@cryptotaxi247 / netdata-1 / commits / 229a733ac

optimize xss checks for speed

Costa Tsaousis (ktsaou) committed Jan 30, 2018 at 23:05 UTC 229a733ac9766c9a1267716665eba6368ac4cf1e
2 files changed +31 -38
web/dashboard.js
+30 -38
@@ -109,56 +109,48 @@ var NETDATA = window.NETDATA || {};
109 enabled_for_data: (typeof netdataCheckXSS === 'undefined')?false:netdataCheckXSS,
110
111 string: function (s) {
112 - if (typeof s === 'string' || typeof s === 'number' || typeof s === 'boolean')
113 - return s.toString()
114 - .replace(/</g, '&lt;')
115 - .replace(/>/g, '&gt;')
116 - .replace(/"/g, '&quot;')
117 - .replace(/'/g, '#27;');
118 -
119 - return '';
112 + return s.toString()
113 + .replace(/</g, '&lt;')
114 + .replace(/>/g, '&gt;')
115 + .replace(/"/g, '&quot;')
116 + .replace(/'/g, '#27;');
117 },
118
119 object: function(name, obj, ignore_regex) {
123 - if(obj === null) return obj;
124 -
125 - var type = typeof(obj);
126 - if(type === 'undefined' || type === 'number') return obj;
127 -
128 - if(typeof ignore_regex !== 'undefined') {
129 - if(ignore_regex.test(name) === true) {
130 - // console.log('XSS: ignoring "' + name + '"');
131 - return obj;
132 - }
120 + if(typeof ignore_regex !== 'undefined' && ignore_regex.test(name) === true) {
121 + // console.log('XSS: ignoring "' + name + '"');
122 + return obj;
123 }
124
135 - if(type === 'object' && Array.isArray(obj))
136 - type = 'array';
137 -
138 - var ret, i, len;
139 - switch (type) {
125 + switch (typeof(obj)) {
126 case 'string':
141 - ret = this.string(obj);
127 + var ret = this.string(obj);
128 if(ret !== obj) console.log('XSS protection changed string ' + name + ' from "' + obj + '" to "' + ret + '"');
129 return ret;
130
131 case 'object':
146 - for(i in obj) {
147 - if(obj.hasOwnProperty(i) === false) continue;
148 - if(this.string(i) !== i) {
149 - console.log('XSS protection removed invalid object member "' + name + '.' + i + '"');
150 - delete obj[i];
151 - }
152 - else
153 - obj[i] = this.object(name + '.' + i, obj[i], ignore_regex);
154 - }
155 - return obj;
132 + if(obj === null) return obj;
133 +
134 + if(Array.isArray(obj) === true) {
135 + // console.log('checking array "' + name + '"');
136
157 - case 'array':
158 - len = obj.length;
159 - while(len--)
160 - obj[len] = this.object(name + '[' + len + ']', obj[len], ignore_regex);
137 + var len = obj.length;
138 + while(len--)
139 + obj[len] = this.object(name + '[' + len + ']', obj[len], ignore_regex);
140 + }
141 + else {
142 + // console.log('checking object "' + name + '"');
143
144 + for(var i in obj) {
145 + if(obj.hasOwnProperty(i) === false) continue;
146 + if(this.string(i) !== i) {
147 + console.log('XSS protection removed invalid object member "' + name + '.' + i + '"');
148 + delete obj[i];
149 + }
150 + else
151 + obj[i] = this.object(name + '.' + i, obj[i], ignore_regex);
152 + }
153 + }
154 return obj;
155
156 default:
web/index.html
+1
@@ -3386,6 +3386,7 @@
3386 document.getElementById('loadSnapshotInfo').innerHTML = '';
3387 document.getElementById('loadSnapshotTimeRange').innerHTML = '';
3388 document.getElementById('loadSnapshotComments').innerHTML = '';
3389 + loadSnapshotModalLog('success', 'Browse for a snapshot file (or drag it and drop it here), then click <b>Import</b> to render it.');
3390 $('#loadSnapshotImport').addClass('disabled');
3391 };
3392