Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions video/info.py
Original file line number Diff line number Diff line change
Expand Up @@ -34,6 +34,7 @@ def _get_info(self, video):
"-count_frames",
"-show_streams",
"-i",
"--",
input_path,
]
with Popen(
Expand Down
7 changes: 4 additions & 3 deletions video/utils.py
Original file line number Diff line number Diff line change
Expand Up @@ -34,13 +34,14 @@ def validate_video_name(name):
raise ValueError("Video name cannot be empty")
# Disallow path separators to ensure this is just a file name.
if os.sep in cleaned or "/" in cleaned or "\\" in cleaned:
raise ValueError(f"Invalid video name: {cleaned}")
# Restrict the video name to a safe subset of characters to avoid
# passing arbitrary strings to external commands.
# Allow letters, digits, underscore, hyphen and dot, and disallow
# leading dot to avoid hidden or special files.
if cleaned.startswith("."):
# leading dot and leading hyphen to avoid hidden/special files and
# command option injection.
if cleaned.startswith(".") or cleaned.startswith("-"):
raise ValueError(f"Invalid video name: {cleaned}")
if not re.fullmatch(r"[A-Za-z0-9._-]+", cleaned):
raise ValueError(f"Invalid video name: {cleaned}")
raise ValueError(f"Invalid video name: {cleaned}")
return cleaned