Hacktoberfest 2026: die Issues, die Maintainer für den Oktober markiert haben – offen und einsteigerfreundlich. Hacktoberfest-Issues durchsuchen

adk web GET/DELETE test endpoints skip the create_test path sanitiser

Offen
#7,033 5 Kommentare 0 Reaktionen 1 zugewiesene Person Auf GitHub ansehen

Maintainer antworten meist innerhalb von 4 Tagen

@surajksharma07 arbeitet bereits daran.

Seit 07.9.2026.

  • #7034 von @Oskii — offen

Bewertung

Dieses Issue wurde noch nicht bewertet.

Beschreibung

request clarification web

Expected Behavior

create_test strips directories from test_name with os.path.basename so a name cannot leave the app tests/ folder.

GET, DELETE, and rebuild of a single test should use the same rule.

Actual Behavior

On main @ b018062, only create_test calls os.path.basename. delete_test, get_test_content, and rebuild_app_tests join test_name as given.

A percent-encoded path segment ../outside.json (%2e%2e%2foutside.json) on DELETE/GET is joined onto tests/ and can read or remove a JSON file in the agent directory, outside tests/.

rebuild?test_name=../outside.json does the same for the rebuild path.

This is the local adk web server. It is unauthenticated. Default bind is loopback. It still matters when --host 0.0.0.0 is used, or when anything else can hit those routes.

Steps to Reproduce

  1. adk web (or the TestClient in tests/unittests/cli/test_adk_web_server_tests.py)
  2. Put outside.json in the agent directory, not in tests/
  3. DELETE /dev/apps/<app>/tests/%2e%2e%2foutside.json
  4. On current main, that file is removed. After sanitising with basename, the request 404s and the file stays.

I can send a PR that shares one helper with create_test and adds those cases to test_adk_web_server_tests.py.

Vorherrschende Sprache
Python
Sterne
21.8k
Forks
4.1k
Ø Merge
1 T. 15 Std.
Gemergte PRs (30 T.)
5

Entwicklungsumgebung

Erste Schritte

  1. Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
  3. Forken Sie das Repository und arbeiten Sie in einem Branch.
  4. Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.

Mehr aus google/adk-python

Alle Issues in google/adk-python

Ähnliche Issues

Weitere Issues zu Python

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.