fix: fetch route fails closed for unknown sites (#94)

Security review found the route's old default handed the TLS fetcher to
any unrecognised site string; unreachable today because the shared read
gates first, but a trap for a future caller that skips the gate. Returns
nil now, matching the registry's zero-entry handling and the function's
own docstring. Review's log-injection finding (unquoted series_url in
read.go error wraps) was verified against Go's url.Parse and does not
hold: control characters are rejected anywhere in the URL, so a
client-supplied value reaching the log cannot carry a newline.
This commit is contained in:
2026-08-12 00:34:24 +07:00
parent d998f8725c
commit 700de20225
2 changed files with 9 additions and 1 deletions
+7 -1
View File
@@ -124,7 +124,13 @@ func (p *Poller) storeCover(ctx context.Context, sr store.Series, sourceURL stri
// absent, the entry's Fallback decides whether plain TLS may take over. One
// routing rule for the poll and the acquirer, so the two cannot drift apart.
func fetcherFor(site string, browser, tls Fetcher) Fetcher {
s := sites[site]
s, known := sites[site]
if !known {
// No registry entry means nothing to fetch or parse; fail closed even
// though the only caller gates first, so a future caller that skips
// the gate cannot hand an arbitrary https URL to the TLS fetcher.
return nil
}
if s.Browser == nil {
return tls
}