Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix: handle InvalidLabelChar in URL validation to prevent panic #24080

Closed
Show file tree
Hide file tree
Changes from 1 commit
Commits
Show all changes
38 commits
Select commit Hold shift click to select a range
f979e0c
handle InvalidLabelChar in URL validation to prevent panic
yazan-abdalrahman Jun 2, 2024
2d8e29a
ci: trigger CI pipeline
yazan-abdalrahman Jun 3, 2024
ba2b828
Merge branch 'main' into fix-url-validation-panic
yazan-abdalrahman Jun 3, 2024
a5199a3
Merge branch 'main' into fix-url-validation-panic
yazan-abdalrahman Jun 4, 2024
78ddde1
Merge branch 'main' into fix-url-validation-panic
yazan-abdalrahman Jun 4, 2024
1fe2399
Merge branch 'main' into fix-url-validation-panic
yazan-abdalrahman Jun 5, 2024
6d254a1
fix lint issues
yazan-abdalrahman Jun 6, 2024
c8488b6
Merge remote-tracking branch 'origin/fix-url-validation-panic' into f…
yazan-abdalrahman Jun 6, 2024
3a875fd
Merge branch 'main' into fix-url-validation-panic
yazan-abdalrahman Jun 6, 2024
9971b64
handle empty value
yazan-abdalrahman Jun 9, 2024
6a92d09
Merge branch 'main' of https://github.com/yazan-abdalrahman/deno into…
yazan-abdalrahman Jun 9, 2024
5db82f3
fix cyclic dependence
yazan-abdalrahman Jun 10, 2024
f942a31
Merge branch 'main' into fix-url-validation-panic
yazan-abdalrahman Jun 10, 2024
9146e36
Merge branch 'main' into fix-url-validation-panic
yazan-abdalrahman Jun 11, 2024
e8b5b29
Merge branch 'main' into fix-url-validation-panic
yazan-abdalrahman Jun 11, 2024
c20874c
Merge branch 'main' into fix-url-validation-panic
yazan-abdalrahman Jun 11, 2024
7cff4e2
Merge branch 'main' into fix-url-validation-panic
yazan-abdalrahman Jun 11, 2024
a8324ae
Merge branch 'main' into fix-url-validation-panic
yazan-abdalrahman Jun 12, 2024
2a4dc4b
Merge branch 'main' into fix-url-validation-panic
yazan-abdalrahman Jun 12, 2024
3655231
Merge branch 'main' into fix-url-validation-panic
yazan-abdalrahman Jun 13, 2024
41b0cb2
Merge branch 'main' into fix-url-validation-panic
yazan-abdalrahman Jun 13, 2024
94fe173
Merge branch 'main' of https://github.com/yazan-abdalrahman/deno into…
yazan-abdalrahman Jun 20, 2024
5178a56
Merge branch 'main' of https://github.com/yazan-abdalrahman/deno into…
yazan-abdalrahman Jun 23, 2024
d4ed2f9
Merge branch 'main' of https://github.com/yazan-abdalrahman/deno into…
yazan-abdalrahman Jun 24, 2024
7a50fde
fix test failures
yazan-abdalrahman Jun 24, 2024
8701009
Merge branch 'main' into fix-url-validation-panic
yazan-abdalrahman Jun 24, 2024
378a168
Remove file
dsherret Jun 24, 2024
f0642d3
Remove processing a URL &&
yazan-abdalrahman Jun 25, 2024
f156f3f
Merge remote-tracking branch 'origin/fix-url-validation-panic' into f…
yazan-abdalrahman Jun 25, 2024
8012e79
Merge branch 'main' into fix-url-validation-panic
yazan-abdalrahman Jun 25, 2024
731de60
Merge branch 'main' into fix-url-validation-panic
yazan-abdalrahman Jun 25, 2024
81cee0c
Merge branch 'main' into fix-url-validation-panic
yazan-abdalrahman Jun 25, 2024
a566a11
Merge branch 'main' into fix-url-validation-panic
yazan-abdalrahman Jun 26, 2024
57da102
Merge branch 'main' into fix-url-validation-panic
yazan-abdalrahman Jun 27, 2024
4f7d572
add support for latin characters for domain and fix IPv6 parsing
yazan-abdalrahman Jul 1, 2024
3978b24
Merge branch 'main' into fix-url-validation-panic
yazan-abdalrahman Jul 1, 2024
e7df56f
Merge remote-tracking branch 'refs/remotes/origin/main' into fix-url-…
yazan-abdalrahman Jul 2, 2024
a1441e4
format
yazan-abdalrahman Jul 2, 2024
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
add support for latin characters for domain and fix IPv6 parsing
  • Loading branch information
yazan-abdalrahman committed Jul 1, 2024
commit 4f7d572e0eb94f7f15ab1fd73397879dca7bbc95
8 changes: 7 additions & 1 deletion ext/net/lib.rs
Original file line number Diff line number Diff line change
Expand Up @@ -35,10 35,16 @@ impl NetPermissionHost {
) -> Result<Self, AnyError> {
let lowercased = host.to_lowercase();
let extracted_host = lowercased.as_str();
let (host_str, port_) = split_host_port(extracted_host)?;
let (host_str, mut port_) = split_host_port(extracted_host)?;
let host =
Host::from_host_and_origin_host(host_str.as_str(), extracted_host)?;

