mirror of
https://github.com/Sea-Haven-Industries/proposal-system.git
synced 2026-10-07 15:08:58 +00:00
fix: sanitize user-controlled values in log entries
Replace CR/LF characters in Request.Method and Request.Path before passing them to log methods to prevent log-injection (CWE-117).
This commit is contained in:
parent
ac616fc2ed
commit
a76186e4c8
1 changed files with 5 additions and 3 deletions
|
|
@ -28,6 +28,8 @@ public class GlobalExceptionHandler : IMiddleware
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
private static string Sanitize(string? value) => (value ?? "").Replace('\r', '_').Replace('\n', '_');
|
||||||
|
|
||||||
private static ProblemDetails MakeProblem(int status, string title, string detail, string code)
|
private static ProblemDetails MakeProblem(int status, string title, string detail, string code)
|
||||||
{
|
{
|
||||||
var problem = new ProblemDetails
|
var problem = new ProblemDetails
|
||||||
|
|
@ -58,7 +60,7 @@ public class GlobalExceptionHandler : IMiddleware
|
||||||
if (exception is ProposalConcurrencyException concurrencyEx)
|
if (exception is ProposalConcurrencyException concurrencyEx)
|
||||||
{
|
{
|
||||||
_logger.LogWarning("Concurrency conflict on {Method} {Path}",
|
_logger.LogWarning("Concurrency conflict on {Method} {Path}",
|
||||||
context.Request.Method, context.Request.Path);
|
Sanitize(context.Request.Method), Sanitize(context.Request.Path));
|
||||||
context.Response.StatusCode = StatusCodes.Status409Conflict;
|
context.Response.StatusCode = StatusCodes.Status409Conflict;
|
||||||
context.Response.ContentType = "application/json";
|
context.Response.ContentType = "application/json";
|
||||||
await context.Response.WriteAsync(JsonSerializer.Serialize(new
|
await context.Response.WriteAsync(JsonSerializer.Serialize(new
|
||||||
|
|
@ -72,7 +74,7 @@ public class GlobalExceptionHandler : IMiddleware
|
||||||
if (exception is DbUpdateConcurrencyException)
|
if (exception is DbUpdateConcurrencyException)
|
||||||
{
|
{
|
||||||
_logger.LogWarning("Unguarded concurrency conflict on {Method} {Path}",
|
_logger.LogWarning("Unguarded concurrency conflict on {Method} {Path}",
|
||||||
context.Request.Method, context.Request.Path);
|
Sanitize(context.Request.Method), Sanitize(context.Request.Path));
|
||||||
context.Response.StatusCode = StatusCodes.Status409Conflict;
|
context.Response.StatusCode = StatusCodes.Status409Conflict;
|
||||||
context.Response.ContentType = "application/json";
|
context.Response.ContentType = "application/json";
|
||||||
await context.Response.WriteAsync(JsonSerializer.Serialize(new
|
await context.Response.WriteAsync(JsonSerializer.Serialize(new
|
||||||
|
|
@ -120,7 +122,7 @@ public class GlobalExceptionHandler : IMiddleware
|
||||||
};
|
};
|
||||||
|
|
||||||
_logger.LogError(exception, "Exception on {Method} {Path}: {Status}",
|
_logger.LogError(exception, "Exception on {Method} {Path}: {Status}",
|
||||||
context.Request.Method, context.Request.Path, (int)statusCode);
|
Sanitize(context.Request.Method), Sanitize(context.Request.Path), (int)statusCode);
|
||||||
|
|
||||||
context.Response.StatusCode = (int)statusCode;
|
context.Response.StatusCode = (int)statusCode;
|
||||||
context.Response.ContentType = "application/problem+json";
|
context.Response.ContentType = "application/problem+json";
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue