moved all sanitization logic into backup class and moved from regex to using internal Uri library

This commit is contained in:
Rune Henriksen
2018-11-08 20:00:51 +01:00
parent 919eea59fc
commit c41f2c6a60
3 changed files with 36 additions and 19 deletions
+33 -17
View File
@@ -19,12 +19,27 @@ using System;
using Duplicati.Server.Serialization.Interface;
using System.Collections.Generic;
using System.Text.RegularExpressions;
using System.Linq;
namespace Duplicati.Server.Database
{
public class Backup : IBackup
{
{
// Sensitive information that may be stored in TargetUrl
private readonly string[] UrlPasswords = new[]{
"authid",
"auth-password",
"sia-password",
};
// Sensitive information that may be stored in Settings
private readonly string[] SettingPasswords = new[]{
"passphrase",
"--authid",
"--send-mail-password",
"--send-xmpp-password"
};
public Backup()
{
this.ID = null;
@@ -100,24 +115,25 @@ namespace Duplicati.Server.Database
public bool IsTemporary { get { return ID == null ? false : ID.IndexOf("-", StringComparison.Ordinal) > 0; } }
/// <summary>
/// Sanitizes the backup TargetUrl
/// Sanitizes the backup TargetUrl from any fields in the PasswordFields list.
/// </summary>
public void SanitizeTargetUrl()
{
var url = this.TargetURL;
// Remove authid
url = Regex.Replace(url, "authid=[^&\n]+[&]?", "");
// remove auth-password
url = Regex.Replace(url, "auth-password=[^&\n]+[&]?", "");
// remove backupsia-password
url = Regex.Replace(url, "sia-password=[^&\n]+[&]?", "");
// Remove edge case of '?&'
url = Regex.Replace(url, Regex.Escape("?&"), "");
// Remove edge case of '&' at end of line
url = Regex.Replace(url, "&$", "");
// Remove edge case of '?' at end of line
url = Regex.Replace(url, Regex.Escape("?") + "$", "");
this.TargetURL = url;
var url = new Duplicati.Library.Utility.Uri(this.TargetURL);
var filteredParameters = url.QueryParameters;
foreach (string field in UrlPasswords) {
filteredParameters.Remove(field);
}
url = url.SetQuery(Duplicati.Library.Utility.Uri.BuildUriQuery(url.QueryParameters));
this.TargetURL = url.ToString();
}
/// <summary>
/// Sanitizes the settings from any fields in the PassworldFields list.
/// </summary>
public void SanitizeSettings()
{
this.Settings = this.Settings.Where((setting) => !SettingPasswords.Contains(setting.Name)).ToArray();
}
}
}
@@ -76,6 +76,8 @@ namespace Duplicati.Server.Serialization.Interface
bool IsTemporary { get; }
void SanitizeTargetUrl();
void SanitizeSettings();
}
}
@@ -121,10 +121,9 @@ namespace Duplicati.Server.WebServer.RESTMethods
var cmdline = Library.Utility.Utility.ParseBool(info.Request.QueryString["cmdline"].Value, false);
var argsonly = Library.Utility.Utility.ParseBool(info.Request.QueryString["argsonly"].Value, false);
var exportPasswords = Library.Utility.Utility.ParseBool(info.Request.QueryString["export-passwords"].Value, false);
var passwordFields = new [] { "passphrase", "--send-mail-password", "--send-xmpp-password" };
if (!exportPasswords)
{
backup.Settings = (Duplicati.Server.Serialization.Interface.ISetting[])backup.Settings.Where((setting) => !passwordFields.Contains(setting.Name)).ToArray();
backup.SanitizeSettings();
backup.SanitizeTargetUrl();
}