if host.is_ipv6()
&& (!extracted_host.contains('[') || !extracted_host.contains(']'))
{
port_ = None;
}

let final_port = if let Some(port_) = port_ {
Some(port_)
} else {
Expand Down
15 changes: 11 additions & 4 deletions ext/net/ops.rs
Original file line number Diff line number Diff line change
Expand Up @@ -85,10 85,17 @@ pub struct IpAddr {
fn normalize_ip_addr(addr: &mut IpAddr) -> Result<(), AnyError> {
let lowercased = addr.hostname.as_str().to_lowercase();
let extracted_host = lowercased.as_str();
let (host_str, port) = split_host_port(extracted_host)?;
addr.hostname =
Host::from_host_and_origin_host(host_str.as_str(), extracted_host)?
.to_string();
let (host_str, mut port) = split_host_port(extracted_host)?;
let host =
Host::from_host_and_origin_host(host_str.as_str(), extracted_host)?;
addr.hostname = host.to_string();

if host.is_ipv6()
&& (!extracted_host.contains('[') || !extracted_host.contains(']'))
{
port = None;
}

if let Some(port) = port {
addr.port = port;
}
Expand Down
18 changes: 17 additions & 1 deletion runtime/permissions/host.rs
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 2,7 @@

use deno_core::error::uri_error;
use deno_core::error::AnyError;
use deno_core::url::quirks::domain_to_ascii;
use fqdn::FQDN;
use std::fmt;
use std::net::Ipv4Addr;
Expand All @@ -24,9 25,20 @@ impl Host {
return Ok(Host::Ipv6(ipv6));
}

let host = FQDN::from_str(host).map_err(|_| {
if let Ok(ipv6) = origin_host.parse::<Ipv6Addr>() {
return Ok(Host::Ipv6(ipv6));
}

let mut ascii_host = domain_to_ascii(host);

if ascii_host.is_empty() {
ascii_host = host.to_string();
}

let host = FQDN::from_str(&ascii_host).map_err(|_| {
uri_error(format!("Failed to parse host: {}\n", origin_host))
})?;

let host_string = host.to_string();

if let Ok(ipv4) = host_string.parse::<Ipv4Addr>() {
Expand All @@ -35,6 47,10 @@ impl Host {

Ok(Host::FQDN(host))
}

pub fn is_ipv6(&self) -> bool {
matches!(self, Host::Ipv6(_))
}
}

impl fmt::Display for Host {
Expand Down
9 changes: 8 additions & 1 deletion runtime/permissions/lib.rs
Original file line number Diff line number Diff line change
Expand Up @@ -713,9 713,16 @@ impl NetDescriptor {
pub fn from_cli_arg(s: &str) -> Result<Self, AnyError> {
let lowercased = s.to_lowercase();
let extracted_host = lowercased.as_str();
let (host_str, port) = split_host_port(extracted_host)?;
let (host_str, mut port) = split_host_port(extracted_host)?;
let host =
Host::from_host_and_origin_host(host_str.as_str(), extracted_host)?;

if host.is_ipv6()
&& (!extracted_host.contains('[') || !extracted_host.contains(']'))
{
port = None;
}

Ok(NetDescriptor(host, port))
}

Expand Down