aboutsummaryrefslogtreecommitdiffstats
path: root/modules/git/command.go
diff options
context:
space:
mode:
authorLunny Xiao <xiaolunwen@gmail.com>2022-03-27 19:54:09 +0800
committerGitHub <noreply@github.com>2022-03-27 12:54:09 +0100
commitc29fbc6d2316b8b42b37c3b379eb2297f7a93aeb (patch)
tree4583000b6e93fd6481bd013011cd58e3272aefad /modules/git/command.go
parent41b60d94db2b51ec4554b09e51ec6523e5cdfea4 (diff)
downloadgitea-c29fbc6d2316b8b42b37c3b379eb2297f7a93aeb.tar.gz
gitea-c29fbc6d2316b8b42b37c3b379eb2297f7a93aeb.zip
Hide sensitive content on admin panel progress monitor (#19218)
Sanitize urls within git process descriptions. Co-authored-by: wxiaoguang <wxiaoguang@gmail.com> Co-authored-by: Andrew Thornton <art27@cantab.net>
Diffstat (limited to 'modules/git/command.go')
-rw-r--r--modules/git/command.go17
1 files changed, 16 insertions, 1 deletions
diff --git a/modules/git/command.go b/modules/git/command.go
index ac26ef8689..8199498a2b 100644
--- a/modules/git/command.go
+++ b/modules/git/command.go
@@ -17,6 +17,7 @@ import (
"code.gitea.io/gitea/modules/log"
"code.gitea.io/gitea/modules/process"
+ "code.gitea.io/gitea/modules/util"
)
var (
@@ -142,7 +143,21 @@ func (c *Command) RunWithContext(rc *RunContext) error {
desc := c.desc
if desc == "" {
- desc = fmt.Sprintf("%s %s [repo_path: %s]", c.name, strings.Join(c.args[c.globalArgsLength:], " "), rc.Dir)
+ args := c.args[c.globalArgsLength:]
+ var argSensitiveURLIndexes []int
+ for i, arg := range c.args {
+ if strings.Contains(arg, "://") && strings.Contains(arg, "@") {
+ argSensitiveURLIndexes = append(argSensitiveURLIndexes, i)
+ }
+ }
+ if len(argSensitiveURLIndexes) > 0 {
+ args = make([]string, len(c.args))
+ copy(args, c.args)
+ for _, urlArgIndex := range argSensitiveURLIndexes {
+ args[urlArgIndex] = util.NewStringURLSanitizer(args[urlArgIndex], true).Replace(args[urlArgIndex])
+ }
+ }
+ desc = fmt.Sprintf("%s %s [repo_path: %s]", c.name, strings.Join(args, " "), rc.Dir)
}
ctx, cancel, finished := process.GetManager().AddContextTimeout(c.parentContext, rc.Timeout, desc)