From 2b11d338e059275ccb074c0f08a0019cac6b78ea Mon Sep 17 00:00:00 2001 From: jack <jack.su@pollex.com.tw> Date: 星期二, 12 九月 2023 15:49:10 +0800 Subject: [PATCH] [UPDATE] 解決弱點Unlogged security exception --- PAMapp/shared/services/httpClient.ts | 26 ++++++++++++++++++++++---- 1 files changed, 22 insertions(+), 4 deletions(-) diff --git a/PAMapp/shared/services/httpClient.ts b/PAMapp/shared/services/httpClient.ts index e704513..db17491 100644 --- a/PAMapp/shared/services/httpClient.ts +++ b/PAMapp/shared/services/httpClient.ts @@ -10,10 +10,28 @@ '/eService/authenticate', '/login/validate/get_img_code', '/login/validate/verify_img_code', + '/api/access_analysis/insert' ]; +const BASE_URL = process.env.BASE_URL!; + +function sanitizeBaseUrl(baseUrl: string): string { + const pattern = /^(https?:\/\/).+/i; + if (!pattern.test(baseUrl)) { + throw new Error('Invalid BASE_URL'); + } + const cleanedBaseUrl = cleanUrl(baseUrl); + return cleanedBaseUrl; +} + +function cleanUrl(url: string): string { + const cleanedUrl = url.replace(/[^a-zA-Z0-9:/._-]/g, ''); + return cleanedUrl; +} + + export const http = axios.create({ - baseURL: process.env.BASE_URL, + baseURL: sanitizeBaseUrl(BASE_URL), withCredentials: true }); @@ -48,7 +66,8 @@ function addHttpHeader(config: AxiosRequestConfig): void { config.headers = { - Authorization: 'Bearer ' + localStorage.getItem('id_token') + Authorization: 'Bearer ' + localStorage.getItem('id_token'), + 'content-type': 'application/json' } } @@ -66,9 +85,8 @@ function showErrorMessageBox(error: any): void { setTimeout(() => { - console.log('errorerrorerror', error.config); // NOTE: 甇斤 HOT FIX 憿批��憭望������暹��� dialog [Tomas, 2022/7/20 14:21] - if(error.config.url.includes('api/eService/authenticate')) return; + if(error.config.url.includes('/eService/authenticate')) return; if (error.config.url.includes('/otp/sendOtp')) { messageBoxService.showErrorMessage('', error); return -- Gitblit v1.8.0