1
0
Fork 0
mirror of https://github.com/moby/moby.git synced 2022-11-09 12:21:53 -05:00
moby--moby/pkg
Liron Levin ca5c2abecf Fix #20508 - Authz plugin enabled with large text/JSON POST payload corrupts body
Based on the discussion, we have changed the following:

1. Send body only if content-type is application/json (based on the
Docker official daemon REST specification, this is the provided for all
APIs that requires authorization.

2. Correctly verify that the msg body is smaller than max cap (this was
the actual bug). Fix includes UT.

3. Minor: Check content length > 0 (it was -1 for load, altough an
attacker can still modify this)

Signed-off-by: Liron Levin <liron@twistlock.com>
2016-02-25 08:11:55 +02:00
..
aaparser apparmor: fix version checks to work properly 2016-02-15 20:36:07 +11:00
archive Windows CI: test-unit on pkg\archive part 2 2016-02-12 15:40:41 -08:00
authorization Fix #20508 - Authz plugin enabled with large text/JSON POST payload corrupts body 2016-02-25 08:11:55 +02:00
broadcaster
chrootarchive
devicemapper
directory
discovery
fileutils
gitutils Windows CI: Unit tests - port pkg\gitutils 2016-02-11 18:19:17 -08:00
graphdb
homedir
httputils
idtools
integration Windows CI: Fix test-unit for pkg\integration 2016-02-11 15:06:22 -08:00
ioutils Cleanup WriteFlusher 2016-02-09 14:02:26 -05:00
jsonlog
jsonmessage
locker
longpath
loopback
mflag Merge pull request #19517 from calavera/validate_config_keys 2016-01-22 15:01:29 -05:00
mount Windows CI: Unit Test - pkg/mount is Unix specific 2016-02-10 18:09:15 -08:00
namesgenerator Adding biologist Christiane Nüsslein Volhard and AI pioneer Marvin Minsky 2016-01-28 14:33:58 +00:00
parsers
pidfile
platform
plugins Add support for forwarding Docker client through SOCKS proxy 2016-02-16 11:09:28 -08:00
pools
progress
promise
proxy
pubsub Use pool for pubsub Publish's waitgroups 2016-02-17 14:36:57 -05:00
random
reexec
registrar
signal
stdcopy
streamformatter
stringid
stringutils
symlink
sysinfo Reuse subsystems mountpoints between checks 2016-01-20 19:20:59 -08:00
system Fixing 'docker save' on Windows. 2016-02-08 18:08:49 -08:00
tailfile
tarsum fix common misspell 2016-02-11 15:49:36 -08:00
term Improvements to ANSI emulation in conemu 2016-01-28 20:37:42 -08:00
tlsconfig
truncindex
urlutil Fix 'tcp+tls' protocol not being accepted 2016-02-08 17:34:39 +00:00
useragent
version
README.md

pkg/ is a collection of utility packages used by the Docker project without being specific to its internals.

Utility packages are kept separate from the docker core codebase to keep it as small and concise as possible. If some utilities grow larger and their APIs stabilize, they may be moved to their own repository under the Docker organization, to facilitate re-use by other projects. However that is not the priority.

The directory pkg is named after the same directory in the camlistore project. Since Brad is a core Go maintainer, we thought it made sense to copy his methods for organizing Go code :) Thanks Brad!

Because utility packages are small and neatly separated from the rest of the codebase, they are a good place to start for aspiring maintainers and contributors. Get in touch if you want to help maintain them!