fix(engine): reject newline usernames in htpasswd

Signed-off-by: Asish Kumar <officialasishkumar@gmail.com>
pull/32033/head
Asish Kumar 6 months ago
parent 900d0ab344
commit 11490eb85c

@ -89,12 +89,12 @@ func funcMap() template.FuncMap {
// By default it uses bcrypt, matching Sprig's existing behavior.
// An optional third argument can explicitly select the hash algorithm.
func htpasswd(username, password string, hashAlgorithms ...string) (string, error) {
if strings.Contains(username, ":") {
return fmt.Sprintf("invalid username: %s", username), nil
}
if strings.ContainsAny(username, "\n\r") {
return "", fmt.Errorf("invalid username %q: must not contain newline characters", username)
}
if strings.Contains(username, ":") {
return fmt.Sprintf("invalid username: %s", username), nil
}
if len(hashAlgorithms) > 1 {
return "", fmt.Errorf("wrong number of args for htpasswd: want 2 or 3 got %d", len(hashAlgorithms)+2)

@ -224,6 +224,11 @@ func TestHtpasswd(t *testing.T) {
tpl: `{{ htpasswd "bad:user" "testpassword" }}`,
expect: `invalid username: bad:user`,
},
{
name: "rejects username with colon and newline",
tpl: "{{ htpasswd \"bad:user\\ninjected\" \"testpassword\" }}",
expectError: `must not contain newline characters`,
},
{
name: "rejects username with newline",
tpl: "{{ htpasswd \"bad\\nuser\" \"testpassword\" }}",

Loading…
Cancel
Save