fix(desktop): constrain baked environment and validate registered feeds

This commit is contained in:
ethernet
2026-09-24 09:16:34 -04:00
parent 5da731b39a
commit edcb3346a7
13 changed files with 74 additions and 24 deletions

View File

@@ -3,15 +3,20 @@ from __future__ import annotations
from collections.abc import Sequence
import json
import re
# Keep this list aligned with the Desktop bundle banner and channel decoder.
_ALLOWED = frozenset({
"HERMES_HOME", "HERMES_DATA_DIR_SUFFIX", "HERMES_DESKTOP_USER_DATA_DIR",
"HERMES_SHARED_AUTH_DIR", "HERMES_GUEST_ONBOARDING", "HERMES_SKIP_INTRO",
})
def validate(values: object) -> dict[str, str | None]:
if not isinstance(values, dict):
raise ValueError("Bundle environment must be a JSON object")
for key, value in values.items():
if not isinstance(key, str) or not re.fullmatch(r"[A-Za-z_][A-Za-z0-9_]*", key):
raise ValueError("Bundle environment names must be valid environment identifiers")
if not isinstance(key, str) or key not in _ALLOWED:
raise ValueError(f"Bundle environment name is not permitted: {key}")
if value is not None and (not isinstance(value, str) or "\0" in value):
raise ValueError(f"Bundle environment value for {key} must be a string without NUL or null")
return values