30c77db7c83eca2bc5f6134fccbdc117b49a6a05

Author
Michael Aquilina <michaelaquilina@gmail.com>
Committer
GitHub <noreply@github.com>
Date

Message

Merge pull request #123 from MichaelAquilina/fix/insecure_activation

fix: insecure activation of virtualenvs

Diff

 1diff --git a/CHANGELOG.rst b/CHANGELOG.rst
 2index f7b53afccbcc9557abd4f7c50cab49a5ffad87ca..975a8d51db41b366e23f041b8d4f648a6f90e226 100644
 3--- a/CHANGELOG.rst
 4+++ b/CHANGELOG.rst
 5@@ -1,6 +1,10 @@
 6 Changelog
 7 =========
 8 
 9+1.16.0
10+------
11+* Fix insecure activation of virtualenvs (#122)
12+
13 1.15.2
14 ------
15 * Use absolute path for ``/usr/bin/stat`` to prevent conflicts with other ``stat`` binaries. Fixes #110
16diff --git a/autoswitch_virtualenv.plugin.zsh b/autoswitch_virtualenv.plugin.zsh
17index d3ce1f513c5521b760309308071b2350745b9851..3b0ef5c08f686cfc154abee4d10a493db105f08e 100644
18--- a/autoswitch_virtualenv.plugin.zsh
19+++ b/autoswitch_virtualenv.plugin.zsh
20@@ -1,4 +1,4 @@
21-export AUTOSWITCH_VERSION="1.15.2"
22+export AUTOSWITCH_VERSION="1.16.0"
23 export AUTOSWITCH_FILE=".venv"
24 
25 RED="\e[31m"
26@@ -8,6 +8,20 @@ BOLD="\e[1m"
27 NORMAL="\e[0m"
28 
29 
30+function _validated_source() {
31+    local target_path="$1"
32+
33+    if [[ "$target_path" == *'..'* ]]; then
34+        printf "AUTOSWITCH WARNING: "
35+        printf "target virtualenv contains invalid characters\n"
36+        printf "virtualenv activation cancelled\n"
37+        return
38+    else
39+        source "$target_path"
40+    fi
41+}
42+
43+
44 function _virtual_env_dir() {
45     local venv_name="$1"
46     local VIRTUAL_ENV_DIR="${AUTOSWITCH_VIRTUAL_ENV_DIR:-$HOME/.virtualenvs}"
47@@ -93,7 +107,9 @@ function _maybeworkon() {
48         fi
49 
50         # Much faster to source the activate file directly rather than use the `workon` command
51-        source "$venv_dir/bin/activate"
52+        local activate_script="$venv_dir/bin/activate"
53+
54+        _validated_source "$activate_script"
55     fi
56 }
57 
58diff --git a/tests/test_maybeworkon.zunit b/tests/test_maybeworkon.zunit
59index d5fe6591f2bd9f558cb88a849e665e88ea260ccd..49ae98dd6cc304b97629edf7136e166938075641 100644
60--- a/tests/test_maybeworkon.zunit
61+++ b/tests/test_maybeworkon.zunit
62@@ -23,6 +23,18 @@
63     rm -rf "$TARGET"
64 }
65 
66+@test '_maybeworkon - do not activate paths which are potentially inscure' {
67+    VIRTUAL_ENV=""
68+
69+    run _maybeworkon "$TARGET/../../../" virtualenv
70+
71+    assert $state equals 0
72+
73+    # first line would be the "switching virtualenv: ...."
74+    assert "${lines[2]}" same_as "AUTOSWITCH WARNING: target virtualenv contains invalid characters"
75+    assert "${lines[3]}" same_as "virtualenv activation cancelled"
76+}
77+
78 @test '_maybeworkon - error message if virtualenv can not be found' {
79     VIRTUAL_ENV=""
80