fix(release-cleanup): 去除 server URL 結尾斜線並驗證 release id 為正整數
- loadConfig 去除 GITEA_SERVER_URL 結尾的 /,避免拼出 //api/v1 錯誤路徑 - cleanupReleases 要求 id 為正整數,非整數一律略過(縱深防禦,不僅依賴編碼) Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
888edfea27
commit
353a6af7c3
+4
-3
@@ -60,12 +60,13 @@ export async function cleanupReleases(client, config) {
|
||||
for (const release of toDelete) {
|
||||
const { id, tag_name: tag, name } = release
|
||||
|
||||
if (isEmptyOrNull(id)) {
|
||||
warn(`略過沒有 id 的成品: ${tag} (${name})`)
|
||||
// 要求 id 為正整數(Gitea release id 本即正整數);非整數一律略過,不僅依賴 URL 編碼防護。
|
||||
if (isEmptyOrNull(id) || !Number.isInteger(Number(id)) || Number(id) <= 0) {
|
||||
warn(`略過沒有有效 id 的成品: ${tag} (${name})`)
|
||||
continue
|
||||
}
|
||||
|
||||
// 對 id 做編碼,避免非預期內容被拼接進 URL(防路徑穿越);正常數值 id 編碼後不變。
|
||||
// id 已驗證為正整數;仍對其編碼作為縱深防禦。
|
||||
const url = `${config.releaseApiUrl}/${encodeURIComponent(id)}`
|
||||
info(`DELETE ${tag} (${name})`)
|
||||
|
||||
|
||||
Reference in New Issue
Block a user