Clean up wrong vanity rules

This commit is contained in:
2026-09-13 10:28:33 +02:00
parent 1c39d1169a
commit 594d5d0150
6 changed files with 145 additions and 20 deletions
+6 -12
View File
@@ -13,15 +13,6 @@ import (
// could be mistaken for a path element, a dotfile or a traversal is excluded.
var vanityRe = regexp.MustCompile(`^[a-z0-9][a-z0-9._-]{1,63}$`)
// reserved names would shadow a route or a well-known file if they were ever
// allowed into the object namespace.
var reserved = map[string]bool{
"d": true, "i": true, "api": true, "static": true, "admin": true,
"login": true, "logout": true, "upload": true,
"favicon.ico": true, "robots.txt": true, "index.html": true,
"sitemap.xml": true, "tokens.json": true, "objects": true,
}
var ErrBadID = errors.New("invalid name")
// CleanID validates an id arriving from a URL or from a vanity request and
@@ -30,6 +21,12 @@ var ErrBadID = errors.New("invalid name")
//
// This is the *only* function permitted to turn caller input into a path
// element; every filesystem path in this package is built from its output.
//
// There is deliberately no list of reserved words. An id appears only under
// /d/ and /i/ in a URL, and only as a directory of its own inside the objects
// directory on disk, so no spelling of it can shadow a route or a file of
// ours: "favicon.png" and "admin" are ordinary names and refusing them would
// be theatre.
func CleanID(s string) (string, error) {
s = strings.ToLower(strings.TrimSpace(s))
if !vanityRe.MatchString(s) {
@@ -40,9 +37,6 @@ func CleanID(s string) (string, error) {
if strings.Contains(s, "..") || strings.HasSuffix(s, ".") {
return "", ErrBadID
}
if reserved[s] {
return "", ErrBadID
}
return s, nil
}