fix: 安全加固(VUL-001~009)+ 构建版本注入 + 死代码清理 #2
@@ -6,6 +6,7 @@ import (
|
||||
"encoding/hex"
|
||||
"fmt"
|
||||
"log"
|
||||
"strings"
|
||||
"time"
|
||||
|
||||
"github.com/volcano-tts/tts-api/common"
|
||||
@@ -94,10 +95,13 @@ func Synthesis(
|
||||
|
||||
if resp.StatusCode != 200 {
|
||||
rawBody := ReadErrorBody(resp.Body)
|
||||
// rawBody 来自上游响应体,可能是攻击者控制的恶意内容(例如包含
|
||||
// \n 伪造日志行)。转义后再嵌入错误消息。
|
||||
safeBody := strings.NewReplacer("\n", "\\n", "\r", "\\r").Replace(rawBody)
|
||||
mtr.UpstreamFinished(opts.Speaker, opts.Model, opts.Format, fmt.Sprintf("http_%d", resp.StatusCode), time.Since(started), 0, 0, 0, resp.StatusCode)
|
||||
return nil, &UpstreamError{
|
||||
Code: resp.StatusCode,
|
||||
Message: fmt.Sprintf("upstream http %d: %s", resp.StatusCode, rawBody),
|
||||
Message: fmt.Sprintf("upstream http %d: %s", resp.StatusCode, safeBody),
|
||||
Stage: "http",
|
||||
}
|
||||
}
|
||||
|
||||
@@ -3,6 +3,7 @@ package middleware
|
||||
import (
|
||||
"log"
|
||||
"net/http"
|
||||
"strings"
|
||||
"time"
|
||||
)
|
||||
|
||||
@@ -23,6 +24,9 @@ func Logger(next http.Handler) http.Handler {
|
||||
next.ServeHTTP(rec, r)
|
||||
duration := time.Since(start)
|
||||
|
||||
log.Printf("%s %s %s %d %v", r.Method, r.RequestURI, r.RemoteAddr, rec.statusCode, duration)
|
||||
// r.RequestURI 是未经解析的原始请求行,攻击者可在 URL 中注入
|
||||
// \n / \r 伪造日志行。转义为可见字符后再记录。
|
||||
uri := strings.NewReplacer("\n", "\\n", "\r", "\\r").Replace(r.RequestURI)
|
||||
log.Printf("%s %s %s %d %v", r.Method, uri, r.RemoteAddr, rec.statusCode, duration)
|
||||
})
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user