url sanitization to strip tokens and passwords

This commit is contained in:
Rune Henriksen
2018-11-04 22:07:24 +01:00
parent 043d119964
commit a7909c421c
3 changed files with 24 additions and 2 deletions
+20 -1
View File
@@ -18,6 +18,7 @@
using System;
using Duplicati.Server.Serialization.Interface;
using System.Collections.Generic;
using System.Text.RegularExpressions;
namespace Duplicati.Server.Database
{
@@ -65,7 +66,7 @@ namespace Duplicati.Server.Database
/// </summary>
public string[] Tags { get; set; }
/// <summary>
/// The backup target url, excluding username/password
/// The backup target url
/// </summary>
public string TargetURL { get; set; }
/// <summary>
@@ -98,6 +99,24 @@ namespace Duplicati.Server.Database
/// </summary>
public bool IsTemporary { get { return ID == null ? false : ID.IndexOf("-", StringComparison.Ordinal) > 0; } }
/// <summary>
/// Sanitizes the backup TargetUrl
/// </summary>
public void SanitizeTargetUrl()
{
var url = this.TargetURL;
// Remove authid
url = Regex.Replace(url, "(!?authid)=[^&\n]+[&]?", "");
// remove auth-password
url = Regex.Replace(url, "(!?auth-password)=[^&\n]+[&]?", "");
// Remove edge case of '?&'
url = Regex.Replace(url, Regex.Escape("?&"), "");
// Remove edge case of '&' at end of line
url = Regex.Replace(url, "&$", "");
// Remove edge case of '?' at end of line
url = Regex.Replace(url, Regex.Escape("?"), "");
this.TargetURL = url;
}
}
}
@@ -42,7 +42,7 @@ namespace Duplicati.Server.Serialization.Interface
/// </summary>
string[] Tags { get; set; }
/// <summary>
/// The backup target url, excluding username/password
/// The backup target url
/// </summary>
string TargetURL { get; set; }
/// <summary>
@@ -74,6 +74,8 @@ namespace Duplicati.Server.Serialization.Interface
/// Gets a value indicating if this instance is not persisted to the database
/// </summary>
bool IsTemporary { get; }
void SanitizeTargetUrl();
}
}
@@ -125,6 +125,7 @@ namespace Duplicati.Server.WebServer.RESTMethods
if (!exportPasswords)
{
backup.Settings = (Duplicati.Server.Serialization.Interface.ISetting[])backup.Settings.Where((setting) => !passwordFields.Contains(setting.Name)).ToArray();
backup.SanitizeTargetUrl();
}
if (cmdline)