Helper/Nix: constructRunCommandLogPath: verify uuid is valid

This shouldn't be possible normally, but it is possible to:

    $db->resultset('RunCommandLogs')->new({ uuid => "../etc/passwd" });

if you have access to the `$db`.
This commit is contained in:
Cole Helbling
2022-01-28 12:45:12 -08:00
parent e381751564
commit 61189ecca9
3 changed files with 18 additions and 10 deletions

View File

@ -82,6 +82,12 @@ subtest "constructRunCommandLogPath" => sub {
qr@/runcommand-logs/[0-9a-f]{2}/[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}@,
"The constructed RunCommandLog path is sufficiently bucketed and UUID-like."
);
my $badlog = $db->resultset('RunCommandLogs')->new({ uuid => "../../../etc/passwd" });
ok(
dies { Hydra::Helper::Nix::constructRunCommandLogPath($badlog) },
"Expected invalid UUID to be rejected and not have a path constructed for it.",
);
};
done_testing;