Compare commits
3
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
79cd5e2920 | ||
|
|
5079f40f46 | ||
|
|
d895de1b47 |
+11
-5
@@ -79,6 +79,7 @@ _EMAIL_RE = re.compile(r"\b[A-Za-z0-9._%+\-]+@[A-Za-z0-9.\-]+\.[A-Za-z]{2,}\b")
|
||||
_EMAIL_KEEP_DOMAIN = "molodetz.nl"
|
||||
|
||||
_MEDIA_SKIP_TAGS = {"a", "code", "pre"}
|
||||
_TRAILING_PUNCT_RE = re.compile(r"[.,;:!?)\]}\"']+$")
|
||||
_TITLE_INLINE_TAGS = {
|
||||
"b", "strong", "i", "em", "code", "del", "s", "mark", "sub", "sup", "span", "br",
|
||||
}
|
||||
@@ -139,6 +140,11 @@ def _alt_from_url(url: str) -> str:
|
||||
|
||||
|
||||
def _embed_url(url: str) -> str:
|
||||
trail = ""
|
||||
punct_match = _TRAILING_PUNCT_RE.search(url)
|
||||
if punct_match:
|
||||
trail = punct_match.group()
|
||||
url = url[: punct_match.start()]
|
||||
youtube = _YOUTUBE_RE.search(url)
|
||||
if youtube:
|
||||
video_id = youtube.group(1)
|
||||
@@ -146,19 +152,19 @@ def _embed_url(url: str) -> str:
|
||||
f'<div class="embed-youtube"><iframe '
|
||||
f'src="https://www.youtube.com/embed/{video_id}" '
|
||||
f'frameborder="0" allowfullscreen allow="{_YOUTUBE_ALLOW}">'
|
||||
f"</iframe></div>"
|
||||
f"</iframe></div>{trail}"
|
||||
)
|
||||
escaped = html.escape(url, quote=True)
|
||||
if _IMAGE_RE.search(url):
|
||||
alt = html.escape(_alt_from_url(url), quote=True)
|
||||
return f'<img src="{escaped}" alt="{alt}" loading="lazy" data-lightbox>'
|
||||
return f'<img src="{escaped}" alt="{alt}" loading="lazy" data-lightbox>{trail}'
|
||||
if _VIDEO_RE.search(url):
|
||||
return f'<video src="{escaped}" controls preload="metadata"></video>'
|
||||
return f'<video src="{escaped}" controls preload="metadata"></video>{trail}'
|
||||
if _AUDIO_RE.search(url):
|
||||
return f'<audio src="{escaped}" controls preload="metadata"></audio>'
|
||||
return f'<audio src="{escaped}" controls preload="metadata"></audio>{trail}'
|
||||
return (
|
||||
f'<a href="{escaped}" target="_blank" rel="noopener noreferrer">'
|
||||
f"{html.escape(url)}</a>"
|
||||
f"{html.escape(url)}</a>{trail}"
|
||||
)
|
||||
|
||||
|
||||
|
||||
@@ -36,6 +36,7 @@ from devplacepy.database.awards import (
|
||||
from devplacepy.content import can_view_project, enrich_items
|
||||
from devplacepy.utils import (
|
||||
get_current_user,
|
||||
get_badge,
|
||||
require_user,
|
||||
require_user_api,
|
||||
time_ago,
|
||||
@@ -201,6 +202,8 @@ async def profile_page(
|
||||
item["poll"] = polls_map.get(uid)
|
||||
|
||||
badges = list(get_table("badges").find(user_uid=profile_user["uid"]))
|
||||
for b in badges:
|
||||
b["icon"] = get_badge(b["badge_name"]).get("icon")
|
||||
achievements = build_achievements({b["badge_name"] for b in badges})
|
||||
badge_total = sum(group["total"] for group in achievements)
|
||||
badge_earned = sum(group["earned"] for group in achievements)
|
||||
|
||||
@@ -67,6 +67,7 @@ class PollOut(_Out):
|
||||
|
||||
class BadgeOut(_Out):
|
||||
name: Optional[str] = Field(None, alias="badge_name")
|
||||
icon: Optional[str] = None
|
||||
created_at: Optional[str] = None
|
||||
model_config = ConfigDict(populate_by_name=True)
|
||||
|
||||
|
||||
@@ -188,17 +188,21 @@ export class ContentRenderer {
|
