bhaskargurram-ai opened a new pull request, #707:
URL: https://github.com/apache/shenyu-dashboard/pull/707
Fixes #613
## What is the problem
Plugin handle metadata stores an optional validation rule (`extObj.rule`) as
a regular expression literal, for example `"/^(true|false)$/"` or `"/^[01]$/"`
in the ShenYu seed data. Seven form call sites passed that admin-editable
string to `eval()` to build the antd `pattern` rule, so any JavaScript stored
in a rule ran in the browser of every user who opened one of these forms:
- `src/routes/System/Plugin/AddModal.js`
- `src/routes/System/NamespacePlugin/AddModal.js`
- `src/routes/Plugin/Common/Selector.js` (2 sites)
- `src/routes/Plugin/Common/CommonRuleHandle.js`
- `src/routes/Plugin/Discovery/ProxySelectorModal.js` (2 sites)
The issue lists the first three files; the last two had the same pattern.
## What this PR does
- Adds `parseRegExpRule()` in `src/utils/regExpRule.js`. It reads the
`/source/flags` literal using the same rules as a JavaScript regex literal: an
escaped `\/` and a `/` inside a character class do not end the source. It
accepts only the standard RegExp flags (`dgimsuvy`) and builds the pattern with
`new RegExp(source, flags)`. An empty source, a bad pattern, unknown or
duplicate flags, or any text after the flags gives `undefined`.
- All seven call sites now use the helper. A pattern rule is added only when
the helper returns a `RegExp`. If a stored rule is not a valid regex literal,
the field gets no pattern rule. Before this change, the same value either threw
during render or was run as code.
- Valid rules behave as before. The validation message still shows the
stored rule text.
## How I tested it
- Added `src/utils/regExpRule.test.js` (25 cases). It covers the two rule
formats in ShenYu's `schema.sql`, flags, escaped and character-class slashes,
invalid flags (`/abc/x`, `/abc/gg`), values that are not regex literals
(`^\d+$`, `abc`, `//`, `/(/`, non-strings), and payloads such as
`(()=>{globalThis.pwned=1})()`, `/x/,globalThis.pwned=1` and
`/x/.constructor.constructor('globalThis.pwned=1')()`. Each payload returns
`undefined` and leaves `global.pwned` unset.
- I also ran a throwaway check that I did not commit. For 10 valid literals,
the parser's `source` and `flags` matched what `eval` returned. The same check
confirmed that `eval` really does run two of the payloads above.
- `npx jest --runInBand`: 53 suites, 273 tests passed.
- `eslint` and `prettier --check` pass on the changed files.
## Checklist
- [x] Unit tests added for the new helper
- [x] `npm run test:unit` passes locally
- [x] ESLint / Prettier clean on changed files
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]