| |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
An unvalidated ?date= query param flowed straight into
liturgy.Load's filepath.Join(dir, date+".json"/".html") before any
network call, letting a crafted date (e.g. "../../../../etc/hostname")
read an arbitrary file whose JSON, if present, unmarshals into
[]liturgy.Section and renders back to the client. Fix both layers:
resolveQuery now falls back to today() on empty or non-YYYY-MM-DD
date (mirroring requestDisplay's normalize-don't-trust pattern), and
liturgy.Load itself rejects a non-matching date before building any
cache path, protecting every caller even if a future one forgets to
validate.
Also bind lectio-web's listener to 127.0.0.1 instead of all
interfaces: it is a personal tool whose Run already prints
http://localhost:<port>, so it should not be reachable from the LAN.
|