Files
feedBack/tests/test_sloppak_file_traversal.py
T
af2949677a rename: slopsmith → feedBack, byron → got-feedBack (#537)
* Update GitHub repo references from feedback* to feedBack*

* rename: slopsmith -> feedBack, byron -> got-feedBack

Renames across the entire codebase:
- slopsmith/Slopsmith/SLOPSMITH/SlopSmith -> feedBack/FeedBack/FEEDBACK/FeedBack
- byron/Byron/Byrongamatos -> got-feedBack/got-feedBack/got-feedBack
- /home/byron/ -> /opt/got-feedBack/
- byron@ougsoft.com -> hi@got-feedBack.org
- github.com/byrongamatos/ -> github.com/got-feedback/
- com.byron. -> com.got-feedback.
- SLOPSMITH_ env vars -> FEEDBACK_ with backward-compat fallback
- Protocol/storage strings migrated with read-old/write-new pattern
- window.slopsmith JS API -> window.feedBack (canonical) + backward-compat alias

Refs: #rename-slopsmith

* rename: complete regen against current main + fix backward-compat alias

Regenerated the slopsmith->feedBack / byron->got-feedBack rename on top of
current main (3 commits had landed since the branch: #572/#554/#574),
resolving the four content conflicts in favour of main's newer content
(autoplay/auto-exit, accuracy-badge, Virtuoso re-home, feedpak badge).

Completion fixes on top of the mechanical rename:
- Re-apply rename to post-branch content the original rename never saw:
  window.slopsmith(.Tour) consumers in lessons.js / notifications.js /
  onboarding-tour.js, and the matching JS + python tests (autoplay_exit,
  progression_*, test_feedpak_extension FEEDBACK_* env vars). The test env
  vars now match server.py (which reads FEEDBACK_SYNC_STARTUP /
  FEEDBACK_SKIP_STARTUP_TASKS), so the sync-startup test exercises the real
  path again.
- Restore the window.slopsmith backward-compat alias dropped during conflict
  resolution, and move the bus aliases to AFTER the _feedBackExisting merge
  block so they reference the fully-assembled object (also fixes the
  loop_api.test.js API-surface regex, which the original PR latently broke).
- Drop the stray empty data/web_library.db (runtime DB lives in CONFIG_DIR)
  and gitignore it.
- Fix stale tone-source test: feed[dB]ack -> fee[dB]ack to match shipped
  source labels.

Verified locally (org CI billing-blocked): JS 819/819 pass; pytest 1669
passed / 1683 collected with 0 import errors; zero residual slopsmith/byron
except the two intentional window.slopsmith aliases.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* rename: implement advertised backward-compat + prune dead community plugins

Address gaps where PR #537's "Backward compatibility" section was advertised
but not implemented, and clean up the community plugin list.

Env vars (FEEDBACK_* canonical, legacy SLOPSMITH_* honoured):
- New lib/env_compat.py (getenv_compat / env_flag_compat) + tests. server.py
  (_env_flag + all FEEDBACK_* reads), diagnostics_hardware, gp2midi and
  tailwind_rebuild now resolve the legacy alias, so existing SLOPSMITH_UI /
  SLOPSMITH_PLUGINS_DIR / etc. deployments keep working.
- Fix the rename collapsing plugins/__init__.py and minigames/routes.py from
  `FEEDBACK_PLUGINS_DIR or SLOPSMITH_PLUGINS_DIR` into a redundant
  `FEEDBACK_ or FEEDBACK_` (the fallback was silently lost).

Storage (app.js update-channel):
- Read feedBack-update-channel, fall back to legacy slopsmith-update-channel,
  and clear the legacy key on write — so a user's update-channel preference
  survives the rename instead of resetting to "stable".

Community plugin list (README): the rename rewrote third-party repo URLs we
don't own. Probed every one; their owners never renamed, so:
- Restore the 13 live community plugins to their real slopsmith-* names.
- Prune 6 that are 404 to the public (topkoa splitscreen/stems, OmikronApex
  tuner, Jafz2001 nam-rig-builder, DeathlySin song-preview, Erikcb91 shuffle).
- Fix a pre-existing Guitar Theory clone-command typo (nam-tone -> guitar-theory).

