2018-11-05 10:06:39 +00:00
|
|
|
/* eslint-disable
|
|
|
|
max-len,
|
|
|
|
no-return-assign,
|
|
|
|
*/
|
|
|
|
// TODO: This file was created by bulk-decaffeinate.
|
|
|
|
// Fix any style issues and re-enable lint.
|
|
|
|
/*
|
|
|
|
* decaffeinate suggestions:
|
|
|
|
* DS102: Remove unnecessary code created because of implicit returns
|
|
|
|
* DS207: Consider shorter variations of null checks
|
|
|
|
* Full docs: https://github.com/decaffeinate/decaffeinate/blob/master/docs/suggestions.md
|
|
|
|
*/
|
|
|
|
// This file is shared between the frontend and server code of web, so that
|
|
|
|
// filename validation is the same in both implementations.
|
2020-12-09 11:55:36 +00:00
|
|
|
// The logic in all copies must be kept in sync:
|
|
|
|
// app/src/Features/Project/SafePath.js
|
|
|
|
// frontend/js/ide/directives/SafePath.js
|
|
|
|
// frontend/js/features/file-tree/util/safe-path.js
|
2018-11-05 10:06:39 +00:00
|
|
|
|
2020-05-19 09:02:56 +00:00
|
|
|
let SafePath
|
2021-04-28 08:45:41 +00:00
|
|
|
// eslint-disable-next-line prefer-regex-literals
|
2020-05-19 09:02:56 +00:00
|
|
|
const BADCHAR_RX = new RegExp(
|
|
|
|
`\
|
2018-11-05 10:06:39 +00:00
|
|
|
[\
|
|
|
|
\\/\
|
|
|
|
\\\\\
|
|
|
|
\\*\
|
|
|
|
\\u0000-\\u001F\
|
|
|
|
\\u007F\
|
|
|
|
\\u0080-\\u009F\
|
|
|
|
\\uD800-\\uDFFF\
|
|
|
|
]\
|
|
|
|
`,
|
2020-05-19 09:02:56 +00:00
|
|
|
'g'
|
|
|
|
)
|
2018-11-05 10:06:39 +00:00
|
|
|
|
2021-04-28 08:45:41 +00:00
|
|
|
// eslint-disable-next-line prefer-regex-literals
|
2020-05-19 09:02:56 +00:00
|
|
|
const BADFILE_RX = new RegExp(
|
|
|
|
`\
|
2018-11-05 10:06:39 +00:00
|
|
|
(^\\.$)\
|
|
|
|
|(^\\.\\.$)\
|
|
|
|
|(^\\s+)\
|
|
|
|
|(\\s+$)\
|
|
|
|
`,
|
2020-05-19 09:02:56 +00:00
|
|
|
'g'
|
|
|
|
)
|
2018-11-05 10:06:39 +00:00
|
|
|
|
2020-05-19 09:02:56 +00:00
|
|
|
// Put a block on filenames which match javascript property names, as they
|
|
|
|
// can cause exceptions where the code puts filenames into a hash. This is a
|
|
|
|
// temporary workaround until the code in other places is made safe against
|
|
|
|
// property names.
|
|
|
|
//
|
|
|
|
// The list of property names is taken from
|
|
|
|
// ['prototype'].concat(Object.getOwnPropertyNames(Object.prototype))
|
2021-04-28 08:45:41 +00:00
|
|
|
// eslint-disable-next-line prefer-regex-literals
|
2020-05-19 09:02:56 +00:00
|
|
|
const BLOCKEDFILE_RX = new RegExp(`\
|
2018-11-05 10:06:39 +00:00
|
|
|
^(\
|
|
|
|
prototype\
|
|
|
|
|constructor\
|
|
|
|
|toString\
|
|
|
|
|toLocaleString\
|
|
|
|
|valueOf\
|
|
|
|
|hasOwnProperty\
|
|
|
|
|isPrototypeOf\
|
|
|
|
|propertyIsEnumerable\
|
|
|
|
|__defineGetter__\
|
|
|
|
|__lookupGetter__\
|
|
|
|
|__defineSetter__\
|
|
|
|
|__lookupSetter__\
|
|
|
|
|__proto__\
|
|
|
|
)$\
|
|
|
|
`)
|
|
|
|
|
2020-05-19 09:02:56 +00:00
|
|
|
const MAX_PATH = 1024 // Maximum path length, in characters. This is fairly arbitrary.
|
2018-11-05 10:06:39 +00:00
|
|
|
|
2020-12-15 10:23:54 +00:00
|
|
|
export default SafePath = {
|
2020-05-19 09:02:56 +00:00
|
|
|
clean(filename) {
|
|
|
|
filename = filename.replace(BADCHAR_RX, '_')
|
|
|
|
// for BADFILE_RX replace any matches with an equal number of underscores
|
|
|
|
filename = filename.replace(BADFILE_RX, match =>
|
|
|
|
new Array(match.length + 1).join('_')
|
|
|
|
)
|
|
|
|
// replace blocked filenames 'prototype' with '@prototype'
|
|
|
|
filename = filename.replace(BLOCKEDFILE_RX, '@$1')
|
|
|
|
return filename
|
|
|
|
},
|
2018-11-05 10:06:39 +00:00
|
|
|
|
2020-05-19 09:02:56 +00:00
|
|
|
isCleanFilename(filename) {
|
|
|
|
return (
|
|
|
|
SafePath.isAllowedLength(filename) &&
|
|
|
|
!filename.match(BADCHAR_RX) &&
|
|
|
|
!filename.match(BADFILE_RX)
|
|
|
|
)
|
|
|
|
},
|
2018-11-05 10:06:39 +00:00
|
|
|
|
2020-05-19 09:02:56 +00:00
|
|
|
isAllowedLength(pathname) {
|
|
|
|
return pathname.length > 0 && pathname.length <= MAX_PATH
|
2021-04-27 07:52:58 +00:00
|
|
|
},
|
2020-12-15 10:23:54 +00:00
|
|
|
}
|