||||
a.textContent = "@" + part.username;
|
||||
fragment.appendChild(a);
|
||||
} else {
|
||||
const el = this.urlToEmbed(part.value);
|
||||
const { cleaned, trail } = this.stripTrailingPunct(part.value);
|
||||
const el = this.urlToEmbed(cleaned);
|
||||
if (el) {
|
||||
fragment.appendChild(el);
|
||||
} else {
|
||||
const a = document.createElement("a");
|
||||
a.href = part.value;
|
||||
a.href = cleaned;
|
||||
a.target = "_blank";
|
||||
a.rel = "noopener noreferrer";
|
||||
a.textContent = part.value;
|
||||
a.textContent = cleaned;
|
||||
fragment.appendChild(a);
|
||||
}
|
||||
if (trail) {
|
||||
fragment.appendChild(document.createTextNode(trail));
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -282,6 +286,14 @@ export class ContentRenderer {
|
||||
return null;
|
||||
}
|
||||
|
||||
stripTrailingPunct(url) {
|
||||
const m = url.match(/[.,;:!?)\]}\"']+$/);
|
||||
if (m) {
|
||||
return { cleaned: url.slice(0, m.index), trail: m[0] };
|
||||
}
|
||||
return { cleaned: url, trail: "" };
|
||||
}
|
||||
|
||||
walkNodes(root, callback) {
|
||||
const skipTags = new Set(["CODE", "PRE", "A", "IFRAME", "IMG", "VIDEO", "SCRIPT", "STYLE"]);
|
||||
const iter = document.createNodeIterator(root, NodeFilter.SHOW_TEXT, null, false);
|
||||
|
||||
@@ -263,3 +263,46 @@ def test_xss_legitimate_link_survives_audit():
|
||||
out = str(render_content("see https://example.com/page ok"))
|
||||
assert 'href="https://example.com/page"' in out
|
||||
assert_no_executable_html(out)
|
||||
|
||||
|
||||
def test_bare_url_with_trailing_period():
|
||||
out = str(render_content("see https://example.com/page."))
|
||||
assert 'href="https://example.com/page"' in out
|
||||
assert "</a>." in out
|
||||
assert "https://example.com/page.</a>" not in out
|
||||
|
||||
|
||||
def test_bare_url_with_trailing_comma():
|
||||
out = str(render_content("check https://example.com/page,"))
|
||||
assert 'href="https://example.com/page"' in out
|
||||
assert "</a>," in out
|
||||
|
||||
|
||||
def test_bare_url_with_trailing_exclamation():
|
||||
out = str(render_content("look https://example.com/page!"))
|
||||
assert 'href="https://example.com/page"' in out
|
||||
assert "</a>!" in out
|
||||
|
||||
|
||||
def test_bare_url_with_trailing_question_mark():
|
||||
out = str(render_content("did you see https://example.com/page?"))
|
||||
assert 'href="https://example.com/page"' in out
|
||||
assert "</a>?" in out
|
||||
|
||||
|
||||
def test_bare_url_with_trailing_paren():
|
||||
out = str(render_content("see (https://example.com/page)"))
|
||||
assert 'href="https://example.com/page"' in out
|
||||
assert "</a>)" in out
|
||||
|
||||
|
||||
def test_bare_url_with_trailing_multiple_punctuation():
|
||||
out = str(render_content("visit https://example.com/page..."))
|
||||
assert 'href="https://example.com/page"' in out
|
||||
assert "</a>..." in out
|
||||
|
||||
|
||||
def test_bare_url_without_trailing_punctuation_unchanged():
|
||||
out = str(render_content("see https://example.com/page ok"))
|
||||
assert 'href="https://example.com/page"' in out
|
||||
assert "https://example.com/page</a> " in out
|
||||
|
||||
Reference in New Issue
Block a user