aboutsummaryrefslogtreecommitdiff
path: root/internal/liturgy/fetch_test.go
Commit message (Collapse)AuthorAgeFilesLines
* dayinfo: show feast/day name + colour (modern niedziela + traditional ↵Lukasz Kasprzak2026-07-241-4/+12
| | | | missalemeum) in cli/tui/web; v0.5.0
* tradlit: offline caching + read; update pre-caches traditional; --clean ↵Lukasz Kasprzak2026-07-241-1/+1
| | | | prunes it; v0.2.0
* web,liturgy: validate date against path traversal; bind lectio-web to localhostLukasz Kasprzak2026-07-231-0/+28
| | | | | | | | | | | | | | | | | An unvalidated ?date= query param flowed straight into liturgy.Load's filepath.Join(dir, date+".json"/".html") before any network call, letting a crafted date (e.g. "../../../../etc/hostname") read an arbitrary file whose JSON, if present, unmarshals into []liturgy.Section and renders back to the client. Fix both layers: resolveQuery now falls back to today() on empty or non-YYYY-MM-DD date (mirroring requestDisplay's normalize-don't-trust pattern), and liturgy.Load itself rejects a non-matching date before building any cache path, protecting every caller even if a future one forgets to validate. Also bind lectio-web's listener to 127.0.0.1 instead of all interfaces: it is a personal tool whose Run already prints http://localhost:<port>, so it should not be reachable from the LAN.
* liturgy: fetch + HTML/JSON cacheLukasz Kasprzak2026-07-231-0/+32