mirror of
https://github.com/onionshare/onionshare.git
synced 2025-01-10 19:52:50 -03:00
fixed critical XSS bug that can deanonymize user
This commit is contained in:
parent
2edde2eb1f
commit
d9aa55b991
2 changed files with 50 additions and 1 deletions
|
@ -9,3 +9,52 @@ function human_readable_filesize(bytes, si) {
|
||||||
} while(bytes >= thresh);
|
} while(bytes >= thresh);
|
||||||
return bytes.toFixed(1)+' '+units[u];
|
return bytes.toFixed(1)+' '+units[u];
|
||||||
};
|
};
|
||||||
|
|
||||||
|
function htmlspecialchars(string, quote_style, charset, double_encode) {
|
||||||
|
var optTemp = 0,
|
||||||
|
i = 0,
|
||||||
|
noquotes = false;
|
||||||
|
if (typeof quote_style === 'undefined' || quote_style === null) {
|
||||||
|
quote_style = 2;
|
||||||
|
}
|
||||||
|
string = string.toString();
|
||||||
|
if (double_encode !== false) {
|
||||||
|
// Put this first to avoid double-encoding
|
||||||
|
string = string.replace(/&/g, '&');
|
||||||
|
}
|
||||||
|
string = string.replace(/</g, '<')
|
||||||
|
.replace(/>/g, '>');
|
||||||
|
|
||||||
|
var OPTS = {
|
||||||
|
'ENT_NOQUOTES': 0,
|
||||||
|
'ENT_HTML_QUOTE_SINGLE': 1,
|
||||||
|
'ENT_HTML_QUOTE_DOUBLE': 2,
|
||||||
|
'ENT_COMPAT': 2,
|
||||||
|
'ENT_QUOTES': 3,
|
||||||
|
'ENT_IGNORE': 4
|
||||||
|
};
|
||||||
|
if (quote_style === 0) {
|
||||||
|
noquotes = true;
|
||||||
|
}
|
||||||
|
if (typeof quote_style !== 'number') {
|
||||||
|
// Allow for a single string or an array of string flags
|
||||||
|
quote_style = [].concat(quote_style);
|
||||||
|
for (i = 0; i < quote_style.length; i++) {
|
||||||
|
// Resolve string input to bitwise e.g. 'ENT_IGNORE' becomes 4
|
||||||
|
if (OPTS[quote_style[i]] === 0) {
|
||||||
|
noquotes = true;
|
||||||
|
} else if (OPTS[quote_style[i]]) {
|
||||||
|
optTemp = optTemp | OPTS[quote_style[i]];
|
||||||
|
}
|
||||||
|
}
|
||||||
|
quote_style = optTemp;
|
||||||
|
}
|
||||||
|
if (quote_style & OPTS.ENT_HTML_QUOTE_SINGLE) {
|
||||||
|
string = string.replace(/'/g, ''');
|
||||||
|
}
|
||||||
|
if (!noquotes) {
|
||||||
|
string = string.replace(/"/g, '"');
|
||||||
|
}
|
||||||
|
|
||||||
|
return string;
|
||||||
|
}
|
||||||
|
|
|
@ -65,7 +65,7 @@ $(function(){
|
||||||
}
|
}
|
||||||
} else {
|
} else {
|
||||||
if(r.path != '/favicon.ico')
|
if(r.path != '/favicon.ico')
|
||||||
update($('<span>').addClass('weblog-error').html(onionshare.strings['other_page_loaded']+': '+r.path));
|
update($('<span>').addClass('weblog-error').html(onionshare.strings['other_page_loaded']+': '+htmlspecialchars(r.path)));
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
Loading…
Reference in a new issue