Skip to content

Protect testcase task-log downloads#5214

Open
M0nd0R wants to merge 1 commit intogoogle:masterfrom
M0nd0R:fix-task-log-access
Open

Protect testcase task-log downloads#5214
M0nd0R wants to merge 1 commit intogoogle:masterfrom
M0nd0R:fix-task-log-access

Conversation

@M0nd0R
Copy link

@M0nd0R M0nd0R commented Mar 21, 2026

This change protects /testcase-detail/task-log by enforcing testcase access checks before returning log content.

It also escapes task log filter values before building the Cloud Logging query so user-controlled task parameters cannot alter the intended filter.

Require testcase access before serving task logs and escape Cloud Logging filter values so task parameters cannot bypass the intended query constraints.
@M0nd0R M0nd0R requested a review from a team as a code owner March 21, 2026 01:59
@google-cla
Copy link

google-cla bot commented Mar 21, 2026

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant