mirror of
https://github.com/go-gitea/gitea.git
synced 2026-09-04 20:13:24 +09:00
fix(httplib): prevent leaking localhost:3000 in public links (#39217)
Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
This commit is contained in:
co-authored by
wxiaoguang
parent
52fcd2d2a0
commit
bcd913a4e2
+27
-4
@@ -10,13 +10,35 @@ import (
|
||||
"net/url"
|
||||
"strings"
|
||||
|
||||
"gitea.dev/modules/reqctx"
|
||||
"gitea.dev/modules/setting"
|
||||
"gitea.dev/modules/util"
|
||||
)
|
||||
|
||||
type RequestContextKeyStruct struct{}
|
||||
type contextKeyType string
|
||||
|
||||
var RequestContextKey = RequestContextKeyStruct{}
|
||||
var (
|
||||
contextKeyRequest = contextKeyType("request")
|
||||
contextKeySupportPublicURL = contextKeyType("support-public-url")
|
||||
)
|
||||
|
||||
// RequestWithContext returns a request with the given context and adds a cleanup function to remove temporary files.
|
||||
// It also sets the request in the context for later retrieval.
|
||||
func RequestWithContext(req *http.Request, ctx reqctx.RequestContext) *http.Request {
|
||||
req = req.WithContext(ctx)
|
||||
ctx.AddCleanUp(func() {
|
||||
if req.MultipartForm != nil {
|
||||
_ = req.MultipartForm.RemoveAll() // remove the temp files buffered to tmp directory
|
||||
}
|
||||
})
|
||||
ctx.SetContextValue(contextKeyRequest, req)
|
||||
return req
|
||||
}
|
||||
|
||||
// MarkRequestSupportPublicURL marks the request context to support public URL detection from request headers.
|
||||
func MarkRequestSupportPublicURL(ctx reqctx.RequestContext) {
|
||||
ctx.SetContextValue(contextKeySupportPublicURL, true)
|
||||
}
|
||||
|
||||
func urlIsRelative(s string, u *url.URL) bool {
|
||||
// Unfortunately, browsers consider a redirect Location with preceding "//", "\\", "/\" and "\/" as meaning redirect to "http(s)://REST_OF_PATH"
|
||||
@@ -80,7 +102,8 @@ func GuessCurrentAppURL(ctx context.Context) string {
|
||||
// GuessCurrentHostURL tries to guess the current full host URL (no sub-path) by http headers, there is no trailing slash.
|
||||
func GuessCurrentHostURL(ctx context.Context) string {
|
||||
// "never" means always trust ROOT_URL and skip any request header detection.
|
||||
if setting.PublicURLDetection == setting.PublicURLNever {
|
||||
detectPublicURL := setting.PublicURLDetection != setting.PublicURLNever && ctx.Value(contextKeySupportPublicURL) == true
|
||||
if !detectPublicURL {
|
||||
return strings.TrimSuffix(setting.AppURL, setting.AppSubURL+"/")
|
||||
}
|
||||
// Try the best guess to get the current host URL (will be used for public URL) by http headers.
|
||||
@@ -92,7 +115,7 @@ func GuessCurrentHostURL(ctx context.Context) string {
|
||||
// Without more information, Gitea is impossible to distinguish between case 2 and case 3, then case 2 would result in
|
||||
// wrong guess like guessed public URL becomes "http://gitea:3000/" behind a "https" reverse proxy, which is not accessible by end users.
|
||||
// So we introduced "PUBLIC_URL_DETECTION" option, to control the guessing behavior to satisfy different use cases.
|
||||
req, ok := ctx.Value(RequestContextKey).(*http.Request)
|
||||
req, ok := ctx.Value(contextKeyRequest).(*http.Request)
|
||||
if !ok {
|
||||
return strings.TrimSuffix(setting.AppURL, setting.AppSubURL+"/")
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user