diff --git a/adapter/volcano/synthesis.go b/adapter/volcano/synthesis.go index 5a461da..0c90237 100644 --- a/adapter/volcano/synthesis.go +++ b/adapter/volcano/synthesis.go @@ -6,6 +6,7 @@ import ( "encoding/hex" "fmt" "log" + "strings" "time" "github.com/volcano-tts/tts-api/common" @@ -94,10 +95,13 @@ func Synthesis( if resp.StatusCode != 200 { rawBody := ReadErrorBody(resp.Body) + // rawBody 来自上游响应体,可能是攻击者控制的恶意内容(例如包含 + // \n 伪造日志行)。转义后再嵌入错误消息。 + safeBody := strings.NewReplacer("\n", "\\n", "\r", "\\r").Replace(rawBody) mtr.UpstreamFinished(opts.Speaker, opts.Model, opts.Format, fmt.Sprintf("http_%d", resp.StatusCode), time.Since(started), 0, 0, 0, resp.StatusCode) return nil, &UpstreamError{ Code: resp.StatusCode, - Message: fmt.Sprintf("upstream http %d: %s", resp.StatusCode, rawBody), + Message: fmt.Sprintf("upstream http %d: %s", resp.StatusCode, safeBody), Stage: "http", } } diff --git a/middleware/logger.go b/middleware/logger.go index ea53db2..7863b3c 100644 --- a/middleware/logger.go +++ b/middleware/logger.go @@ -3,6 +3,7 @@ package middleware import ( "log" "net/http" + "strings" "time" ) @@ -23,6 +24,9 @@ func Logger(next http.Handler) http.Handler { next.ServeHTTP(rec, r) duration := time.Since(start) - log.Printf("%s %s %s %d %v", r.Method, r.RequestURI, r.RemoteAddr, rec.statusCode, duration) + // r.RequestURI 是未经解析的原始请求行,攻击者可在 URL 中注入 + // \n / \r 伪造日志行。转义为可见字符后再记录。 + uri := strings.NewReplacer("\n", "\\n", "\r", "\\r").Replace(r.RequestURI) + log.Printf("%s %s %s %d %v", r.Method, uri, r.RemoteAddr, rec.statusCode, duration) }) }