Canonicalize the request path before tripwire matching (#57) - #58
Merged
Merged
Conversation
A hidden-path tripwire matched the raw path, so a scan could dress a decoy path up and slip past while a webserver still resolved it to the file being hunted: //.env, /%2Eenv, /%252Eenv, /static/..%2f.git/config, /x/../.env. Missing the scan defeats the point of the tripwire. canonicalizeTripwirePath now reduces the path the way a server would before matching — drop query/fragment, ASCII percent-decode (bounded, so double encoding resolves), collapse duplicate slashes, resolve . and .. keeping one trailing slash — and the configured decoy paths are canonicalized the same way so both sides line up. Legitimate lookalikes (/environment, /env/config) are unaffected. Full suite green.
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #57.
The bug
TripwireRulematched the raw request path, stripping only the query and fragment. A scan for a decoy path could dress it up and still resolve, at the origin, to the file it was hunting for — while the tripwire matched nothing://.env(duplicate slash)/%2Eenv,/%252Eenv(percent- and double-encoded dot)/static/..%2f.git/config,/x/../.env(traversal)Missing that scan defeats the tripwire's whole purpose.
The fix
canonicalizeTripwirePathreduces the path the way a webserver would before matching: drop query/fragment, ASCII percent-decode (bounded, so double-encoding resolves), collapse duplicate slashes, resolve.and..(keeping a single trailing slash). The configured decoy paths are canonicalized the same way, so both sides of the match line up. Done in the rule, so it holds regardless of how a given adapter or server passes the path.Legitimate lookalikes (
/environment,/env/config,/assets/env.js) are unaffected — added as a guard test.Full package suite green (489), Express adapter green (15).
Note: ASCII-only percent-decode leaves high bytes encoded (so a null-byte or overlong-UTF-8 truncation trick is out of scope here); those are origin-specific and can be a follow-up if seen.