Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion ogc/edr/edr_routes.py
Original file line number Diff line number Diff line change
Expand Up @@ -111,7 +111,7 @@ def static_files(self, request: pygeoapi.api.APIRequest, file_path: str) -> Tupl

# Use a safe join to ensure the untrusted path is a subpath of the trusted static directory
safe_path = safe_join(static_path, file_path)
if safe_path is not None and os.path.isfile(safe_path):
if safe_path is not None and os.path.isfile(safe_path) and not os.path.islink(safe_path):
mime_type, _ = mimetypes.guess_type(safe_path)
mime_type = mime_type or "application/octet-stream"
with open(safe_path, "rb") as f:
Expand Down
10 changes: 10 additions & 0 deletions ogc/edr/test/test_edr_routes.py
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@
import pytest
import numpy as np
import tempfile
from unittest.mock import patch
from pygeoapi.api import APIRequest
from http import HTTPStatus
from typing import Dict, List, Any
Expand Down Expand Up @@ -60,6 +61,15 @@
assert status == HTTPStatus.NOT_FOUND


def test_edr_routes_static_files_prevents_following_symlinks():
"""Test the EDR static routes prevents following symlinks."""
request = mock_request()
edr_routes = EdrRoutes(layers=[])
with patch("os.path.islink", returns=True):
_, status, _ = edr_routes.static_files(request, "img/logo.png")
assert status == HTTPStatus.NOT_FOUND


def test_edr_routes_static_files_invalid_path():
"""Test the EDR static routes with an invalid static file path."""
request = mock_request()
Expand Down Expand Up @@ -363,7 +373,7 @@
request = mock_request(single_layer_cube_args)
edr_routes = EdrRoutes(layers=layers)

with pytest.raises(EDRException) as exception_info:

Check warning on line 376 in ogc/edr/test/test_edr_routes.py

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Refactor this exception test to have only one invocation possibly throwing an exception.

See more on https://sonarcloud.io/project/issues?id=creare-com_ogc&issues=AZ9cRkpMldJHH9vRw6sa&open=AZ9cRkpMldJHH9vRw6sa&pullRequest=39
edr_routes.collection_query(
request,
collection_id=layers[0].group,
Expand Down
Loading