Skip to content

Commit e0079d1

Browse files
authored
fix: reject HP_SHARED_KEY with FRP-incompatible characters (#104)
* fix: reject HP_SHARED_KEY containing characters that break FRP TOML config Signed-off-by: Oleksander Piskun <oleksandr2088@icloud.com> * chore: bump /info endpoint version to 0.4 Signed-off-by: Oleksander Piskun <oleksandr2088@icloud.com> * fix: move HP_SHARED_KEY validation after strip_quotes and stop rejecting apostrophes Signed-off-by: Oleksander Piskun <oleksandr2088@icloud.com> --------- Signed-off-by: Oleksander Piskun <oleksandr2088@icloud.com>
1 parent f68704b commit e0079d1

2 files changed

Lines changed: 14 additions & 1 deletion

File tree

‎haproxy_agent.py‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -728,7 +728,7 @@ async def get_info(request: web.Request):
728728
k8s_status["reachable"] = False
729729

730730
return web.json_response({
731-
"version": 0.3,
731+
"version": 0.4,
732732
"docker": True,
733733
"kubernetes": k8s_status,
734734
})

‎start.sh‎

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -127,6 +127,19 @@ fi
127127
HP_SHARED_KEY="$(strip_quotes "$HP_SHARED_KEY")"
128128
export HP_SHARED_KEY
129129

130+
# After stripping any surrounding quotes, the remaining value must not contain
131+
# characters that would corrupt the generated FRP TOML config line
132+
# `metadatas.token = "..."`:
133+
# " - terminates the TOML basic string
134+
# \ - starts a TOML escape sequence inside that string
135+
FORBIDDEN_COUNT=$(printf '%s' "$HP_SHARED_KEY" | LC_ALL=C tr -cd '"\\' | wc -c)
136+
if [ "$FORBIDDEN_COUNT" -gt 0 ]; then
137+
echo "ERROR: HP_SHARED_KEY contains a forbidden character."
138+
echo "The following characters are not allowed: double quote (\"), backslash (\\)."
139+
echo "Please choose a password without these characters."
140+
exit 1
141+
fi
142+
130143
# Strip surrounding quotes from other commonly affected environment variables
131144
NC_INSTANCE_URL="$(strip_quotes "$NC_INSTANCE_URL")"
132145
HP_FRP_ADDRESS="$(strip_quotes "$HP_FRP_ADDRESS")"

0 commit comments

Comments
 (0)