fix(nextcloud-files): WR-09/IN-02 ungueltige Pfadzeichen sind 400, Vorschau ohne SVG

- WR-09: ein einzelnes UTF-16-Ersatzzeichen in einem Pfadsegment ist 400 invalidPath (bzw.
  invalidName) statt eines URIError mit 500; die Weboberflaeche wiederholt keine 4xx
- IN-02: Vorschaubilder nur als Rasterbild, image/svg+xml wird wie ein fehlendes
  Vorschaubild behandelt (CSP-Sandbox und nosniff bleiben)

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-10-08 22:42:31 +02:00
parent ee05131add
commit 08abfef8e2
5 changed files with 39 additions and 2 deletions
@@ -222,6 +222,19 @@ describe('NextcloudFilesService — preview', () => {
expect(res.headers).toEqual({});
});
it('image/svg+xml als Vorschau -> 404, nichts geschrieben (IN-02)', async () => {
const { service } = setup({
status: 200,
text: '<svg xmlns="http://www.w3.org/2000/svg"><script>alert(1)</script></svg>',
headers: { 'content-type': 'image/svg+xml' },
});
const res = new FakeRes();
await expect(service.preview(res as never, 't1', 'u1', '42')).rejects.toMatchObject({
response: { code: 'notFound' },
});
expect(res.written).toHaveLength(0);
});
it('image/png wird gestreamt; mit Version einen Tag gecacht, ohne eine Stunde', async () => {
const png = { status: 200, text: 'PNG', headers: { 'content-type': 'image/png' } };
const withV = setup(png);
@@ -134,7 +134,12 @@ export class NextcloudFilesService {
'x-content-type-options': 'nosniff',
'content-security-policy': "default-src 'none'; sandbox",
},
accept: (contentType) => contentType.toLowerCase().startsWith('image/'),
// Nur Rasterbilder (IN-02): SVG kann Skript enthalten; CSP-Sandbox und nosniff entschaerfen
// das zwar, aber eine Vorschau braucht kein SVG (Nextcloud rendert Vorschauen als PNG/JPEG).
accept: (contentType) => {
const type = contentType.toLowerCase();
return type.startsWith('image/') && !type.startsWith('image/svg');
},
maxBytes: PREVIEW_MAX_BYTES,
onExpired: () => this.account.markExpired(tenantId, userId),
});
@@ -78,6 +78,16 @@ describe('buildNcUrl / encodeSegments', () => {
});
describe('Pfade', () => {
it('ein einzelnes UTF-16-Ersatzzeichen ist invalidPath statt eines URIError (WR-09)', () => {
expect(codeOf(() => validateSegment('a\uD800b'))).toBe('invalidPath');
expect(codeOf(() => validateSegment('\uDC00'))).toBe('invalidPath');
expect(codeOf(() => parseUserPath('/ok/\uD83D'))).toBe('invalidPath');
expect(codeOf(() => validateNewName('x\uDFFF'))).toBe('invalidName');
// ein vollstaendiges Paar (Emoji) bleibt erlaubt
expect(validateSegment('Foto \uD83D\uDE00.jpg')).toBe('Foto 😀.jpg');
expect(encodeSegments(['😀'])).toBe('%F0%9F%98%80');
});
it('parseUserPath: Wurzel und normale Pfade', () => {
expect(parseUserPath('')).toEqual([]);
expect(parseUserPath('/')).toEqual([]);
@@ -104,9 +104,14 @@ const MAX_SEGMENT_BYTES = 255;
const MAX_SEGMENTS = 100;
const MAX_PATH_CHARS = 4096;
/** Ein einzelnes UTF-16-Ersatzzeichen ohne Partner (z. B. `"\uD800"` aus einem JSON-Koerper). */
const LONE_SURROGATE = /[\uD800-\uDBFF](?![\uDC00-\uDFFF])|(?<![\uD800-\uDBFF])[\uDC00-\uDFFF]/;
/**
* Ein einzelnes Pfadsegment pruefen (D-H): nicht leer, nicht `.`/`..`, kein
* `/`, `\`, NUL oder Steuerzeichen, hoechstens 255 UTF-8-Byte.
* `/`, `\`, NUL oder Steuerzeichen, kein einzelnes Ersatzzeichen (WR-09: daran
* scheitert `encodeURIComponent` mit einem URIError, der sonst als 500 endete),
* hoechstens 255 UTF-8-Byte.
*/
export function validateSegment(segment: string): string {
if (
@@ -116,6 +121,7 @@ export function validateSegment(segment: string): string {
segment === '..' ||
// biome-ignore lint/suspicious/noControlCharactersInRegex: Steuerzeichen sind hier gerade der Prueffall
/[\\/\u0000-\u001f\u007f]/.test(segment) ||
LONE_SURROGATE.test(segment) ||
Buffer.byteLength(segment, 'utf8') > MAX_SEGMENT_BYTES
) {
throw ncErrorDefault('invalidPath');