[Android] Add defense path validation to download endpoints
Nicolas Pomepuy
git at videolan.org
Fri Oct 2 07:29:56 UTC 2026
vlc-android | branch: master | Nicolas Pomepuy <nicolas at videolabs.io> | Thu Sep 24 14:33:30 2026 +0200| [1ab17d00be14cff1f6a80611a0364779ebef794f] | committer: Nicolas Pomepuy
Add defense path validation to download endpoints
> https://code.videolan.org/videolan/vlc-android/commit/1ab17d00be14cff1f6a80611a0364779ebef794f
---
.../remoteaccessserver/routing/RemoteAccessRoutingResources.kt | 8 ++++++++
1 file changed, 8 insertions(+)
diff --git a/application/remote-access-server/src/main/java/org/videolan/vlc/remoteaccessserver/routing/RemoteAccessRoutingResources.kt b/application/remote-access-server/src/main/java/org/videolan/vlc/remoteaccessserver/routing/RemoteAccessRoutingResources.kt
index 7d9129029d..63ac5cf168 100644
--- a/application/remote-access-server/src/main/java/org/videolan/vlc/remoteaccessserver/routing/RemoteAccessRoutingResources.kt
+++ b/application/remote-access-server/src/main/java/org/videolan/vlc/remoteaccessserver/routing/RemoteAccessRoutingResources.kt
@@ -105,6 +105,10 @@ fun Route.resourceRouting(appContext: Context, settings: SharedPreferences) {
//simple media. It's a direct download
appContext.getFromMl { getMedia(id.toLong()) }?.let { media ->
media.uri.path?.let { path ->
+ if (!isPathSafeForRemoteAccess(path)) {
+ call.respond(HttpStatusCode.Forbidden)
+ return at get
+ }
val file = File(path)
val name = media.title.slugify("_") + media.uri.toString().substring(media.uri.toString().lastIndexOf("."))
call.response.header(
@@ -143,6 +147,10 @@ fun Route.resourceRouting(appContext: Context, settings: SharedPreferences) {
call.respond(HttpStatusCode.NotFound)
return at get
}
+ if (!isPathSafeForRemoteAccess(path)) {
+ call.respond(HttpStatusCode.Forbidden)
+ return at get
+ }
val file = File(path)
if (!file.exists() || !file.canRead()) {
call.respond(HttpStatusCode.NotFound)
More information about the Android
mailing list