mirror of
https://github.com/modrinth/code.git
synced 2026-08-25 00:55:25 +00:00
feat: instance sharing thru shared-instances service (#6569)
* feat: implement instance share page + search_users backend call * feat: invite players modal * feat: use tanstack queries for friends sync across app pages * feat: base shared instances implementation * fix: admon style * feat: impl instance admonitions like server panel * fix: impl get + del usage * feat: support modpack links * feat: invite notif accepting * fix: lint + fmt * feat: impl install to play * feat: impl usage of UpdateToPlayModal * feat: warnings on deleting/disabling shared-instance version content * fix: send instance name * feat: align with backend * feat: shared instances qa * feat: wrong account protection * feat: qa * fix: smartly apply updates * fix: install bug * fix: 401/404 differentiation * fix: fmt+prepr * feat: qa * feat: qa * fix: signing out messes up revoke/deleted checks * feat: qa * fix: fmt + lint * feat: lock content if part of shared instance * fix: lint * [do not merge] feat: rough invite links impl temp (#6666) * fix: wrong cmd * feat: invite page * fix: server-manager DTO mismatch * fix: drop anonymous invite link acceptance * refactor: structured shared-instance unavailable errors * refactor: centralise error presentations * refactor: dedupe shared instance diff detection * fix: logging in reqwests * refactor: move app.vue shared instances into handler * refactor: break up Share.vue * refactor: split up shared instances state outside of instance index * refactor: dedicated shared instances install/update modals + split up page * refactor: centralized managed content * refactor: split up install shared to own runner + shared.rs split up * refactor: dedupe sql for instance metadata enrichmnt * refactor: friends composable + dedupe friends logic across usages * chore: reduced unused code * fix: align with backend * fix: lint * fix: file sha changes * fix: invite links not working due to icon signed * feat: qa * feat: reporting frontend dummy * fix: try use header * remove: file hash field * fix: pin box * feat: malware warning for shared instances * fix: cache rule * feat: config files syncing * feat: disable config sharing * fix: header * fix: use mark ready * fix: dont cause push update for configs * fix: lint * feat: sharing page in settings * feat: move config + change flow * fix: qa * fix: lint prepr * feat: proxy file upload thru shared instances backend * fix: use collapisible * fix: push config * fix: config * feat: swap out sign in modal for new one * fix: report flow * fix: exclude configs.zip from external warnings * fix: nuxi init * fix: config bundle downloading * fix: error notif * fix: polling * fix: qa * fix: lint + prepr * feat: shared instances moderation frontend + hook up report flow * fix: report copy * fix: lint * fix: lint * fix: modrinth ids being undefined * feat: instance quarantining * fix: prepr + fmt * fix: quarantined -> locked terminology * fix: missing endpoint impls + fmt * fix: missing api in build.rs * fix: share tab jittery * fix: fmt *PT bug * fix: invites count as users even if pending * fix: prepr * fix: invite page owner in users list * fix: lint * fix: qa * fix: lint * fix: members stale not clearing * fix: invite use joined_at field * fix: lint * fix: qa --------- Co-authored-by: sychic <47618543+Sychic@users.noreply.github.com>
This commit is contained in:
@@ -13,6 +13,20 @@ use typed_path::{
|
||||
#[repr(transparent)]
|
||||
pub struct SafeRelativeUtf8UnixPathBuf(Utf8UnixPathBuf);
|
||||
|
||||
pub fn is_safe_file_name(file_name: &str) -> bool {
|
||||
if file_name.contains('/') || file_name.contains('\\') {
|
||||
return false;
|
||||
}
|
||||
|
||||
SafeRelativeUtf8UnixPathBuf::try_from(file_name.to_string()).is_ok_and(
|
||||
|path| {
|
||||
path.components()
|
||||
.exactly_one()
|
||||
.is_ok_and(|component| component.is_normal())
|
||||
},
|
||||
)
|
||||
}
|
||||
|
||||
impl<'de> Deserialize<'de> for SafeRelativeUtf8UnixPathBuf {
|
||||
fn deserialize<D: Deserializer<'de>>(
|
||||
deserializer: D,
|
||||
@@ -146,3 +160,32 @@ fn safe_relative_path_deserialization_contract() {
|
||||
.expect_err("Path should be considered invalid");
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn safe_file_name_contract() {
|
||||
let valid_file_names = [
|
||||
"file.txt",
|
||||
"file.name.with.dots.tar.gz",
|
||||
"file..name.jar",
|
||||
"123_456-789.file",
|
||||
];
|
||||
for file_name in valid_file_names {
|
||||
assert!(is_safe_file_name(file_name));
|
||||
}
|
||||
|
||||
let invalid_file_names = [
|
||||
"",
|
||||
".",
|
||||
"..",
|
||||
"../file.txt",
|
||||
"directory/file.txt",
|
||||
r"..\file.txt",
|
||||
r"directory\file.txt",
|
||||
"C:file.txt",
|
||||
"C:/file.txt",
|
||||
"NUL.txt",
|
||||
];
|
||||
for file_name in invalid_file_names {
|
||||
assert!(!is_safe_file_name(file_name));
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user