mirror of
https://github.com/louislam/dockge.git
synced 2025-02-26 13:35:57 +00:00
Compare commits
3 commits
035782c5ab
...
f63718b1d4
Author | SHA1 | Date | |
---|---|---|---|
|
f63718b1d4 | ||
|
673fb8f8dd | ||
|
52ea324129 |
1 changed files with 3 additions and 0 deletions
|
@ -294,11 +294,14 @@ export class MainTerminal extends InteractiveTerminal {
|
||||||
// Check if the command is allowed
|
// Check if the command is allowed
|
||||||
const cmdParts = input.split(" ");
|
const cmdParts = input.split(" ");
|
||||||
const executable = cmdParts[0].trim();
|
const executable = cmdParts[0].trim();
|
||||||
|
const knownOperators = ["||", "&", ";"];
|
||||||
log.debug("console", "Executable: " + executable);
|
log.debug("console", "Executable: " + executable);
|
||||||
log.debug("console", "Executable length: " + executable.length);
|
log.debug("console", "Executable length: " + executable.length);
|
||||||
|
|
||||||
if (!allowedCommandList.includes(executable)) {
|
if (!allowedCommandList.includes(executable)) {
|
||||||
throw new Error("Command not allowed.");
|
throw new Error("Command not allowed.");
|
||||||
|
} else if (knownOperators.some(operator => input.includes(operator))) {
|
||||||
|
throw new Error("Control operators are not allowed.");
|
||||||
}
|
}
|
||||||
super.write(input);
|
super.write(input);
|
||||||
}
|
}
|
||||||
|
|
Loading…
Add table
Reference in a new issue