fix: prevent nil pointer panic in webhook sendLog

Add missing return statements after error checks in sendLog. When
json.Marshal or http.NewRequest fails, the error is logged but
execution continues. If http.NewRequest returns a nil *Request,
the subsequent req.Header.Set call panics with a nil pointer
dereference.

This bug was introduced in PR #129 (2023-07-14) and has been
present for nearly 3 years.

Signed-off-by: Sebastien Tardif <sebtardif@ncf.ca>
This commit is contained in:
Sebastien Tardif
2026-06-08 18:45:53 -07:00
parent b348ff29f0
commit 50e64f7e78
2 changed files with 26 additions and 0 deletions
+2
View File
@@ -131,11 +131,13 @@ func (wl *WebhookLogger) sendLog(lf LogFields) {
jsonLog, err := json.Marshal(lf)
if err != nil {
fmt.Fprintf(os.Stderr, "failed to parse the log data: %v\n", err.Error())
return
}
req, err := http.NewRequest(http.MethodPost, wl.url, bytes.NewReader(jsonLog))
if err != nil {
fmt.Fprintln(os.Stderr, err)
return
}
req.Header.Set("Content-Type", "application/json; charset=utf-8")
+24
View File
@@ -0,0 +1,24 @@
// Copyright 2023 Versity Software
// This file is licensed under the Apache License, Version 2.0
// (the "License"); you may not use this file except in compliance
// with the License. You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing,
// software distributed under the License is distributed on an
// "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
// KIND, either express or implied. See the License for the
// specific language governing permissions and limitations
// under the License.
package s3log
import "testing"
func TestSendLog_InvalidURL_NoPanic(t *testing.T) {
wl := &WebhookLogger{url: "://invalid"}
// sendLog must not panic when http.NewRequest fails due to
// an invalid URL. Before the fix, the nil req was dereferenced.
wl.sendLog(LogFields{})
}