angular / angular/angular-cli

Generate command should respect file name safety conventions.

Offen
#25,282 1 Kommentar 1 Reaktion 0 zugewiesene Personen Auf GitHub ansehen
area: @angular-devkit/schematics freq1: low severity2: inconvenient type: bug/fix
Vorherrschende Sprache
TypeScript
Sterne
27k
Forks
11.8k
Ø Merge
14 Std. 23 Min.
Gemergte PRs (30 T.)
162

Beschreibung

### Command

generate

### Is this a regression?

- [ ] Yes, this behavior used to work in the previous version

### The previous version in which this bug was not present was

_No response_

### Description

Long story short is that the Angular CLI generate or g command is capable of doing some illegal and difficult to reverse file operations.

Longer version: I was going to create a component this morning to make building PrimeNG p-tables simpler and more dynamic. At the time I started, what I was thinking of was specific to a set of tables I intended to use in an administrative context, so I navigated to something like /src/modules/sales/costing-tool/components/templates and typed "ng g c admin-table". 

Before I hit enter, I thought about it and decided that rather than creating a module and specific use component that I'd rather make a general use component for generating p-tables dynamically & that it belonged in a shared module rather than a feature module. I thought I'd already deleted the CLI command out of the terminal so without looking I typed cd.. and hit enter. Which was the beginning of a 2+ hour headache that ended up costing me 2 days of work and which potentially could've cost me all the work I've done since May 5. 

So the command I effectively entered was "ng g c admin-tablecd..", and what happened is that the CLI was able to somehow dodge the OS level naming safety conventions & it created a folder named admin-tablecd.., which caused there to be an unresolvable reference in my project structure and made it unloadable and unbuildable. And there was nothing I could do to delete the offending folder. I tried deleting it through the UI, using DOS commands, using WSL commands including rmdir with the -rf flag, nothing would get rid of it, even after a reboot. I had just about resolved myself to having to clone my latest remote to a new local repo which would've set me back to the 5th when I tried rmdir with the "\\?\c:\path\to\bad\directory" syntax which finally worked.

I think that optimally the generate command should respect naming safety conventions, or minimally provide a complimentary command to remove generated components.

### Minimal Reproduction

Via the CLI, generate a component with a name that ends in a directory traversal operator, i.e. new-componentcd..

### Exception or Error

```text
The system cannot find the file or directory specified
```

### Your Environment

```text
Angular:

Package Version
------------------------------------------------------
@angular-devkit/architect 0.1502.4
@angular-devkit/core 15.2.4
@angular-devkit/schematics 15.2.4
@schematics/angular 15.2.4
```

### Anything else relevant?

Can't think of anything.

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Beginne am Einstiegspunkt des Angular CLI-Befehls `generate` und reproduziere den gemeldeten Komponentennamen, der mit `cd..` endet. Verfolge, wie dieser Name zu einem Pfad wird, und überprüfe anschließend, dass unsichere Namen behandelt werden, ohne ein nicht auflösbares Verzeichnis zu erstellen; das Issue ist erledigt, wenn die Minimalreproduktion den problematischen Pfad nicht mehr erzeugt.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
angular, typescript
Bereich
cli
Issue-Typ
Bug
Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Aktivitätsstatus
Veraltet
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
35/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.