@@ -16,6 +16,7 @@ use crate::logging; |
| 16 | 16 | use crate::request::{RequestOwner, RequestRegistry, RequestState}; |
| 17 | 17 | use crate::request_store; |
| 18 | 18 | use crate::runtime::RuntimePaths; |
| 19 | +use crate::validate::validate_request_identity; |
| 19 | 20 | use crate::window::parse_optional_parent_window; |
| 20 | 21 | |
| 21 | 22 | pub fn run() -> io::Result<()> { |
@@ -118,6 +119,18 @@ fn handle_connection(stream: UnixStream, state: &mut DaemonState) -> io::Result< |
| 118 | 119 | app_id, |
| 119 | 120 | parent_window, |
| 120 | 121 | }) => { |
| 122 | + let validation = validate_request_identity(&id, &sender, app_id.as_deref()); |
| 123 | + if let Err(error) = validation { |
| 124 | + let mapping = map_portal_error(&error); |
| 125 | + return write_response( |
| 126 | + reader.into_inner(), |
| 127 | + ControlResponse::Error { |
| 128 | + code: mapping.code as u32, |
| 129 | + reason: mapping.reason.to_string(), |
| 130 | + }, |
| 131 | + ); |
| 132 | + } |
| 133 | + |
| 121 | 134 | let owner = RequestOwner::new(sender, app_id); |
| 122 | 135 | let parsed_parent_window = match parse_optional_parent_window(parent_window.as_deref()) |
| 123 | 136 | { |
@@ -157,6 +170,18 @@ fn handle_connection(stream: UnixStream, state: &mut DaemonState) -> io::Result< |
| 157 | 170 | app_id, |
| 158 | 171 | target, |
| 159 | 172 | }) => { |
| 173 | + let validation = validate_request_identity(&id, &sender, app_id.as_deref()); |
| 174 | + if let Err(error) = validation { |
| 175 | + let mapping = map_portal_error(&error); |
| 176 | + return write_response( |
| 177 | + reader.into_inner(), |
| 178 | + ControlResponse::Error { |
| 179 | + code: mapping.code as u32, |
| 180 | + reason: mapping.reason.to_string(), |
| 181 | + }, |
| 182 | + ); |
| 183 | + } |
| 184 | + |
| 160 | 185 | let owner = RequestOwner::new(sender, app_id); |
| 161 | 186 | let target_state = map_transition_target(target); |
| 162 | 187 | match state.requests.transition(&id, &owner, target_state) { |
@@ -410,6 +435,64 @@ mod tests { |
| 410 | 435 | ); |
| 411 | 436 | } |
| 412 | 437 | |
| 438 | + #[test] |
| 439 | + fn invalid_request_id_maps_to_invalid_request() { |
| 440 | + let (mut client, server) = UnixStream::pair().expect("pair should be created"); |
| 441 | + client |
| 442 | + .write_all(b"begin id=req/1 sender=:1.2 parent=x11:0x2a\n") |
| 443 | + .expect("begin request should be written"); |
| 444 | + |
| 445 | + let mut state = DaemonState { |
| 446 | + health: HealthStatus::Healthy, |
| 447 | + requests: RequestRegistry::new(Duration::from_secs(5)), |
| 448 | + running: true, |
| 449 | + }; |
| 450 | + handle_connection(server, &mut state).expect("begin should be handled"); |
| 451 | + |
| 452 | + let mut response_line = String::new(); |
| 453 | + let mut reader = BufReader::new(client); |
| 454 | + reader |
| 455 | + .read_line(&mut response_line) |
| 456 | + .expect("response should be readable"); |
| 457 | + let response = ControlResponse::parse_line(&response_line).expect("response should parse"); |
| 458 | + assert_eq!( |
| 459 | + response, |
| 460 | + ControlResponse::Error { |
| 461 | + code: 2, |
| 462 | + reason: "invalid_request".to_string(), |
| 463 | + } |
| 464 | + ); |
| 465 | + } |
| 466 | + |
| 467 | + #[test] |
| 468 | + fn invalid_sender_maps_to_invalid_request() { |
| 469 | + let (mut client, server) = UnixStream::pair().expect("pair should be created"); |
| 470 | + client |
| 471 | + .write_all(b"transition id=req-1 sender=org.test.App state=cancelled\n") |
| 472 | + .expect("transition request should be written"); |
| 473 | + |
| 474 | + let mut state = DaemonState { |
| 475 | + health: HealthStatus::Healthy, |
| 476 | + requests: RequestRegistry::new(Duration::from_secs(5)), |
| 477 | + running: true, |
| 478 | + }; |
| 479 | + handle_connection(server, &mut state).expect("transition should be handled"); |
| 480 | + |
| 481 | + let mut response_line = String::new(); |
| 482 | + let mut reader = BufReader::new(client); |
| 483 | + reader |
| 484 | + .read_line(&mut response_line) |
| 485 | + .expect("response should be readable"); |
| 486 | + let response = ControlResponse::parse_line(&response_line).expect("response should parse"); |
| 487 | + assert_eq!( |
| 488 | + response, |
| 489 | + ControlResponse::Error { |
| 490 | + code: 2, |
| 491 | + reason: "invalid_request".to_string(), |
| 492 | + } |
| 493 | + ); |
| 494 | + } |
| 495 | + |
| 413 | 496 | #[test] |
| 414 | 497 | fn transition_owner_mismatch_maps_to_stable_reason() { |
| 415 | 498 | let (mut client, server) = UnixStream::pair().expect("pair should be created"); |