Fix #15
git-svn-id: file:///srv/svn/repo/yukari/trunk@25 f3bd38d9-da89-464d-a02a-eb04e43141b5
This commit is contained in:
parent
63b833ac86
commit
f063eb1ef3
21
morty.go
21
morty.go
@ -11,7 +11,6 @@ import (
|
|||||||
"io"
|
"io"
|
||||||
"log"
|
"log"
|
||||||
"net/url"
|
"net/url"
|
||||||
"path"
|
|
||||||
"regexp"
|
"regexp"
|
||||||
"strings"
|
"strings"
|
||||||
"time"
|
"time"
|
||||||
@ -382,7 +381,7 @@ func sanitizeHTML(rc *RequestConfig, out io.Writer, htmlDoc []byte) {
|
|||||||
for _, attr := range attrs {
|
for _, attr := range attrs {
|
||||||
if bytes.Equal(attr[0], []byte("action")) {
|
if bytes.Equal(attr[0], []byte("action")) {
|
||||||
formURL, _ = url.Parse(string(attr[1]))
|
formURL, _ = url.Parse(string(attr[1]))
|
||||||
mergeURIs(rc.BaseURL, formURL)
|
formURL = mergeURIs(rc.BaseURL, formURL)
|
||||||
break
|
break
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@ -526,19 +525,15 @@ func sanitizeAttr(rc *RequestConfig, out io.Writer, attrName, attrValue, escaped
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
func mergeURIs(u1, u2 *url.URL) {
|
func mergeURIs(u1, u2 *url.URL) (*url.URL) {
|
||||||
if u2.Scheme == "" || u2.Scheme == "//" {
|
return u1.ResolveReference(u2)
|
||||||
u2.Scheme = u1.Scheme
|
|
||||||
}
|
|
||||||
if u2.Host == "" && u1.Path != "" {
|
|
||||||
u2.Host = u1.Host
|
|
||||||
if len(u2.Path) == 0 || u2.Path[0] != '/' {
|
|
||||||
u2.Path = path.Join(u1.Path[:strings.LastIndexByte(u1.Path, byte('/'))], u2.Path)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
func (rc *RequestConfig) ProxifyURI(uri string) (string, error) {
|
func (rc *RequestConfig) ProxifyURI(uri string) (string, error) {
|
||||||
|
// remove javascript protocol
|
||||||
|
if strings.HasPrefix(uri, "javascript:") {
|
||||||
|
return "", nil
|
||||||
|
}
|
||||||
// TODO check malicious data: - e.g. data:script
|
// TODO check malicious data: - e.g. data:script
|
||||||
if strings.HasPrefix(uri, "data:") {
|
if strings.HasPrefix(uri, "data:") {
|
||||||
return uri, nil
|
return uri, nil
|
||||||
@ -552,7 +547,7 @@ func (rc *RequestConfig) ProxifyURI(uri string) (string, error) {
|
|||||||
if err != nil {
|
if err != nil {
|
||||||
return "", err
|
return "", err
|
||||||
}
|
}
|
||||||
mergeURIs(rc.BaseURL, u)
|
u = mergeURIs(rc.BaseURL, u)
|
||||||
|
|
||||||
uri = u.String()
|
uri = u.String()
|
||||||
|
|
||||||
|
Loading…
x
Reference in New Issue
Block a user