Skip to content

Commit

Permalink
add missing qs validation
Browse files Browse the repository at this point in the history
  • Loading branch information
morphy2k committed Sep 2, 2020
1 parent b50a40a commit 2d83380
Show file tree
Hide file tree
Showing 2 changed files with 41 additions and 2 deletions.
12 changes: 12 additions & 0 deletions controller/location.go
Original file line number Diff line number Diff line change
Expand Up @@ -474,6 +474,18 @@ Loop:
return
}

if l := len(q); l < 2 || l > 100 {
s := &Status{}
s.BadRequest("Query string has an invalid length").Render(w)
return
}

if !isAlnumBlankPunct(q) {
s := &Status{}
s.BadRequest("Query string contains invalid characters").Render(w)
return
}

tags := strings.Split(q, ",")

result, err = featuregroup.GetByTags(tags, lID, opts)
Expand Down
31 changes: 29 additions & 2 deletions controller/user.go
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,7 @@ import (
"errors"
"fmt"
"net/http"
"net/url"
"strconv"

"github.com/tarkov-database/rest-api/model"
Expand Down Expand Up @@ -39,7 +40,14 @@ Loop:
for p, v := range r.URL.Query() {
switch p {
case "locked":
locked, err := strconv.ParseBool(v[0])
s, err := url.QueryUnescape(v[0])
if err != nil {
s := &Status{}
s.BadRequest(fmt.Sprintf("Query string error: %s", err)).Render(w)
return
}

locked, err := strconv.ParseBool(s)
if err != nil {
s := &Status{}
s.BadRequest(err.Error()).Render(w)
Expand All @@ -54,7 +62,26 @@ Loop:

break Loop
case "email":
result, err = user.GetByEmail(v[0], opts)
addr, err := url.QueryUnescape(v[0])
if err != nil {
s := &Status{}
s.BadRequest(fmt.Sprintf("Query string error: %s", err)).Render(w)
return
}

if l := len(addr); l < 3 || l > 100 {
s := &Status{}
s.BadRequest("Query string has an invalid length").Render(w)
return
}

if !isAlnumBlankPunct(addr) {
s := &Status{}
s.BadRequest("Query string contains invalid characters").Render(w)
return
}

result, err = user.GetByEmail(addr, opts)
if err != nil {
handleError(err, w)
return
Expand Down

0 comments on commit 2d83380

Please sign in to comment.