@cryptotaxi247 / netdata-1 / commits / a9eca43bc

check xss on all api methods, even /api/v1/data

Costa Tsaousis (ktsaou) committed Jan 29, 2018 at 21:19 UTC a9eca43bcc40fa5ad7b58e3055e8a2a6a685778f
2 files changed +25 -20
web/dashboard.js
+23 -18
@@ -166,26 +166,17 @@ var NETDATA = window.NETDATA || {};
166 }
167 },
168
169 - checkOptional: function(name, obj, ignore_pattern) {
169 + checkOptional: function(name, obj, ignore_regex) {
170 if(this.enabled === true) {
171 - var regex;
172 - if(typeof ignore_pattern !== 'undefined')
173 - regex = new RegExp(ignore_pattern);
174 -
175 - //console.log('XSS: checking "' + name + '"...');
176 - return this.object(name, obj, regex);
171 + // console.log('XSS: checking "' + name + '"...');
172 + return this.object(name, obj, ignore_regex);
173 }
174 return obj;
175 },
176
181 - checkAlways: function(name, obj, ignore_pattern) {
182 - //console.log('XSS: checking "' + name + '"...');
183 -
184 - var regex;
185 - if(typeof ignore_pattern === 'string')
186 - regex = new RegExp(ignore_pattern);
187 -
188 - return this.object(name, obj, regex);
177 + checkAlways: function(name, obj, ignore_regex) {
178 + // console.log('XSS: checking "' + name + '"...');
179 + return this.object(name, obj, ignore_regex);
180 }
181 };
182
@@ -4986,6 +4977,7 @@ var NETDATA = window.NETDATA || {};
4977 var data = this.getSnapshotData(key);
4978 if (data !== null) {
4979 ok = true;
4980 + data = NETDATA.xss.checkAlways('/api/v1/data', data, this.library.xssRegexIgnore);
4981 this.updateChartWithData(data);
4982 }
4983 else {
@@ -5017,6 +5009,8 @@ var NETDATA = window.NETDATA || {};
5009 xhrFields: { withCredentials: true } // required for the cookie
5010 })
5011 .done(function(data) {
5012 + data = NETDATA.xss.checkOptional('/api/v1/data', data, that.library.xssRegexIgnore);
5013 +
5014 that.xhr = undefined;
5015 that.retries_on_data_failures = 0;
5016 ok = true;
@@ -8373,6 +8367,7 @@ var NETDATA = window.NETDATA || {};
8367 toolboxPanAndZoom: NETDATA.dygraphToolboxPanAndZoom,
8368 initialized: false,
8369 enabled: true,
8370 + xssRegexIgnore: new RegExp('^/api/v1/data\.result.data$'),
8371 format: function(state) { void(state); return 'json'; },
8372 options: function(state) { return 'ms|flip' + (this.isLogScale(state)?'|abs':'').toString(); },
8373 legend: function(state) {
@@ -8417,6 +8412,7 @@ var NETDATA = window.NETDATA || {};
8412 toolboxPanAndZoom: null,
8413 initialized: false,
8414 enabled: true,
8415 + xssRegexIgnore: new RegExp('^/api/v1/data\.result$'),
8416 format: function(state) { void(state); return 'array'; },
8417 options: function(state) { void(state); return 'flip|abs'; },
8418 legend: function(state) { void(state); return null; },
@@ -8436,6 +8432,7 @@ var NETDATA = window.NETDATA || {};
8432 toolboxPanAndZoom: null,
8433 initialized: false,
8434 enabled: true,
8435 + xssRegexIgnore: new RegExp('^/api/v1/data\.result$'),
8436 format: function(state) { void(state); return 'ssvcomma'; },
8437 options: function(state) { void(state); return 'null2zero|flip|abs'; },
8438 legend: function(state) { void(state); return null; },
@@ -8455,6 +8452,7 @@ var NETDATA = window.NETDATA || {};
8452 toolboxPanAndZoom: null,
8453 initialized: false,
8454 enabled: true,
8455 + xssRegexIgnore: new RegExp('^/api/v1/data\.result.data$'),
8456 format: function(state) { void(state); return 'json'; },
8457 options: function(state) { void(state); return 'objectrows|ms'; },
8458 legend: function(state) { void(state); return null; },
@@ -8474,6 +8472,7 @@ var NETDATA = window.NETDATA || {};
8472 toolboxPanAndZoom: null,
8473 initialized: false,
8474 enabled: true,
8475 + xssRegexIgnore: new RegExp('^/api/v1/data\.result.rows$'),
8476 format: function(state) { void(state); return 'datatable'; },
8477 options: function(state) { void(state); return ''; },
8478 legend: function(state) { void(state); return null; },
@@ -8493,6 +8492,7 @@ var NETDATA = window.NETDATA || {};
8492 toolboxPanAndZoom: null,
8493 initialized: false,
8494 enabled: true,
8495 + xssRegexIgnore: new RegExp('^/api/v1/data\.result.data$'),
