mirror of
https://github.com/helmfile/helmfile.git
synced 2026-09-30 08:00:19 +02:00
feat: support disabling insecure template functions only (#2689)
Signed-off-by: fabiobaiao <53570695+fabiobaiao@users.noreply.github.com>
This commit is contained in:
+11
-10
@@ -24,22 +24,23 @@ import (
|
||||
|
||||
type Values = map[string]any
|
||||
|
||||
var DisableInsecureFeaturesErr = DisableInsecureFeaturesError{envvar.DisableInsecureFeatures + " is active, insecure function calls are disabled"}
|
||||
var DisableInsecureFunctionsErr = DisableInsecureFunctionsError{envvar.DisableInsecureFeatures + " or " + envvar.DisableInsecureTemplateFunctions + " is active, insecure function calls are disabled"}
|
||||
|
||||
type DisableInsecureFeaturesError struct {
|
||||
type DisableInsecureFunctionsError struct {
|
||||
err string
|
||||
}
|
||||
|
||||
func (e DisableInsecureFeaturesError) Error() string {
|
||||
func (e DisableInsecureFunctionsError) Error() string {
|
||||
return e.err
|
||||
}
|
||||
|
||||
var (
|
||||
disableInsecureFeatures bool
|
||||
disableInsecureFeatures, disableInsecureTemplateFunctions bool
|
||||
)
|
||||
|
||||
func init() {
|
||||
disableInsecureFeatures, _ = strconv.ParseBool(os.Getenv(envvar.DisableInsecureFeatures))
|
||||
disableInsecureTemplateFunctions, _ = strconv.ParseBool(os.Getenv(envvar.DisableInsecureTemplateFunctions))
|
||||
}
|
||||
|
||||
func (c *Context) createFuncMap() template.FuncMap {
|
||||
@@ -80,22 +81,22 @@ func (c *Context) createFuncMap() template.FuncMap {
|
||||
return []fs.DirEntry{}, nil
|
||||
}
|
||||
}
|
||||
if disableInsecureFeatures {
|
||||
if disableInsecureFeatures || disableInsecureTemplateFunctions {
|
||||
// disable insecure functions
|
||||
funcMap["exec"] = func(string, []any, ...string) (string, error) {
|
||||
return "", DisableInsecureFeaturesErr
|
||||
return "", DisableInsecureFunctionsErr
|
||||
}
|
||||
funcMap["envExec"] = func(map[string]any, string, []any, ...string) (string, error) {
|
||||
return "", DisableInsecureFeaturesErr
|
||||
return "", DisableInsecureFunctionsErr
|
||||
}
|
||||
funcMap["readFile"] = func(string) (string, error) {
|
||||
return "", DisableInsecureFeaturesErr
|
||||
return "", DisableInsecureFunctionsErr
|
||||
}
|
||||
funcMap["readDir"] = func(string) ([]string, error) {
|
||||
return nil, DisableInsecureFeaturesErr
|
||||
return nil, DisableInsecureFunctionsErr
|
||||
}
|
||||
funcMap["readDirEntries"] = func(string) ([]string, error) {
|
||||
return nil, DisableInsecureFeaturesErr
|
||||
return nil, DisableInsecureFunctionsErr
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
@@ -38,14 +38,31 @@ func TestCreateFuncMap_DisabledInsecureFeatures(t *testing.T) {
|
||||
funcMaps := ctx.createFuncMap()
|
||||
args := make([]any, 0)
|
||||
_, err1 := funcMaps["exec"].(func(command string, args []any, inputs ...string) (string, error))("ls", args)
|
||||
require.ErrorIs(t, err1, DisableInsecureFeaturesErr)
|
||||
require.ErrorIs(t, err1, DisableInsecureFunctionsErr)
|
||||
_, err2 := funcMaps["readFile"].(func(filename string) (string, error))("context_funcs_test.go")
|
||||
require.ErrorIs(t, err2, DisableInsecureFeaturesErr)
|
||||
require.ErrorIs(t, err2, DisableInsecureFunctionsErr)
|
||||
}
|
||||
|
||||
disableInsecureFeatures = currentVal
|
||||
}
|
||||
|
||||
func TestCreateFuncMap_DisabledInsecureTemplateFunctions(t *testing.T) {
|
||||
currentVal := disableInsecureTemplateFunctions
|
||||
|
||||
{
|
||||
disableInsecureTemplateFunctions = true
|
||||
ctx := &Context{basePath: "."}
|
||||
funcMaps := ctx.createFuncMap()
|
||||
args := make([]any, 0)
|
||||
_, err1 := funcMaps["exec"].(func(command string, args []any, inputs ...string) (string, error))("ls", args)
|
||||
require.ErrorIs(t, err1, DisableInsecureFunctionsErr)
|
||||
_, err2 := funcMaps["readFile"].(func(filename string) (string, error))("context_funcs_test.go")
|
||||
require.ErrorIs(t, err2, DisableInsecureFunctionsErr)
|
||||
}
|
||||
|
||||
disableInsecureTemplateFunctions = currentVal
|
||||
}
|
||||
|
||||
func newFSExpecting(expectedFilename string, expected string) *filesystem.FileSystem {
|
||||
return filesystem.FromFileSystem(filesystem.FileSystem{
|
||||
ReadFile: func(filename string) ([]byte, error) {
|
||||
|
||||
Reference in New Issue
Block a user