fix(release): validate remote backend path
This commit is contained in:
@@ -130,6 +130,7 @@ if [[ -n "${RELEASE_REMOTE_URL:-}" ]]; then
|
||||
command -v ssh >/dev/null 2>&1 || fail "ssh is required for remote backend verification"
|
||||
remote_ssh="${RELEASE_REMOTE_SSH:-YCWY}"
|
||||
remote_backend_path="${RELEASE_REMOTE_BACKEND_PATH:-/opt/wygj/app/ruoyi-admin.jar}"
|
||||
[[ "$remote_backend_path" =~ ^/[A-Za-z0-9._/-]+$ ]] || fail "remote backend path must be an absolute safe path: $remote_backend_path"
|
||||
remote_backend_sha256="$(ssh -o BatchMode=yes -o ConnectTimeout=10 "$remote_ssh" "sha256sum '$remote_backend_path'" | awk '{print $1}')" || fail "remote backend hash check failed: $remote_ssh:$remote_backend_path"
|
||||
[[ "$remote_backend_sha256" =~ ^[0-9a-f]{64}$ ]] || fail "remote backend hash is invalid: $remote_ssh:$remote_backend_path"
|
||||
local_backend_sha256="$(sha256 "$backend_jar")"
|
||||
|
||||
Reference in New Issue
Block a user