Replace child_process.exec by child_process.spawnSync (#428)

child_process.exec uses a shell to parse and launch command.

Since here some arguments comes from external, it's unsecured.

This MR uses spawnSync instead.
This commit is contained in:
Yadd
2024-03-11 15:03:25 +04:00
committed by GitHub
parent 423e7f2c00
commit faa42c2b22
2 changed files with 43 additions and 44 deletions
@@ -1,5 +1,5 @@
import { LdapConfiguration } from './ldap_user';
import { exec } from 'child_process';
import { spawnSync } from 'child_process';
import ldif from 'ldif';
import { logger } from "./logger"
import { User, UserProvider } from "./user_privider";
@@ -14,37 +14,37 @@ export class ShellLdapUserProvider implements UserProvider {
async find(username: string): Promise<User> {
return new Promise<User>((resolve, reject) => {
let cmd = `ldapsearch -x -H ${this.config.url} -b '${this.config.baseDn}' '(uid=${username})'`;
const args = [ '-x', '-H', this.config.url, '-b', this.config.baseDn, `(uid=${username})` ];
logger.info("Executing command to get data from LDAP for " + username);
exec(cmd, (error, stdout, stderr) => {
if (stderr) {
logger.info("ERROR: " + stderr);
}
if (error) {
logger.info(`ERROR running sync for the user: ${error.message}`);
reject(new Error(error.message));
} else {
if (stdout) {
try {
if (stdout.lastIndexOf("# search result") > 0) {
stdout = stdout.substring(0, stdout.lastIndexOf("# search result"))
}
let obj = ldif.parse(stdout).shift().toObject({});
resolve({
lastName: obj.attributes.sn,
firstName: obj.attributes.givenName,
email: obj.attributes.mail,
uid: obj.attributes.uid} as User);
} catch (e) {
console.error(e)
resolve({ } as User);
const ret = spawnSync('ldapsearch', args);
if (ret.stderr) {
logger.info("ERROR:", ret.stderr);
}
if (ret.error) {
logger.info(`ERROR running sync for the user: ${ret.error.message}`);
reject(new Error(ret.error.message));
} else {
if (ret.stdout) {
let stdout = ret.stdout.toString();
try {
if (ret.stdout.lastIndexOf("# search result") > 0) {
stdout = stdout.substring(0, stdout.lastIndexOf("# search result"))
}
} else {
logger.info("No user");
let obj = ldif.parse(stdout).shift().toObject({});
resolve({
lastName: obj.attributes.sn,
firstName: obj.attributes.givenName,
email: obj.attributes.mail,
uid: obj.attributes.uid} as User);
} catch (e) {
console.error(e)
resolve({ } as User);
}
} else {
logger.info("No user");
resolve({ } as User);
}
});
}
});
}