5ec5570e172da798bf3277fad43c07d5ae63246d

Author
Ayman Bagabas <ayman.bagabas@gmail.com>
Committer
Ayman Bagabas <ayman.bagabas@gmail.com>
Date

Message

feat(backend): validate repo name

only allow alphanumeric, dashes, underscores, periods, and slashes

Diff

 1diff --git a/server/backend/sqlite/sqlite.go b/server/backend/sqlite/sqlite.go
 2index f3ffc7e62aca6a806b7aaa723989ae507f1d2c9c..d3dcb81ade248ca0ecb7fa688978d37a0413e8fc 100644
 3--- a/server/backend/sqlite/sqlite.go
 4+++ b/server/backend/sqlite/sqlite.go
 5@@ -123,6 +123,10 @@ func (d *SqliteBackend) SetAnonAccess(level backend.AccessLevel) error {
 6 // It implements backend.Backend.
 7 func (d *SqliteBackend) CreateRepository(name string, opts backend.RepositoryOptions) (backend.Repository, error) {
 8 	name = utils.SanitizeRepo(name)
 9+	if err := utils.ValidateRepo(name); err != nil {
10+		return nil, err
11+	}
12+
13 	repo := name + ".git"
14 	rp := filepath.Join(d.reposPath(), repo)
15 
16@@ -165,6 +169,10 @@ func (d *SqliteBackend) CreateRepository(name string, opts backend.RepositoryOpt
17 // ImportRepository imports a repository from remote.
18 func (d *SqliteBackend) ImportRepository(name string, remote string, opts backend.RepositoryOptions) (backend.Repository, error) {
19 	name = utils.SanitizeRepo(name)
20+	if err := utils.ValidateRepo(name); err != nil {
21+		return nil, err
22+	}
23+
24 	repo := name + ".git"
25 	rp := filepath.Join(d.reposPath(), repo)
26 
27@@ -217,7 +225,14 @@ func (d *SqliteBackend) DeleteRepository(name string) error {
28 // It implements backend.Backend.
29 func (d *SqliteBackend) RenameRepository(oldName string, newName string) error {
30 	oldName = utils.SanitizeRepo(oldName)
31+	if err := utils.ValidateRepo(oldName); err != nil {
32+		return err
33+	}
34+
35 	newName = utils.SanitizeRepo(newName)
36+	if err := utils.ValidateRepo(newName); err != nil {
37+		return err
38+	}
39 	oldRepo := oldName + ".git"
40 	newRepo := newName + ".git"
41 	op := filepath.Join(d.reposPath(), oldRepo)
42diff --git a/server/utils/utils.go b/server/utils/utils.go
43index e6fcc332c611233124cb7692691d0d63dbd23bd2..f3b01eb30cbf16da473366aeaf0be22e77b016e0 100644
44--- a/server/utils/utils.go
45+++ b/server/utils/utils.go
46@@ -33,3 +33,18 @@ func ValidateUsername(username string) error {
47 
48 	return nil
49 }
50+
51+// ValidateRepo returns an error if the given repository name is invalid.
52+func ValidateRepo(repo string) error {
53+	if repo == "" {
54+		return fmt.Errorf("repo cannot be empty")
55+	}
56+
57+	for _, r := range repo {
58+		if !unicode.IsLetter(r) && !unicode.IsDigit(r) && r != '-' && r != '_' && r != '.' && r != '/' {
59+			return fmt.Errorf("repo can only contain letters, numbers, hyphens, underscores, periods, and slashes")
60+		}
61+	}
62+
63+	return nil
64+}