moved all sanitization logic into backup class and moved from regex to using internal Uri library
This commit is contained in:
@@ -19,12 +19,27 @@ using System;
|
||||
using Duplicati.Server.Serialization.Interface;
|
||||
using System.Collections.Generic;
|
||||
using System.Text.RegularExpressions;
|
||||
using System.Linq;
|
||||
|
||||
namespace Duplicati.Server.Database
|
||||
{
|
||||
public class Backup : IBackup
|
||||
{
|
||||
|
||||
{
|
||||
// Sensitive information that may be stored in TargetUrl
|
||||
private readonly string[] UrlPasswords = new[]{
|
||||
"authid",
|
||||
"auth-password",
|
||||
"sia-password",
|
||||
};
|
||||
|
||||
// Sensitive information that may be stored in Settings
|
||||
private readonly string[] SettingPasswords = new[]{
|
||||
"passphrase",
|
||||
"--authid",
|
||||
"--send-mail-password",
|
||||
"--send-xmpp-password"
|
||||
};
|
||||
|
||||
public Backup()
|
||||
{
|
||||
this.ID = null;
|
||||
@@ -100,24 +115,25 @@ namespace Duplicati.Server.Database
|
||||
public bool IsTemporary { get { return ID == null ? false : ID.IndexOf("-", StringComparison.Ordinal) > 0; } }
|
||||
|
||||
/// <summary>
|
||||
/// Sanitizes the backup TargetUrl
|
||||
/// Sanitizes the backup TargetUrl from any fields in the PasswordFields list.
|
||||
/// </summary>
|
||||
public void SanitizeTargetUrl()
|
||||
{
|
||||
var url = this.TargetURL;
|
||||
// Remove authid
|
||||
url = Regex.Replace(url, "authid=[^&\n]+[&]?", "");
|
||||
// remove auth-password
|
||||
url = Regex.Replace(url, "auth-password=[^&\n]+[&]?", "");
|
||||
// remove backupsia-password
|
||||
url = Regex.Replace(url, "sia-password=[^&\n]+[&]?", "");
|
||||
// Remove edge case of '?&'
|
||||
url = Regex.Replace(url, Regex.Escape("?&"), "");
|
||||
// Remove edge case of '&' at end of line
|
||||
url = Regex.Replace(url, "&$", "");
|
||||
// Remove edge case of '?' at end of line
|
||||
url = Regex.Replace(url, Regex.Escape("?") + "$", "");
|
||||
this.TargetURL = url;
|
||||
var url = new Duplicati.Library.Utility.Uri(this.TargetURL);
|
||||
var filteredParameters = url.QueryParameters;
|
||||
foreach (string field in UrlPasswords) {
|
||||
filteredParameters.Remove(field);
|
||||
}
|
||||
url = url.SetQuery(Duplicati.Library.Utility.Uri.BuildUriQuery(url.QueryParameters));
|
||||
this.TargetURL = url.ToString();
|
||||
}
|
||||
|
||||
/// <summary>
|
||||
/// Sanitizes the settings from any fields in the PassworldFields list.
|
||||
/// </summary>
|
||||
public void SanitizeSettings()
|
||||
{
|
||||
this.Settings = this.Settings.Where((setting) => !SettingPasswords.Contains(setting.Name)).ToArray();
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -76,6 +76,8 @@ namespace Duplicati.Server.Serialization.Interface
|
||||
bool IsTemporary { get; }
|
||||
|
||||
void SanitizeTargetUrl();
|
||||
|
||||
void SanitizeSettings();
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
@@ -121,10 +121,9 @@ namespace Duplicati.Server.WebServer.RESTMethods
|
||||
var cmdline = Library.Utility.Utility.ParseBool(info.Request.QueryString["cmdline"].Value, false);
|
||||
var argsonly = Library.Utility.Utility.ParseBool(info.Request.QueryString["argsonly"].Value, false);
|
||||
var exportPasswords = Library.Utility.Utility.ParseBool(info.Request.QueryString["export-passwords"].Value, false);
|
||||
var passwordFields = new [] { "passphrase", "--send-mail-password", "--send-xmpp-password" };
|
||||
if (!exportPasswords)
|
||||
{
|
||||
backup.Settings = (Duplicati.Server.Serialization.Interface.ISetting[])backup.Settings.Where((setting) => !passwordFields.Contains(setting.Name)).ToArray();
|
||||
backup.SanitizeSettings();
|
||||
backup.SanitizeTargetUrl();
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user