OpenListTeam / OpenListTeam/OpenList
[BUG] 文件分享时有可能暴露文件真实物理路径
Nobody has claimed this yet.
- Dominant language
- Go
- Stars
- 24.7k
- Forks
- 2.3k
- Avg merge
- 1d 20h
- Merged PRs (30d)
- 36
Description
请确认以下事项
-
我已确认阅读并同意 AGPL-3.0 第15条 。
本程序不提供任何明示或暗示的担保,使用风险由您自行承担。 -
我已确认阅读并同意 AGPL-3.0 第16条 。
无论何种情况,版权持有人或其他分发者均不对使用本程序所造成的任何损失承担责任。 -
我确认我的描述清晰,语法礼貌,能帮助开发者快速定位问题,并符合社区规则。
-
我已确认阅读了OpenList文档。
-
我已确认没有重复的问题或讨论。
-
我已确认是
OpenList的问题,而不是其他原因(例如 网络 ,依赖或操作)。 -
我认为此问题必须由
OpenList处理,而非第三方。 -
我已确认这个问题在最新版本中没有被修复。
-
我没有阅读这个清单,只是闭眼选中了所有的复选框,请关闭这个 Issue
OpenList 版本(必填)
v4.1.10
使用的存储驱动(必填)
物理储存
问题描述(必填)
单文件分享时,如果在链接后加入任意字符会暴露文件真实物理路径
例如:对于单文件分享链接:/@s/ivcInKg8/
在尾部加上任意字符xx变为/@s/ivcInKg8/xx
访问时返回错误页面:failed to get obj: stat /xx/share/apk/apkcombo-installer.apk/xx: not a directory
日志(必填)
无
配置文件内容(必填)
配置文件中未找到相关设置
复现链接(可选)
No response
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reproducing the single-file share request and the modified URL described in the issue, then trace the handler that produces the failed to get obj error. No source file or test is named, so locate the share-path and physical-storage handling first. Done means appended path text no longer reveals the real physical path in the error response.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- go
- Domain
- backend, security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 52/100