security: use signed middleware #197

Merged
pxlrbt merged 2 commits from fix/signed-middleware into main 2024-08-12 08:25:24 +00:00
pxlrbt commented 2024-08-12 08:24:14 +00:00 (Migrated from github.com)

fix: use signed URL

The current version might allow a path traversal attack with badly configured webservers through the route for the export file download, because the route was using {path} and ->where('path', '.*').

Thanks to Kevin Pohl for making me aware of this issue.

fix: use signed URL The current version might allow a path traversal attack with badly configured webservers through the route for the export file download, because the route was using `{path}` and `->where('path', '.*')`. Thanks to Kevin Pohl for making me aware of this issue.
InfluxOW (Migrated from github.com) reviewed 2024-08-19 08:56:54 +00:00
@ -3,1 +5,4 @@
Route::get('filament-excel/{path}', function (string $path) {
$path = Storage::disk('filament-excel')->path($path);
$filename = substr($path, 37);
InfluxOW (Migrated from github.com) commented 2024-08-19 08:56:54 +00:00

@pxlrbt you broke file downloading functionality with this change. Initial $path variable contains UUID + filename. But Storage::disk('filament-excel')->path($path) contains absolute path for $path. It leads to The filename and the fallback cannot contain the "/" and "\" characters. exception.

For example, if initial $path contains d98006dc-0cf4-41b0-8381-1cb6c9521ba0-filename.xls, then Storage::disk('filament-excel')->path($path) contains /var/www/html/storage/app/filament-excel/d98006dc-0cf4-41b0-8381-1cb6c9521ba0-filename.xls. If you substr the first one, you'll get actual filename. If you substr the second one, you'll receive cel/d98006dc-0cf4-41b0-8381-1cb6c9521ba0-filename.xls which leads to an exceptions.
Fix this, please.

@pxlrbt you broke file downloading functionality with this change. Initial `$path` variable contains UUID + filename. But `Storage::disk('filament-excel')->path($path)` contains absolute path for `$path`. It leads to `The filename and the fallback cannot contain the "/" and "\" characters.` exception. For example, if initial `$path` contains `d98006dc-0cf4-41b0-8381-1cb6c9521ba0-filename.xls`, then `Storage::disk('filament-excel')->path($path)` contains `/var/www/html/storage/app/filament-excel/d98006dc-0cf4-41b0-8381-1cb6c9521ba0-filename.xls`. If you substr the first one, you'll get actual filename. If you substr the second one, you'll receive `cel/d98006dc-0cf4-41b0-8381-1cb6c9521ba0-filename.xls` which leads to an exceptions. Fix this, please.
pxlrbt (Migrated from github.com) reviewed 2024-08-19 09:16:39 +00:00
@ -3,1 +5,4 @@
Route::get('filament-excel/{path}', function (string $path) {
$path = Storage::disk('filament-excel')->path($path);
$filename = substr($path, 37);
pxlrbt (Migrated from github.com) commented 2024-08-19 09:16:38 +00:00

@InfluxOW Thanks for reporting. I fixed the order in #198.

@InfluxOW Thanks for reporting. I fixed the order in #198.
Sign in to join this conversation.
No description provided.