Andrea Cosentino created CAMEL-25163:
----------------------------------------
Summary: camel-google-storage - apply the download directory
containment check on the expression branch
Key: CAMEL-25163
URL: https://issues.apache.org/jira/browse/CAMEL-25163
Project: Camel
Issue Type: Improvement
Components: camel-google-storage
Reporter: Andrea Cosentino
{{GoogleCloudStorageConsumer.evaluateFileExpression()}} confines the resolved
local download path to the configured {{downloadFileName}} directory only when
{{downloadFileName}} contains no {{$}}:
{code:java}
boolean confineToDirectory = !downloadFileName.contains("$");
...
if (confineToDirectory && result != null) {
GoogleCloudStorageFileNameHelper.assertWithinDirectory(downloadFileName,
result, blogName);
}
{code}
The current comment explains the skip as "when the configuration already
contains an expression the local path is built by the route author, who is
trusted". That is only partly accurate: the template is written by the route
author, but {{${file:name}}} interpolates
{{GoogleCloudStorageConstants.FILE_NAME}}, which is set from {{blob.getName()}}
a few lines above and therefore reflects the remote object name rather than
route configuration.
A configuration such as {{downloadFileName=/tmp/downloads/${file:name}}} - a
natural way to write it - resolves the remote object name into the path with no
containment check, so an object name containing parent-directory segments
resolves outside the configured directory.
The containment check should also apply to the expression branch: resolve the
static prefix of the configured {{downloadFileName}} (the part before the first
expression token) and assert the evaluated result stays within it. Where
{{downloadFileName}} is a fully dynamic expression with no static prefix, the
existing behaviour can stay, but that case should be explicit rather than
implied.
h3. Affected code
*
{{components/camel-google/camel-google-storage/src/main/java/org/apache/camel/component/google/storage/GoogleCloudStorageConsumer.java}}
({{evaluateFileExpression}})
*
{{components/camel-google/camel-google-storage/src/main/java/org/apache/camel/component/google/storage/GoogleCloudStorageFileNameHelper.java}}
h3. Acceptance
Tests for a directory + expression configuration with a plain object name, with
an object name containing parent-directory segments, and for the fully dynamic
expression case.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)