fix(util): reject invalid characters between time-estimate units - #38416
Merged
bircni merged 3 commits intoJul 12, 2026
Conversation
TimeEstimateParse only verified that the first token starts at the beginning of the string and the last token ends at its end, but never checked the gaps between consecutive tokens. Non-whitespace garbage embedded between two valid units (e.g. "1h 2x 3m", "1h_2m", "1h,1m") was silently dropped and the string was accepted with a wrong value instead of being rejected, so the issue time-estimate form saved an unintended duration rather than reporting the input as invalid. Reject any non-whitespace content between two matched units. Assisted-by: Claude Code:claude-fable-5 Signed-off-by: TowyTowy <towy@airreps.link>
bircni
approved these changes
Jul 12, 2026
wxiaoguang
approved these changes
Jul 12, 2026
Signed-off-by: wxiaoguang <wxiaoguang@gmail.com>
bircni
enabled auto-merge (squash)
July 12, 2026 13:15
bircni
pushed a commit
that referenced
this pull request
Jul 12, 2026
) (#38423) Backport #38416 by @TowyTowy ### What / why `TimeEstimateParse` (used by the issue time-estimate form) only checked that the first token starts at the beginning of the string and the last token ends at its end, but never checked the gaps between consecutive tokens. Non-whitespace garbage embedded between two valid units was silently dropped and the string accepted with a wrong value instead of being reported as invalid. Examples that were wrongly accepted before this change: - `1h 2x 3m` → 3780s (parsed as 1h3m) - `1h_2m` → 3720s - `1h,1m` → 3660s All three now return an "invalid time string" error, while valid inputs such as `1h 1m 1s` and `1h1m1s` keep working. ### How Reject any non-whitespace content between two matched units. Signed-off-by: TowyTowy <towy@airreps.link> Signed-off-by: wxiaoguang <wxiaoguang@gmail.com> Co-authored-by: TowyTowy <85077986+TowyTowy@users.noreply.github.com> Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
zjjhot
added a commit
to zjjhot/gitea
that referenced
this pull request
Jul 13, 2026
* 'main' of https://github.com/go-gitea/gitea: fix: various security fixes (go-gitea#38406) fix(util): reject invalid characters between time-estimate units (go-gitea#38416) feat(actions): implement adaptive auto-refresh for workflow runs list (go-gitea#38329) fix(turnstile): route CAPTCHA verification through the configured proxy (go-gitea#38412) fix: represent a deleted assignee team as a Ghost team (go-gitea#38413) [skip ci] Updated translations via Crowdin fix: refresh pull request merge box when the commit status is pending (go-gitea#38410) chore: remove Yarden Shoham from maintainers (go-gitea#38407) fix: actions task state concurrent update (go-gitea#38405) fix(actions): keep workflow run trailing on one row with long branch names (go-gitea#38382) fix(pull): re-evaluate review official flag on target branch change (go-gitea#38319) fix(web): use locale-aware date formatting for contribution calendar tooltips (go-gitea#38398) fix(security): harden access checks and migration validation (go-gitea#38324) fix: enforce public-only token scope and harden push options / locale parsing (go-gitea#38323) fix: co-author detection (go-gitea#38392) fix(api): stop leaking private repo metadata after access revocation (go-gitea#38321) fix(lfs): require proof of possession for cross-repo objects (go-gitea#38322) fix: incorrect co-author detection on commit page (go-gitea#38386)
zjjhot
added a commit
to zjjhot/gitea
that referenced
this pull request
Jul 13, 2026
* main: fix: various security fixes (go-gitea#38406) fix(util): reject invalid characters between time-estimate units (go-gitea#38416) feat(actions): implement adaptive auto-refresh for workflow runs list (go-gitea#38329) fix(turnstile): route CAPTCHA verification through the configured proxy (go-gitea#38412) fix: represent a deleted assignee team as a Ghost team (go-gitea#38413) [skip ci] Updated translations via Crowdin fix: refresh pull request merge box when the commit status is pending (go-gitea#38410) chore: remove Yarden Shoham from maintainers (go-gitea#38407) fix: actions task state concurrent update (go-gitea#38405) fix(actions): keep workflow run trailing on one row with long branch names (go-gitea#38382) fix(pull): re-evaluate review official flag on target branch change (go-gitea#38319) fix(web): use locale-aware date formatting for contribution calendar tooltips (go-gitea#38398) fix(security): harden access checks and migration validation (go-gitea#38324) fix: enforce public-only token scope and harden push options / locale parsing (go-gitea#38323) fix: co-author detection (go-gitea#38392) fix(api): stop leaking private repo metadata after access revocation (go-gitea#38321) fix(lfs): require proof of possession for cross-repo objects (go-gitea#38322) fix: incorrect co-author detection on commit page (go-gitea#38386)
zeekay
pushed a commit
to hanzoai/git
that referenced
this pull request
Jul 26, 2026
…gitea#38416) ### What / why `TimeEstimateParse` (used by the issue time-estimate form) only checked that the first token starts at the beginning of the string and the last token ends at its end, but never checked the gaps between consecutive tokens. Non-whitespace garbage embedded between two valid units was silently dropped and the string accepted with a wrong value instead of being reported as invalid. Examples that were wrongly accepted before this change: - `1h 2x 3m` → 3780s (parsed as 1h3m) - `1h_2m` → 3720s - `1h,1m` → 3660s All three now return an "invalid time string" error, while valid inputs such as `1h 1m 1s` and `1h1m1s` keep working. ### How Reject any non-whitespace content between two matched units. --------- Signed-off-by: TowyTowy <towy@airreps.link> Signed-off-by: wxiaoguang <wxiaoguang@gmail.com> Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What / why
TimeEstimateParse(used by the issue time-estimate form) only checked that the first token starts at the beginning of the string and the last token ends at its end, but never checked the gaps between consecutive tokens. Non-whitespace garbage embedded between two valid units was silently dropped and the string accepted with a wrong value instead of being reported as invalid.Examples that were wrongly accepted before this change:
1h 2x 3m→ 3780s (parsed as 1h3m)1h_2m→ 3720s1h,1m→ 3660sAll three now return an "invalid time string" error, while valid inputs such as
1h 1m 1sand1h1m1skeep working.How
Reject any non-whitespace content between two matched units.