OLD | NEW |
---|---|
1 // Copyright (c) 2012 The Chromium Authors. All rights reserved. | 1 // Copyright (c) 2012 The Chromium Authors. All rights reserved. |
2 // Use of this source code is governed by a BSD-style license that can be | 2 // Use of this source code is governed by a BSD-style license that can be |
3 // found in the LICENSE file. | 3 // found in the LICENSE file. |
4 | 4 |
5 #include "webkit/browser/database/database_util.h" | 5 #include "webkit/browser/database/database_util.h" |
6 | 6 |
7 #include "base/basictypes.h" | 7 #include "base/basictypes.h" |
8 #include "base/strings/utf_string_conversions.h" | 8 #include "base/strings/utf_string_conversions.h" |
9 #include "webkit/browser/database/database_tracker.h" | 9 #include "webkit/browser/database/database_tracker.h" |
10 #include "webkit/browser/database/vfs_backend.h" | 10 #include "webkit/browser/database/vfs_backend.h" |
11 #include "webkit/common/database/database_identifier.h" | |
11 | 12 |
12 namespace webkit_database { | 13 namespace webkit_database { |
13 | 14 |
15 namespace { | |
16 | |
17 bool IsSafeSuffix(const base::string16& suffix) { | |
18 base::char16 prev_c = 0; | |
19 for (base::string16::const_iterator it = suffix.begin(); | |
20 it < suffix.end(); ++it) { | |
21 base::char16 c = *it; | |
22 if (!(IsAsciiAlpha(c) || IsAsciiDigit(c) || | |
michaeln
2014/06/09 18:30:58
here it is...
| |
23 c == '-' || c == '.' || c == '_')) { | |
24 return false; | |
25 } | |
26 if (c == '.' && prev_c == '.') | |
27 return false; | |
28 prev_c = c; | |
29 } | |
30 return true; | |
31 } | |
32 | |
33 } | |
34 | |
14 const char DatabaseUtil::kJournalFileSuffix[] = "-journal"; | 35 const char DatabaseUtil::kJournalFileSuffix[] = "-journal"; |
15 | 36 |
16 bool DatabaseUtil::CrackVfsFileName(const base::string16& vfs_file_name, | 37 bool DatabaseUtil::CrackVfsFileName(const base::string16& vfs_file_name, |
17 std::string* origin_identifier, | 38 std::string* origin_identifier, |
18 base::string16* database_name, | 39 base::string16* database_name, |
19 base::string16* sqlite_suffix) { | 40 base::string16* sqlite_suffix) { |
20 // 'vfs_file_name' is of the form <origin_identifier>/<db_name>#<suffix>. | 41 // 'vfs_file_name' is of the form <origin_identifier>/<db_name>#<suffix>. |
21 // <suffix> is optional. | 42 // <suffix> is optional. |
22 DCHECK(!vfs_file_name.empty()); | 43 DCHECK(!vfs_file_name.empty()); |
23 size_t first_slash_index = vfs_file_name.find('/'); | 44 size_t first_slash_index = vfs_file_name.find('/'); |
24 size_t last_pound_index = vfs_file_name.rfind('#'); | 45 size_t last_pound_index = vfs_file_name.rfind('#'); |
25 // '/' and '#' must be present in the string. Also, the string cannot start | 46 // '/' and '#' must be present in the string. Also, the string cannot start |
26 // with a '/' (origin_identifier cannot be empty) and '/' must come before '#' | 47 // with a '/' (origin_identifier cannot be empty) and '/' must come before '#' |
27 if ((first_slash_index == base::string16::npos) || | 48 if ((first_slash_index == base::string16::npos) || |
28 (last_pound_index == base::string16::npos) || | 49 (last_pound_index == base::string16::npos) || |
29 (first_slash_index == 0) || | 50 (first_slash_index == 0) || |
30 (first_slash_index > last_pound_index)) { | 51 (first_slash_index > last_pound_index)) { |
31 return false; | 52 return false; |
32 } | 53 } |
33 | 54 |
34 if (origin_identifier) { | 55 std::string origin_id = base::UTF16ToASCII( |
35 *origin_identifier = base::UTF16ToASCII( | |
