check xss on all api methods, even /api/v1/data
Costa Tsaousis (ktsaou) committed
Jan 29, 2018 at 21:19 UTC
a9eca43bcc40fa5ad7b58e3055e8a2a6a685778f
2 files changed
+25
-20
web/dashboard.js
+23
-18
@@ -166,26 +166,17 @@ var NETDATA = window.NETDATA || {};
166
}
167
},
168
169
- checkOptional: function(name, obj, ignore_pattern) {
169
+ checkOptional: function(name, obj, ignore_regex) {
170
if(this.enabled === true) {
171
- var regex;
172
- if(typeof ignore_pattern !== 'undefined')
173
- regex = new RegExp(ignore_pattern);
174
-
175
- //console.log('XSS: checking "' + name + '"...');
176
- return this.object(name, obj, regex);
171
+ // console.log('XSS: checking "' + name + '"...');
172
+ return this.object(name, obj, ignore_regex);
173
}
174
return obj;
175
},
176
181
- checkAlways: function(name, obj, ignore_pattern) {
182
- //console.log('XSS: checking "' + name + '"...');
183
-
184
- var regex;
185
- if(typeof ignore_pattern === 'string')
186
- regex = new RegExp(ignore_pattern);
187
-
188
- return this.object(name, obj, regex);
177
+ checkAlways: function(name, obj, ignore_regex) {
178
+ // console.log('XSS: checking "' + name + '"...');
179
+ return this.object(name, obj, ignore_regex);
180
}
181
};
182
@@ -4986,6 +4977,7 @@ var NETDATA = window.NETDATA || {};
4977
var data = this.getSnapshotData(key);
4978
if (data !== null) {
4979
ok = true;
4980
+ data = NETDATA.xss.checkAlways('/api/v1/data', data, this.library.xssRegexIgnore);
4981
this.updateChartWithData(data);
4982
}
4983
else {
@@ -5017,6 +5009,8 @@ var NETDATA = window.NETDATA || {};
5009
xhrFields: { withCredentials: true } // required for the cookie
5010
})
5011
.done(function(data) {
5012
+ data = NETDATA.xss.checkOptional('/api/v1/data', data, that.library.xssRegexIgnore);
5013
+
5014
that.xhr = undefined;
5015
that.retries_on_data_failures = 0;
5016
ok = true;
@@ -8373,6 +8367,7 @@ var NETDATA = window.NETDATA || {};
8367
toolboxPanAndZoom: NETDATA.dygraphToolboxPanAndZoom,
8368
initialized: false,
8369
enabled: true,
8370
+ xssRegexIgnore: new RegExp('^/api/v1/data\.result.data$'),
8371
format: function(state) { void(state); return 'json'; },
8372
options: function(state) { return 'ms|flip' + (this.isLogScale(state)?'|abs':'').toString(); },
8373
legend: function(state) {
@@ -8417,6 +8412,7 @@ var NETDATA = window.NETDATA || {};
8412
toolboxPanAndZoom: null,
8413
initialized: false,
8414
enabled: true,
8415
+ xssRegexIgnore: new RegExp('^/api/v1/data\.result$'),
8416
format: function(state) { void(state); return 'array'; },
8417
options: function(state) { void(state); return 'flip|abs'; },
8418
legend: function(state) { void(state); return null; },
@@ -8436,6 +8432,7 @@ var NETDATA = window.NETDATA || {};
8432
toolboxPanAndZoom: null,
8433
initialized: false,
8434
enabled: true,
8435
+ xssRegexIgnore: new RegExp('^/api/v1/data\.result$'),
8436
format: function(state) { void(state); return 'ssvcomma'; },
8437
options: function(state) { void(state); return 'null2zero|flip|abs'; },
8438
legend: function(state) { void(state); return null; },
@@ -8455,6 +8452,7 @@ var NETDATA = window.NETDATA || {};
8452
toolboxPanAndZoom: null,
8453
initialized: false,
8454
enabled: true,
8455
+ xssRegexIgnore: new RegExp('^/api/v1/data\.result.data$'),
8456
format: function(state) { void(state); return 'json'; },
8457
options: function(state) { void(state); return 'objectrows|ms'; },
8458
legend: function(state) { void(state); return null; },
@@ -8474,6 +8472,7 @@ var NETDATA = window.NETDATA || {};
8472
toolboxPanAndZoom: null,
8473
initialized: false,
8474
enabled: true,
8475
+ xssRegexIgnore: new RegExp('^/api/v1/data\.result.rows$'),
8476
format: function(state) { void(state); return 'datatable'; },
8477
options: function(state) { void(state); return ''; },
8478
legend: function(state) { void(state); return null; },
@@ -8493,6 +8492,7 @@ var NETDATA = window.NETDATA || {};
8492
toolboxPanAndZoom: null,
8493
initialized: false,
8494
enabled: true,
8495
+ xssRegexIgnore: new RegExp('^/api/v1/data\.result.data$'),
8496
