Repository navigation
Conversation
Contributor
WebDAV temp-storage paths and names come from the client. Resolve every temp path strictly inside the temp directory (the directory itself is not a valid resource), and require names that reach temp storage to be a single plain path segment. Temp writes (copy, move, create file, create folder) build their target through one helper and reject invalid input with 400 before touching the filesystem. Rejections are logged without the request path. Adds DotWebdavTempPathContainmentTest, registered in MainSuite3a.
oidacra
force-pushed
the
713-webdav-temp-path-hardening
branch
from
October 7, 2026 20:47
f7ddc90 to
7a4bf22
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
WebDAV temp-path resolution joined request-derived input onto the temp directory
without containment, so a path with a parent-directory traversal could resolve
outside the intended temp root.
Fix
isWithinTempDir(File)toDotWebdavHelper: canonicalizes the candidate andthe temp root, allowing only paths contained within the root (fail-closed).
loadTempFile(returns null),createTempFileandcreateTempFolder(reject before creating), logging on rejection.
Tests
DotWebdavTempPathContainmentTest(registered inMainSuite3a):escaping paths rejected; in-bounds dot-prefixed temp file still resolves inside the
root. Confirmed failing before the fix, passing after (
Tests run: 3, Failures: 0).Risk
Rollback-safe: no DB schema, ES mapping, API contract, or serialized-state change.
Fixes dotCMS/private-issues#713