From 28f0b38789f230e305e972dbd72bb8fa23b398bf Mon Sep 17 00:00:00 2001 From: Taran Nathan Date: Thu, 11 Jun 2026 00:13:04 -0400 Subject: [PATCH] add envoy, and add some protections for filenames --- gleam.toml | 1 + manifest.toml | 1 + src/filestuffs.gleam | 5 ++++- src/router.gleam | 16 +++++++++++----- 4 files changed, 17 insertions(+), 6 deletions(-) diff --git a/gleam.toml b/gleam.toml index fc50466..d145cdb 100644 --- a/gleam.toml +++ b/gleam.toml @@ -24,6 +24,7 @@ gleam_json = ">= 3.1.0 and < 4.0.0" gleam_time = ">= 1.8.0 and < 2.0.0" simplifile = ">= 2.4.0 and < 3.0.0" mist = ">= 6.0.3 and < 7.0.0" +envoy = ">= 1.2.0 and < 2.0.0" [dev_dependencies] gleeunit = ">= 1.0.0 and < 2.0.0" diff --git a/manifest.toml b/manifest.toml index 717b1ae..4baa82e 100644 --- a/manifest.toml +++ b/manifest.toml @@ -32,6 +32,7 @@ packages = [ [requirements] argv = { version = ">= 1.1.0 and < 2.0.0" } +envoy = { version = ">= 1.2.0 and < 2.0.0" } gleam_erlang = { version = ">= 1.3.0 and < 2.0.0" } gleam_http = { version = ">= 4.3.0 and < 5.0.0" } gleam_json = { version = ">= 3.1.0 and < 4.0.0" } diff --git a/src/filestuffs.gleam b/src/filestuffs.gleam index 7121b60..7e0c49e 100644 --- a/src/filestuffs.gleam +++ b/src/filestuffs.gleam @@ -1,6 +1,8 @@ import argv +import envoy import gleam/erlang/process import gleam/io +import gleam/result import mist import router import wisp @@ -24,7 +26,8 @@ pub fn wassup() -> Int { fn web(file_path: String, password: String) -> Nil { wisp.configure_logger() - let secret_key_base = wisp.random_string(64) + let secret_key_base = + result.unwrap(envoy.get("SECRET_KEY_BASE"), wisp.random_string(64)) let assert Ok(_) = router.handle_request(_, file_path, password) diff --git a/src/router.gleam b/src/router.gleam index a30d11b..2036bc7 100644 --- a/src/router.gleam +++ b/src/router.gleam @@ -1,6 +1,7 @@ import gleam/bool import gleam/list import gleam/result +import gleam/string import simplifile import wisp @@ -40,13 +41,18 @@ pub fn upload(req: wisp.Request, password: String) -> wisp.Response { return: wisp.response(401), ) - wisp.log_debug(result.unwrap(list.key_find(form.values, "password"), "")) - case form.files { [#("file", wisp.UploadedFile(file_name:, path: temp_path)), ..] -> { - let destination = - "./files/" - <> result.unwrap(list.key_find(form.values, "filename"), file_name) + let user_path_name = + result.unwrap(list.key_find(form.values, "filename"), file_name) + + let destination = "./files/" <> user_path_name + + use <- bool.guard( + string.contains(does: user_path_name, contain: "/") + || string.contains(does: user_path_name, contain: ".."), + wisp.bad_request("bad filename, no slashes allowed"), + ) let result = { use _ <- result.try(simplifile.create_directory_all("./files")) -- 2.47.3