "undefined" ||
containerName.length === 0 ||
typeof casefolderID === "undefined" ||
casefolderID.length === 0 ||
typeof blobName === "undefined" ||
blobName.length === 0 ||
typeof checkHash === "undefined" ||
checkHash.length === 0
) {
return res.status(400).json();
}
var checkquerypath =
"/api/file/deleteblob?container=" +
containerName +
@@ -21,8 +34,9 @@ ApiProxy.get(async (req, res) => {
"&blobname=" +
blobName;
//console.log(hashAPIPath(checkquerypath), checkHash);
//console.log(hashAPIPath(checkquerypath) == "&hash=" + checkHash);
if (hashAPIPath(checkquerypath) != "&hash=" + checkHash) {
return res.status(400).json();
}
if (hashAPIPath(checkquerypath) == "&hash=" + checkHash) {
await deleteBlob(
@@ -31,8 +45,6 @@ ApiProxy.get(async (req, res) => {
).then((data) => {
return res.status(200).json({ data: data });
});
} else {
return res.status(400).json();
}
});
+17 -2
View File
@@ -13,6 +13,19 @@ ApiProxy.get(async (req, res) => {
var blobName = req.query.blobname;
var checkHash = req.query.hash;
if (
typeof containerName === "undefined" ||
containerName.length === 0 ||
typeof casefolderID === "undefined" ||
casefolderID.length === 0 ||
typeof blobName === "undefined" ||
blobName.length === 0 ||
typeof checkHash === "undefined" ||
checkHash.length === 0
) {
return res.status(400).json();
}
var checkquerypath =
"/api/file/deleteblob?container=" +
containerName +
@@ -21,6 +34,10 @@ ApiProxy.get(async (req, res) => {
"&blobname=" +
encodeURIComponent(blobName);
if (hashAPIPath(checkquerypath) != "&hash=" + checkHash) {
return res.status(400).json();
}
if (hashAPIPath(checkquerypath) == "&hash=" + checkHash) {
await deleteBlob(
containerName,
@@ -28,8 +45,6 @@ ApiProxy.get(async (req, res) => {
).then((data) => {
return res.status(200).json({ data: data });
});
} else {
return res.status(400).json();
}
});
+15 -8
View File
@@ -43,18 +43,27 @@ ApiProxy.get(async (req, res) => {
var casefolderID = req.query.casefolderID;
var checkHash = req.query.hash;
if (
typeof containerName === "undefined" ||
containerName.length === 0 ||
typeof casefolderID === "undefined" ||
casefolderID.length === 0 ||
typeof checkHash === "undefined" ||
checkHash.length === 0
) {
return res.status(400).json();
}
var checkquerypath =
"/api/file/getbloblist?container=" +
containerName +
"&casefolderID=" +
casefolderID;
// console.log("-----", casefolderID);
// console.log("-----", req.query);
// console.log("-----", checkquerypath);
// console.log("-----", hashAPIPath(checkquerypath));
// console.log("-----", checkHash);
// console.log(hashAPIPath(checkquerypath) == "&hash=" + checkHash);
if (hashAPIPath(checkquerypath) != "&hash=" + checkHash) {
return res.status(400).json();
}
if (hashAPIPath(checkquerypath) == "&hash=" + checkHash) {
casefolderID.split("/").length > 1
@@ -68,8 +77,6 @@ ApiProxy.get(async (req, res) => {
: await getBlobs(containerName, casefolderID).then((data) => {
return res.status(200).json({ "value": [data] });
});
} else {
return res.status(400).json();
}
});