format: function(state) { void(state); return 'json'; },
8497
options: function(state) { void(state); return ''; },
8498
legend: function(state) { void(state); return null; },
@@ -8512,6 +8512,7 @@ var NETDATA = window.NETDATA || {};
8512
toolboxPanAndZoom: null,
8513
initialized: false,
8514
enabled: true,
8515
+ xssRegexIgnore: new RegExp('^/api/v1/data\.result$'),
8516
format: function(state) { void(state); return 'csvjsonarray'; },
8517
options: function(state) { void(state); return 'milliseconds'; },
8518
legend: function(state) { void(state); return null; },
@@ -8531,6 +8532,7 @@ var NETDATA = window.NETDATA || {};
8532
toolboxPanAndZoom: null,
8533
initialized: false,
8534
enabled: true,
8535
+ xssRegexIgnore: new RegExp('^/api/v1/data\.result.data$'),
8536
format: function(state) { void(state); return 'json'; },
8537
options: function(state) { void(state); return 'objectrows|ms'; },
8538
legend: function(state) { void(state); return null; },
@@ -8550,6 +8552,7 @@ var NETDATA = window.NETDATA || {};
8552
toolboxPanAndZoom: null,
8553
initialized: false,
8554
enabled: true,
8555
+ xssRegexIgnore: new RegExp('^/api/v1/data\.result.data$'),
8556
format: function(state) { void(state); return 'json'; },
8557
options: function(state) { void(state); return ''; },
8558
legend: function(state) { void(state); return null; },
@@ -8569,6 +8572,7 @@ var NETDATA = window.NETDATA || {};
8572
toolboxPanAndZoom: null,
8573
initialized: false,
8574
enabled: true,
8575
+ xssRegexIgnore: new RegExp('^/api/v1/data\.result$'),
8576
format: function(state) { void(state); return 'array'; },
8577
options: function(state) { void(state); return 'absolute'; },
8578
legend: function(state) { void(state); return null; },
@@ -8589,6 +8593,7 @@ var NETDATA = window.NETDATA || {};
8593
toolboxPanAndZoom: null,
8594
initialized: false,
8595
enabled: true,
8596
+ xssRegexIgnore: new RegExp('^/api/v1/data\.result$'),
8597
format: function(state) { void(state); return 'array'; },
8598
options: function(state) { void(state); return 'absolute'; },
8599
legend: function(state) { void(state); return null; },
@@ -9012,7 +9017,7 @@ var NETDATA = window.NETDATA || {};
9017
xhrFields: { withCredentials: true } // required for the cookie
9018
})
9019
.done(function(data) {
9015
- data = NETDATA.xss.checkOptional('/api/v1/alarms', data, '.*\.(calc|calc_parsed|warn|warn_parsed|crit|crit_parsed)$');
9020
+ data = NETDATA.xss.checkOptional('/api/v1/alarms', data /*, '.*\.(calc|calc_parsed|warn|warn_parsed|crit|crit_parsed)$' */);
9021
9022
if(NETDATA.alarms.first_notification_id === 0 && typeof data.latest_alarm_log_unique_id === 'number')
9023
NETDATA.alarms.first_notification_id = data.latest_alarm_log_unique_id;
@@ -9198,13 +9203,13 @@ var NETDATA = window.NETDATA || {};
9203
xhrFields: { withCredentials: true } // required for the cookie
9204
})
9205
.done(function(data) {
9206
+ data = NETDATA.xss.checkOptional('/api/v1/registry?action=hello', data);
9207
+
9208
if(typeof data.status !== 'string' || data.status !== 'ok') {
9209
NETDATA.error(408, host + ' response: ' + JSON.stringify(data));
9210
data = null;
9211
}
9212
9206
- data = NETDATA.xss.checkOptional('/api/v1/registry?action=hello', data);
9207
-
9213
if(typeof callback === 'function')
9214
return callback(data);
9215
})
web/index.html
+2
-2
@@ -3285,7 +3285,7 @@
3285
document.getElementById('loadSnapshotFilename').innerHTML = filename;
3286
var result = null;
3287
try {
3288
- result = NETDATA.xss.checkAlways('snapshot', JSON.parse(e.target.result), '^(snapshot\.info|snapshot\.data)$');
3288
+ result = NETDATA.xss.checkAlways('snapshot', JSON.parse(e.target.result), /^(snapshot\.info|snapshot\.data)$/);
3289
3290
//console.log(result);
3291
var date_after = new Date(result.after_ms);
@@ -5629,6 +5629,6 @@
5629
</div>
5630
</div>
5631
<div id="hiddenDownloadLinks" style="display: none;" hidden></div>
5632
- <script type="text/javascript" src="dashboard.js?v20180128-2"></script>
5632
+ <script type="text/javascript" src="dashboard.js?v20180129-1"></script>
5633
</body>
5634
</html>