Add input validation to schematic commands
SchematicCommandHandler: - Add validation for schematic names to prevent path traversal - Restrict names to alphanumeric, hyphens, and underscores only - Add length limit (max 64 characters) - Apply validation to both save and paste commands - Prevent filesystem attacks via malicious schematic names Security improvement: blocks names like "../../config" or "../../../etc/passwd" All changes tested and verified with build + tests passing.
This commit is contained in:
parent
fe38a46496
commit
5526910bef
1 changed files with 23 additions and 0 deletions
|
|
@ -111,6 +111,12 @@ public class SchematicCommandHandler {
|
||||||
private static void handleSave(String name, CommandSender sender, Player player, PlayerCommandHandler cooldowns) {
|
private static void handleSave(String name, CommandSender sender, Player player, PlayerCommandHandler cooldowns) {
|
||||||
if (!cooldowns.cooldown(sender, "schematic-save", 2500)) return;
|
if (!cooldowns.cooldown(sender, "schematic-save", 2500)) return;
|
||||||
|
|
||||||
|
// Validate schematic name to prevent path traversal
|
||||||
|
if (!isValidSchematicName(name)) {
|
||||||
|
send(player, "<dark_red><bold>Schematics <reset><red>Invalid name. Use only letters, numbers, hyphens and underscores.");
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
Location[] sel = selections.get(player);
|
Location[] sel = selections.get(player);
|
||||||
if (sel == null || sel[0] == null || sel[1] == null) {
|
if (sel == null || sel[0] == null || sel[1] == null) {
|
||||||
send(player, "<dark_red><bold>Schematics <reset><red>Selection incomplete. Set both positions first.");
|
send(player, "<dark_red><bold>Schematics <reset><red>Selection incomplete. Set both positions first.");
|
||||||
|
|
@ -133,7 +139,24 @@ public class SchematicCommandHandler {
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Validates schematic name to prevent path traversal and filesystem issues.
|
||||||
|
* Only allows alphanumeric characters, hyphens, and underscores.
|
||||||
|
*/
|
||||||
|
private static boolean isValidSchematicName(String name) {
|
||||||
|
if (name == null || name.isEmpty() || name.length() > 64) {
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
return name.matches("^[a-zA-Z0-9_-]+$");
|
||||||
|
}
|
||||||
|
|
||||||
private static void handlePaste(String name, CommandSender sender, Player player) {
|
private static void handlePaste(String name, CommandSender sender, Player player) {
|
||||||
|
// Validate schematic name to prevent path traversal
|
||||||
|
if (!isValidSchematicName(name)) {
|
||||||
|
send(player, "<dark_red><bold>Schematics <reset><red>Invalid name. Use only letters, numbers, hyphens and underscores.");
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
LPSchematic s = LoParkour.getSchematicManager().getSchematic(name);
|
LPSchematic s = LoParkour.getSchematicManager().getSchematic(name);
|
||||||
if (s == null) {
|
if (s == null) {
|
||||||
send(sender, LoParkour.PREFIX + "Schematic '" + name + "' not found.");
|
send(sender, LoParkour.PREFIX + "Schematic '" + name + "' not found.");
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue