mirror of
https://github.com/Cockatrice/Cockatrice.git
synced 2026-09-28 00:42:19 -07:00
[Client/Server] Keep non-deck files out of the deck storage (#7352)
The local deck and replay browsers list every file in the folder, so a stray file (e.g. a PNG screenshot of a deck) can be parsed as a garbage plaintext deck, opened in the editor, and uploaded. The server also accepts oversized deck payloads with only silent truncation. Hide files that are not in a supported deck/replay format in the two QFileSystemModel views (directories stay visible), skip them when opening, reject them when uploading, and make the server reject deck uploads larger than MAX_FILE_LENGTH instead of truncating them. Co-authored-by: Lukas Brübach <Bruebach.Lukas@bdosecurity.de>
This commit is contained in:
parent
fa8220df3c
commit
2632f8a040
3 changed files with 35 additions and 0 deletions
|
|
@ -982,6 +982,10 @@ Response::ResponseCode AbstractServerSocketInterface::cmdDeckUpload(const Comman
|
|||
return Response::RespInvalidData;
|
||||
}
|
||||
|
||||
if (cmd.deck_list().size() > static_cast<std::string::size_type>(MAX_FILE_LENGTH)) {
|
||||
return Response::RespInvalidData;
|
||||
}
|
||||
|
||||
sqlInterface->checkSql();
|
||||
|
||||
QString deckStr = fileFromStdString(cmd.deck_list());
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue