Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix: handle InvalidLabelChar in URL validation to prevent panic #24080

Closed
Show file tree
Hide file tree
Changes from 9 commits
Commits
Show all changes
38 commits
Select commit Hold shift click to select a range
f979e0c
handle InvalidLabelChar in URL validation to prevent panic
yazan-abdalrahman Jun 2, 2024
2d8e29a
ci: trigger CI pipeline
yazan-abdalrahman Jun 3, 2024
ba2b828
Merge branch 'main' into fix-url-validation-panic
yazan-abdalrahman Jun 3, 2024
a5199a3
Merge branch 'main' into fix-url-validation-panic
yazan-abdalrahman Jun 4, 2024
78ddde1
Merge branch 'main' into fix-url-validation-panic
yazan-abdalrahman Jun 4, 2024
1fe2399
Merge branch 'main' into fix-url-validation-panic
yazan-abdalrahman Jun 5, 2024
6d254a1
fix lint issues
yazan-abdalrahman Jun 6, 2024
c8488b6
Merge remote-tracking branch 'origin/fix-url-validation-panic' into f…
yazan-abdalrahman Jun 6, 2024
3a875fd
Merge branch 'main' into fix-url-validation-panic
yazan-abdalrahman Jun 6, 2024
9971b64
handle empty value
yazan-abdalrahman Jun 9, 2024
6a92d09
Merge branch 'main' of https://github.com/yazan-abdalrahman/deno into…
yazan-abdalrahman Jun 9, 2024
5db82f3
fix cyclic dependence
yazan-abdalrahman Jun 10, 2024
f942a31
Merge branch 'main' into fix-url-validation-panic
yazan-abdalrahman Jun 10, 2024
9146e36
Merge branch 'main' into fix-url-validation-panic
yazan-abdalrahman Jun 11, 2024
e8b5b29
Merge branch 'main' into fix-url-validation-panic
yazan-abdalrahman Jun 11, 2024
c20874c
Merge branch 'main' into fix-url-validation-panic
yazan-abdalrahman Jun 11, 2024
7cff4e2
Merge branch 'main' into fix-url-validation-panic
yazan-abdalrahman Jun 11, 2024
a8324ae
Merge branch 'main' into fix-url-validation-panic
yazan-abdalrahman Jun 12, 2024
2a4dc4b
Merge branch 'main' into fix-url-validation-panic
yazan-abdalrahman Jun 12, 2024
3655231
Merge branch 'main' into fix-url-validation-panic
yazan-abdalrahman Jun 13, 2024
41b0cb2
Merge branch 'main' into fix-url-validation-panic
yazan-abdalrahman Jun 13, 2024
94fe173
Merge branch 'main' of https://github.com/yazan-abdalrahman/deno into…
yazan-abdalrahman Jun 20, 2024
5178a56
Merge branch 'main' of https://github.com/yazan-abdalrahman/deno into…
yazan-abdalrahman Jun 23, 2024
d4ed2f9
Merge branch 'main' of https://github.com/yazan-abdalrahman/deno into…
yazan-abdalrahman Jun 24, 2024
7a50fde
fix test failures
yazan-abdalrahman Jun 24, 2024
8701009
Merge branch 'main' into fix-url-validation-panic
yazan-abdalrahman Jun 24, 2024
378a168
Remove file
dsherret Jun 24, 2024
f0642d3
Remove processing a URL &&
yazan-abdalrahman Jun 25, 2024
f156f3f
Merge remote-tracking branch 'origin/fix-url-validation-panic' into f…
yazan-abdalrahman Jun 25, 2024
8012e79
Merge branch 'main' into fix-url-validation-panic
yazan-abdalrahman Jun 25, 2024
731de60
Merge branch 'main' into fix-url-validation-panic
yazan-abdalrahman Jun 25, 2024
81cee0c
Merge branch 'main' into fix-url-validation-panic
yazan-abdalrahman Jun 25, 2024
a566a11
Merge branch 'main' into fix-url-validation-panic
yazan-abdalrahman Jun 26, 2024
57da102
Merge branch 'main' into fix-url-validation-panic
yazan-abdalrahman Jun 27, 2024
4f7d572
add support for latin characters for domain and fix IPv6 parsing
yazan-abdalrahman Jul 1, 2024
3978b24
Merge branch 'main' into fix-url-validation-panic
yazan-abdalrahman Jul 1, 2024
e7df56f
Merge remote-tracking branch 'refs/remotes/origin/main' into fix-url-…
yazan-abdalrahman Jul 2, 2024
a1441e4
format
yazan-abdalrahman Jul 2, 2024
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

