fix(security): 添加路径验证和CSV转义防止安全漏洞

This commit is contained in:
ssss
2026-07-03 14:28:22 +08:00
parent fa0b93446f
commit d3e4b2b8de
3 changed files with 426 additions and 62 deletions

View File

@@ -0,0 +1,54 @@
namespace WCTDataMiner.Core.Security;
/// <summary>
/// 安全相关常量定义
/// </summary>
public static class SecurityConstants
{
/// <summary>
/// 默认允许的输出目录
/// </summary>
public static readonly string[] DefaultAllowedExportDirectories =
[
"exports",
"output",
"data/exports",
"data/output"
];
/// <summary>
/// 路径最大长度限制
/// </summary>
public const int MaxPathLength = 260;
/// <summary>
/// 文件名最大长度限制
/// </summary>
public const int MaxFileNameLength = 255;
/// <summary>
/// 禁止的路径模式
/// </summary>
public static readonly string[] ForbiddenPathPatterns =
[
"..", // 路径遍历
"~", // 用户主目录
"\\\\", // UNC 路径开始
"|", // 管道字符Windows 禁止)
">", // 重定向字符
"<", // 重定向字符
"*", // 通配符(用于文件名时)
"?" // 通配符(用于文件名时)
];
/// <summary>
/// 安全的文件扩展名白名单
/// </summary>
public static readonly string[] AllowedExportExtensions =
[
".csv",
".json",
".txt",
".log"
];
}