OpenListTeam / OpenListTeam/OpenList

[BUG] 文件分享时有可能暴露文件真实物理路径

Open
#2,153 5 comments 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

bug
Dominant language
Go
Stars
24.7k
Forks
2.3k
Avg merge
1d 20h
Merged PRs (30d)
36

Description

请确认以下事项
  • 我已确认阅读并同意 AGPL-3.0 第15条
    本程序不提供任何明示或暗示的担保,使用风险由您自行承担。

  • 我已确认阅读并同意 AGPL-3.0 第16条
    无论何种情况,版权持有人或其他分发者均不对使用本程序所造成的任何损失承担责任。

  • 我确认我的描述清晰,语法礼貌,能帮助开发者快速定位问题,并符合社区规则。

  • 我已确认阅读了OpenList文档

  • 我已确认没有重复的问题或讨论。

  • 我已确认是OpenList的问题,而不是其他原因(例如 网络依赖操作)。

  • 我认为此问题必须由OpenList处理,而非第三方。

  • 我已确认这个问题在最新版本中没有被修复。

  • 我没有阅读这个清单,只是闭眼选中了所有的复选框,请关闭这个 Issue

OpenList 版本(必填)

v4.1.10

使用的存储驱动(必填)

物理储存

问题描述(必填)

单文件分享时,如果在链接后加入任意字符会暴露文件真实物理路径
例如:对于单文件分享链接:/@s/ivcInKg8/
在尾部加上任意字符xx变为/@s/ivcInKg8/xx
访问时返回错误页面:failed to get obj: stat /xx/share/apk/apkcombo-installer.apk/xx: not a directory

Image

日志(必填)

配置文件内容(必填)

配置文件中未找到相关设置

复现链接(可选)

No response

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reproducing the single-file share request and the modified URL described in the issue, then trace the handler that produces the failed to get obj error. No source file or test is named, so locate the share-path and physical-storage handling first. Done means appended path text no longer reveals the real physical path in the error response.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
backend, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
52/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.