openInEditor runs the editor command through a shell
I maintainer di solito rispondono entro 1 giorno
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 53/100
- Tipo di issue
- Bug
- Chiarezza
- Specificata chiaramente
- Stato di attività
- Attiva
- Stack tecnologico
- node.js, typescript
Direzione di ricerca
Start with src/main/files.ts:58 and read how openInEditor constructs and launches the editor command; then inspect the related Windows launcher constraint in issue #178. Add tests covering editor commands with spaces in paths and with arguments, as proposed. Done means editor commands are launched without treating the command as shell text, with the Windows .cmd case handled.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
From Finding 4b of the earlier SECURITY-REVIEW.md (also noted in the Oct 7 audit), checked against the current code.
Problem
openInEditor (src/main/files.ts:58) runs spawn(\${command} "${file}"`, { shell: true }). The file path is confined to the project and filtered for quotes, line breaks and (on POSIX) $, backtick and `. But editorCommand itself is shell text, so code; <anything> runs. Changing it needs a native confirmation, so this is not exploitable without the user, but the shell string is a fragile sink at the same trust level as the terminal.
Proposal
Split editorCommand into a program and arguments (shell-style parsing), and run spawn(program, [...args, file], { shell: false }). On Windows, .cmd launchers such as code.cmd need resolving to the executable or an explicit cmd.exe /d /s /c call with quoted arguments (see #178 for the same Node.js restriction). Add tests for editor commands with spaces in paths and with arguments.
- Lingua principale
- TypeScript
- Stelle
- 2
- Fork
- 2
- Merge medio
- 5h 28m
- PR unite (30g)
- 24
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Nessun modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di PierrunoYT/patch
-
enhancement priority: low security severity: low
Difficoltà 4/5 3-5 giorni Idoneità per principianti 35/100
PierrunoYT/patch#260 ·
I maintainer di solito rispondono entro 1 giorno
-
bug priority: low severity: low
Difficoltà 3/5 1-2 giorni Idoneità per principianti 25/100
PierrunoYT/patch#259 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
platform: macos priority: medium security severity: low tests
Difficoltà 4/5 3-5 giorni Idoneità per principianti 15/100
PierrunoYT/patch#257 ·
I maintainer di solito rispondono entro 1 giorno
-
bug platform: windows priority: medium severity: medium
Difficoltà 4/5 3-5 giorni Idoneità per principianti 30/100
PierrunoYT/patch#242 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
bug priority: high severity: high
Difficoltà 4/5 3-5 giorni Idoneità per principianti 42/100
PierrunoYT/patch#240 ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di PierrunoYT/patch
Issue simili
-
[Feature]: [P3] engine-rs: the package source hash should ignore line endings and untracked filesAperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
maniator/verticopolis#880 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 62/100
siyuan-note/siyuan#20353 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
black-forest-labs/skills#17 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
Albert-Weasker/niubigeo#168 ·
I maintainer di solito rispondono entro 1 giorno