fix several newline problems (#15028) [backend]

* prevent newlines where they shouldn't be
* 'contentLength' shouldn't be negative
This commit is contained in:
Miran 2020-07-21 22:49:08 +02:00 • committed by GitHub
commit 5fafa2fd5c
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23
3 changed files with 37 additions and 2 deletions

View file

@ -146,7 +146,11 @@ proc send*(ftp: AsyncFtpClient, m: string): Future[TaintedString] {.async.} =
## Send a message to the server, and wait for a primary reply. ## Send a message to the server, and wait for a primary reply.
## ``\c\L`` is added for you. ## ``\c\L`` is added for you.
## ##
## You need to make sure that the message ``m`` doesn't contain any newline
## characters. Failing to do so will raise ``AssertionDefect``.
##
## **Note:** The server may return multiple lines of coded replies. ## **Note:** The server may return multiple lines of coded replies.
doAssert(not m.contains({'\c', '\L'}), "message shouldn't contain any newline characters")
await ftp.csock.send(m & "\c\L") await ftp.csock.send(m & "\c\L")
return await ftp.expectReply() return await ftp.expectReply()

View file

@ -245,7 +245,8 @@ proc contentLength*(response: Response | AsyncResponse): int =
## ##
## A ``ValueError`` exception will be raised if the value is not an integer. ## A ``ValueError`` exception will be raised if the value is not an integer.
var contentLengthHeader = response.headers.getOrDefault("Content-Length") var contentLengthHeader = response.headers.getOrDefault("Content-Length")
return contentLengthHeader.parseInt() result = contentLengthHeader.parseInt()
doAssert(result >= 0 and result <= high(int32))
proc lastModified*(response: Response | AsyncResponse): DateTime = proc lastModified*(response: Response | AsyncResponse): DateTime =
## Retrieves the specified response's last modified time. ## Retrieves the specified response's last modified time.
@ -1033,6 +1034,11 @@ proc request*(client: HttpClient | AsyncHttpClient, url: string,
## ##
## This procedure will follow redirects up to a maximum number of redirects ## This procedure will follow redirects up to a maximum number of redirects
## specified in ``client.maxRedirects``. ## specified in ``client.maxRedirects``.
##
## You need to make sure that the ``url`` doesn't contain any newline
## characters. Failing to do so will raise ``AssertionDefect``.
doAssert(not url.contains({'\c', '\L'}), "url shouldn't contain any newline characters")
result = await client.requestAux(url, httpMethod, body, headers, multipart) result = await client.requestAux(url, httpMethod, body, headers, multipart)
var lastURL = url var lastURL = url

View file

@ -43,7 +43,7 @@
## For SSL support this module relies on OpenSSL. If you want to ## For SSL support this module relies on OpenSSL. If you want to
## enable SSL, compile with ``-d:ssl``. ## enable SSL, compile with ``-d:ssl``.
import net, strutils, strtabs, base64, os import net, strutils, strtabs, base64, os, strutils
import asyncnet, asyncdispatch import asyncnet, asyncdispatch
export Port export Port
@ -65,6 +65,11 @@ type
Smtp* = SmtpBase[Socket] Smtp* = SmtpBase[Socket]
AsyncSmtp* = SmtpBase[AsyncSocket] AsyncSmtp* = SmtpBase[AsyncSocket]
proc containsNewline(xs: seq[string]): bool =
for x in xs:
if x.contains({'\c', '\L'}):
return true
proc debugSend*(smtp: Smtp | AsyncSmtp, cmd: string) {.multisync.} = proc debugSend*(smtp: Smtp | AsyncSmtp, cmd: string) {.multisync.} =
## Sends ``cmd`` on the socket connected to the SMTP server. ## Sends ``cmd`` on the socket connected to the SMTP server.
## ##
@ -119,6 +124,14 @@ else:
proc createMessage*(mSubject, mBody: string, mTo, mCc: seq[string], proc createMessage*(mSubject, mBody: string, mTo, mCc: seq[string],
otherHeaders: openarray[tuple[name, value: string]]): Message = otherHeaders: openarray[tuple[name, value: string]]): Message =
## Creates a new MIME compliant message. ## Creates a new MIME compliant message.
##
## You need to make sure that ``mSubject``, ``mTo`` and ``mCc`` don't contain
## any newline characters. Failing to do so will raise ``AssertionDefect``.
doAssert(not mSubject.contains({'\c', '\L'}),
"'mSubject' shouldn't contain any newline characters")
doAssert(not (mTo.containsNewline() or mCc.containsNewline()),
"'mTo' and 'mCc' shouldn't contain any newline characters")
result.msgTo = mTo result.msgTo = mTo
result.msgCc = mCc result.msgCc = mCc
result.msgSubject = mSubject result.msgSubject = mSubject
@ -130,6 +143,13 @@ proc createMessage*(mSubject, mBody: string, mTo, mCc: seq[string],
proc createMessage*(mSubject, mBody: string, mTo, proc createMessage*(mSubject, mBody: string, mTo,
mCc: seq[string] = @[]): Message = mCc: seq[string] = @[]): Message =
## Alternate version of the above. ## Alternate version of the above.
##
## You need to make sure that ``mSubject``, ``mTo`` and ``mCc`` don't contain
## any newline characters. Failing to do so will raise ``AssertionDefect``.
doAssert(not mSubject.contains({'\c', '\L'}),
"'mSubject' shouldn't contain any newline characters")
doAssert(not (mTo.containsNewline() or mCc.containsNewline()),
"'mTo' and 'mCc' shouldn't contain any newline characters")
result.msgTo = mTo result.msgTo = mTo
result.msgCc = mCc result.msgCc = mCc
result.msgSubject = mSubject result.msgSubject = mSubject
@ -247,6 +267,11 @@ proc sendMail*(smtp: Smtp | AsyncSmtp, fromAddr: string,
## Sends ``msg`` from ``fromAddr`` to the addresses specified in ``toAddrs``. ## Sends ``msg`` from ``fromAddr`` to the addresses specified in ``toAddrs``.
## Messages may be formed using ``createMessage`` by converting the ## Messages may be formed using ``createMessage`` by converting the
## Message into a string. ## Message into a string.
##
## You need to make sure that ``fromAddr`` and ``toAddrs`` don't contain
## any newline characters. Failing to do so will raise ``AssertionDefect``.
doAssert(not (toAddrs.containsNewline() or fromAddr.contains({'\c', '\L'})),
"'toAddrs' and 'fromAddr' shouldn't contain any newline characters")
await smtp.debugSend("MAIL FROM:<" & fromAddr & ">\c\L") await smtp.debugSend("MAIL FROM:<" & fromAddr & ">\c\L")
await smtp.checkReply("250") await smtp.checkReply("250")