d475692ffc0ebe196afd2f1db7a0dfc9c4bfbaff
- Author
- Michael Aquilina <michaelaquilina@gmail.com>
- Committer
- Michael Aquilina <michaelaquilina@gmail.com>
- Date
Message
fix: insecure activation of virtualenvs
See Issue #122
Diff
1diff --git a/autoswitch_virtualenv.plugin.zsh b/autoswitch_virtualenv.plugin.zsh
2index d3ce1f513c5521b760309308071b2350745b9851..042c789b2b0b45c01d0011d7d1adfa78810626f7 100644
3--- a/autoswitch_virtualenv.plugin.zsh
4+++ b/autoswitch_virtualenv.plugin.zsh
5@@ -8,6 +8,20 @@ BOLD="\e[1m"
6 NORMAL="\e[0m"
7
8
9+function _validated_source() {
10+ local target_path="$1"
11+
12+ if [[ "$target_path" == *'..'* ]]; then
13+ printf "AUTOSWITCH WARNING: "
14+ printf "target virtualenv contains invalid characters\n"
15+ printf "virtualenv activation cancelled\n"
16+ return
17+ else
18+ source "$target_path"
19+ fi
20+}
21+
22+
23 function _virtual_env_dir() {
24 local venv_name="$1"
25 local VIRTUAL_ENV_DIR="${AUTOSWITCH_VIRTUAL_ENV_DIR:-$HOME/.virtualenvs}"
26@@ -93,7 +107,9 @@ function _maybeworkon() {
27 fi
28
29 # Much faster to source the activate file directly rather than use the `workon` command
30- source "$venv_dir/bin/activate"
31+ local activate_script="$venv_dir/bin/activate"
32+
33+ _validated_source "$activate_script"
34 fi
35 }
36
37diff --git a/tests/test_maybeworkon.zunit b/tests/test_maybeworkon.zunit
38index d5fe6591f2bd9f558cb88a849e665e88ea260ccd..49ae98dd6cc304b97629edf7136e166938075641 100644
39--- a/tests/test_maybeworkon.zunit
40+++ b/tests/test_maybeworkon.zunit
41@@ -23,6 +23,18 @@
42 rm -rf "$TARGET"
43 }
44
45+@test '_maybeworkon - do not activate paths which are potentially inscure' {
46+ VIRTUAL_ENV=""
47+
48+ run _maybeworkon "$TARGET/../../../" virtualenv
49+
50+ assert $state equals 0
51+
52+ # first line would be the "switching virtualenv: ...."
53+ assert "${lines[2]}" same_as "AUTOSWITCH WARNING: target virtualenv contains invalid characters"
54+ assert "${lines[3]}" same_as "virtualenv activation cancelled"
55+}
56+
57 @test '_maybeworkon - error message if virtualenv can not be found' {
58 VIRTUAL_ENV=""
59