optimize xss checks for speed
Costa Tsaousis (ktsaou) committed
Jan 30, 2018 at 23:05 UTC
229a733ac9766c9a1267716665eba6368ac4cf1e
2 files changed
+31
-38
web/dashboard.js
+30
-38
@@ -109,56 +109,48 @@ var NETDATA = window.NETDATA || {};
109
enabled_for_data: (typeof netdataCheckXSS === 'undefined')?false:netdataCheckXSS,
110
111
string: function (s) {
112
- if (typeof s === 'string' || typeof s === 'number' || typeof s === 'boolean')
113
- return s.toString()
114
- .replace(/</g, '<')
115
- .replace(/>/g, '>')
116
- .replace(/"/g, '"')
117
- .replace(/'/g, '#27;');
118
-
119
- return '';
112
+ return s.toString()
113
+ .replace(/</g, '<')
114
+ .replace(/>/g, '>')
115
+ .replace(/"/g, '"')
116
+ .replace(/'/g, '#27;');
117
},
118
119
object: function(name, obj, ignore_regex) {
123
- if(obj === null) return obj;
124
-
125
- var type = typeof(obj);
126
- if(type === 'undefined' || type === 'number') return obj;
127
-
128
- if(typeof ignore_regex !== 'undefined') {
129
- if(ignore_regex.test(name) === true) {
130
- // console.log('XSS: ignoring "' + name + '"');
131
- return obj;
132
- }
120
+ if(typeof ignore_regex !== 'undefined' && ignore_regex.test(name) === true) {
121
+ // console.log('XSS: ignoring "' + name + '"');
122
+ return obj;
123
}
124
135
- if(type === 'object' && Array.isArray(obj))
136
- type = 'array';
137
-
138
- var ret, i, len;
139
- switch (type) {
125
+ switch (typeof(obj)) {
126
case 'string':
141
- ret = this.string(obj);
127
+ var ret = this.string(obj);
128
if(ret !== obj) console.log('XSS protection changed string ' + name + ' from "' + obj + '" to "' + ret + '"');
129
return ret;
130
131
case 'object':
146
- for(i in obj) {
147
- if(obj.hasOwnProperty(i) === false) continue;
148
- if(this.string(i) !== i) {
149
- console.log('XSS protection removed invalid object member "' + name + '.' + i + '"');
150
- delete obj[i];
151
- }
152
- else
153
- obj[i] = this.object(name + '.' + i, obj[i], ignore_regex);
154
- }
155
- return obj;
132
+ if(obj === null) return obj;
133
+
134
+ if(Array.isArray(obj) === true) {
135
+ // console.log('checking array "' + name + '"');
136
157
- case 'array':
158
- len = obj.length;
159
- while(len--)
160
- obj[len] = this.object(name + '[' + len + ']', obj[len], ignore_regex);
137
+ var len = obj.length;
138
+ while(len--)
139
+ obj[len] = this.object(name + '[' + len + ']', obj[len], ignore_regex);
140
+ }
141
+ else {
142
+ // console.log('checking object "' + name + '"');
143
144
+ for(var i in obj) {
145
+ if(obj.hasOwnProperty(i) === false) continue;
146
+ if(this.string(i) !== i) {
147
+ console.log('XSS protection removed invalid object member "' + name + '.' + i + '"');
148
+ delete obj[i];
149
+ }
150
+ else
151
+ obj[i] = this.object(name + '.' + i, obj[i], ignore_regex);
152
+ }
153
+ }
154
return obj;
155
156
default:
web/index.html
+1
@@ -3386,6 +3386,7 @@
3386
document.getElementById('loadSnapshotInfo').innerHTML = '';
3387
document.getElementById('loadSnapshotTimeRange').innerHTML = '';
3388
document.getElementById('loadSnapshotComments').innerHTML = '';
3389
+ loadSnapshotModalLog('success', 'Browse for a snapshot file (or drag it and drop it here), then click <b>Import</b> to render it.');
3390
$('#loadSnapshotImport').addClass('disabled');
3391
};
3392