Verified: env_compat 7/7, JS 819/819, pytest 1690 collected / 0 import errors,
rename-sensitive + startup suites green.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: byrongamatos <xasiklas@gmail.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-23 11:03:01 +02:00

113 lines
4.1 KiB
Python

"""Endpoint tests for path-traversal rejection on the sloppak file route.
`GET /api/sloppak/{filename:path}/file/{rel_path:path}` serves files from
inside a sloppak bundle. Both params are attacker-controlled `:path`
segments, so the handler must (1) contain `filename` under DLC_DIR,
(2) only serve actual `.sloppak` bundles, and (3) contain `rel_path`
inside the resolved sloppak. These tests pin that contract so future
refactors of `resolve_source_dir`/routing can't reintroduce the
arbitrary-file-read class of bug (feedBack#638).
"""
import importlib
import sys
import pytest
from fastapi.testclient import TestClient
@pytest.fixture()
def dlc_client(tmp_path, monkeypatch):
"""Spin up a TestClient with a temp DLC_DIR; sync startup, no scan."""
dlc = tmp_path / "dlc"
dlc.mkdir()
config = tmp_path / "cfg"
config.mkdir()
monkeypatch.setenv("DLC_DIR", str(dlc))
monkeypatch.setenv("CONFIG_DIR", str(config))
monkeypatch.setenv("FEEDBACK_SYNC_STARTUP", "1")
sys.modules.pop("server", None)
server = importlib.import_module("server")
# The sloppak source-dir cache is module-level and survives the
# server re-import; clear it so a prior test's filename key can't
# shadow this test's temp DLC_DIR.
server.sloppak_mod._source_cache.clear()
monkeypatch.setattr(server, "load_plugins", lambda *a, **kw: None)
monkeypatch.setattr(server, "startup_scan", lambda: None)
static_tmp = tmp_path / "static"
static_tmp.mkdir()
monkeypatch.setattr(server, "STATIC_DIR", static_tmp)
tc = TestClient(server.app, client=("127.0.0.1", 50000))
try:
yield tc, server, dlc
finally:
tc.close()
meta_db = getattr(server, "meta_db", None)
conn = getattr(meta_db, "conn", None)
if conn is not None:
conn.close()
def _make_sloppak(dlc, name="song.sloppak"):
"""Create a minimal directory-form sloppak with one served file."""
pak = dlc / name
(pak / "stems").mkdir(parents=True)
(pak / "stems" / "full.ogg").write_bytes(b"OggS-fake")
return pak
def test_filename_dotdot_traversal_is_403(dlc_client):
tc, _server, _dlc = dlc_client
# `filename` escapes DLC_DIR — must 403 before any filesystem read,
# never serve /etc/passwd (the original report).
r = tc.get("/api/sloppak/..%2F..%2F..%2F..%2Fetc/file/passwd")
assert r.status_code == 403, r.text
def test_rel_path_dotdot_traversal_is_403(dlc_client):
"""A real sloppak is present, but `rel_path` escapes it — 403."""
tc, _server, dlc = dlc_client
_make_sloppak(dlc)
# Drop a secret as a sibling of the sloppak inside DLC_DIR.
(dlc / "secret.txt").write_text("top secret")
r = tc.get("/api/sloppak/song.sloppak/file/..%2Fsecret.txt")
assert r.status_code == 403, r.text
def test_contained_non_sloppak_is_404(dlc_client):
"""A contained-but-non-sloppak `filename` (plain dir) must not turn
the endpoint into read-any-file-under-DLC_DIR — the is_sloppak gate
rejects it with 404."""
tc, _server, dlc = dlc_client
plain = dlc / "Artist"
plain.mkdir()
(plain / "notes.txt").write_text("not a sloppak")
r = tc.get("/api/sloppak/Artist/file/notes.txt")
assert r.status_code == 404, r.text
def test_dot_filename_is_404(dlc_client):
"""`filename=.` resolves to DLC_DIR itself; the is_sloppak gate
blocks it rather than serving arbitrary DLC files."""
tc, _server, dlc = dlc_client
(dlc / "config.json").write_text("{}")
r = tc.get("/api/sloppak/./file/config.json")
assert r.status_code == 404, r.text
def test_missing_sloppak_is_404(dlc_client):
"""A safe-but-missing sloppak path produces 404, not 403 — guards
against over-rejecting legitimate filenames."""
tc, _server, _dlc = dlc_client
r = tc.get("/api/sloppak/missing.sloppak/file/stems/full.ogg")
assert r.status_code == 404, r.text
def test_legitimate_file_is_served(dlc_client):
"""A real file inside a real sloppak serves with 200 + bytes."""
tc, _server, dlc = dlc_client
_make_sloppak(dlc)
r = tc.get("/api/sloppak/song.sloppak/file/stems/full.ogg")
assert r.status_code == 200, r.text
assert r.content == b"OggS-fake"