google / google/adk-python

adk web GET/DELETE test endpoints skip the create_test path sanitiser

Abierto
#7,033 5 comentarios 0 reacciones 1 asignado Reclamado por @surajksharma07 Ver en GitHub
request clarification web
Lenguaje dominante
Python
Estrellas
21.5k
Forks
4k
Merge medio
1 d 14 h
PR fusionados (30 d)
37

Descripción

## Expected Behavior

`create_test` strips directories from `test_name` with `os.path.basename` so a name cannot leave the app `tests/` folder.

GET, DELETE, and rebuild of a single test should use the same rule.

## Actual Behavior

On `main` @ `b018062`, only `create_test` calls `os.path.basename`. `delete_test`, `get_test_content`, and `rebuild_app_tests` join `test_name` as given.

A percent-encoded path segment `../outside.json` (`%2e%2e%2foutside.json`) on DELETE/GET is joined onto `tests/` and can read or remove a JSON file in the agent directory, outside `tests/`.

`rebuild?test_name=../outside.json` does the same for the rebuild path.

This is the local `adk web` server. It is unauthenticated. Default bind is loopback. It still matters when `--host 0.0.0.0` is used, or when anything else can hit those routes.

## Steps to Reproduce

1. `adk web` (or the TestClient in `tests/unittests/cli/test_adk_web_server_tests.py`)
2. Put `outside.json` in the agent directory, not in `tests/`
3. `DELETE /dev/apps//tests/%2e%2e%2foutside.json`
4. On current `main`, that file is removed. After sanitising with `basename`, the request 404s and the file stays.

I can send a PR that shares one helper with `create_test` and adds those cases to `test_adk_web_server_tests.py`.

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.