-
Notifications
You must be signed in to change notification settings - Fork 172
Expand file tree
/
Copy pathtest_security.py
More file actions
120 lines (101 loc) · 4.62 KB
/
Copy pathtest_security.py
File metadata and controls
120 lines (101 loc) · 4.62 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
import os
import pytest
from frictionless import FrictionlessException, Resource, platform
# General
def test_resource_source_path_error_bad_path_not_safe_absolute():
with pytest.raises(FrictionlessException) as excinfo:
Resource({"name": "name", "path": os.path.abspath("data/table.csv")})
error = excinfo.value.error
reasons = excinfo.value.reasons
assert len(reasons) == 1
assert error.type == "resource-error"
assert error.note == "descriptor is not valid"
assert reasons[0].type == "resource-error"
assert reasons[0].note.count('table.csv" is not safe')
def test_resource_source_path_error_bad_path_not_safe_traversing():
with pytest.raises(FrictionlessException) as excinfo:
Resource(
{
"name": "name",
"path": (
"data/../data/table.csv"
if not platform.type == "windows"
else "data\\..\\table.csv"
),
}
)
error = excinfo.value.error
reasons = excinfo.value.reasons
assert len(reasons) == 1
assert error.type == "resource-error"
assert error.note == "descriptor is not valid"
assert reasons[0].type == "resource-error"
assert reasons[0].note.count('table.csv" is not safe')
def test_resource_dialect_from_path_error_path_not_safe():
dialect = os.path.abspath("data/dialect.json")
with pytest.raises(FrictionlessException) as excinfo:
Resource({"name": "name", "path": "path", "dialect": dialect})
error = excinfo.value.error
reasons = excinfo.value.reasons
assert len(reasons) == 1
assert error.type == "resource-error"
assert error.note == "descriptor is not valid"
assert reasons[0].type == "resource-error"
assert reasons[0].note.count('dialect.json" is not safe')
def test_resource_schema_from_path_error_path_not_safe():
schema = os.path.abspath("data/schema.json")
with pytest.raises(FrictionlessException) as excinfo:
Resource({"name": "name", "path": "path", "schema": schema})
error = excinfo.value.error
reasons = excinfo.value.reasons
assert len(reasons) == 1
assert error.type == "resource-error"
assert error.note == "descriptor is not valid"
assert reasons[0].type == "resource-error"
assert reasons[0].note.count('schema.json" is not safe')
def test_resource_extrapaths_error_bad_path_not_safe_absolute():
extrapath = os.path.abspath("data/chunk2.csv")
with pytest.raises(FrictionlessException) as excinfo:
Resource({"name": "name", "path": "path", "extrapaths": [extrapath]})
error = excinfo.value.error
reasons = excinfo.value.reasons
assert len(reasons) == 1
assert error.type == "resource-error"
assert error.note == "descriptor is not valid"
assert reasons[0].type == "resource-error"
assert reasons[0].note.count('chunk2.csv" is not safe')
@pytest.mark.skipif(platform.type == "windows", reason="Fix on Windows")
def test_resource_extrapaths_error_bad_path_not_safe_traversing():
extrapath = "data/../chunk2.csv"
with pytest.raises(FrictionlessException) as excinfo:
Resource({"name": "name", "path": "path", "extrapaths": [extrapath]})
error = excinfo.value.error
reasons = excinfo.value.reasons
assert len(reasons) == 1
assert error.type == "resource-error"
assert error.note == "descriptor is not valid"
assert reasons[0].type == "resource-error"
assert reasons[0].note.count('chunk2.csv" is not safe')
def test_resource_profiles_error_bad_path_not_safe_absolute():
profile = os.path.abspath("data/profiles/camtrap.json")
with pytest.raises(FrictionlessException) as excinfo:
Resource({"name": "name", "path": "path", "profiles": [profile]})
error = excinfo.value.error
reasons = excinfo.value.reasons
assert len(reasons) == 1
assert error.type == "resource-error"
assert error.note == "descriptor is not valid"
assert reasons[0].type == "resource-error"
assert reasons[0].note.count('camtrap.json" is not safe')
@pytest.mark.skipif(platform.type == "windows", reason="Fix on Windows")
def test_resource_profiles_error_bad_path_not_safe_traversing():
profile = "data/profiles/../profiles/camtrap.json"
with pytest.raises(FrictionlessException) as excinfo:
Resource({"name": "name", "path": "path", "profiles": [profile]})
error = excinfo.value.error
reasons = excinfo.value.reasons
assert len(reasons) == 1
assert error.type == "resource-error"
assert error.note == "descriptor is not valid"
assert reasons[0].type == "resource-error"
assert reasons[0].note.count('camtrap.json" is not safe')