fixed issues identified by lgtm
Costa Tsaousis (ktsaou) committed
Sep 17, 2018 at 14:20 UTC
ff1b8161bfa4bd684ea9a0edfcd86d8dcd939005
8 files changed
+34
-25
node.d/fronius.node.js
+2
-2
@@ -6,8 +6,8 @@
6
7
// example configuration in netdata/conf.d/node.d/fronius.conf.md
8
9
-var url = require("url");
10
-var http = require("http");
9
+require("url");
10
+require("http");
11
var netdata = require("netdata");
12
13
netdata.debug("loaded " + __filename + " plugin");
node.d/named.node.js
+4
-4
@@ -37,8 +37,8 @@ statistics-channels {
37
};
38
*/
39
40
-var url = require('url');
41
-var http = require('http');
40
+require('url');
41
+require('http');
42
var XML = require('pixl-xml');
43
var netdata = require('netdata');
44
@@ -80,11 +80,11 @@ var named = {
80
multiplier: multiplier, // the multiplier
81
divisor: divisor, // the divisor
82
hidden: false // is hidden (boolean)
83
- }
83
+ };
84
}
85
}
86
87
- if(found === false)
87
+ if(!found)
88
return null;
89
90
chart = service.chart(id, chart);
node.d/sma_webbox.node.js
+2
-2
@@ -24,8 +24,8 @@
24
}
25
*/
26
27
-var url = require('url');
28
-var http = require('http');
27
+require('url');
28
+require('http');
29
var netdata = require('netdata');
30
31
if(netdata.options.DEBUG === true) netdata.debug('loaded ' + __filename + ' plugin');
node.d/snmp.node.js
+6
-4
@@ -276,14 +276,16 @@ netdata.processors.snmp = {
276
277
switch(varbinds[i].type) {
278
case net_snmp.ObjectType.OctetString:
279
- if(service.snmp_oids_index[varbinds[i].oid].type !== 'title')
279
+ if(service.snmp_oids_index[varbinds[i].oid].type !== 'title') {
280
// parse floating point values, exposed as strings
281
value = parseFloat(varbinds[i].value) * 1000;
282
- if(__DEBUG === true) netdata.debug(service.module.name + ': ' + service.name + ': found ' + service.module.name + ' value of OIDs ' + varbinds[i].oid + ", ObjectType " + net_snmp.ObjectType[varbinds[i].type] + " (" + netdata.stringify(varbinds[i].type) + "), typeof(" + typeof(varbinds[i].value) + "), in JSON: " + netdata.stringify(varbinds[i].value) + ", value = " + value.toString() + " (parsed as float in string)");
283
- else
282
+ if (__DEBUG === true) netdata.debug(service.module.name + ': ' + service.name + ': found ' + service.module.name + ' value of OIDs ' + varbinds[i].oid + ", ObjectType " + net_snmp.ObjectType[varbinds[i].type] + " (" + netdata.stringify(varbinds[i].type) + "), typeof(" + typeof(varbinds[i].value) + "), in JSON: " + netdata.stringify(varbinds[i].value) + ", value = " + value.toString() + " (parsed as float in string)");
283
+ }
284
+ else {
285
// just use the string
286
value = varbinds[i].value;
286
- if(__DEBUG === true) netdata.debug(service.module.name + ': ' + service.name + ': found ' + service.module.name + ' value of OIDs ' + varbinds[i].oid + ", ObjectType " + net_snmp.ObjectType[varbinds[i].type] + " (" + netdata.stringify(varbinds[i].type) + "), typeof(" + typeof(varbinds[i].value) + "), in JSON: " + netdata.stringify(varbinds[i].value) + ", value = " + value.toString() + " (parsed as string)");
287
+ if (__DEBUG === true) netdata.debug(service.module.name + ': ' + service.name + ': found ' + service.module.name + ' value of OIDs ' + varbinds[i].oid + ", ObjectType " + net_snmp.ObjectType[varbinds[i].type] + " (" + netdata.stringify(varbinds[i].type) + "), typeof(" + typeof(varbinds[i].value) + "), in JSON: " + netdata.stringify(varbinds[i].value) + ", value = " + value.toString() + " (parsed as string)");
288
+ }
289
break;
290
291
case net_snmp.ObjectType.Counter64:
node.d/stiebeleltron.node.js
+2
-2
@@ -6,8 +6,8 @@
6
7
// example configuration in netdata/conf.d/node.d/stiebeleltron.conf.md
8
9
-var url = require("url");
10
-var http = require("http");
9
+require("url");
10
+require("http");
11
var netdata = require("netdata");
12
13
netdata.debug("loaded " + __filename + " plugin");
web/goto-host-from-alarm.html
+11
-4
@@ -22,6 +22,13 @@
22
<script type="text/javascript" src="dashboard.js?v20170724-7"></script>
23
24
<script>
25
+function escapeUserInputXss(s) {
26
+ return s.toString().replace(/</g, '<')
27
+ .replace(/>/g, '>')
28
+ .replace(/"/g, '"')
29
+ .replace(/'/g, '#27;');
30
+}
31
+
32
var urlOptions = {
33
host: null,
34
chart: null,
@@ -87,7 +94,7 @@ function gotoServerValidateUrl(id, guid, url) {
94
var finalURL = netdataURL(url);
95
96
setTimeout(function() {
90
