mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-10-04 14:39:42 +02:00
COD-107 fix: shellescape -J jumpHost + structural validator (close command-injection)
buildSshConnectionArgs interpolated jumpHost raw while its siblings (identityFile/socksProxy/extraSshOptions) were shellescaped. The token array is joined and run via execAsync (/bin/sh -c), so a jumpHost like "x; touch /tmp/pwned" executed. The Zod denylist only blocked backtick/newline/$( and let ;|& and spaces through. - shellescape jumpHost in buildSshConnectionArgs (primary fix) - replace jumpHost denylist with a structural allowlist: [user@]host[:port], comma-separated multi-hop, bracketed IPv6; no shell metachar can appear - update/extend tests: escaped -J assertion + injection-safety case Verified: remote-ssh-options (11) + case-routes (33) pass, tsc --noEmit clean, regex accepts valid forms / rejects 8 injection payloads. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
268a0bbdbd
commit
e83ff72b61
@@ -87,9 +87,19 @@ describe('COD-107 buildSshConnectionArgs — shared ssh connection tokens', () =
|
||||
expect(idxProxy).toBeLessThan(idxExtra);
|
||||
});
|
||||
|
||||
it('supports an explicit -J jump host', () => {
|
||||
it('supports an explicit -J jump host (shellescaped, like its siblings)', () => {
|
||||
const args = buildSshConnectionArgs({ ...baseRemote, jumpHost: 'bastion@10.0.0.1:22' });
|
||||
expect(args.join(' ')).toContain('-J bastion@10.0.0.1:22');
|
||||
expect(args.join(' ')).toContain("-J 'bastion@10.0.0.1:22'");
|
||||
});
|
||||
|
||||
it('shellescapes a -J jump host containing shell metacharacters (no injection)', () => {
|
||||
// Defense-in-depth: even if a metachar-laden value slipped past schema validation,
|
||||
// it must stay a single shell token and never break out of the ssh command.
|
||||
const args = buildSshConnectionArgs({ ...baseRemote, jumpHost: 'x; touch /tmp/pwned' });
|
||||
const joined = args.join(' ');
|
||||
// The whole value is wrapped in single quotes — the `;` cannot start a new command.
|
||||
expect(joined).toContain("-J 'x; touch /tmp/pwned'");
|
||||
expect(joined).not.toContain('-J x;');
|
||||
});
|
||||
|
||||
it('expands a $HOME-prefixed identity path', () => {
|
||||
|
||||
Reference in New Issue
Block a user