Clean up wrong vanity rules

This commit is contained in:
2026-09-13 10:28:33 +02:00
parent 1c39d1169a
commit 594d5d0150
6 changed files with 145 additions and 20 deletions
+13 -4
View File
@@ -23,12 +23,11 @@ func TestCleanID(t *testing.T) {
}
}
// Anything that could escape the objects directory, shadow a route, or
// collide on a case-insensitive filesystem must be refused.
// Anything that could escape the objects directory or collide on a
// case-insensitive filesystem must be refused.
invalid := []string{
"", "a", ".", "..", "...", "../etc/passwd", "a/b", `a\b`, "/abs",
".hidden", "a..b", "trailing.", "api", "static", "d", "i",
"robots.txt", "tokens.json", "with space", "emoji-🙂",
".hidden", "a..b", "trailing.", "d", "i", "with space", "emoji-🙂",
strings.Repeat("x", 65), "a\x00b", "a\nb",
}
for _, in := range invalid {
@@ -36,6 +35,16 @@ func TestCleanID(t *testing.T) {
t.Errorf("CleanID(%q) = %q, want an error", in, got)
}
}
// Names that merely look like something of ours are ordinary names: an id
// lives under /d/ and /i/ and in a directory of its own, so it shadows
// nothing. Refusing these would take names from people for no benefit.
for _, in := range []string{"api", "static", "admin", "upload", "login",
"robots.txt", "tokens.json", "favicon.png", "index.html"} {
if got, err := CleanID(in); err != nil || got != in {
t.Errorf("CleanID(%q) = %q, %v; want it accepted unchanged", in, got, err)
}
}
}
func TestCleanIDAcceptsGeneratedUUIDs(t *testing.T) {