v1.3.55: validate zip magic bytes on upload (UI + backend)
This commit is contained in:
@@ -52,7 +52,7 @@ spec:
|
|||||||
serviceAccountName: fission-console
|
serviceAccountName: fission-console
|
||||||
containers:
|
containers:
|
||||||
- name: console
|
- name: console
|
||||||
image: naeel/fission-console:v1.3.54
|
image: naeel/fission-console:v1.3.55
|
||||||
imagePullPolicy: Always
|
imagePullPolicy: Always
|
||||||
ports:
|
ports:
|
||||||
- containerPort: 8090
|
- containerPort: 8090
|
||||||
|
|||||||
@@ -1333,6 +1333,12 @@ func (s *Server) handleCreateFunctionFromArchive(w http.ResponseWriter, r *http.
|
|||||||
archiveFilenameCreate = fhCreate.Filename
|
archiveFilenameCreate = fhCreate.Filename
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Проверяем magic bytes: zip должен начинаться с PK (0x50 0x4B)
|
||||||
|
if len(archiveBytes) < 4 || archiveBytes[0] != 0x50 || archiveBytes[1] != 0x4B {
|
||||||
|
writeJSONError(w, http.StatusBadRequest, "загруженный файл не является zip-архивом (ожидается .zip)")
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
nsCtx, nsCancel := context.WithTimeout(r.Context(), 60*time.Second)
|
nsCtx, nsCancel := context.WithTimeout(r.Context(), 60*time.Second)
|
||||||
defer nsCancel()
|
defer nsCancel()
|
||||||
if err := s.nsManager.EnsureUserNS(nsCtx, ns); err != nil {
|
if err := s.nsManager.EnsureUserNS(nsCtx, ns); err != nil {
|
||||||
|
|||||||
@@ -102,7 +102,7 @@
|
|||||||
<div class="nubes">NUBES</div>
|
<div class="nubes">NUBES</div>
|
||||||
<div class="product">FISSION CONSOLE</div>
|
<div class="product">FISSION CONSOLE</div>
|
||||||
</div>
|
</div>
|
||||||
<div style="font-size:0.65rem; color:var(--text-secondary); margin-left:10px; align-self:center; opacity:0.7;">v1.3.54</div>
|
<div style="font-size:0.65rem; color:var(--text-secondary); margin-left:10px; align-self:center; opacity:0.7;">v1.3.55</div>
|
||||||
</div>
|
</div>
|
||||||
<div class="row" style="margin:0;">
|
<div class="row" style="margin:0;">
|
||||||
<button class="btn ghost" onclick="reloadAll()">Refresh</button>
|
<button class="btn ghost" onclick="reloadAll()">Refresh</button>
|
||||||
@@ -462,7 +462,7 @@
|
|||||||
</div>
|
</div>
|
||||||
|
|
||||||
<div class="actions" style="justify-content:space-between; align-items:center;">
|
<div class="actions" style="justify-content:space-between; align-items:center;">
|
||||||
<span style="font-size:0.75rem; color:var(--text-secondary);">v1.3.54</span>
|
<span style="font-size:0.75rem; color:var(--text-secondary);">v1.3.55</span>
|
||||||
<button class="btn ghost" onclick="closeHelp()">Закрыть</button>
|
<button class="btn ghost" onclick="closeHelp()">Закрыть</button>
|
||||||
</div>
|
</div>
|
||||||
</div>
|
</div>
|
||||||
|
|||||||
@@ -42,6 +42,7 @@ async function submitCreateArchive() {
|
|||||||
if (!lang) throw new Error('language is required');
|
if (!lang) throw new Error('language is required');
|
||||||
const archiveFile = document.getElementById('ca-archive-file').files[0];
|
const archiveFile = document.getElementById('ca-archive-file').files[0];
|
||||||
if (!archiveFile) throw new Error('выберите .zip архив');
|
if (!archiveFile) throw new Error('выберите .zip архив');
|
||||||
|
if (!archiveFile.name.toLowerCase().endsWith('.zip')) throw new Error('файл должен быть .zip архивом, не .' + archiveFile.name.split('.').pop());
|
||||||
|
|
||||||
var fd = new FormData();
|
var fd = new FormData();
|
||||||
fd.append('name', name);
|
fd.append('name', name);
|
||||||
|
|||||||
Reference in New Issue
Block a user