1 change: 1 addition & 0 deletions Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -109,6 109,7 @@ faster-hex = "0.9"
fastwebsockets = { version = "0.6", features = ["upgrade", "unstable-split"] }
filetime = "0.2.16"
flate2 = { version = "1.0.26", default-features = false }
fqdn = "0.3.4"
fs3 = "0.5.0"
futures = "0.3.21"
glob = "0.3.1"
Expand Down
39 changes: 39 additions & 0 deletions cli/args/flags.rs
Original file line number Diff line number Diff line change
Expand Up @@ -9789,4 9789,43 @@ mod tests {
}
);
}

#[test]
fn wildcard_flags() {
#[rustfmt::skip]
let r = flags_from_vec(svec![
"deno",
"run",
"--allow-read",
"--allow-write=notion-next",
"--allow-net=api.notion.com,*.amazonaws.com",
"--allow-env",
"script.ts"
]);

let flags = r.unwrap();
assert_eq!(
flags,
Flags {
subcommand: DenoSubcommand::Run(RunFlags::new_default(
"script.ts".to_string()
)),
permissions: PermissionFlags {
allow_env: Some(vec![],),
allow_net: Some(vec![
"api.notion.com".to_string(),
"*.amazonaws.com".to_string(),
],),
allow_read: Some(vec![],),
allow_write: Some(vec!["notion-next".to_string(),],),
..Default::default()
},
unstable_config: UnstableConfig {
..Default::default()
},
code_cache_enabled: true,
..Flags::default()
}
);
}
}
1 change: 1 addition & 0 deletions ext/net/Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -16,6 16,7 @@ path = "lib.rs"
[dependencies]
deno_core.workspace = true
deno_tls.workspace = true
fqdn.workspace = true
pin-project.workspace = true
rustls-tokio-stream.workspace = true
serde.workspace = true
Expand Down
87 changes: 87 additions & 0 deletions ext/net/host.rs
Original file line number Diff line number Diff line change
@@ -0,0 1,87 @@
// Copyright 2018-2024 the Deno authors. All rights reserved. MIT license.

use deno_core::anyhow::Context;
use deno_core::error::AnyError;
use fqdn::FQDN;
use std::fmt;
use std::net::Ipv4Addr;
use std::net::Ipv6Addr;
use std::str::FromStr;

#[derive(Clone, Eq, PartialEq, Hash, Debug)]
pub enum Host {
FQDN(FQDN),
Ipv4(Ipv4Addr),
Ipv6(Ipv6Addr),
}

impl Host {
pub fn from_host_and_origin_host(
host: &str,
origin_host: &str,
) -> Result<Self, AnyError> {
if let Ok(ipv6) = host.parse::<Ipv6Addr>() {
return Ok(Host::Ipv6(ipv6));
}

let host = FQDN::from_str(host)
.with_context(|| format!("Failed to parse host: {}\n", origin_host))?;
let host_string = host.to_string();

if let Ok(ipv4) = host_string.parse::<Ipv4Addr>() {
return Ok(Host::Ipv4(ipv4));
}

Ok(Host::FQDN(host))
}
}

impl fmt::Display for Host {
fn fmt(&self, f: &mut fmt::Formatter<'_>) -> fmt::Result {
match self {
Host::FQDN(fqdn) => write!(f, "{}", fqdn),
Host::Ipv4(ipv4) => write!(f, "{}", ipv4),
Host::Ipv6(ipv6) => write!(f, "[{}]", ipv6),
}
}
}

pub fn split_host_port(s: &str) -> Result<(String, Option<u16>), AnyError> {
let mut host = s.to_string();
let mut port = None;

let have_port = host.contains(':') && !host.contains('[');

if host.starts_with('[') && host.contains(']') {
if host.ends_with("]:") {
return Err(AnyError::msg("Invalid format: [ipv6]:port"));
}
if let Some(pos) = host.rfind("]:") {
let port_str = &host[pos 2..];
let port_ = port_str.parse::<u16>().ok();
host = host[1..pos].to_string();
port = port_;
} else {
host = host[1..(host.len() - 1)].to_string();
}
} else if let Some(pos) = host.rfind(':') {
let port_str = &host[pos 1..];
if let Ok(parsed_port) = port_str.parse::<u16>() {
host.truncate(pos);
port = Some(parsed_port);
}
}

if have_port && port.is_none() {
return Err(AnyError::msg("No port specified after ':'"));
}

Ok((host, port))
}

pub fn extract_host(s: &str) -> String {
if let Some(index) = s.find("://") {
return s[index 3..].split('/').next().unwrap_or(s).to_string();
}
s.to_string()
}
Loading
Loading