5 ms·
await $`dep deploy --branch=${branch}` … await $`mkdir /tmp/${name}` Code like this[1] looks prone to shell injection [1] https://github.com/google/zx h
by lixtra 5y ago
await $`dep deploy --branch=${branch}`
…
await $`mkdir /tmp/${name}`
Code like this[1] looks prone to shell injection
[1] https://github.com/google/zx https://github.com/google/zx
- pitaj 5y agoTemplate tag functions in JS can intercept the interpolation values passed in. So it's possible they're automatically escaping to prevent shell injection. They could also be parsing out the first word as the command and not using shell execution at all.
- lixtra 5y agoIndeed, escaping is what they seem to do.
- mst 5y agoThat example is immediately followed by two sentences of text, of which the second sentence is: > The zx package provides useful wrappers around child_process, escapes arguments and gives sensible defaults. lit-html and at least one SQL generating package I've seen use the template string custom interpolation mechanism to auto-escape things - it's a pretty established pattern at this point in javascript land ... but also, yes, until you learn that, it totally does look prone to injection. I've got in the habit of going and finding the template string interpolation function and double checking, because otherwise I find it hard to convince my brain to believe it isn't prone to injection and it interferes with my skim reading the code ;)