-
Notifications
You must be signed in to change notification settings - Fork 39
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
fix(showcase): prevent arbitrary url evaluation
- Loading branch information
Showing
9 changed files
with
67 additions
and
7 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,8 +1,8 @@ | ||
export * from './date-picker-input/index'; | ||
export * from './otter-picker/index'; | ||
export * from './copy-text/index'; | ||
export * from './date-picker-input/index'; | ||
export * from './date-picker-input-hebrew/index'; | ||
export * from './in-page-nav/index'; | ||
export * from './otter-icon/index'; | ||
export * from './otter-picker/index'; | ||
export * from './scroll-back-top/index'; | ||
export * from './sidenav/index'; | ||
export * from './date-picker-input/index'; | ||
export * from './date-picker-input-hebrew/index'; |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,2 @@ | ||
export * from './otter-icon-pres.component'; | ||
|
32 changes: 32 additions & 0 deletions
32
apps/showcase/src/components/utilities/otter-icon/otter-icon-pres.component.ts
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,32 @@ | ||
import { ChangeDetectionStrategy, Component, computed, input, ViewEncapsulation } from '@angular/core'; | ||
import { O3rComponent } from '@o3r/core'; | ||
|
||
@O3rComponent({ componentType: 'Component' }) | ||
@Component({ | ||
selector: 'o3r-otter-icon-pres', | ||
standalone: true, | ||
templateUrl: './otter-icon-pres.template.html', | ||
styleUrls: ['./otter-icon-pres.style.scss'], | ||
encapsulation: ViewEncapsulation.None, | ||
changeDetection: ChangeDetectionStrategy.OnPush | ||
}) | ||
export class OtterIconPresComponent { | ||
/** Path of the otter icon */ | ||
public path = input.required<string>(); | ||
|
||
/** Width of the icon */ | ||
public width = input.required<number>(); | ||
|
||
/** Height of the icon */ | ||
public height = input.required<number>(); | ||
|
||
private readonly BASE_URL = location.href.split('/#', 1)[0]; | ||
|
||
private readonly ICON_MATCHER = /^\/assets\/[\w-/]+\.svg$/; | ||
|
||
/** Url of the otter icon or default otter if wrong pattern */ | ||
public realUrl = computed(() => { | ||
const path = this.path(); | ||
Check failure on line 29 in apps/showcase/src/components/utilities/otter-icon/otter-icon-pres.component.ts GitHub Actions / checks / test (ubuntu-latest)OtterIconPresComponent › should create
Check failure on line 29 in apps/showcase/src/components/utilities/otter-icon/otter-icon-pres.component.ts GitHub Actions / checks / test (windows-latest)OtterIconPresComponent › should create
Check failure on line 29 in apps/showcase/src/components/utilities/otter-icon/otter-icon-pres.component.ts GitHub Actions / UT Tests report-ubuntu-latestOtterIconPresComponent ► OtterIconPresComponent should create ► OtterIconPresComponent should create
Raw output
|
||
return this.ICON_MATCHER.test(path) ? `${this.BASE_URL}${path}` : `${this.BASE_URL}/assets/otter.svg`; | ||
}); | ||
} |
21 changes: 21 additions & 0 deletions
21
apps/showcase/src/components/utilities/otter-icon/otter-icon-pres.spec.ts
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,21 @@ | ||
import { ComponentFixture, TestBed } from '@angular/core/testing'; | ||
|
||
import { OtterIconPresComponent } from './otter-icon-pres.component'; | ||
|
||
describe('OtterIconPresComponent', () => { | ||
let component: OtterIconPresComponent; | ||
let fixture: ComponentFixture<OtterIconPresComponent>; | ||
|
||
beforeEach(() => { | ||
TestBed.configureTestingModule({ | ||
imports: [OtterIconPresComponent] | ||
}); | ||
fixture = TestBed.createComponent(OtterIconPresComponent); | ||
component = fixture.componentInstance; | ||
fixture.detectChanges(); | ||
}); | ||
|
||
it('should create', () => { | ||
expect(component).toBeTruthy(); | ||
}); | ||
}); |
3 changes: 3 additions & 0 deletions
3
apps/showcase/src/components/utilities/otter-icon/otter-icon-pres.style.scss
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,3 @@ | ||
o3r-otter-icon-pres { | ||
|
||
} |
1 change: 1 addition & 0 deletions
1
apps/showcase/src/components/utilities/otter-icon/otter-icon-pres.template.html
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1 @@ | ||
<img [attr.width]="width()" [attr.height]="height()" [src]="realUrl()" alt="{{realUrl()}}" /> |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters