From 11490eb85c478c8061219c5e189562f7c17e38ec Mon Sep 17 00:00:00 2001 From: Asish Kumar Date: Wed, 22 Apr 2026 13:49:28 +0530 Subject: [PATCH] fix(engine): reject newline usernames in htpasswd Signed-off-by: Asish Kumar --- pkg/engine/funcs.go | 6 +++--- pkg/engine/funcs_test.go | 5 +++++ 2 files changed, 8 insertions(+), 3 deletions(-) diff --git a/pkg/engine/funcs.go b/pkg/engine/funcs.go index bb8b96723..967b67aed 100644 --- a/pkg/engine/funcs.go +++ b/pkg/engine/funcs.go @@ -89,12 +89,12 @@ func funcMap() template.FuncMap { // By default it uses bcrypt, matching Sprig's existing behavior. // An optional third argument can explicitly select the hash algorithm. func htpasswd(username, password string, hashAlgorithms ...string) (string, error) { - if strings.Contains(username, ":") { - return fmt.Sprintf("invalid username: %s", username), nil - } if strings.ContainsAny(username, "\n\r") { return "", fmt.Errorf("invalid username %q: must not contain newline characters", username) } + if strings.Contains(username, ":") { + return fmt.Sprintf("invalid username: %s", username), nil + } if len(hashAlgorithms) > 1 { return "", fmt.Errorf("wrong number of args for htpasswd: want 2 or 3 got %d", len(hashAlgorithms)+2) diff --git a/pkg/engine/funcs_test.go b/pkg/engine/funcs_test.go index 38b6277a7..98a51ed17 100644 --- a/pkg/engine/funcs_test.go +++ b/pkg/engine/funcs_test.go @@ -224,6 +224,11 @@ func TestHtpasswd(t *testing.T) { tpl: `{{ htpasswd "bad:user" "testpassword" }}`, expect: `invalid username: bad:user`, }, + { + name: "rejects username with colon and newline", + tpl: "{{ htpasswd \"bad:user\\ninjected\" \"testpassword\" }}", + expectError: `must not contain newline characters`, + }, { name: "rejects username with newline", tpl: "{{ htpasswd \"bad\\nuser\" \"testpassword\" }}",