Handle malformed CommandBoard paths (#76)

This commit is contained in:
phucnguyen1707 2026-06-15 15:25:09 +07:00 committed by GitHub
parent ae371b91d0
commit cb192906bd
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
3 changed files with 72 additions and 38 deletions

View file

@ -7,6 +7,7 @@
"build": "node scripts/check-assets.js && vite build", "build": "node scripts/check-assets.js && vite build",
"dev": "vite --host 0.0.0.0", "dev": "vite --host 0.0.0.0",
"start": "node server.js", "start": "node server.js",
"test": "vitest run server.test.js",
"test:e2e": "playwright test" "test:e2e": "playwright test"
}, },
"dependencies": { "dependencies": {

View file

@ -7,7 +7,6 @@ import { createCommandBoardServer } from "../commandboard-api/dist/index.js";
const appDirectory = fileURLToPath(new URL(".", import.meta.url)); const appDirectory = fileURLToPath(new URL(".", import.meta.url));
const distDirectory = resolve(appDirectory, "dist"); const distDirectory = resolve(appDirectory, "dist");
const indexFile = join(distDirectory, "index.html"); const indexFile = join(distDirectory, "index.html");
const apiServer = createCommandBoardServer();
const port = readPort(process.env.PORT, 4173); const port = readPort(process.env.PORT, 4173);
const mimeTypes = { const mimeTypes = {
@ -21,7 +20,10 @@ const mimeTypes = {
".webmanifest": "application/manifest+json; charset=utf-8" ".webmanifest": "application/manifest+json; charset=utf-8"
}; };
createServer((request, response) => { export function createCommandBoardWebServer() {
const apiServer = createCommandBoardServer();
return createServer((request, response) => {
const url = new URL(request.url ?? "/", `http://${request.headers.host ?? "localhost"}`); const url = new URL(request.url ?? "/", `http://${request.headers.host ?? "localhost"}`);
if (url.pathname === "/health" || url.pathname.startsWith("/api/")) { if (url.pathname === "/health" || url.pathname.startsWith("/api/")) {
@ -54,17 +56,17 @@ createServer((request, response) => {
} }
sendFile(file, request.method === "HEAD", response); sendFile(file, request.method === "HEAD", response);
}).listen(port, () => { });
}
if (process.argv[1] && resolve(process.argv[1]) === fileURLToPath(import.meta.url)) {
createCommandBoardWebServer().listen(port, () => {
console.log(`CommandBoard.run PWA listening on http://localhost:${port}`); console.log(`CommandBoard.run PWA listening on http://localhost:${port}`);
}); });
function resolveStaticPath(pathname) {
let decodedPath;
try {
decodedPath = decodeURIComponent(pathname);
} catch {
return null;
} }
export function resolveStaticPath(pathname) {
const decodedPath = decodeURIComponent(pathname);
const normalizedPath = normalize(decodedPath).replace(/^(\.\.[/\\])+/, ""); const normalizedPath = normalize(decodedPath).replace(/^(\.\.[/\\])+/, "");
let candidate = join(distDirectory, normalizedPath); let candidate = join(distDirectory, normalizedPath);

View file

@ -0,0 +1,31 @@
import { afterAll, beforeAll, describe, expect, it } from "vitest";
import { createCommandBoardWebServer } from "./server.js";
let server;
let baseUrl;
beforeAll(async () => {
server = createCommandBoardWebServer();
await new Promise((resolve) => server.listen(0, resolve));
const address = server.address();
if (!address || typeof address === "string") {
throw new Error("Expected web server to bind to a local port");
}
baseUrl = `http://127.0.0.1:${address.port}`;
});
afterAll(async () => {
await new Promise((resolve, reject) => {
server.close((error) => (error ? reject(error) : resolve()));
});
});
describe("CommandBoard web server", () => {
it("rejects malformed path encoding as a client error", async () => {
const response = await fetch(`${baseUrl}/%E0%A4%A`);
const body = await response.text();
expect(response.status).toBe(400);
expect(body).toBe("Invalid path encoding");
});
});