mirror of
https://github.com/gesellix/Bose-SoundTouch.git
synced 2026-09-07 15:07:17 +00:00
fix(example-dlna-server): sanitize logged request values
CodeQL alert 313 (go/log-injection). The access-log middleware logged r.URL.Path and SOAP-body-derived objectID/browseFlag verbatim, without stripping newlines -- an attacker-controlled request could inject fake log lines or control characters. Add the same sanitizeLog helper this repo already uses in ~18 other packages for exactly this class of finding. Alert 312 (go/reflected-xss, same file/area) was investigated and left open deliberately: objectID is only ever used as a lookup key in pkg/dlna/dlnatest, never echoed into the response, and every actual output field goes through xmlEsc/xmlAttr (encoding/xml.EscapeText) before being written -- looks like a CodeQL false positive rather than a real gap, but not dismissing it yet per discussion. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 5
parent
966214c5a0
commit
14437fd568
@@ -0,0 +1,13 @@
|
||||
package main
|
||||
|
||||
import "strings"
|
||||
|
||||
// sanitizeLog strips newline characters from s to prevent log-injection
|
||||
// (CodeQL go/log-injection). Values from HTTP requests may contain
|
||||
// attacker-controlled newlines.
|
||||
func sanitizeLog(s string) string {
|
||||
s = strings.ReplaceAll(s, "\n", `\n`)
|
||||
s = strings.ReplaceAll(s, "\r", `\r`)
|
||||
|
||||
return s
|
||||
}
|
||||
@@ -654,8 +654,8 @@ func withAccessLog(logger *slog.Logger, next http.Handler) http.Handler {
|
||||
r.Body = io.NopCloser(bytes.NewReader(body))
|
||||
|
||||
browseAttrs = []any{
|
||||
"objectID", between(string(body), "<ObjectID>", "</ObjectID>"),
|
||||
"browseFlag", between(string(body), "<BrowseFlag>", "</BrowseFlag>"),
|
||||
"objectID", sanitizeLog(between(string(body), "<ObjectID>", "</ObjectID>")),
|
||||
"browseFlag", sanitizeLog(between(string(body), "<BrowseFlag>", "</BrowseFlag>")),
|
||||
}
|
||||
}
|
||||
|
||||
@@ -664,7 +664,7 @@ func withAccessLog(logger *slog.Logger, next http.Handler) http.Handler {
|
||||
|
||||
attrs := []any{
|
||||
"method", r.Method,
|
||||
"path", r.URL.Path,
|
||||
"path", sanitizeLog(r.URL.Path),
|
||||
"status", rec.status,
|
||||
"bytes", rec.bytes,
|
||||
"from", r.RemoteAddr,
|
||||
|
||||
Reference in New Issue
Block a user