Skip to content

Sanitize URL before sending it to logs.#34

Open
koscelansky wants to merge 1 commit intomasterfrom
sanitize-url
Open

Sanitize URL before sending it to logs.#34
koscelansky wants to merge 1 commit intomasterfrom
sanitize-url

Conversation

@koscelansky
Copy link
Collaborator

No description provided.

@lukas-manduch
Copy link
Collaborator

What are we going to do about this PR? Can I merge it?

@koscelansky
Copy link
Collaborator Author

I don't know. You said to me 1y or maybe two ago. That you do not like the solution and you will think about better one. I guess it never happened. The idea here is that security advisor is complaining (quite rightly), that malicious agent can break the logs by adding whitespace to url.

This is one way of dealing with it.

@koscelansky
Copy link
Collaborator Author

Found it. It should be https://pkg.go.dev/net/url#URL.ESCAPEDPATH.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

Comments