fix: 安全加固(VUL-001~009)+ 构建版本注入 + 死代码清理 #2

Merged
sun merged 12 commits from develop into main 2026-08-27 11:01:48 +08:00
2 changed files with 10 additions and 2 deletions
Showing only changes of commit 91b0c8acee - Show all commits
+5 -1
View File
@@ -6,6 +6,7 @@ import (
"encoding/hex"
"fmt"
"log"
"strings"
"time"
"github.com/volcano-tts/tts-api/common"
@@ -94,10 +95,13 @@ func Synthesis(
if resp.StatusCode != 200 {
rawBody := ReadErrorBody(resp.Body)
// rawBody 来自上游响应体,可能是攻击者控制的恶意内容(例如包含
// \n 伪造日志行)。转义后再嵌入错误消息。
safeBody := strings.NewReplacer("\n", "\\n", "\r", "\\r").Replace(rawBody)
mtr.UpstreamFinished(opts.Speaker, opts.Model, opts.Format, fmt.Sprintf("http_%d", resp.StatusCode), time.Since(started), 0, 0, 0, resp.StatusCode)
return nil, &UpstreamError{
Code: resp.StatusCode,
Message: fmt.Sprintf("upstream http %d: %s", resp.StatusCode, rawBody),
Message: fmt.Sprintf("upstream http %d: %s", resp.StatusCode, safeBody),
Stage: "http",
}
}
+5 -1
View File
@@ -3,6 +3,7 @@ package middleware
import (
"log"
"net/http"
"strings"
"time"
)
@@ -23,6 +24,9 @@ func Logger(next http.Handler) http.Handler {
next.ServeHTTP(rec, r)
duration := time.Since(start)
log.Printf("%s %s %s %d %v", r.Method, r.RequestURI, r.RemoteAddr, rec.statusCode, duration)
// r.RequestURI 是未经解析的原始请求行,攻击者可在 URL 中注入
// \n / \r 伪造日志行。转义为可见字符后再记录。
uri := strings.NewReplacer("\n", "\\n", "\r", "\\r").Replace(r.RequestURI)
log.Printf("%s %s %s %d %v", r.Method, uri, r.RemoteAddr, rec.statusCode, duration)
})
}