8496 format: function(state) { void(state); return 'json'; },
8497 options: function(state) { void(state); return ''; },
8498 legend: function(state) { void(state); return null; },
@@ -8512,6 +8512,7 @@ var NETDATA = window.NETDATA || {};
8512 toolboxPanAndZoom: null,
8513 initialized: false,
8514 enabled: true,
8515 + xssRegexIgnore: new RegExp('^/api/v1/data\.result$'),
8516 format: function(state) { void(state); return 'csvjsonarray'; },
8517 options: function(state) { void(state); return 'milliseconds'; },
8518 legend: function(state) { void(state); return null; },
@@ -8531,6 +8532,7 @@ var NETDATA = window.NETDATA || {};
8532 toolboxPanAndZoom: null,
8533 initialized: false,
8534 enabled: true,
8535 + xssRegexIgnore: new RegExp('^/api/v1/data\.result.data$'),
8536 format: function(state) { void(state); return 'json'; },
8537 options: function(state) { void(state); return 'objectrows|ms'; },
8538 legend: function(state) { void(state); return null; },
@@ -8550,6 +8552,7 @@ var NETDATA = window.NETDATA || {};
8552 toolboxPanAndZoom: null,
8553 initialized: false,
8554 enabled: true,
8555 + xssRegexIgnore: new RegExp('^/api/v1/data\.result.data$'),
8556 format: function(state) { void(state); return 'json'; },
8557 options: function(state) { void(state); return ''; },
8558 legend: function(state) { void(state); return null; },
@@ -8569,6 +8572,7 @@ var NETDATA = window.NETDATA || {};
8572 toolboxPanAndZoom: null,
8573 initialized: false,
8574 enabled: true,
8575 + xssRegexIgnore: new RegExp('^/api/v1/data\.result$'),
8576 format: function(state) { void(state); return 'array'; },
8577 options: function(state) { void(state); return 'absolute'; },
8578 legend: function(state) { void(state); return null; },
@@ -8589,6 +8593,7 @@ var NETDATA = window.NETDATA || {};
8593 toolboxPanAndZoom: null,
8594 initialized: false,
8595 enabled: true,
8596 + xssRegexIgnore: new RegExp('^/api/v1/data\.result$'),
8597 format: function(state) { void(state); return 'array'; },
8598 options: function(state) { void(state); return 'absolute'; },
8599 legend: function(state) { void(state); return null; },
@@ -9012,7 +9017,7 @@ var NETDATA = window.NETDATA || {};
9017 xhrFields: { withCredentials: true } // required for the cookie
9018 })
9019 .done(function(data) {
9015 - data = NETDATA.xss.checkOptional('/api/v1/alarms', data, '.*\.(calc|calc_parsed|warn|warn_parsed|crit|crit_parsed)$');
9020 + data = NETDATA.xss.checkOptional('/api/v1/alarms', data /*, '.*\.(calc|calc_parsed|warn|warn_parsed|crit|crit_parsed)$' */);
9021
9022 if(NETDATA.alarms.first_notification_id === 0 && typeof data.latest_alarm_log_unique_id === 'number')
9023 NETDATA.alarms.first_notification_id = data.latest_alarm_log_unique_id;
@@ -9198,13 +9203,13 @@ var NETDATA = window.NETDATA || {};
9203 xhrFields: { withCredentials: true } // required for the cookie
9204 })
9205 .done(function(data) {
9206 + data = NETDATA.xss.checkOptional('/api/v1/registry?action=hello', data);
9207 +
9208 if(typeof data.status !== 'string' || data.status !== 'ok') {
9209 NETDATA.error(408, host + ' response: ' + JSON.stringify(data));
9210 data = null;
9211 }
9212
9206 - data = NETDATA.xss.checkOptional('/api/v1/registry?action=hello', data);
9207 -
9213 if(typeof callback === 'function')
9214 return callback(data);
9215 })
web/index.html
+2 -2
@@ -3285,7 +3285,7 @@
3285 document.getElementById('loadSnapshotFilename').innerHTML = filename;
3286 var result = null;
3287 try {
3288 - result = NETDATA.xss.checkAlways('snapshot', JSON.parse(e.target.result), '^(snapshot\.info|snapshot\.data)$');
3288 + result = NETDATA.xss.checkAlways('snapshot', JSON.parse(e.target.result), /^(snapshot\.info|snapshot\.data)$/);
3289
3290 //console.log(result);
3291 var date_after = new Date(result.after_ms);
@@ -5629,6 +5629,6 @@
5629 </div>
5630 </div>
5631 <div id="hiddenDownloadLinks" style="display: none;" hidden></div>
5632 - <script type="text/javascript" src="dashboard.js?v20180128-2"></script>
5632 + <script type="text/javascript" src="dashboard.js?v20180129-1"></script>
5633 </body>
5634 </html>