d475692ffc0ebe196afd2f1db7a0dfc9c4bfbaff

Author
Michael Aquilina <michaelaquilina@gmail.com>
Committer
Michael Aquilina <michaelaquilina@gmail.com>
Date

Message

fix: insecure activation of virtualenvs

See Issue #122

Diff

 1diff --git a/autoswitch_virtualenv.plugin.zsh b/autoswitch_virtualenv.plugin.zsh
 2index d3ce1f513c5521b760309308071b2350745b9851..042c789b2b0b45c01d0011d7d1adfa78810626f7 100644
 3--- a/autoswitch_virtualenv.plugin.zsh
 4+++ b/autoswitch_virtualenv.plugin.zsh
 5@@ -8,6 +8,20 @@ BOLD="\e[1m"
 6 NORMAL="\e[0m"
 7 
 8 
 9+function _validated_source() {
10+    local target_path="$1"
11+
12+    if [[ "$target_path" == *'..'* ]]; then
13+        printf "AUTOSWITCH WARNING: "
14+        printf "target virtualenv contains invalid characters\n"
15+        printf "virtualenv activation cancelled\n"
16+        return
17+    else
18+        source "$target_path"
19+    fi
20+}
21+
22+
23 function _virtual_env_dir() {
24     local venv_name="$1"
25     local VIRTUAL_ENV_DIR="${AUTOSWITCH_VIRTUAL_ENV_DIR:-$HOME/.virtualenvs}"
26@@ -93,7 +107,9 @@ function _maybeworkon() {
27         fi
28 
29         # Much faster to source the activate file directly rather than use the `workon` command
30-        source "$venv_dir/bin/activate"
31+        local activate_script="$venv_dir/bin/activate"
32+
33+        _validated_source "$activate_script"
34     fi
35 }
36 
37diff --git a/tests/test_maybeworkon.zunit b/tests/test_maybeworkon.zunit
38index d5fe6591f2bd9f558cb88a849e665e88ea260ccd..49ae98dd6cc304b97629edf7136e166938075641 100644
39--- a/tests/test_maybeworkon.zunit
40+++ b/tests/test_maybeworkon.zunit
41@@ -23,6 +23,18 @@
42     rm -rf "$TARGET"
43 }
44 
45+@test '_maybeworkon - do not activate paths which are potentially inscure' {
46+    VIRTUAL_ENV=""
47+
48+    run _maybeworkon "$TARGET/../../../" virtualenv
49+
50+    assert $state equals 0
51+
52+    # first line would be the "switching virtualenv: ...."
53+    assert "${lines[2]}" same_as "AUTOSWITCH WARNING: target virtualenv contains invalid characters"
54+    assert "${lines[3]}" same_as "virtualenv activation cancelled"
55+}
56+
57 @test '_maybeworkon - error message if virtualenv can not be found' {
58     VIRTUAL_ENV=""
59