Skip to content

Prevent SQL source disclosure through path aliases - #1476

Merged
lovasoa merged 3 commits into
mainfrom
codex/sql-source-disclosure
Sep 27, 2026
Merged

lovasoa merged 3 commits into
mainfrom
codex/sql-source-disclosure

Conversation

@lovasoa

@lovasoa lovasoa commented Sep 22, 2026

Copy link
Copy Markdown
Collaborator

Mixed-case .SQL requests could resolve to a SQLPage source file on case-insensitive storage but be served as a static asset. SQLPage now routes every ASCII case variant of the .sql extension through the SQL executor. Unprivileged paths also reject trailing-space aliases used by SQL Server and, on Windows, trailing-dot and NTFS stream aliases.

Regression tests cover mixed-case routes and noncanonical file paths.

Validation: cargo fmt --all; cargo clippy --all-targets --all-features -- -D warnings; cargo test --lib (222 passed).

Comment thread src/filesystem.rs
Comment on lines +231 to +234
// SQL Server ignores trailing spaces when comparing file-store paths.
// Windows can also alias trailing dots and NTFS stream names to the
// same file. Reject these spellings before routing can serve a SQL
// file as an ordinary static asset.

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[nit] this shouldn't be a comment, it should be 3 different tests we can run in the CI. I see you have some of them already

@lovasoa
lovasoa force-pushed the codex/sql-source-disclosure branch from 5ecc246 to 496418b Compare September 24, 2026 21:35
@lovasoa
lovasoa merged commit 6ecc864 into main Sep 27, 2026
52 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants