Documentation
¶
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func NormalizeMethod ¶
NormalizeMethod validates and cleans a service invocation method name. It rejects methods containing '#', '?', '\', null bytes, control characters (bytes 0x01-0x1f and 0x7f), or a percent-encoded '/', '\' or '.' (%2F, %5C, %2E in any case), then resolves path traversal via path.Clean. The caller is responsible for percent-decoding (for HTTP) before calling. Encoded separators and dots are rejected because the ACL matches them as literal characters, while an HTTP app decodes them into path segments. A literal backslash is rejected because it is re-encoded to %5C on the wire to the app, which decodes it back into a character the ACL did not split on.
func ValidateName ¶
ValidateName checks that a name (e.g. an actor type, actor ID, reminder or timer name) does not contain characters that could cause path traversal or injection when the name is embedded in a URL path. Unlike NormalizeMethod, this rejects any name containing '/' or '\' since names are identifiers, not paths, and, like NormalizeMethod, a percent-encoded '/', '\' or '.', which the app would decode into a path segment.
Types ¶
This section is empty.