google / google/adk-python

adk web GET/DELETE test endpoints skip the create_test path sanitiser

Ouverte
#7,033 5 commentaires 0 réactions 1 personne assignée Réclamée par @surajksharma07 Voir sur GitHub
request clarification web
Langage dominant
Python
Étoiles
21.5k
Forks
4k
Merge moyen
1 j 22 h
PR mergées (30 j)
31

Description

## Expected Behavior

`create_test` strips directories from `test_name` with `os.path.basename` so a name cannot leave the app `tests/` folder.

GET, DELETE, and rebuild of a single test should use the same rule.

## Actual Behavior

On `main` @ `b018062`, only `create_test` calls `os.path.basename`. `delete_test`, `get_test_content`, and `rebuild_app_tests` join `test_name` as given.

A percent-encoded path segment `../outside.json` (`%2e%2e%2foutside.json`) on DELETE/GET is joined onto `tests/` and can read or remove a JSON file in the agent directory, outside `tests/`.

`rebuild?test_name=../outside.json` does the same for the rebuild path.

This is the local `adk web` server. It is unauthenticated. Default bind is loopback. It still matters when `--host 0.0.0.0` is used, or when anything else can hit those routes.

## Steps to Reproduce

1. `adk web` (or the TestClient in `tests/unittests/cli/test_adk_web_server_tests.py`)
2. Put `outside.json` in the agent directory, not in `tests/`
3. `DELETE /dev/apps//tests/%2e%2e%2foutside.json`
4. On current `main`, that file is removed. After sanitising with `basename`, the request 404s and the file stays.

I can send a PR that shares one helper with `create_test` and adds those cases to `test_adk_web_server_tests.py`.

Guide de contribution

Ouvrir le guide de contribution

Évaluation

Cette issue n'a pas encore été évaluée.

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.