[
https://issues.apache.org/jira/browse/CAMEL-25163?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Andrea Cosentino reassigned CAMEL-25163:
----------------------------------------
Assignee: Andrea Cosentino
> camel-google-storage - apply the download directory containment check on the
> expression branch
> ----------------------------------------------------------------------------------------------
>
> Key: CAMEL-25163
> URL: https://issues.apache.org/jira/browse/CAMEL-25163
> Project: Camel
> Issue Type: Improvement
> Components: camel-google-storage
> Reporter: Andrea Cosentino
> Assignee: Andrea Cosentino
> Priority: Major
>
> {{GoogleCloudStorageConsumer.evaluateFileExpression()}} confines the resolved
> local download path to the configured {{downloadFileName}} directory only
> when {{downloadFileName}} contains no {{$}}:
> {code:java}
> boolean confineToDirectory = !downloadFileName.contains("$");
> ...
> if (confineToDirectory && result != null) {
> GoogleCloudStorageFileNameHelper.assertWithinDirectory(downloadFileName,
> result, blogName);
> }
> {code}
> The current comment explains the skip as "when the configuration already
> contains an expression the local path is built by the route author, who is
> trusted". That is only partly accurate: the template is written by the route
> author, but {{${file:name}}} interpolates
> {{GoogleCloudStorageConstants.FILE_NAME}}, which is set from
> {{blob.getName()}} a few lines above and therefore reflects the remote object
> name rather than route configuration.
> A configuration such as {{downloadFileName=/tmp/downloads/${file:name}}} - a
> natural way to write it - resolves the remote object name into the path with
> no containment check, so an object name containing parent-directory segments
> resolves outside the configured directory.
> The containment check should also apply to the expression branch: resolve the
> static prefix of the configured {{downloadFileName}} (the part before the
> first expression token) and assert the evaluated result stays within it.
> Where {{downloadFileName}} is a fully dynamic expression with no static
> prefix, the existing behaviour can stay, but that case should be explicit
> rather than implied.
> h3. Affected code
> *
> {{components/camel-google/camel-google-storage/src/main/java/org/apache/camel/component/google/storage/GoogleCloudStorageConsumer.java}}
> ({{evaluateFileExpression}})
> *
> {{components/camel-google/camel-google-storage/src/main/java/org/apache/camel/component/google/storage/GoogleCloudStorageFileNameHelper.java}}
> h3. Acceptance
> Tests for a directory + expression configuration with a plain object name,
> with an object name containing parent-directory segments, and for the fully
> dynamic expression case.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)