Dwi Siswanto
20cbf0bd73
refactor: use path-aware filesystem containment checks ( #7420 )
...
* feat(filepath): add IsPathWithinAnyDirectory func
Signed-off-by: Dwi Siswanto <git@dw1.io >
* refactor: use path-aware filesystem containment checks
Several filesystem trust boundaries relied on
lexical prefix checks to decide whether a path
fell under an allowed directory. That let sibling
paths be treated as if they were children of
trusted directories.
Replace those checks with canonical path
containment checks for helper payload loading,
template archive extraction, custom template
metadata, template path classification, and
headless screenshot output validation.
Signed-off-by: Dwi Siswanto <git@dw1.io >
* adding more tests
* fixing tests
* adding test
---------
Signed-off-by: Dwi Siswanto <git@dw1.io >
Co-authored-by: Mzack9999 <mzack9999@protonmail.com >
2026-06-04 21:03:51 +05:30
dahe
da17fa42e3
fix: add continue after handling default template version in GetNewTemplatesInVersions
2026-04-10 18:21:49 +08:00
ayuxsec
bfffb3b7d4
fix(installer): log update summary table to stderr ( #6769 )
2026-01-19 12:09:19 +07:00
Mzack9999
b49beef554
improving update template + empty folder edge case ( #6573 )
...
* improving update template + empty folder edge case
* lint
* index cleanup
* cleaning path
* win fix
* fix
* chore(cmd): rm templates
Signed-off-by: Dwi Siswanto <git@dw1.io >
---------
Signed-off-by: Dwi Siswanto <git@dw1.io >
Co-authored-by: Dwi Siswanto <git@dw1.io >
2025-12-14 23:35:22 +07:00
Mzack9999
0e498bcd76
improve volume name handling
2025-12-06 11:19:27 +04:00
Patrick Stoeckle
bfef42f9e3
chore(typos): fix typos
2025-10-10 17:32:54 +02:00
Tarun Koyalwar
19247ae74b
Path-Based Fuzzing SQL fix ( #6400 )
...
* setup claude
* migrate to using errkit
* fix unused imports + lint errors
* update settings.json
* fix url encoding issue
* fix lint error
* fix the path fuzzing component
* fix lint error
2025-08-25 13:36:58 +05:30
Sandeep Singh
b4644af80a
Lint + test fixes after utils dep update ( #6393 )
...
* fix: remove undefined errorutil.ShowStackTrace
* feat: add make lint support and integrate with test
* refactor: migrate errorutil to errkit across codebase
- Replace deprecated errorutil with modern errkit
- Convert error declarations from var to func for better compatibility
- Fix all SA1019 deprecation warnings
- Maintain error chain support and stack traces
* fix: improve DNS test reliability using Google DNS
- Configure test to use Google DNS (8.8.8.8) for stability
- Fix nil pointer issue in DNS client initialization
- Keep production defaults unchanged
* fixing logic
* removing unwanted branches in makefile
---------
Co-authored-by: Mzack9999 <mzack9999@protonmail.com >
2025-08-20 05:28:23 +05:30
Dwi Siswanto
70eeb6c210
fix: prevent unnecessary template updates ( #6379 )
...
* test(installer): adds `TestIsOutdatedVersionFix`
Signed-off-by: Dwi Siswanto <git@dw1.io >
* fix: prevent unnecessary template updates
when version API fails.
* fix `catalog/config.IsOutdatedVersion` logic for
empty version strings
* add GitHub API fallback when PDTM API is unavail
* only show outdated msg for actual version
mismatches
Signed-off-by: Dwi Siswanto <git@dw1.io >
---------
Signed-off-by: Dwi Siswanto <git@dw1.io >
2025-08-16 04:50:20 +05:30
HD Moore
5b89811b90
Support concurrent Nuclei engines in the same process ( #6322 )
...
* support for concurrent nuclei engines
* clarify LfaAllowed race
* remove unused mutex
* update LfaAllowed logic to prevent races until it can be reworked for per-execution ID
* Update pkg/templates/parser.go
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
* debug tests
* debug gh action
* fixig gh template test
* using atomic
* using synclockmap
* restore tests concurrency
* lint
* wiring executionId in js fs
---------
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
Co-authored-by: Mzack9999 <mzack9999@protonmail.com >
2025-07-19 00:10:58 +05:30
Mzack9999
87de71dee9
bumping version + memory cleanup
2025-07-07 18:12:50 +02:00
Dwi Siswanto
87ed0b2bb9
build: bump all direct modules ( #6290 )
...