- document.getElementById('gotoServerList').innerHTML += '<tr><td style="padding-left: 20px;"><a href="' + finalURL + '" target="_blank">' + url + '</a></td><td style="padding-left: 30px;"><code id="' + guid + '-' + id + '-status">checking...</code></td></tr>';
97
+ document.getElementById('gotoServerList').innerHTML += '<tr><td style="padding-left: 20px;"><a href="' + escapeUserInputXss(finalURL) + '" target="_blank">' + escapeUserInputXss(url) + '</a></td><td style="padding-left: 30px;"><code id="' + guid + '-' + id + '-status">checking...</code></td></tr>';
98
99
NETDATA.registry.hello(url, function(data) {
100
if(typeof data !== 'undefined' && data !== null && typeof data.machine_guid === 'string' && data.machine_guid === guid) {
@@ -100,7 +107,7 @@ function gotoServerValidateUrl(id, guid, url) {
107
if(gotoServerMiddleClick) {
108
window.open(finalURL);
109
gotoServerMiddleClick = false;
103
- document.getElementById('gotoServerResponse').innerHTML = '<b>Opening new window to ' + NETDATA.registry.machines[guid].name + '<br/><a href="' + finalURL + '">' + url + '</a></b><br/>(check your pop-up blocker if it fails)';
110
+ document.getElementById('gotoServerResponse').innerHTML = '<b>Opening new window to ' + NETDATA.registry.machines[guid].name + '<br/><a href="' + escapeUserInputXss(finalURL) + '">' + escapeUserInputXss(url) + '</a></b><br/>(check your pop-up blocker if it fails)';
111
}
112
else {
113
document.getElementById('gotoServerResponse').innerHTML += 'found it! It is at:<br/><small>' + url + '</small>';
@@ -185,13 +192,13 @@ var netdataRegistryCallback = function(machines_array) {
192
}
193
}
194
188
- document.getElementById('bodylog').innerHTML = "Sorry... your account is not linked to a netdata server named: <b>" + urlOptions.host + '</b>';
195
+ document.getElementById('bodylog').innerHTML = "Sorry... your account is not linked to a netdata server named: <b>" + escapeUserInputXss(urlOptions.host) + '</b>';
196
};
197
198
netdataQueryParse();
199
</script>
200
<body>
194
-<div class="container" id="">
201
+<div class="container">
202
<div id="bodylog" style="padding-top: 8vmax; font-size: 2.0vmax;">
203
<span id="message">Please wait...</span>
204
web/index.html
+3
-3
@@ -580,7 +580,7 @@
580
// control the welcome modal and analytics
581
var this_is_demo = null;
582
583
- function xssFix(s) {
583
+ function escapeUserInputXss(s) {
584
return s.toString().replace(/</g, '<')
585
.replace(/>/g, '>')
586
.replace(/"/g, '"')
@@ -1112,7 +1112,7 @@
1112
1113
function netdataURL(url, forReload) {
1114
if(typeof url === 'undefined')
1115
- url = xssFix(document.location.toString());
1115
+ url = document.location.toString();
1116
1117
if(url.indexOf('#') !== -1)
1118
url = url.substring(0, url.indexOf('#'));
@@ -1121,7 +1121,7 @@
1121
1122
// console.log('netdataURL: ' + url + hash);
1123
1124
- return url + hash;
1124
+ return escapeUserInputXss(url + hash);
1125
}
1126
1127
function netdataReload(url) {
web/registry.html
+4
-4
@@ -115,11 +115,11 @@ var netdataRegistryCallback = function(machines_array) {
115
while(len--) {
116
var u = machines[len];
117
118
- var status = "enabled";
118
+ //var status = "enabled";
119
found++;
120
121
- if(u.guid === NETDATA.registry.machine_guid)
122
- status = "disabled"
121
+ //if(u.guid === NETDATA.registry.machine_guid)
122
+ // status = "disabled";
123
124
el += registryAddServer(u);
125
a1 += '<li id="registry_action_' + u.guid + '"><a href="#" onclick="deleteRegistryModalHandler(\'' + u.guid + '\',\'' + u.name + '\',\'' + u.url + '\'); return false;"><i class="fa fa-trash-o" aria-hidden="true" style="color: #999;"></i></a></li>';
@@ -148,7 +148,7 @@ var netdataRegistryCallback = function(machines_array) {
148
a1 += '<li role="separator" class="divider"></li>';
149
150
el += '<li><a href="https://github.com/firehol/netdata/wiki/mynetdata-menu-item" style="color: #999;" target="_blank">What is this?</a></li>';
151
- a1 += '<li><a href="#" style="color: #999;" onclick="switchRegistryModalHandler(); return false;"><i class="fa fa-cog" aria-hidden="true" style="color: #999;"></i></a></li>'
151
+ a1 += '<li><a href="#" style="color: #999;" onclick="switchRegistryModalHandler(); return false;"><i class="fa fa-cog" aria-hidden="true" style="color: #999;"></i></a></li>';
152
153
document.getElementById('mynetdata_servers').innerHTML = el;
154
//document.getElementById('mynetdata_servers2').innerHTML = el;