fix(audit-2026-06-11/C-2+F-SE-H-03): reject control chars in content-type; disable Rhai debug
C-2 follow-up: sanitize_stored_content_type previously let a CRLF pass
through an allowlisted prefix (e.g. "image/png\r\nX-Injected: 1" matched
the image/ branch and returned the original), which would inject a
response header / panic HeaderValue on download. Now any control byte
(<0x20 or 0x7f) coerces to application/octet-stream up front.
F-SE-H-03: disable_symbol("debug") to match "print" (the comment
already claimed both were disabled) so scripts can't write
attacker-controlled bytes to the operator's stderr.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -49,6 +49,22 @@ fn validate_rejects_syntax_errors() {
|
||||
assert!(matches!(err, ExecError::Parse(_)));
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn debug_and_print_symbols_are_disabled() {
|
||||
// Audit 2026-06-11 (F-SE-H-03) — neither `print` nor `debug` may
|
||||
// reach the host's stdout/stderr; both are disabled at the symbol
|
||||
// level, so a script that calls them fails to parse/validate.
|
||||
for src in [r#"print("x")"#, r#"debug("x")"#] {
|
||||
let err = engine()
|
||||
.validate(src)
|
||||
.expect_err("disabled output symbol should be rejected");
|
||||
assert!(
|
||||
matches!(err, ExecError::Parse(_)),
|
||||
"{src} should be a parse-time rejection, got {err:?}"
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn returns_unwrapped_value_as_200_body() {
|
||||
let resp = engine()
|
||||
|
||||
Reference in New Issue
Block a user