Commit 26a3a0b
committed
fix(security): trim allowlist/denylist patterns to prevent config-side bypass (M4)
ActionForCommand trims the command string before matching, but the
allowlist and denylist patterns from the user's config were never
trimmed. If a user accidentally included trailing whitespace in a
pattern (e.g. via copy-paste), the match would silently fail.
Fix: apply strings.TrimSpace() to patterns before comparing, so
config-side whitespace is ignored just like command-side whitespace.
Also corrected the Denylist struct doc: it says "Exact match only"
but the code uses strings.HasPrefix (prefix match), which is the
intended behavior since the deny list is for broad-stroke blocking.
Fixes M4 from security audit.1 parent b62bb8d commit 26a3a0b
2 files changed
Lines changed: 31 additions & 7 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
217 | 217 | | |
218 | 218 | | |
219 | 219 | | |
220 | | - | |
| 220 | + | |
221 | 221 | | |
222 | 222 | | |
223 | 223 | | |
| |||
279 | 279 | | |
280 | 280 | | |
281 | 281 | | |
282 | | - | |
283 | | - | |
| 282 | + | |
| 283 | + | |
284 | 284 | | |
285 | 285 | | |
286 | 286 | | |
287 | 287 | | |
288 | 288 | | |
289 | | - | |
| 289 | + | |
290 | 290 | | |
291 | | - | |
| 291 | + | |
292 | 292 | | |
293 | 293 | | |
294 | 294 | | |
295 | | - | |
| 295 | + | |
296 | 296 | | |
297 | | - | |
| 297 | + | |
298 | 298 | | |
299 | 299 | | |
300 | 300 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
649 | 649 | | |
650 | 650 | | |
651 | 651 | | |
| 652 | + | |
| 653 | + | |
| 654 | + | |
| 655 | + | |
| 656 | + | |
| 657 | + | |
| 658 | + | |
| 659 | + | |
| 660 | + | |
| 661 | + | |
| 662 | + | |
| 663 | + | |
| 664 | + | |
| 665 | + | |
| 666 | + | |
| 667 | + | |
| 668 | + | |
| 669 | + | |
| 670 | + | |
| 671 | + | |
| 672 | + | |
| 673 | + | |
| 674 | + | |
| 675 | + | |
652 | 676 | | |
653 | 677 | | |
654 | 678 | | |
| |||
0 commit comments