--- parser3/src/classes/op.C 2001/11/01 16:11:03 1.55 +++ parser3/src/classes/op.C 2001/11/22 12:40:48 1.62 @@ -2,9 +2,9 @@ Parser: parser @b operators. Copyright (c) 2001 ArtLebedev Group (http://www.artlebedev.com) - Author: Alexander Petrosyan (http://design.ru/paf) + Author: Alexander Petrosyan (http://paf.design.ru) - $Id: op.C,v 1.55 2001/11/01 16:11:03 paf Exp $ + $Id: op.C,v 1.62 2001/11/22 12:40:48 paf Exp $ */ #include "classes.h" @@ -53,16 +53,20 @@ static void _if(Request& r, const String static void _untaint(Request& r, const String& method_name, MethodParams *params) { Pool& pool=r.pool(); - const String& lang_name=params->as_string(0, "lang must be string"); - String::Untaint_lang lang=static_cast( - untaint_lang_name2enum->get_int(lang_name)); - if(!lang) - throw Exception(0, 0, - &lang_name, - "invalid untaint language"); + uchar lang; + if(params->size()==1) + lang=String::UL_AS_IS; // mark as simply 'tainted'. useful in html from sql + else { + const String& lang_name=params->as_string(0, "lang must be string"); + lang=untaint_lang_name2enum->get_int(lang_name); + if(!lang) + throw Exception(0, 0, + &lang_name, + "invalid taint language"); + } { - Value& vbody=params->as_junction(1, "body must be code"); + Value& vbody=params->as_junction(params->size()-1, "body must be code"); Temp_lang temp_lang(r, lang); // set temporarily specified ^untaint[language; r.write_pass_lang(r.process(vbody)); // process marking tainted with that lang @@ -72,13 +76,12 @@ static void _untaint(Request& r, const S static void _taint(Request& r, const String&, MethodParams *params) { Pool& pool=r.pool(); - String::Untaint_lang lang; + uchar lang; if(params->size()==1) lang=String::UL_TAINTED; // mark as simply 'tainted'. useful in table:set else { const String& lang_name=params->as_string(0, "lang must be string"); - lang=static_cast( - untaint_lang_name2enum->get_int(lang_name)); + lang=untaint_lang_name2enum->get_int(lang_name); if(!lang) throw Exception(0, 0, &lang_name, @@ -118,11 +121,11 @@ static void _process(Request& r, const S // evaluate source to process const String& source= - r.process(params->as_no_junction(0, "body must be string")).as_string(); + r.process(params->as_junction(0, "body must be code")).as_string(); // process source code, append processed methods to 'self' class // maybe-define new @main - r.use_buf(source.cstr(), place, &self_class); + r.use_buf(source.cstr(String::UL_UNSPECIFIED, r.connection), place, &self_class); // maybe-execute @main[] if(const Method *method=self_class.get_method(*main_method_name)) { @@ -176,16 +179,16 @@ static void _for(Request& r, const Strin Value& body_code=params->as_junction(3, "body must be code"); Value *delim_maybe_code=params->size()>4?¶ms->get(4):0; + if(to-from>=MAX_LOOPS) // too long loop? + throw Exception(0, 0, + &method_name, + "endless loop detected"); + bool need_delim=false; VInt *vint=new(pool) VInt(pool, 0); - int endless_loop_count=0; for(int i=from; i<=to; i++) { - if(++endless_loop_count>=MAX_LOOPS) // endless loop? - throw Exception(0, 0, - &method_name, - "endless loop detected"); vint->set_int(i); - r.self/*root*/->put_element(var_name, vint); + r.root->put_element(var_name, vint); Value& processed_body=r.process(body_code); if(delim_maybe_code) { // delimiter set? @@ -336,7 +339,7 @@ MOP::MOP(Pool& apool) : Methoded(apool), add_native_method("if", Method::CT_ANY, _if, 2, 3); // ^untaint[as-is|uri|sql|js|html|html-typo]{code} - add_native_method("untaint", Method::CT_ANY, _untaint, 2, 2); + add_native_method("untaint", Method::CT_ANY, _untaint, 1, 2); // ^taint[as-is|uri|sql|js|html|html-typo]{code} add_native_method("taint", Method::CT_ANY, _taint, 1, 2);