search: reject remote paths with extra segments · Entire
search: reject remote paths with extra segments
ba35ac0→main·
pfleidi·1mo ago·2 files·+17 added/-1 removed
ParseGitHubRemote now errors when the parsed repo still contains a slash, i.e. the remote path carried segments beyond owner/repo. A GitHub repo name never contains a slash, so this only rejects malformed remotes; previously such input silently produced a bogus owner/repo that would be sent to the search service as an invalid filter.
Sessions
74ae73bbc656View transcript
Changes
2
cmd/entire/cli/search
Mgithub.go+5/-1
Msearch_test.go+12
2 unmodified lines
3
4
5
6
7
8
9
2 unmodified lines
12
13
14
14
15
16
17
18
2 unmodified lines
21
22
23
24
25
26
27
28
2 unmodified lines
import (
"fmt"
"strings"
"github.com/entireio/cli/cmd/entire/cli/gitremote"
)
2 unmodified lines
// to GitHub. It accepts direct GitHub remotes (SCP-style SSH, ssh://, and
// https://) as well as Entire mirror remotes (entire://host/gh/owner/repo),
// whose forge prefix maps back to github.com. Remotes resolving to any other
// host are rejected.
// host, or whose path holds extra segments beyond owner/repo, are rejected.
func ParseGitHubRemote(remoteURL string) (owner, repo string, err error) {
info, err := gitremote.ParseURL(remoteURL)
if err != nil {
2 unmodified lines
if host := info.CanonicalHost(); host != "github.com" {
return "", "", fmt.Errorf("remote is not a GitHub repository (host: %%s)", host)
}
if strings.Contains(info.Repo, "/") {
return "", "", fmt.Errorf("remote path has extra segments beyond owner/repo: %%s", gitremote.RedactURL(remoteURL))
}
return info.Owner, info.Repo, nil
}
Mcmd/entire/cli/search/github.go+5/-1
104 unmodified lines
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
104 unmodified lines
}
}
func TestParseGitHubRemote_RejectsExtraPathSegments(t *testing.T) {
t.Parallel()
for _, remoteURL := range []string{
"https://github.com/entirehq/entire.io/extra.git",
"entire://aws-us-east-2.entire.io/gh/entirehq/entire.io/extra",
} {
if _, _, err := ParseGitHubRemote(remoteURL); err == nil {
t.Errorf("expected error for malformed remote %q, got none", remoteURL)
}
}
}
func TestParseGitHubRemote_EntireMirror(t *testing.T) {
t.Parallel()
owner, repo, err := ParseGitHubRemote("entire://aws-us-east-2.entire.io/gh/entirehq/entire.io")
Mcmd/entire/cli/search/search_test.go+12