mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-10-07 07:59:42 +02:00
fix: validate WS resize dimensions to match HTTP route bounds
The HTTP resize route validates via ResizeSchema (cols: 1-500, rows: 1-200, integers only). The WS handler only checked typeof === 'number', allowing floats, negatives, and extreme values through to ptyProcess. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -81,7 +81,15 @@ export function registerWsRoutes(app: FastifyInstance, ctx: SessionPort): void {
|
|||||||
if (msg.t === 'i' && typeof msg.d === 'string') {
|
if (msg.t === 'i' && typeof msg.d === 'string') {
|
||||||
if (msg.d.length > MAX_INPUT_LENGTH) return;
|
if (msg.d.length > MAX_INPUT_LENGTH) return;
|
||||||
session.write(msg.d);
|
session.write(msg.d);
|
||||||
} else if (msg.t === 'z' && typeof msg.c === 'number' && typeof msg.r === 'number') {
|
} else if (
|
||||||
|
msg.t === 'z' &&
|
||||||
|
Number.isInteger(msg.c) &&
|
||||||
|
Number.isInteger(msg.r) &&
|
||||||
|
msg.c >= 1 &&
|
||||||
|
msg.c <= 500 &&
|
||||||
|
msg.r >= 1 &&
|
||||||
|
msg.r <= 200
|
||||||
|
) {
|
||||||
session.resize(msg.c, msg.r);
|
session.resize(msg.c, msg.r);
|
||||||
}
|
}
|
||||||
} catch {
|
} catch {
|
||||||
|
|||||||
Reference in New Issue
Block a user