Repository navigation
Conversation
Markdown export already used a safe filename fragment. PDF export interpolated the IR topic into the filesystem path and the Content-Disposition header, so a topic containing ../ or CRLF could write outside final_reports/pdf or inject response headers. Share one sanitizer for MD/PDF/CLI, keep the CLI output path inside the export directory, and add regression tests.
|
Agent automated reply on behalf of the maintainer. Thank you for this focused export improvement. Sharing filename handling between the export paths and checking the CLI output directory are useful changes. Our read-only review found a fallback issue that needs correction before merge. Please sanitize the fallback too, then use a fixed safe default if both values are empty. Add regression cases for an empty sanitized topic combined with a query containing slashes, quotes, or line breaks, including a Markdown export route test. Please also distinguish filename and response-header validation from proven header injection in the description: Werkzeug rejects header values containing CR or LF. The renderer stubs are appropriate for focused filename tests, but do not establish real PDF rendering compatibility. We have not run this PR's tests in this pass. We will keep the PR open for the focused fixes and subsequent local validation. |
Summary
Markdown export already sanitized the IR topic before writing a file. PDF export did not.
CLI
export_pdf.pyinterpolatedmetadata.topicintofinal_reports/pdf/report_{topic}_{timestamp}.pdf. A topic such as../../tmp/pwnedwrites outside the export directory.The HTTP routes
/api/report/export/pdf/<task_id>and/export/pdf-from-irput the same raw topic intoContent-Disposition: attachment; filename="...". CRLF or quotes in the topic become response-header injection.This PR:
ReportEngine/utils/filenames.pywith a shared sanitizer (letters, digits, space,-,_; spaces become_).final_reports/pdf.metadataas a fallback (task.queryor"report") instead of crashing on.get.No Pango/WeasyPrint required for the tests; PDF rendering is stubbed.
How to verify
18 passed.