Andrea Cosentino created CAMEL-25163:
----------------------------------------

             Summary: camel-google-storage - apply the download directory 
containment check on the expression branch
                 Key: CAMEL-25163
                 URL: https://issues.apache.org/jira/browse/CAMEL-25163
             Project: Camel
          Issue Type: Improvement
          Components: camel-google-storage
            Reporter: Andrea Cosentino


{{GoogleCloudStorageConsumer.evaluateFileExpression()}} confines the resolved 
local download path to the configured {{downloadFileName}} directory only when 
{{downloadFileName}} contains no {{$}}:

{code:java}
boolean confineToDirectory = !downloadFileName.contains("$");
...
if (confineToDirectory && result != null) {
    GoogleCloudStorageFileNameHelper.assertWithinDirectory(downloadFileName, 
result, blogName);
}
{code}

The current comment explains the skip as "when the configuration already 
contains an expression the local path is built by the route author, who is 
trusted". That is only partly accurate: the template is written by the route 
author, but {{${file:name}}} interpolates 
{{GoogleCloudStorageConstants.FILE_NAME}}, which is set from {{blob.getName()}} 
a few lines above and therefore reflects the remote object name rather than 
route configuration.

A configuration such as {{downloadFileName=/tmp/downloads/${file:name}}} - a 
natural way to write it - resolves the remote object name into the path with no 
containment check, so an object name containing parent-directory segments 
resolves outside the configured directory.

The containment check should also apply to the expression branch: resolve the 
static prefix of the configured {{downloadFileName}} (the part before the first 
expression token) and assert the evaluated result stays within it. Where 
{{downloadFileName}} is a fully dynamic expression with no static prefix, the 
existing behaviour can stay, but that case should be explicit rather than 
implied.

h3. Affected code

* 
{{components/camel-google/camel-google-storage/src/main/java/org/apache/camel/component/google/storage/GoogleCloudStorageConsumer.java}}
 ({{evaluateFileExpression}})
* 
{{components/camel-google/camel-google-storage/src/main/java/org/apache/camel/component/google/storage/GoogleCloudStorageFileNameHelper.java}}

h3. Acceptance

Tests for a directory + expression configuration with a plain object name, with 
an object name containing parent-directory segments, and for the fully dynamic 
expression case.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to