fix: A11 + A18 — path traversal avatar et XSS/flags sur la vue publique (v7.3.2)
FlowDeck CI / docker (push) Successful in 1m44s
FlowDeck CI / lint (push) Successful in 1m49s
FlowDeck CI / test (push) Successful in 22m0s

- A11 : `GET /api/settings/avatar/{filename:path}` → `resolve()` + `relative_to()` (motif de `serve_uploaded_file`), 403 hors de `/data/avatars`
- A18 : `GET /workspace/public/{id}` → 404 HTML explicite pour `permission_type` restricted/private, `html.escape` sur le nom, l'icône et les titres de lignes (le f-string HTML ne passe pas par Jinja2)
- `tests/test_audit_p0_fixes.py` : 3 tests de non-régression (traversal, échappement, hidden restricted)
- ROADMAP A11/A18 cochés · CHANGELOG/WORKLOAD/VERSION → 7.3.2 · suite **1019/1019** · `ruff check app tests` OK
This commit is contained in:
2026-09-30 22:40:34 -04:00
parent 69a0aceba6
commit 8ab6569974
8 changed files with 84 additions and 11 deletions
+36
View File
@@ -0,0 +1,36 @@
"""Non-régression de l'audit sécurité 2026-09-30 — A11 (traversal) et A18 (XSS public)."""
from conftest import anon
def test_avatar_path_traversal_denied(client):
"""A11 : `:path` accepte les `/` — la lecture doit rester dans /data/avatars."""
r = client.get("/api/settings/avatar/..%2f..%2fetc%2fpasswd")
assert r.status_code in (403, 404), r.status_code
def test_public_view_escapes_output(client):
"""A18 : titre de base et titre de ligne interpolés dans un f-string HTML."""
cid = client.post("/db/api", json={"name": "<script>alert(1)</script>"}).json()["id"]
client.post(f"/db/{cid}/pages/api", json={"title": "<img src=x onerror=alert(1)>"})
anon(client)
r = client.get(f"/workspace/public/{cid}")
assert r.status_code == 200
assert "<script>alert(1)" not in r.text
assert "&lt;script&gt;" in r.text
assert "<img src=x" not in r.text
def test_public_view_hides_restricted_collection(client):
"""A18 : `permission_type` restricted/private → 404 (pas de fuite)."""
cid = client.post("/db/api", json={"name": "Internal"}).json()["id"]
from app.db import get_conn
with get_conn() as conn:
conn.execute("UPDATE collections SET permission_type='restricted' WHERE id=?", (cid,))
conn.commit()
anon(client)
r = client.get(f"/workspace/public/{cid}")
assert r.status_code == 404
assert "Internal" not in r.text