fixes identified by LGTM (#4220)
* fixes identified by LGTM * fixed hex of quote and slash * fixed hex of quote and slash on all files * escape more characters * removed test * do not read document.location * exclude full subpaths for LGTM * exclude the tests path * excluded lgtm paths in quotes * excluded sub-paths on LGTM * fix xss identified by LGTM
Costa Tsaousis committed
Sep 18, 2018 at 13:34 UTC
8e0b0bcb551ac14d2b24bbf2551ef9f6cd96e405
4 files changed
+71
-24
.lgtm.yml
+20
-1
@@ -4,6 +4,25 @@ path_classifiers:
4
test:
5
- exclude: python.d/python_modules/third_party/*
6
- exclude: python.d/python_modules/urllib3/*
7
+ - exclude: python.d/python_modules/urllib3/util/*
8
+ - exclude: python.d/python_modules/urllib3/packages/*
9
+ - exclude: python.d/python_modules/urllib3/packages/backports/*
10
+ - exclude: python.d/python_modules/urllib3/packages/ssl_match_hostname/*
11
+ - exclude: python.d/python_modules/urllib3/contrib/*
12
+ - exclude: python.d/python_modules/urllib3/contrib/_securetransport/*
13
- exclude: python.d/python_modules/pyyaml2/*
14
- exclude: python.d/python_modules/pyyaml3/*
9
-
15
+ - exclude: node.d/node_modules/lib/*
16
+ - exclude: node.d/node_modules/lib/ber/*
17
+ - exclude: node.d/node_modules/asn1-ber.js
18
+ - exclude: node.d/node_modules/extend.js
19
+ - exclude: node.d/node_modules/net-snmp.js
20
+ - exclude: node.d/node_modules/pixl-xml.js
21
+ - exclude: web/lib/*
22
+ - exclude: web/css/*
23
+ - exclude: tests/web/*
24
+ - exclude: tests/web/lib/*
25
+ - exclude: tests/web/fixtures/*
26
+ - exclude: tests/profile/*
27
+ - exclude: tests/node.d/*
28
+ - exclude: tests/*
web/dashboard.js
+1
-1
@@ -118,7 +118,7 @@ var NETDATA = window.NETDATA || {};
118
.replace(/</g, '<')
119
.replace(/>/g, '>')
120
.replace(/"/g, '"')
121
- .replace(/'/g, '#27;');
121
+ .replace(/'/g, ''');
122
},
123
124
object: function(name, obj, ignore_regex) {
web/goto-host-from-alarm.html
+22
-9
@@ -22,11 +22,24 @@
22
<script type="text/javascript" src="dashboard.js?v20170724-7"></script>
23
24
<script>
25
-function escapeUserInputXss(s) {
26
- return s.toString().replace(/</g, '<')
25
+function escapeUserInputHTML(s) {
26
+ return s.toString()
27
+ .replace(/&/g, '&')
28
+ .replace(/</g, '<')
29
.replace(/>/g, '>')
30
.replace(/"/g, '"')
29
- .replace(/'/g, '#27;');
31
+ .replace(/#/g, '#')
32
+ .replace(/'/g, ''')
33
+ .replace(/\(/g,'(')
34
+ .replace(/\)/g,')')
35
+ .replace(/\//g,'/');
36
+}
37
+function escapeUserInputJS(s) {
38
+ return s.toString()
39
+ .replace(/"/g, '"')
40
+ .replace(/'/g, ''')
41
+ .replace(/\(/g,'(')
42
+ .replace(/\)/g,')');
43
}
44
45
var urlOptions = {
@@ -94,7 +107,7 @@ function gotoServerValidateUrl(id, guid, url) {
107
var finalURL = netdataURL(url);
108
109
setTimeout(function() {
97
- document.getElementById('gotoServerList').innerHTML += '<tr><td style="padding-left: 20px;"><a href="' + escapeUserInputXss(finalURL) + '" target="_blank">' + escapeUserInputXss(url) + '</a></td><td style="padding-left: 30px;"><code id="' + guid + '-' + id + '-status">checking...</code></td></tr>';
110
+ document.getElementById('gotoServerList').innerHTML += '<tr><td style="padding-left: 20px;"><a href="' + escapeUserInputJS(finalURL) + '" target="_blank">' + escapeUserInputHTML(url) + '</a></td><td style="padding-left: 30px;"><code id="' + guid + '-' + id + '-status">checking...</code></td></tr>';
111
112
NETDATA.registry.hello(url, function(data) {
113
if(typeof data !== 'undefined' && data !== null && typeof data.machine_guid === 'string' && data.machine_guid === guid) {
@@ -107,11 +120,11 @@ function gotoServerValidateUrl(id, guid, url) {
120
if(gotoServerMiddleClick) {
121
window.open(finalURL);
122
gotoServerMiddleClick = false;
110
- document.getElementById('gotoServerResponse').innerHTML = '<b>Opening new window to ' + NETDATA.registry.machines[guid].name + '<br/><a href="' + escapeUserInputXss(finalURL) + '">' + escapeUserInputXss(url) + '</a></b><br/>(check your pop-up blocker if it fails)';
