fix(nextcloud-files): WR-09/IN-02 ungueltige Pfadzeichen sind 400, Vorschau ohne SVG
- WR-09: ein einzelnes UTF-16-Ersatzzeichen in einem Pfadsegment ist 400 invalidPath (bzw. invalidName) statt eines URIError mit 500; die Weboberflaeche wiederholt keine 4xx - IN-02: Vorschaubilder nur als Rasterbild, image/svg+xml wird wie ein fehlendes Vorschaubild behandelt (CSP-Sandbox und nosniff bleiben) Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -104,9 +104,14 @@ const MAX_SEGMENT_BYTES = 255;
|
||||
const MAX_SEGMENTS = 100;
|
||||
const MAX_PATH_CHARS = 4096;
|
||||
|
||||
/** Ein einzelnes UTF-16-Ersatzzeichen ohne Partner (z. B. `"\uD800"` aus einem JSON-Koerper). */
|
||||
const LONE_SURROGATE = /[\uD800-\uDBFF](?![\uDC00-\uDFFF])|(?<![\uD800-\uDBFF])[\uDC00-\uDFFF]/;
|
||||
|
||||
/**
|
||||
* Ein einzelnes Pfadsegment pruefen (D-H): nicht leer, nicht `.`/`..`, kein
|
||||
* `/`, `\`, NUL oder Steuerzeichen, hoechstens 255 UTF-8-Byte.
|
||||
* `/`, `\`, NUL oder Steuerzeichen, kein einzelnes Ersatzzeichen (WR-09: daran
|
||||
* scheitert `encodeURIComponent` mit einem URIError, der sonst als 500 endete),
|
||||
* hoechstens 255 UTF-8-Byte.
|
||||
*/
|
||||
export function validateSegment(segment: string): string {
|
||||
if (
|
||||
@@ -116,6 +121,7 @@ export function validateSegment(segment: string): string {
|
||||
segment === '..' ||
|
||||
// biome-ignore lint/suspicious/noControlCharactersInRegex: Steuerzeichen sind hier gerade der Prueffall
|
||||
/[\\/\u0000-\u001f\u007f]/.test(segment) ||
|
||||
LONE_SURROGATE.test(segment) ||
|
||||
Buffer.byteLength(segment, 'utf8') > MAX_SEGMENT_BYTES
|
||||
) {
|
||||
throw ncErrorDefault('invalidPath');
|
||||
|
||||
Reference in New Issue
Block a user