commands/http: Ensure request URLs start with expected prefix
Matt Bell committed
Nov 3, 2014 at 19:51 UTC
446acdcdb56220f326cf372c8aff39e7c2b117b6
1 file changed
+6
-1
commands/http/parse.go
+6
-1
@@ -1,6 +1,7 @@
1
package http
2
3
import (
4
+ "errors"
5
"net/http"
6
"strings"
7
@@ -9,7 +10,11 @@ import (
10
11
// Parse parses the data in a http.Request and returns a command Request object
12
func Parse(r *http.Request, root *cmds.Command) (cmds.Request, error) {
12
- path := strings.Split(r.URL.Path, "/")[3:]
13
+ if !strings.HasPrefix(r.URL.Path, ApiPath) {
14
+ return nil, errors.New("Unexpected path prefix")
15
+ }
16
+ path := strings.Split(strings.TrimPrefix(r.URL.Path, ApiPath+"/"), "/")
17
+
18
stringArgs := make([]string, 0)
19
20
cmd, err := root.Get(path[:len(path)-1])