[ 
https://issues.apache.org/jira/browse/CAMEL-25163?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Andrea Cosentino reassigned CAMEL-25163:
----------------------------------------

    Assignee: Andrea Cosentino

> camel-google-storage - apply the download directory containment check on the 
> expression branch
> ----------------------------------------------------------------------------------------------
>
>                 Key: CAMEL-25163
>                 URL: https://issues.apache.org/jira/browse/CAMEL-25163
>             Project: Camel
>          Issue Type: Improvement
>          Components: camel-google-storage
>            Reporter: Andrea Cosentino
>            Assignee: Andrea Cosentino
>            Priority: Major
>
> {{GoogleCloudStorageConsumer.evaluateFileExpression()}} confines the resolved 
> local download path to the configured {{downloadFileName}} directory only 
> when {{downloadFileName}} contains no {{$}}:
> {code:java}
> boolean confineToDirectory = !downloadFileName.contains("$");
> ...
> if (confineToDirectory && result != null) {
>     GoogleCloudStorageFileNameHelper.assertWithinDirectory(downloadFileName, 
> result, blogName);
> }
> {code}
> The current comment explains the skip as "when the configuration already 
> contains an expression the local path is built by the route author, who is 
> trusted". That is only partly accurate: the template is written by the route 
> author, but {{${file:name}}} interpolates 
> {{GoogleCloudStorageConstants.FILE_NAME}}, which is set from 
> {{blob.getName()}} a few lines above and therefore reflects the remote object 
> name rather than route configuration.
> A configuration such as {{downloadFileName=/tmp/downloads/${file:name}}} - a 
> natural way to write it - resolves the remote object name into the path with 
> no containment check, so an object name containing parent-directory segments 
> resolves outside the configured directory.
> The containment check should also apply to the expression branch: resolve the 
> static prefix of the configured {{downloadFileName}} (the part before the 
> first expression token) and assert the evaluated result stays within it. 
> Where {{downloadFileName}} is a fully dynamic expression with no static 
> prefix, the existing behaviour can stay, but that case should be explicit 
> rather than implied.
> h3. Affected code
> * 
> {{components/camel-google/camel-google-storage/src/main/java/org/apache/camel/component/google/storage/GoogleCloudStorageConsumer.java}}
>  ({{evaluateFileExpression}})
> * 
> {{components/camel-google/camel-google-storage/src/main/java/org/apache/camel/component/google/storage/GoogleCloudStorageFileNameHelper.java}}
> h3. Acceptance
> Tests for a directory + expression configuration with a plain object name, 
> with an object name containing parent-directory segments, and for the fully 
> dynamic expression case.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to