fix: sanitize user-controlled values in log entries

Replace CR/LF characters in Request.Method and Request.Path before
passing them to log methods to prevent log-injection (CWE-117).
This commit is contained in:
amoussa1229 2026-07-14 01:33:09 +00:00
parent ac616fc2ed
commit a76186e4c8

View file

@ -28,6 +28,8 @@ public class GlobalExceptionHandler : IMiddleware
}
}
private static string Sanitize(string? value) => (value ?? "").Replace('\r', '_').Replace('\n', '_');
private static ProblemDetails MakeProblem(int status, string title, string detail, string code)
{
var problem = new ProblemDetails
@ -58,7 +60,7 @@ public class GlobalExceptionHandler : IMiddleware
if (exception is ProposalConcurrencyException concurrencyEx)
{
_logger.LogWarning("Concurrency conflict on {Method} {Path}",
context.Request.Method, context.Request.Path);
Sanitize(context.Request.Method), Sanitize(context.Request.Path));
context.Response.StatusCode = StatusCodes.Status409Conflict;
context.Response.ContentType = "application/json";
await context.Response.WriteAsync(JsonSerializer.Serialize(new
@ -72,7 +74,7 @@ public class GlobalExceptionHandler : IMiddleware
if (exception is DbUpdateConcurrencyException)
{
_logger.LogWarning("Unguarded concurrency conflict on {Method} {Path}",
context.Request.Method, context.Request.Path);
Sanitize(context.Request.Method), Sanitize(context.Request.Path));
context.Response.StatusCode = StatusCodes.Status409Conflict;
context.Response.ContentType = "application/json";
await context.Response.WriteAsync(JsonSerializer.Serialize(new
@ -120,7 +122,7 @@ public class GlobalExceptionHandler : IMiddleware
};
_logger.LogError(exception, "Exception on {Method} {Path}: {Status}",
context.Request.Method, context.Request.Path, (int)statusCode);
Sanitize(context.Request.Method), Sanitize(context.Request.Path), (int)statusCode);
context.Response.StatusCode = (int)statusCode;
context.Response.ContentType = "application/problem+json";