From af3e9cdfdc5efce82e77971ca7752ea727cb9249 Mon Sep 17 00:00:00 2001 From: Kenneth Skovhede Date: Thu, 7 Jun 2018 13:14:11 +0200 Subject: [PATCH] Added input validation for B2 paths to avoid users ending up with weird error messages, once the full path for each file is constructed. --- .../ngax/scripts/services/EditUriBuiltins.js | 24 +++++++++++++++++++ 1 file changed, 24 insertions(+) diff --git a/Duplicati/Server/webroot/ngax/scripts/services/EditUriBuiltins.js b/Duplicati/Server/webroot/ngax/scripts/services/EditUriBuiltins.js index a9ff0804b..db13637ac 100644 --- a/Duplicati/Server/webroot/ngax/scripts/services/EditUriBuiltins.js +++ b/Duplicati/Server/webroot/ngax/scripts/services/EditUriBuiltins.js @@ -875,6 +875,30 @@ backupApp.service('EditUriBuiltins', function(AppService, AppUtils, SystemInfo, EditUriBackendConfig.require_field(scope, 'Username', gettextCatalog.getString('B2 Cloud Storage Account ID')) && EditUriBackendConfig.require_field(scope, 'Password', gettextCatalog.getString('B2 Cloud Storage Application Key')); + if (res) { + var re = new RegExp('[^A-Za-z0-9-]'); + var bucketname = scope['Server'] || ''; + var ix = bucketname.search(/[^A-Za-z0-9-]/g); + + if (ix >= 0) { + EditUriBackendConfig.show_error_dialog(gettextCatalog.getString('The \'{{fieldname}}\' field contains an invalid character: {{character}} (value: {{value}}, index: {{pos}})', { value: bucketname[ix].charCodeAt(), pos: ix, character: bucketname[ix], fieldname: gettextCatalog.getString('Bucket Name') })); + res = false; + } + } + + if (res) { + var pathname = scope['Path'] || ''; + for (var i = pathname.length - 1; i >= 0; i--) { + var char = pathname.charCodeAt(i); + + if (char == '\\'.charCodeAt(0) || char == 127 || char < 32) { + EditUriBackendConfig.show_error_dialog(gettextCatalog.getString('The \'{{fieldname}}\' field contains an invalid character: {{character}} (value: {{value}}, index: {{pos}})', { value: char, pos: i, character: pathname[i], fieldname: gettextCatalog.getString('Path') })); + res = false; + break; + } + } + } + if (res) continuation(); };