ValidatePath rejects a request whose percent-DECODED URL path is not a value the database can be asked about. Every handler that resolves a workspace, collection, item, comment or attachment from a path segment hands that segment to the store verbatim, and the store binds it into a text comparison.
(decorate func(http.Handler) http.Handler)
| 117 | // |
| 118 | // BUG-2782. |
| 119 | func ValidatePath(decorate func(http.Handler) http.Handler) func(http.Handler) http.Handler { |
| 120 | var reject http.Handler = http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { |
| 121 | // Set explicitly rather than relying on jsonContentType, which is |
| 122 | // mounted below this middleware and never runs for a rejection. |
| 123 | // Without it net/http sniffs the JSON body as text/plain. |
| 124 | w.Header().Set("Content-Type", "application/json") |
| 125 | // Not "is not valid UTF-8": a NUL is valid UTF-8 and is rejected |
| 126 | // here too, so that wording would be false for half the inputs |
| 127 | // this refuses. |
| 128 | writeError(w, http.StatusBadRequest, "invalid_path", |
| 129 | "Request path contains invalid UTF-8 or a NUL byte") |
| 130 | }) |
| 131 | if decorate != nil { |
| 132 | reject = decorate(reject) |
| 133 | } |
| 134 | return func(next http.Handler) http.Handler { |
| 135 | return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { |
| 136 | if !bindableText(r.URL.Path) { |
| 137 | reject.ServeHTTP(w, r) |
| 138 | return |
| 139 | } |
| 140 | next.ServeHTTP(w, r) |
| 141 | }) |
| 142 | } |
| 143 | } |
| 144 | |
| 145 | // bindableText reports whether a decoded string can be bound into a text |
| 146 | // comparison. It is the shared predicate of both middlewares in this file: |
no test coverage detected