36 vfs_file_name.substr(0, first_slash_index)); | 56 vfs_file_name.substr(0, first_slash_index)); |
37 } | 57 if (!IsValidOriginIdentifier(origin_id)) |
58 return false; | |
59 | |
60 base::string16 suffix = vfs_file_name.substr( | |
61 last_pound_index + 1, vfs_file_name.length() - last_pound_index - 1); | |
62 if (!IsSafeSuffix(suffix)) | |
63 return false; | |
64 | |
65 if (origin_identifier) | |
66 *origin_identifier = origin_id; | |
67 | |
38 if (database_name) { | 68 if (database_name) { |
39 *database_name = vfs_file_name.substr( | 69 *database_name = vfs_file_name.substr( |
40 first_slash_index + 1, last_pound_index - first_slash_index - 1); | 70 first_slash_index + 1, last_pound_index - first_slash_index - 1); |
41 } | 71 } |
42 if (sqlite_suffix) { | 72 |
43 *sqlite_suffix = vfs_file_name.substr( | 73 if (sqlite_suffix) |
44 last_pound_index + 1, vfs_file_name.length() - last_pound_index - 1); | 74 *sqlite_suffix = suffix; |
45 } | 75 |
46 return true; | 76 return true; |
47 } | 77 } |
48 | 78 |
49 base::FilePath DatabaseUtil::GetFullFilePathForVfsFile( | 79 base::FilePath DatabaseUtil::GetFullFilePathForVfsFile( |
50 DatabaseTracker* db_tracker, const base::string16& vfs_file_name) { | 80 DatabaseTracker* db_tracker, const base::string16& vfs_file_name) { |
51 std::string origin_identifier; | 81 std::string origin_identifier; |
52 base::string16 database_name; | 82 base::string16 database_name; |
53 base::string16 sqlite_suffix; | 83 base::string16 sqlite_suffix; |
54 if (!CrackVfsFileName(vfs_file_name, &origin_identifier, | 84 if (!CrackVfsFileName(vfs_file_name, &origin_identifier, |
55 &database_name, &sqlite_suffix)) { | 85 &database_name, &sqlite_suffix)) { |
56 return base::FilePath(); // invalid vfs_file_name | 86 return base::FilePath(); // invalid vfs_file_name |
57 } | 87 } |
58 | 88 |
59 base::FilePath full_path = db_tracker->GetFullDBFilePath( | 89 base::FilePath full_path = db_tracker->GetFullDBFilePath( |
60 origin_identifier, database_name); | 90 origin_identifier, database_name); |
61 if (!full_path.empty() && !sqlite_suffix.empty()) { | 91 if (!full_path.empty() && !sqlite_suffix.empty()) { |
62 DCHECK(full_path.Extension().empty()); | 92 DCHECK(full_path.Extension().empty()); |
63 full_path = full_path.InsertBeforeExtensionASCII( | 93 full_path = full_path.InsertBeforeExtensionASCII( |
64 base::UTF16ToASCII(sqlite_suffix)); | 94 base::UTF16ToASCII(sqlite_suffix)); |
65 } | 95 } |
66 // Watch out for directory traversal attempts from a compromised renderer. | 96 // Watch out for directory traversal attempts from a compromised renderer. |
67 if (full_path.value().find(FILE_PATH_LITERAL("..")) != | 97 if (full_path.value().find(FILE_PATH_LITERAL("..")) != |
68 base::FilePath::StringType::npos) | 98 base::FilePath::StringType::npos) |
69 return base::FilePath(); | 99 return base::FilePath(); |
70 return full_path; | 100 return full_path; |
71 } | 101 } |
72 | 102 |
73 bool DatabaseUtil::IsValidOriginIdentifier( | 103 bool DatabaseUtil::IsValidOriginIdentifier( |
74 const std::string& origin_identifier) { | 104 const std::string& origin_identifier) { |
75 std::string dotdot = ".."; | 105 return GetOriginFromIdentifier(origin_identifier).is_valid(); |
76 char forbidden[] = {'\\', '/', '\0'}; | |
77 | |
78 std::string::size_type pos = origin_identifier.find(dotdot); | |
79 if (pos == std::string::npos) | |
80 pos = origin_identifier.find_first_of(forbidden, 0, arraysize(forbidden)); | |
81 | |
82 return pos == std::string::npos; | |
83 } | 106 } |
84 | 107 |
85 } // namespace webkit_database | 108 } // namespace webkit_database |
OLD | NEW |