From 7f8794885279695133a219ee464e861a264a4309 Mon Sep 17 00:00:00 2001 From: "kritik.b" Date: Thu, 16 Apr 2026 14:13:23 +0530 Subject: [PATCH] fix(docker): wire tests into CI, fix resolvePath separator, correct image namespace - Add `node --test docker-server.test.mjs` step to ci-tests.yml so the path-traversal guard tests run in every CI pass instead of being silently skipped. - Fix resolvePath containment check: `startsWith(root)` would allow sibling directories like `/app/dist-evil/`; now guards with `root + sep` or exact match. - Update docker-compose.yaml default image from `abhigyanpatwari` namespace to `brainifii` to match what docker.yml publishes to GHCR. --- .github/workflows/ci-tests.yml | 3 +++ docker-compose.yaml | 2 +- docker-server.mjs | 4 ++-- 3 files changed, 6 insertions(+), 3 deletions(-) diff --git a/.github/workflows/ci-tests.yml b/.github/workflows/ci-tests.yml index 27eb75383..7010ee6f3 100644 --- a/.github/workflows/ci-tests.yml +++ b/.github/workflows/ci-tests.yml @@ -41,6 +41,9 @@ jobs: --outputFile=web-test-results.json working-directory: gitnexus-web + - name: Run docker-server integration tests + run: node --test docker-server.test.mjs + - name: Upload test reports if: always() uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 diff --git a/docker-compose.yaml b/docker-compose.yaml index 9665e4ef1..849a3ae14 100644 --- a/docker-compose.yaml +++ b/docker-compose.yaml @@ -1,6 +1,6 @@ services: gitnexus: - image: ${IMAGE_NAME:-ghcr.io/abhigyanpatwari/gitnexus:latest} + image: ${IMAGE_NAME:-ghcr.io/brainifii/gitnexus:latest} container_name: ${CONTAINER_NAME:-gitnexus} ports: - '${HOST_PORT:-4173}:4173' diff --git a/docker-server.mjs b/docker-server.mjs index c72f1b609..adf84a07b 100644 --- a/docker-server.mjs +++ b/docker-server.mjs @@ -1,7 +1,7 @@ import { createReadStream } from 'node:fs'; import { stat } from 'node:fs/promises'; import { createServer } from 'node:http'; -import { extname, join, normalize } from 'node:path'; +import { extname, join, normalize, sep } from 'node:path'; const host = '0.0.0.0'; const port = Number(process.env.PORT || '4173'); @@ -30,7 +30,7 @@ function resolvePath(urlPath) { if (decoded.includes('\0')) return null; const cleanPath = normalize(decoded.replace(/^\/+/, '')); const candidate = join(root, cleanPath); - if (!candidate.startsWith(root)) return null; + if (candidate !== root && !candidate.startsWith(root + sep)) return null; return candidate; }