* chore: fix non-constant fmt string in call
Signed-off-by: Dwi Siswanto <git@dw1.io >
* build: bump all direct modules
Signed-off-by: Dwi Siswanto <git@dw1.io >
* chore(hosterrorscache): update import path
Signed-off-by: Dwi Siswanto <git@dw1.io >
* fix(charts): break changes
Signed-off-by: Dwi Siswanto <git@dw1.io >
* build: pinned `github.com/zmap/zcrypto` to v0.0.0-20240512203510-0fef58d9a9db
Signed-off-by: Dwi Siswanto <git@dw1.io >
* chore: golangci-lint auto fixes
Signed-off-by: Dwi Siswanto <git@dw1.io >
* chore: satisfy lints
Signed-off-by: Dwi Siswanto <git@dw1.io >
* build: migrate `github.com/xanzy/go-gitlab` => `gitlab.com/gitlab-org/api/client-go`
Signed-off-by: Dwi Siswanto <git@dw1.io >
* feat(json): update build constraints
Signed-off-by: Dwi Siswanto <git@dw1.io >
* chore: dont panicking on close err
Signed-off-by: Dwi Siswanto <git@dw1.io >
---------
Signed-off-by: Dwi Siswanto <git@dw1.io >
2025-07-01 00:40:44 +07:00
Dwi Siswanto
622c5503fa
perf(*): replace encoding/json w/ sonic or go-json (fallback) ( #6019 )
...
* perf(*): replace `encoding/json` w/ sonic
Signed-off-by: Dwi Siswanto <git@dw1.io >
* feat(utils): add `json` pkg (sonic wrapper)
Signed-off-by: Dwi Siswanto <git@dw1.io >
* chore(*): use `sonic` wrapper instead
Signed-off-by: Dwi Siswanto <git@dw1.io >
* chore(*): replace `sonic.ConfigStd` -> `json` (wrapper)
Signed-off-by: Dwi Siswanto <git@dw1.io >
* test(model): adjust expected marshal'd JSON
Signed-off-by: Dwi Siswanto <git@dw1.io >
* feat(json): dynamic backend; `sonic` -> `go-json` (fallback)
Signed-off-by: Dwi Siswanto <git@dw1.io >
* chore(json): merge config - as its not usable
Signed-off-by: Dwi Siswanto <git@dw1.io >
* chore(json): rm go version constraints
Signed-off-by: Dwi Siswanto <git@dw1.io >
* chore: go mod tidy
Signed-off-by: Dwi Siswanto <git@dw1.io >
---------
Signed-off-by: Dwi Siswanto <git@dw1.io >
2025-02-11 03:01:37 +05:30
Dwi Siswanto
d699c278cd
fix(installer): handle removal of deleted templates during update ( #5998 )
...
* fix(installer): handle removal of deleted templates during update
Signed-off-by: Dwi Siswanto <git@dw1.io >
* chore(installer): no log for non-existent deleted templates err
Signed-off-by: Dwi Siswanto <git@dw1.io >
* feat(installer): purge empty dirs after removing deleted templates
Signed-off-by: Dwi Siswanto <git@dw1.io >
* Revert "feat(installer): purge empty dirs after removing deleted templates"
This reverts commit 8175e2a291 .
* fix(installer): use semicolons as delimiters
Signed-off-by: Dwi Siswanto <git@dw1.io >
* feat(installer): add mods count in `*templateUpdateResults.String`
Signed-off-by: Dwi Siswanto <git@dw1.io >
---------
Signed-off-by: Dwi Siswanto <git@dw1.io >
2025-01-27 15:22:11 +05:30
Mzack9999
ac0107c242
revert
2024-06-11 14:58:58 +02:00
Mzack9999
9f1414e3e8
.
2024-06-11 13:38:28 +02:00
Tarun Koyalwar
3e54ca54b0
feat: fix utils and add goroutine leak unit tests ( #5112 )
...
* feat: fixed leak
* add go leak unit test in sdk
* added goleak unit tests
* bugfix: add random user agents to fuzzing requests
* misc
* misc
* fix lint + use utils pr + misc
* fix ratelimit memleak in sdk
* close protocolstate shared resources in nuclei sdk/lib
* add missing close references
* ignore read/write loop of intransit connections
* close unnecessary idle conns
* add ignore method
* using fixed utils
* dep update
---------
Co-authored-by: Ice3man <nizamulrana@gmail.com >
Co-authored-by: mzack <marco.rivoli.nvh@gmail.com >
Co-authored-by: sandeep <8293321+ehsandeep@users.noreply.github.com >
2024-05-01 00:28:11 +05:30
Tarun Koyalwar
79c98e8bf9
use pdtm params from utils
2024-02-17 17:07:43 +05:30
Tarun Koyalwar
83681fb308
misc sdk enhancements ( #4301 )
...
* add template sign/parse methods
* export installer package
* add readme
* consistent implementation of writefailure
* fix lint error
2023-10-30 19:02:06 +05:30