LivelyKernel / LivelyKernel/lively4-server

make parameter passing to shell scripts secure

Open
#7 14 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
JavaScript
Stars
4
Forks
6
PR merge metrics
No merged PRs in 30d

Description

Is there an accepted general way to pass parameters to the scripts securely? I just stripping our \' enough?

``` JS
var repository = req.headers["gitrepository"]
var msg = req.headers["gitcommitmessage"].replace(/'/g,"")
// # TODO...
var cmd = 'cd ' + repository + "; git commit -m '"+ msg +"' -a "
```

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the JavaScript command construction shown in the issue, focusing on the repository and commit-message header values passed to the shell. Read the existing comment thread before choosing a completion criterion; done should mean the accepted parameter-passing approach prevents shell command injection.

Written by the indexing model from the issue text.

Assessment

Tech stack
git, javascript, shell
Domain
backend, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.