--- parser3/src/classes/string.C 2008/07/21 07:37:37 1.167 +++ parser3/src/classes/string.C 2009/04/10 11:31:06 1.170 @@ -1,11 +1,11 @@ /** @file Parser: @b string parser class. - Copyright (c) 2001-2005 ArtLebedev Group (http://www.artlebedev.com) + Copyright (c) 2001-2009 ArtLebedev Group (http://www.artlebedev.com) Author: Alexandr Petrosian (http://paf.design.ru) */ -static const char * const IDENT_STRING_C="$Date: 2008/07/21 07:37:37 $"; +static const char * const IDENT_STRING_C="$Date: 2009/04/10 11:31:06 $"; #include "classes.h" #include "pa_vmethod_frame.h" @@ -360,7 +360,7 @@ static void replace_action(Table& table, *ai.dest << ai.src->mid(poststart, postfinish); } -/// @todo use pcre:study somehow +/// @todo use pcre_study somehow static void _match(Request& r, MethodParams& params) { Value& regexp=params.as_no_junction(0, "regexp must not be code"); @@ -639,19 +639,28 @@ static void _append(Request& r, MethodPa static void _base64(Request& r, MethodParams& params) { if(params.count()) { - // decode + // decode: ^string:base64[encoded] const char* cstr=params.as_string(0, PARAMETER_MUST_BE_STRING).cstr(); - char* decoded_cstr=0; - size_t decoded_size=0; - pa_base64_decode(cstr, strlen(cstr), decoded_cstr, decoded_size); - if(decoded_cstr && decoded_size) - r.write_assign_lang(*new String(decoded_cstr, decoded_size, true)); + char* decoded=0; + size_t length=0; + pa_base64_decode(cstr, strlen(cstr), decoded, length); + if(decoded && length){ + if(memchr((const char*)decoded, 0, length)) + throw Exception(PARSER_RUNTIME, + 0, + "Invalid \\x00 character found while decode to string. Decode it to file instead."); + + fix_line_breaks(decoded, length); + if(length){ + r.write_assign_lang(*new String(decoded, length, true/*tainted*/)); + } + } } else { - // encode + // encode: ^str.base64[] VString& self=GET_SELF(r, VString); const char* cstr=self.string().cstr(); const char* encoded=pa_base64_encode(cstr, strlen(cstr)); - r.write_assign_lang(*new String(encoded, 0, true/*once ?param=base64(something) was needed*/)); + r.write_assign_lang(*new String(encoded, 0, true/*tainted. once ?param=base64(something) was needed*/)); } } @@ -739,8 +748,8 @@ MString::MString(): Methoded("string") { // ^string:base64[encoded string] << decode add_native_method("base64", Method::CT_ANY, _base64, 0, 1); - // ^string.escape[] - // ^string:unescape[escaped%uXXXXstring] - add_native_method("escape", Method::CT_ANY, _escape, 0, 0); - add_native_method("unescape", Method::CT_STATIC, _unescape, 1, 1); + // ^string.js-escape[] + // ^string:js-unescape[escaped%uXXXXstring] + add_native_method("js-escape", Method::CT_ANY, _escape, 0, 0); + add_native_method("js-unescape", Method::CT_STATIC, _unescape, 1, 1); }