Uploaded image for project: 'Guacamole'
  1. Guacamole
  2. GUACAMOLE-1261

Users/groups with identifiers containing slashes cannot be modified

    XMLWordPrintableJSON

    Details

    • Type: Bug
    • Status: Reopened
    • Priority: Minor
    • Resolution: Unresolved
    • Affects Version/s: None
    • Fix Version/s: 1.4.0
    • Component/s: guacamole
    • Labels:
      None

      Description

      When a forward slash in included in the name of a User Group, the hyperlink that is supposed direct the user to the settings page for that User Group is broken, redirecting the user to the main page. This is because the slash is not properly escaped in the URL, leading to it's interpretation as part of the path.

      Once this happens, the only way to delete/update that User Group is through deleting/updating its entry in the MySQL/Postgresql database directly.

      This is likely present in other areas of the website, such as users, connections, etc. The most probable solution involves improving input validation through, for example, disallowing the use of forward slashes in names.

        Attachments

          Activity

            People

            • Assignee:
              vnick Nick Couchman
              Reporter:
              dgmcdona David McDonald
            • Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

              • Created:
                Updated: