Expose allows all special chars but prevents directory traversal
This commit is contained in:
@@ -1 +1 @@
|
|||||||
Version 1.99.4 (2012-02-28 10:18:22) stable
|
Version 1.99.4 (2012-02-28 10:45:41) stable
|
||||||
|
|||||||
+13
-9
@@ -4153,8 +4153,12 @@ class PluginManager(object):
|
|||||||
class Expose(object):
|
class Expose(object):
|
||||||
def __init__(self,base=None):
|
def __init__(self,base=None):
|
||||||
current.session.forget()
|
current.session.forget()
|
||||||
base = base or os.path.join(current.request.folder,'static','work')
|
base = base or os.path.join(current.request.folder,'static')
|
||||||
filename = os.path.join(base,*current.request.args)
|
args = self.args = current.request.raw_args and \
|
||||||
|
current.request.raw_args.split('/') or []
|
||||||
|
filename = os.path.join(base,*args)
|
||||||
|
if not os.path.normpath(filename).startswith(base):
|
||||||
|
raise HTTP(401,"NOT AUTHORIZED")
|
||||||
if not os.path.isdir(filename):
|
if not os.path.isdir(filename):
|
||||||
current.response.headers['Content-Type'] = contenttype(filename)
|
current.response.headers['Content-Type'] = contenttype(filename)
|
||||||
raise HTTP(200,open(filename,'rb'),**current.response.headers)
|
raise HTTP(200,open(filename,'rb'),**current.response.headers)
|
||||||
@@ -4162,21 +4166,21 @@ class Expose(object):
|
|||||||
self.folders = [f[len(path)-1:] for f in sorted(glob.glob(path)) \
|
self.folders = [f[len(path)-1:] for f in sorted(glob.glob(path)) \
|
||||||
if os.path.isdir(f) and not self.isprivate(f)]
|
if os.path.isdir(f) and not self.isprivate(f)]
|
||||||
self.filenames = [f[len(path)-1:] for f in sorted(glob.glob(path)) \
|
self.filenames = [f[len(path)-1:] for f in sorted(glob.glob(path)) \
|
||||||
if not os.path.isdir(f) and not self.isprivate(f)]
|
if not os.path.isdir(f) and not self.isprivate(f)]
|
||||||
def breadcrumbs(self):
|
def breadcrumbs(self):
|
||||||
path = []
|
path = []
|
||||||
span = SPAN()
|
span = SPAN()
|
||||||
span.append(A('base',_href=URL()))
|
span.append(A('base',_href=URL()))
|
||||||
span.append('/')
|
span.append('/')
|
||||||
args = current.request.args
|
args = current.request.raw_args and \
|
||||||
|
current.request.raw_args.split('/') or []
|
||||||
for arg in args:
|
for arg in args:
|
||||||
path.append(arg)
|
path.append(arg)
|
||||||
span.append(A(arg,_href=URL(args='/'.join(path))))
|
span.append(A(arg,_href=URL(args='/'.join(path))))
|
||||||
span.append('/')
|
span.append('/')
|
||||||
return span
|
return span
|
||||||
def table_folders(self):
|
def table_folders(self):
|
||||||
args = current.request.args
|
return TABLE(*[TR(TD(A(folder,_href=URL(args=self.args+[folder])))) \
|
||||||
return TABLE(*[TR(TD(A(folder,_href=URL(args=args+[folder])))) \
|
|
||||||
for folder in self.folders])
|
for folder in self.folders])
|
||||||
@staticmethod
|
@staticmethod
|
||||||
def isprivate(f):
|
def isprivate(f):
|
||||||
@@ -4185,9 +4189,9 @@ class Expose(object):
|
|||||||
def isimage(f):
|
def isimage(f):
|
||||||
return f.rsplit('.')[-1].lower() in ('png','jpg','jpeg','gif','tiff')
|
return f.rsplit('.')[-1].lower() in ('png','jpg','jpeg','gif','tiff')
|
||||||
def table_files(self,width=160):
|
def table_files(self,width=160):
|
||||||
args = current.request.args
|
return TABLE(*[TR(TD(A(f,_href=URL(args=self.args+[f]))),
|
||||||
return TABLE(*[TR(TD(A(f,_href=URL(args=args+[f]))),
|
TD(IMG(_src=URL(args=self.args+[f]),
|
||||||
TD(IMG(_src=URL(args=args+[f]),_style='max-width:%spx' % width) \
|
_style='max-width:%spx' % width) \
|
||||||
if width and self.isimage(f) else '')) \
|
if width and self.isimage(f) else '')) \
|
||||||
for f in self.filenames])
|
for f in self.filenames])
|
||||||
def xml(self):
|
def xml(self):
|
||||||
|
|||||||
Reference in New Issue
Block a user