mirror of
https://github.com/Sea-Haven-Industries/proposal-system.git
synced 2026-10-07 12:48:57 +00:00
fix: sanitize user-controlled values in log entries
Replace CR/LF characters in Request.Method and Request.Path before passing them to log methods to prevent log-injection (CWE-117).
This commit is contained in:
parent
ac616fc2ed
commit
a76186e4c8
1 changed files with 5 additions and 3 deletions
|
|
@ -28,6 +28,8 @@ public class GlobalExceptionHandler : IMiddleware
|
|||
}
|
||||
}
|
||||
|
||||
private static string Sanitize(string? value) => (value ?? "").Replace('\r', '_').Replace('\n', '_');
|
||||
|
||||
private static ProblemDetails MakeProblem(int status, string title, string detail, string code)
|
||||
{
|
||||
var problem = new ProblemDetails
|
||||
|
|
@ -58,7 +60,7 @@ public class GlobalExceptionHandler : IMiddleware
|
|||
if (exception is ProposalConcurrencyException concurrencyEx)
|
||||
{
|
||||
_logger.LogWarning("Concurrency conflict on {Method} {Path}",
|
||||
context.Request.Method, context.Request.Path);
|
||||
Sanitize(context.Request.Method), Sanitize(context.Request.Path));
|
||||
context.Response.StatusCode = StatusCodes.Status409Conflict;
|
||||
context.Response.ContentType = "application/json";
|
||||
await context.Response.WriteAsync(JsonSerializer.Serialize(new
|
||||
|
|
@ -72,7 +74,7 @@ public class GlobalExceptionHandler : IMiddleware
|
|||
if (exception is DbUpdateConcurrencyException)
|
||||
{
|
||||
_logger.LogWarning("Unguarded concurrency conflict on {Method} {Path}",
|
||||
context.Request.Method, context.Request.Path);
|
||||
Sanitize(context.Request.Method), Sanitize(context.Request.Path));
|
||||
context.Response.StatusCode = StatusCodes.Status409Conflict;
|
||||
context.Response.ContentType = "application/json";
|
||||
await context.Response.WriteAsync(JsonSerializer.Serialize(new
|
||||
|
|
@ -120,7 +122,7 @@ public class GlobalExceptionHandler : IMiddleware
|
|||
};
|
||||
|
||||
_logger.LogError(exception, "Exception on {Method} {Path}: {Status}",
|
||||
context.Request.Method, context.Request.Path, (int)statusCode);
|
||||
Sanitize(context.Request.Method), Sanitize(context.Request.Path), (int)statusCode);
|
||||
|
||||
context.Response.StatusCode = (int)statusCode;
|
||||
context.Response.ContentType = "application/problem+json";
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue