From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from firstgate.proxmox.com (firstgate.proxmox.com [212.224.123.68]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by lists.proxmox.com (Postfix) with ESMTPS id 27EFF73A7E for ; Fri, 16 Apr 2021 14:41:27 +0200 (CEST) Received: from firstgate.proxmox.com (localhost [127.0.0.1]) by firstgate.proxmox.com (Proxmox) with ESMTP id 12FA824612 for ; Fri, 16 Apr 2021 14:41:27 +0200 (CEST) Received: from dana.proxmox.com (unknown [94.136.29.99]) by firstgate.proxmox.com (Proxmox) with ESMTP id 25B6224608 for ; Fri, 16 Apr 2021 14:41:23 +0200 (CEST) Received: by dana.proxmox.com (Postfix, from userid 10037) id 2CDCA1C0E9C; Fri, 16 Apr 2021 14:35:22 +0200 (CEST) From: Lorenz Stechauner To: pve-devel@lists.proxmox.com Date: Fri, 16 Apr 2021 14:34:38 +0200 Message-Id: <20210416123438.93188-1-l.stechauner@proxmox.com> X-Mailer: git-send-email 2.20.1 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-SPAM-LEVEL: Spam detection results: 2 KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment KAM_LAZY_DOMAIN_SECURITY 1 Sending domain does not have any anti-forgery methods NO_DNS_FOR_FROM 0.379 Envelope sender has no MX or A DNS records RDNS_NONE 1.274 Delivered to internal network by a host with no rDNS SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_NONE 0.001 SPF: sender does not publish an SPF Record URIBL_BLOCKED 0.001 ADMINISTRATOR NOTICE: The query to URIBL was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block for more information. [accesscontrol.pm, acl.pm] Subject: [pve-devel] [PATCH pve-access-control] fix #1500: permission path syntax check for access control X-BeenThere: pve-devel@lists.proxmox.com X-Mailman-Version: 2.1.29 Precedence: list List-Id: Proxmox VE development discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 16 Apr 2021 12:41:27 -0000 Syntax for permission paths is now checked on API calls for creation or update on permissions. Signed-off-by: Lorenz Stechauner --- PVE/API2/ACL.pm | 4 ++++ PVE/AccessControl.pm | 31 +++++++++++++++++++++++++++++++ 2 files changed, 35 insertions(+) diff --git a/PVE/API2/ACL.pm b/PVE/API2/ACL.pm index c340267..857c672 100644 --- a/PVE/API2/ACL.pm +++ b/PVE/API2/ACL.pm @@ -141,6 +141,10 @@ __PACKAGE__->register_method ({ my $path = PVE::AccessControl::normalize_path($param->{path}); raise_param_exc({ path => "invalid ACL path '$param->{path}'" }) if !$path; + if (!$param->{delete} && !PVE::AccessControl::check_path($path)) { + raise_param_exc({ path => "invalid ACL path '$param->{path}'" }); + } + PVE::AccessControl::lock_user_config( sub { diff --git a/PVE/AccessControl.pm b/PVE/AccessControl.pm index 8b5be1e..5ac2df2 100644 --- a/PVE/AccessControl.pm +++ b/PVE/AccessControl.pm @@ -60,6 +60,24 @@ cfs_register_file('priv/tfa.cfg', \&parse_priv_tfa_config, \&write_priv_tfa_config); +sub get_permission_paths { + return ( + '/', + '/access', + '/access/groups', + '/access/realm', + '/nodes', + '/nodes/{node}', + '/pool', + '/pool/{poolid}', + '/sdn', + '/storage', + '/storage/{storage}', + '/vms', + '/vms/{vmid}', + ) +} + sub verify_username { PVE::Auth::Plugin::verify_username(@_); } @@ -929,6 +947,19 @@ sub normalize_path { return $path; } +sub check_path { + my $path = normalize_path(shift); + my @regex_str_arr = (); + foreach (get_permission_paths()) { + my $regex_str = $_; + $regex_str =~ s/\{vmid\}/\\d{3,}/; + $regex_str =~ s/\{[a-z]+\}/[[:alnum:]\\.\\-\\_]+/; + push(@regex_str_arr, $regex_str); + } + my $regex_str = '^(' . join('|', @regex_str_arr) . ')$'; + return $path =~ m@$regex_str@; +} + PVE::JSONSchema::register_format('pve-groupid', \&verify_groupname); sub verify_groupname { my ($groupname, $noerr) = @_; -- 2.20.1