Skip to content

Commit de9bcd1

Browse files
authored
Avoid 500 panic error when uploading invalid maven package file (#31014)
PackageDescriptor.Metadata might be nil (and maybe not only for maven). This is only a quick fix. The new `if` block is written intentionally to avoid unnecessary indenting to the existing code.
1 parent f48cc50 commit de9bcd1

File tree

4 files changed

+20
-2
lines changed

4 files changed

+20
-2
lines changed

options/locale/locale_en-US.ini

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3415,6 +3415,7 @@ error.unit_not_allowed = You are not allowed to access this repository section.
34153415
title = Packages
34163416
desc = Manage repository packages.
34173417
empty = There are no packages yet.
3418+
no_metadata = No metadata.
34183419
empty.documentation = For more information on the package registry, see <a target="_blank" rel="noopener noreferrer" href="%s">the documentation</a>.
34193420
empty.repo = Did you upload a package, but it's not shown here? Go to <a href="%[1]s">package settings</a> and link it to this repo.
34203421
registry.documentation = For more information on the %s registry, see <a target="_blank" rel="noopener noreferrer" href="%s">the documentation</a>.

templates/package/content/maven.tmpl

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,8 @@
1-
{{if eq .PackageDescriptor.Package.Type "maven"}}
1+
{{if and (eq .PackageDescriptor.Package.Type "maven") (not .PackageDescriptor.Metadata)}}
2+
<h4 class="ui top attached header">{{ctx.Locale.Tr "packages.installation"}}</h4>
3+
<div class="ui attached segment">{{ctx.Locale.Tr "packages.no_metadata"}}</div>
4+
{{end}}
5+
{{if and (eq .PackageDescriptor.Package.Type "maven") .PackageDescriptor.Metadata}}
26
<h4 class="ui top attached header">{{ctx.Locale.Tr "packages.installation"}}</h4>
37
<div class="ui attached segment">
48
<div class="ui form">

templates/package/metadata/maven.tmpl

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,7 @@
1-
{{if eq .PackageDescriptor.Package.Type "maven"}}
1+
{{if and (eq .PackageDescriptor.Package.Type "maven") (not .PackageDescriptor.Metadata)}}
2+
<div class="item">{{svg "octicon-note" 16 "tw-mr-2"}} {{ctx.Locale.Tr "packages.no_metadata"}}</div>
3+
{{end}}
4+
{{if and (eq .PackageDescriptor.Package.Type "maven") .PackageDescriptor.Metadata}}
25
{{if .PackageDescriptor.Metadata.Name}}<div class="item">{{svg "octicon-note" 16 "tw-mr-2"}} {{.PackageDescriptor.Metadata.Name}}</div>{{end}}
36
{{if .PackageDescriptor.Metadata.ProjectURL}}<div class="item">{{svg "octicon-link-external" 16 "tw-mr-2"}} <a href="{{.PackageDescriptor.Metadata.ProjectURL}}" target="_blank" rel="noopener noreferrer me">{{ctx.Locale.Tr "packages.details.project_site"}}</a></div>{{end}}
47
{{range .PackageDescriptor.Metadata.Licenses}}<div class="item" title="{{ctx.Locale.Tr "packages.details.license"}}">{{svg "octicon-law" 16 "tw-mr-2"}} {{.}}</div>{{end}}

tests/integration/api_packages_maven_test.go

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -15,6 +15,7 @@ import (
1515
"code.gitea.io/gitea/models/unittest"
1616
user_model "code.gitea.io/gitea/models/user"
1717
"code.gitea.io/gitea/modules/packages/maven"
18+
"code.gitea.io/gitea/modules/test"
1819
"code.gitea.io/gitea/tests"
1920

2021
"github.com/stretchr/testify/assert"
@@ -241,4 +242,13 @@ func TestPackageMaven(t *testing.T) {
241242
putFile(t, fmt.Sprintf("/%s/maven-metadata.xml", snapshotVersion), "test", http.StatusCreated)
242243
putFile(t, fmt.Sprintf("/%s/maven-metadata.xml", snapshotVersion), "test-overwrite", http.StatusCreated)
243244
})
245+
246+
t.Run("InvalidFile", func(t *testing.T) {
247+
ver := packageVersion + "-invalid"
248+
putFile(t, fmt.Sprintf("/%s/%s", ver, filename), "any invalid content", http.StatusCreated)
249+
req := NewRequestf(t, "GET", "/%s/-/packages/maven/%s-%s/%s", user.Name, groupID, artifactID, ver)
250+
resp := MakeRequest(t, req, http.StatusOK)
251+
assert.Contains(t, resp.Body.String(), "No metadata.")
252+
assert.True(t, test.IsNormalPageCompleted(resp.Body.String()))
253+
})
244254
}

0 commit comments

Comments
 (0)