security: use signed middleware #197
No reviewers
Labels
No labels
bug
documentation
duplicate
enhancement
good first issue
help wanted
invalid
missing information
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
pxlrbt/filament-excel!197
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "fix/signed-middleware"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
fix: use signed URL
The current version might allow a path traversal attack with badly configured webservers through the route for the export file download, because the route was using
{path}and->where('path', '.*').Thanks to Kevin Pohl for making me aware of this issue.
@ -3,1 +5,4 @@Route::get('filament-excel/{path}', function (string $path) {$path = Storage::disk('filament-excel')->path($path);$filename = substr($path, 37);@pxlrbt you broke file downloading functionality with this change. Initial
$pathvariable contains UUID + filename. ButStorage::disk('filament-excel')->path($path)contains absolute path for$path. It leads toThe filename and the fallback cannot contain the "/" and "\" characters.exception.For example, if initial
$pathcontainsd98006dc-0cf4-41b0-8381-1cb6c9521ba0-filename.xls, thenStorage::disk('filament-excel')->path($path)contains/var/www/html/storage/app/filament-excel/d98006dc-0cf4-41b0-8381-1cb6c9521ba0-filename.xls. If you substr the first one, you'll get actual filename. If you substr the second one, you'll receivecel/d98006dc-0cf4-41b0-8381-1cb6c9521ba0-filename.xlswhich leads to an exceptions.Fix this, please.
@ -3,1 +5,4 @@Route::get('filament-excel/{path}', function (string $path) {$path = Storage::disk('filament-excel')->path($path);$filename = substr($path, 37);@InfluxOW Thanks for reporting. I fixed the order in #198.