123
+ document.getElementById('gotoServerResponse').innerHTML = '<b>Opening new window to ' + NETDATA.registry.machines[guid].name + '<br/><a href="' + escapeUserInputJS(finalURL) + '">' + escapeUserInputHTML(url) + '</a></b><br/>(check your pop-up blocker if it fails)';
124
}
125
else {
113
- document.getElementById('gotoServerResponse').innerHTML += 'found it! It is at:<br/><small>' + url + '</small>';
114
- document.location = finalURL;
126
+ document.getElementById('gotoServerResponse').innerHTML += 'found it! It is at:<br/><small>' + escapeUserInputHTML(url) + '</small>';
127
+ document.location = escapeUserInputJS(finalURL);
128
}
129
}
130
}
@@ -127,7 +140,7 @@ function gotoServerValidateUrl(id, guid, url) {
140
141
if(thisIsHttps === true && urlsInHttp > 0) {
142
document.getElementById('gotoServerResponse').innerHTML += '<br/>redirecting myself to HTTP to allow checking';
130
- document.location = document.location.toString().replace('https://', 'http://');
143
+ document.location = escapeUserInputJS(document.location.toString().replace('https://', 'http://'));
144
}
145
}
146
}
@@ -192,7 +205,7 @@ var netdataRegistryCallback = function(machines_array) {
205
}
206
}
207
195
- document.getElementById('bodylog').innerHTML = "Sorry... your account is not linked to a netdata server named: <b>" + escapeUserInputXss(urlOptions.host) + '</b>';
208
+ document.getElementById('bodylog').innerHTML = "Sorry... your account is not linked to a netdata server named: <b>" + escapeUserInputHTML(urlOptions.host) + '</b>';
209
};
210
211
netdataQueryParse();
web/index.html
+28
-13
@@ -580,11 +580,24 @@
580
// control the welcome modal and analytics
581
var this_is_demo = null;
582
583
- function escapeUserInputXss(s) {
584
- return s.toString().replace(/</g, '<')
583
+ function escapeUserInputHTML(s) {
584
+ return s.toString()
585
+ .replace(/&/g, '&')
586
+ .replace(/</g, '<')
587
.replace(/>/g, '>')
588
.replace(/"/g, '"')
587
- .replace(/'/g, '#27;');
589
+ .replace(/#/g, '#')
590
+ .replace(/'/g, ''')
591
+ .replace(/\(/g,'(')
592
+ .replace(/\)/g,')')
593
+ .replace(/\//g,'/');
594
+ }
595
+ function escapeUserInputJS(s) {
596
+ return s.toString()
597
+ .replace(/"/g, '"')
598
+ .replace(/'/g, ''')
599
+ .replace(/\(/g,'(')
600
+ .replace(/\)/g,')');
601
}
602
603
// --------------------------------------------------------------------
@@ -1102,7 +1115,8 @@
1115
document.location.hostname.endsWith('.mynetdata.io') ||
1116
document.location.hostname.endsWith('.netdata.rocks') ||
1117
document.location.hostname.endsWith('.firehol.org') ||
1105
- document.location.hostname.endsWith('.netdata.online'))
1118
+ document.location.hostname.endsWith('.netdata.online') ||
1119
+ document.location.hostname.endsWith('.netdata.cloud'))
1120
this_is_demo = true;
1121
}
1122
}
@@ -1112,7 +1126,8 @@
1126
1127
function netdataURL(url, forReload) {
1128
if(typeof url === 'undefined')
1115
- url = document.location.toString();
1129
+ // url = document.location.toString();
1130
+ url = '';
1131
1132
if(url.indexOf('#') !== -1)
1133
url = url.substring(0, url.indexOf('#'));
@@ -1121,7 +1136,7 @@
1136
1137
// console.log('netdataURL: ' + url + hash);
1138
1124
- return escapeUserInputXss(url + hash);
1139
+ return url + hash;
1140
}
1141
1142
function netdataReload(url) {
@@ -1141,13 +1156,13 @@
1156
var gotoServerMiddleClick = false;
1157
var gotoServerStop = false;
1158
function gotoServerValidateUrl(id, guid, url) {
1144
- var penaldy = 0;
1159
+ var penalty = 0;
1160
var error = 'failed';
1161
1162
if(document.location.toString().startsWith('http://') && url.toString().startsWith('https://'))
1163
// we penalize https only if the current url is http
1164
// to allow the user walk through all its servers.
