Chromium Code Reviews| Index: fpdfsdk/src/javascript/app.cpp |
| diff --git a/fpdfsdk/src/javascript/app.cpp b/fpdfsdk/src/javascript/app.cpp |
| index 3b92a992d9d0be2b46db2266d0e51847b0a34fdd..e40e446e83212784edadb181d5600524794aef90 100644 |
| --- a/fpdfsdk/src/javascript/app.cpp |
| +++ b/fpdfsdk/src/javascript/app.cpp |
| @@ -1037,15 +1037,13 @@ FX_BOOL app::response(OBJ_METHOD_PARAMS) |
| CFX_WideString swTitle = L"PDF"; |
| #endif |
| CFX_WideString swDefault = L""; |
| - CFX_WideString swResponse = L""; |
| bool bPassWord = false; |
| - |
| + |
| v8::Isolate* isolate = GetIsolate(cc); |
| - |
| - int iLength = params.size(); |
| + |
| + int iLength = params.size(); |
| if (iLength > 0 && params[0].GetType() == VT_object) |
| { |
| - |
| JSObject pObj = (JSObject )params[0]; |
| v8::Handle<v8::Value> pValue = JS_GetObjectElement(isolate,pObj,L"cQuestion"); |
| swQuestion = CJS_Value(isolate,pValue,GET_VALUE_TYPE(pValue)).operator CFX_WideString(); |
| @@ -1101,22 +1099,31 @@ FX_BOOL app::response(OBJ_METHOD_PARAMS) |
| CPDFDoc_Environment* pApp = pContext->GetReaderApp(); |
| ASSERT(pApp != NULL); |
| - int nLength = 2048; |
| - char* pBuff = new char[nLength]; |
| - nLength = pApp->JS_appResponse(swQuestion, swTitle, swDefault, swLabel, bPassWord, pBuff, nLength); |
| - if(nLength<=0) |
| + |
| + const int MAX_INPUT_BYTES = 2048; |
| + const int MAX_INPUT_CODE_UNITS = MAX_INPUT_BYTES / 2; |
| + unsigned short* pBuff = new unsigned short[MAX_INPUT_CODE_UNITS + 1]; |
| + if (!pBuff) |
| + return FALSE; |
| + |
| + memset(pBuff, 0, MAX_INPUT_BYTES + 2); |
| + int nLengthBytes = pApp->JS_appResponse(swQuestion, swTitle, swDefault, swLabel, bPassWord, pBuff, MAX_INPUT_BYTES); |
| + if (nLengthBytes <= 0) |
|
Tom Sepez
2014/07/29 18:53:37
hmm. Just noticed this. Why do we think that an
jun_fang
2014/07/29 19:03:17
An empty string means that users don't input anyth
|
| { |
| - delete[] pBuff; |
| vRet.SetNull(); |
| + delete[] pBuff; |
| return FALSE; |
| } |
| - else |
| - { |
| - nLength = nLength > sizeof(pBuff) ? sizeof(pBuff) : nLength; |
| - vRet = swResponse = CFX_WideString::FromUTF16LE((unsigned short*)pBuff, nLength / 2); |
| - } |
| - delete[] pBuff; |
| + // Don't trust the app_response method to actually tell us the length. Instead, stop at U+0000, with which we pre-filled the buffer, |
| + // thus avoiding problems with strings containing embedded U+0000 code units. |
| + int nCodeUnits; |
| + for (nCodeUnits = 0; nCodeUnits < MAX_INPUT_CODE_UNITS; ++nCodeUnits) |
| + if (!pBuff[nCodeUnits]) |
| + break; |
| + |
| + vRet = CFX_WideString::FromUTF16LE(pBuff, nCodeUnits); |
| + delete[] pBuff; |
| return TRUE; |
| } |