Files
mediamtx/internal/externalcmd/cmd_test.go
T
Alessandro RosandGitHub e6c20adf28 prevent code injection in case of MTX_QUERY in hooks (#5707)
When MTX_QUERY is used explicitly in hooks, for instance "curl
http://something/?$MTX_QUERY", it can be used to inject arbitrary
commands. MTX_QUERY is now url-encoded to prevent any abuse regardless
of the configuration.
2026-04-29 22:59:40 +02:00

47 lines
837 B
Go

//go:build !windows
package externalcmd
import (
"os"
"path/filepath"
"testing"
"time"
"github.com/stretchr/testify/require"
)
func TestCmdRunExpandAfterSplit(t *testing.T) {
// if os.Expand runs before shellquote.Split, a variable value containing a
// single quote produces unbalanced quotes that cause shellquote.Split to fail.
p := &Pool{}
p.Initialize()
out := filepath.Join(t.TempDir(), "out")
cmd := &Cmd{
Pool: p,
Cmdstr: "sh -c 'echo \"$MY_VAR\" > " + out + "'",
Env: Environment{
"MY_VAR": "it's",
},
}
cmd.Start()
poolClosed := make(chan struct{})
go func() {
p.Close()
close(poolClosed)
}()
select {
case <-poolClosed:
case <-time.After(10 * time.Second):
t.Fatal("timeout")
}
byts, err := os.ReadFile(out)
require.NoError(t, err)
require.Equal(t, "it's\n", string(byts))
}