fix(api): reject invalid UUID variants
This commit is contained in:
@@ -10,7 +10,7 @@ import (
|
|||||||
// IdentityParam 只接受 UUIDv7 路径参数,避免把内部自增 ID 暴露为外部标识。
|
// IdentityParam 只接受 UUIDv7 路径参数,避免把内部自增 ID 暴露为外部标识。
|
||||||
func IdentityParam(c *gin.Context, name string) (string, bool) {
|
func IdentityParam(c *gin.Context, name string) (string, bool) {
|
||||||
identity, err := uuid.Parse(c.Param(name))
|
identity, err := uuid.Parse(c.Param(name))
|
||||||
if err != nil || identity.Version() != 7 {
|
if err != nil || identity.Version() != 7 || identity.Variant() != uuid.RFC4122 {
|
||||||
Error(c, http.StatusBadRequest, "invalid_request", "请求参数无效")
|
Error(c, http.StatusBadRequest, "invalid_request", "请求参数无效")
|
||||||
return "", false
|
return "", false
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -41,6 +41,7 @@ func TestIdentityParamRejectsNonUUIDV7(t *testing.T) {
|
|||||||
}{
|
}{
|
||||||
{name: "internal numeric ID", value: "42"},
|
{name: "internal numeric ID", value: "42"},
|
||||||
{name: "UUID v4", value: "550e8400-e29b-41d4-a716-446655440000"},
|
{name: "UUID v4", value: "550e8400-e29b-41d4-a716-446655440000"},
|
||||||
|
{name: "UUID v7 with invalid variant", value: "018f0c9a-7b3c-7cc1-78c8-0242ac120002"},
|
||||||
}
|
}
|
||||||
|
|
||||||
for _, tt := range tests {
|
for _, tt := range tests {
|
||||||
|
|||||||
Reference in New Issue
Block a user