dotdot: introducing dot file path cleanup

RFC3986 details how a path part passed in as part of a URI should be
"cleaned" from dot sequences before getting used. The described
algorithm is now implemented in lib/dotdot.c with the accompanied test
case in test 1395.

Bug: http://curl.haxx.se/bug/view.cgi?id=1200
Reported-by: Alex Vinnik
This commit is contained in:
Daniel Stenberg 2013-06-15 23:47:02 +02:00
parent ec248b590d
commit 7877619f85
9 changed files with 402 additions and 14 deletions

View file

@ -93,7 +93,7 @@ test1200 test1201 test1202 test1203 test1204 test1205 test1206 test1207 \
test1208 test1209 test1210 test1211 test1212 test1213 test1214 test1215 \
test1216 test1217 test1218 test1219 \
test1220 test1221 test1222 test1223 test1224 test1225 test1226 test1227 \
test1228 test1229 test1230 \
test1228 test1229 test1230 test1231 \
\
test1300 test1301 test1302 test1303 test1304 test1305 test1306 test1307 \
test1308 test1309 test1310 test1311 test1312 test1313 test1314 test1315 \

61
tests/data/test1231 Normal file
View file

@ -0,0 +1,61 @@
<testcase>
<info>
<keywords>
HTTP
HTTP GET
dotdot removal
</keywords>
</info>
#
# Server-side
<reply name="1">
<data>
HTTP/1.1 200 OK
Content-Length: 6
Connection: close
-foo-
</data>
<data1>
HTTP/1.1 200 OK
Content-Length: 7
Connection: close
-cool-
</data1>
</reply>
#
# Client-side
<client>
<server>
http
</server>
<name>
HTTP URL with dotdot removal from path
</name>
<command>
http://%HOSTIP:%HTTPPORT/../../hej/but/who/../1231?stupid=me/../1231#soo/../1231 http://%HOSTIP:%HTTPPORT/../../hej/but/who/../12310001#/../12310001
</command>
</client>
#
# Verify data after the test has been "shot"
<verify>
<strip>
^User-Agent:.*
</strip>
<protocol>
GET /hej/but/1231?stupid=me/../1231 HTTP/1.1
Host: %HOSTIP:%HTTPPORT
Accept: */*
GET /hej/but/12310001 HTTP/1.1
Host: %HOSTIP:%HTTPPORT
Accept: */*
</protocol>
</verify>
</testcase>

26
tests/data/test1395 Normal file
View file

@ -0,0 +1,26 @@
<testcase>
<info>
<keywords>
unittest
</keywords>
</info>
#
# Client-side
<client>
<server>
none
</server>
<features>
unittest
</features>
<name>
Curl_dedotdotify
</name>
<tool>
unit1395
</tool>
</client>
</testcase>