From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from firstgate.proxmox.com (firstgate.proxmox.com [IPv6:2a01:7e0:0:424::9]) by lore.proxmox.com (Postfix) with ESMTPS id 532911FF187 for ; Fri, 19 Dec 2025 12:39:38 +0100 (CET) Received: from firstgate.proxmox.com (localhost [127.0.0.1]) by firstgate.proxmox.com (Proxmox) with ESMTP id 5FB95A32C; Fri, 19 Dec 2025 12:40:27 +0100 (CET) Mime-Version: 1.0 Date: Fri, 19 Dec 2025 12:40:23 +0100 Message-Id: To: "Dominik Csapak" X-Mailer: aerc 0.20.0 References: <20251216153736.363490-1-s.sterz@proxmox.com> <610194d7-e3c1-4720-bbd1-d8c9d18529a2@proxmox.com> In-Reply-To: <610194d7-e3c1-4720-bbd1-d8c9d18529a2@proxmox.com> From: "Shannon Sterz" X-Bm-Milter-Handled: 55990f41-d878-4baa-be0a-ee34c49e34d2 X-Bm-Transport-Timestamp: 1766144410910 X-SPAM-LEVEL: Spam detection results: 0 AWL 0.038 Adjusted score from AWL reputation of From: address BAYES_00 -1.9 Bayes spam probability is 0 to 1% DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment RCVD_IN_VALIDITY_CERTIFIED_BLOCKED 0.001 ADMINISTRATOR NOTICE: The query to Validity was blocked. See https://knowledge.validity.com/hc/en-us/articles/20961730681243 for more information. RCVD_IN_VALIDITY_RPBL_BLOCKED 0.001 ADMINISTRATOR NOTICE: The query to Validity was blocked. See https://knowledge.validity.com/hc/en-us/articles/20961730681243 for more information. RCVD_IN_VALIDITY_SAFE_BLOCKED 0.001 ADMINISTRATOR NOTICE: The query to Validity was blocked. See https://knowledge.validity.com/hc/en-us/articles/20961730681243 for more information. SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record URIBL_BLOCKED 0.001 ADMINISTRATOR NOTICE: The query to URIBL was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block for more information. [lib.rs, proxmox.com] URIBL_SBL_A 0.1 Contains URL's A record listed in the Spamhaus SBL blocklist [188.114.96.3] Subject: Re: [pdm-devel] [PATCH datacenter-manager] ui: wizzard/edit remote: validate remote host and port X-BeenThere: pdm-devel@lists.proxmox.com X-Mailman-Version: 2.1.29 Precedence: list List-Id: Proxmox Datacenter Manager development discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-To: Proxmox Datacenter Manager development discussion Cc: Proxmox Datacenter Manager development discussion Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Errors-To: pdm-devel-bounces@lists.proxmox.com Sender: "pdm-devel" On Fri Dec 19, 2025 at 10:05 AM CET, Dominik Csapak wrote: > s/wizzard/wizard/ in the commit subject > > On 12/16/25 4:37 PM, Shannon Sterz wrote: >> we did not validate these fields before, leading to situations where >> users could enter a value with a schema here (such as "https://") that >> lead to errors down the line. > > could you elaborate what can lead to errors down the line? > > i tried in an unpatched pdm > > http://somehost:someport > and > https://somehost:someport > > and it always behaved like expected? > e.g. in the wizard we simply strip the http/https part (not intuitive, > but ok imho) > > and the web-url behaves like it should, namely a 'web-url' > > and copy/pasting a url from an address bar should work > (the only thing we might want to do is to strip/disallow the fragment there) yeah sorry i kind of hurried this, i'll send a proper fix in a minute. the problem isn't the address/host:port field nor the web url, it's the table of endpoints. we