Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -30,6 +30,8 @@
import com.healthmarketscience.rmiio.SimpleRemoteOutputStream;
import com.healthmarketscience.rmiio.exporter.RemoteStreamExporter;
import org.apache.commons.io.FileUtils;
import org.apache.commons.io.FilenameUtils;
import org.apache.commons.lang3.StringUtils;
import org.apache.logging.log4j.Logger;

import org.apache.geode.logging.internal.log4j.api.LogService;
Expand Down Expand Up @@ -66,7 +68,13 @@ public FileUploader(RemoteStreamExporter exporter) {
public RemoteFile uploadFile(String filename) throws IOException {
Path tempDir = createSecuredTempDirectory(STAGED_DIR_PREFIX);

File stagedFile = new File(tempDir.toString(), filename);
File stagedFile;
try {
stagedFile = getStagedFile(tempDir, filename);
} catch (RuntimeException e) {
FileUtils.deleteQuietly(tempDir.toFile());
throw e;
}
BufferedOutputStream bos = new BufferedOutputStream(new FileOutputStream(stagedFile));

RemoteOutputStreamMonitor monitor = new RemoteOutputStreamMonitor() {
Expand Down Expand Up @@ -116,4 +124,26 @@ public static Path createSecuredTempDirectory(String prefix) throws IOException

return tempDir;
}

/**
* Returns the file within {@code stagingDir} that an uploaded file named {@code fileName} is
* staged as. Only the last name segment of {@code fileName} is used, so the returned file is
* always a direct child of {@code stagingDir}.
*
* @throws IllegalArgumentException if {@code fileName} has no usable name segment
*/
public static File getStagedFile(Path stagingDir, String fileName) throws IOException {
String name = FilenameUtils.getName(fileName);
if (StringUtils.isBlank(name) || ".".equals(name) || "..".equals(name)) {
throw new IllegalArgumentException("Uploaded file name is not valid.");
}

Path dir = stagingDir.toRealPath();
Path stagedFile = dir.resolve(name).normalize();
if (!dir.equals(stagedFile.getParent())) {
throw new IllegalArgumentException("Uploaded file name is not valid.");
}

return stagedFile.toFile();
}
}
Original file line number Diff line number Diff line change
Expand Up @@ -151,7 +151,7 @@ public ResponseEntity<ClusterManagementResult> deploy(
throw new IllegalArgumentException("No file uploaded");
}
Path tempDir = FileUploader.createSecuredTempDirectory("uploaded-");
File targetFile = new File(tempDir.toFile(), file.getOriginalFilename());
File targetFile = FileUploader.getStagedFile(tempDir, file.getOriginalFilename());
file.transferTo(targetFile);
Deployment deployment = new Deployment();
if (StringUtils.isNotBlank(json)) {
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -50,6 +50,7 @@
import org.apache.geode.management.internal.ManagementAgent;
import org.apache.geode.management.internal.SystemManagementService;
import org.apache.geode.management.internal.beans.FileUploader;
import org.apache.geode.management.internal.cli.result.model.ResultModel;
import org.apache.geode.management.internal.cli.shell.Gfsh;
import org.apache.geode.management.internal.web.controllers.support.LoginHandlerInterceptor;
import org.apache.geode.management.internal.web.util.UriUtils;
Expand Down Expand Up @@ -243,20 +244,22 @@ protected String processCommand(final String command, final Map<String, String>
final MultipartFile[] multipartFiles) throws IOException {
List<String> filePaths = null;
Path tempDir = null;
if (multipartFiles != null) {
tempDir = FileUploader.createSecuredTempDirectory("uploaded-");
// staging the files to local
filePaths = new ArrayList<>();
for (MultipartFile multipartFile : multipartFiles) {
File dest = new File(tempDir.toFile(), multipartFile.getOriginalFilename());
multipartFile.transferTo(dest);
filePaths.add(dest.getAbsolutePath());
try {
if (multipartFiles != null) {
tempDir = FileUploader.createSecuredTempDirectory("uploaded-");
// staging the files to local
filePaths = new ArrayList<>();
for (MultipartFile multipartFile : multipartFiles) {
File dest = FileUploader.getStagedFile(tempDir, multipartFile.getOriginalFilename());
multipartFile.transferTo(dest);
filePaths.add(dest.getAbsolutePath());
}
}
}

MemberMXBean manager = getManagingMemberMXBean();
try {
MemberMXBean manager = getManagingMemberMXBean();
return manager.processCommand(command, environment, filePaths);
} catch (IllegalArgumentException e) {
return ResultModel.createError(e.getMessage()).toJson();
} finally {
if (tempDir != null) {
FileUtils.deleteDirectory(tempDir.toFile());
Expand Down
Loading