1150
- penaldy = 500;
1165
+ penalty = 500;
1166
1167
else if(document.location.toString().startsWith('https://') && url.toString().startsWith('http://'))
1168
error = 'can\'t check';
@@ -1155,7 +1170,7 @@
1170
var finalURL = netdataURL(url);
1171
1172
setTimeout(function() {
1158
- document.getElementById('gotoServerList').innerHTML += '<tr><td style="padding-left: 20px;"><a href="' + finalURL + '" target="_blank">' + url + '</a></td><td style="padding-left: 30px;"><code id="' + guid + '-' + id + '-status">checking...</code></td></tr>';
1173
+ document.getElementById('gotoServerList').innerHTML += '<tr><td style="padding-left: 20px;"><a href="' + escapeUserInputJS(finalURL) + '" target="_blank">' + escapeUserInputHTML(url) + '</a></td><td style="padding-left: 30px;"><code id="' + guid + '-' + id + '-status">checking...</code></td></tr>';
1174
1175
NETDATA.registry.hello(url, function(data) {
1176
if(typeof data !== 'undefined' && data !== null && typeof data.machine_guid === 'string' && data.machine_guid === guid) {
@@ -1168,10 +1183,10 @@
1183
if(gotoServerMiddleClick) {
1184
window.open(finalURL, '_blank');
1185
gotoServerMiddleClick = false;
1171
- document.getElementById('gotoServerResponse').innerHTML = '<b>Opening new window to ' + NETDATA.registry.machines[guid].name + '<br/><a href="' + finalURL + '">' + url + '</a></b><br/>(check your pop-up blocker if it fails)';
1186
+ document.getElementById('gotoServerResponse').innerHTML = '<b>Opening new window to ' + NETDATA.registry.machines[guid].name + '<br/><a href="' + escapeUserInputJS(finalURL) + '">' + escapeUserInputHTML(url) + '</a></b><br/>(check your pop-up blocker if it fails)';
1187
}
1188
else {
1174
- document.getElementById('gotoServerResponse').innerHTML += 'found it! It is at:<br/><small>' + url + '</small>';
1189
+ document.getElementById('gotoServerResponse').innerHTML += 'found it! It is at:<br/><small>' + escapeUserInputHTML(url) + '</small>';
1190
document.location = finalURL;
1191
}
1192
}
@@ -1188,7 +1203,7 @@
1203
}
1204
}
1205
});
1191
- }, (id * 50) + penaldy);
1206
+ }, (id * 50) + penalty);
1207
}
1208
1209
function gotoServerModalHandler(guid) {
@@ -5740,6 +5755,6 @@
5755
</div>
5756
</div>
5757
<div id="hiddenDownloadLinks" style="display: none;" hidden></div>
5743
- <script type="text/javascript" src="dashboard.js?v20180917-1"></script>
5758
+ <script type="text/javascript" src="dashboard.js?v20180918-1"></script>
5759
</body>
5760
</html>