don't validate the input there and the update endpoint doesn't even do server side validation. hence, adding a protocol leads to errors when trying to contact the remote afterward. > > >> >> Signed-off-by: Shannon Sterz >> --- >> we might not want to call it a "Web UI URL" when editing a remote. a url >> indicates that i should be able, for example, to copy the url from my >> browser's address bar and paste it here. this isn't the case. we may >> want to call it ":Port" just like we do in the add dialog. >> >> lib/pdm-api-types/src/lib.rs | 3 +++ >> ui/src/remotes/edit_remote.rs | 2 ++ >> ui/src/remotes/wizard_page_connect.rs | 3 ++- >> 3 files changed, 7 insertions(+), 1 deletion(-) >> >> diff --git a/lib/pdm-api-types/src/lib.rs b/lib/pdm-api-types/src/lib.rs >> index 5daaa3f..d4cc7ef 100644 >> --- a/lib/pdm-api-types/src/lib.rs >> +++ b/lib/pdm-api-types/src/lib.rs >> @@ -137,6 +137,9 @@ pub const HOST_PORT_FORMAT: ApiStringFormat = ApiStringFormat::Pattern(&HOST_POR >> pub const HOST_OPTIONAL_PORT_FORMAT: ApiStringFormat = >> ApiStringFormat::Pattern(&HOST_OPTIONAL_PORT_REGEX); >> pub const HTTP_URL_FORMAT: ApiStringFormat = ApiStringFormat::Pattern(&HTTP_URL_REGEX); >> +pub const HOST_OPTIONAL_PORT_SCHEMA: Schema = StringSchema::new("A host with an optional port.") >> + .format(&HOST_OPTIONAL_PORT_FORMAT) >> + .schema(); >> >> pub const DAILY_DURATION_FORMAT: ApiStringFormat = >> ApiStringFormat::VerifyFn(|s| parse_daily_duration(s).map(drop)); >> diff --git a/ui/src/remotes/edit_remote.rs b/ui/src/remotes/edit_remote.rs >> index 925d11a..1b6b580 100644 >> --- a/ui/src/remotes/edit_remote.rs >> +++ b/ui/src/remotes/edit_remote.rs >> @@ -1,6 +1,7 @@ >> use std::rc::Rc; >> >> use anyhow::Error; >> +use pdm_api_types::HOST_OPTIONAL_PORT_SCHEMA; >> use serde_json::Value; >> use yew::html::IntoEventCallback; >> use yew::virtual_dom::{VComp, VNode}; >> @@ -118,6 +119,7 @@ fn edit_remote_input_panel(_form_ctx: &FormContext, remote_id: &str) -> Html { >> tr!("Web UI URL"), >> Field::new() >> .name("web-url") >> + .schema(&HOST_OPTIONAL_PORT_SCHEMA) >> .placeholder(tr!("Use first endpoint.")), >> ) >> .with_custom_child( >> diff --git a/ui/src/remotes/wizard_page_connect.rs b/ui/src/remotes/wizard_page_connect.rs >> index fb04f60..b850b5c 100644 >> --- a/ui/src/remotes/wizard_page_connect.rs >> +++ b/ui/src/remotes/wizard_page_connect.rs >> @@ -15,7 +15,7 @@ use pwt_macros::builder; >> use proxmox_yew_comp::{KVGrid, KVGridRow, SchemaValidation, WizardPageRenderInfo}; >> >> use pdm_api_types::remotes::{RemoteType, TlsProbeOutcome}; >> -use pdm_api_types::CERT_FINGERPRINT_SHA256_SCHEMA; >> +use pdm_api_types::{CERT_FINGERPRINT_SHA256_SCHEMA, HOST_OPTIONAL_PORT_SCHEMA}; >> use proxmox_acme_api::CertificateInfo; >> >> #[derive(Clone, PartialEq, Properties)] >> @@ -242,6 +242,7 @@ impl Component for PdmWizardPageConnect { >> Field::new() >> .name("hostname") >> .placeholder(tr!(":Port")) >> + .schema(&HOST_OPTIONAL_PORT_SCHEMA) >> .required(true), >> ) >> .with_large_field( >> -- >> 2.47.3 >> >> >> >> _______________________________________________ >> pdm-devel mailing list >> pdm-devel@lists.proxmox.com >> https://lists.proxmox.com/cgi-bin/mailman/listinfo/pdm-devel >> >> _______________________________________________ pdm-devel mailing list pdm-devel@lists.proxmox.com https://lists.proxmox.com/cgi-bin/mailman/listinfo/pdm-devel