snoopdave commented on code in PR #203:
URL: https://github.com/apache/roller/pull/203#discussion_r4174827626


##########
app/src/main/java/org/apache/roller/weblogger/util/InlineImageData.java:
##########
@@ -0,0 +1,156 @@
+/*
+ * Licensed to the Apache Software Foundation (ASF) under one or more
+ * contributor license agreements.  See the NOTICE file distributed with
+ * this work for additional information regarding copyright ownership.
+ * The ASF licenses this file to You under the Apache License, Version 2.0
+ * (the "License"); you may not use this file except in compliance with
+ * the License.  You may obtain a copy of the License at
+ *
+ *     http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.apache.roller.weblogger.util;
+
+import java.util.ArrayList;
+import java.util.Base64;
+import java.util.List;
+import java.util.Locale;
+import java.util.regex.Matcher;
+import java.util.regex.Pattern;
+
+/** Image data URLs accepted in entry content and their locations in HTML. */
+public final class InlineImageData {
+
+    // MySQL's TEXT column holds 65,535 bytes. Leave room for the rest of an 
entry.
+    public static final int MAX_FIELD_BYTES = 60000;
+
+    private static final Pattern IMAGE_TAG = 
Pattern.compile("(?is)<img\\b[^>]*>");
+    private static final Pattern SOURCE_ATTRIBUTE = Pattern.compile(

Review Comment:
   🐞Claude Issue: **Important:** `SOURCE_ATTRIBUTE` can match `src=` inside 
another attribute's quoted value. For example, in `<img 
alt='src="data:image/png;base64,..."' src="https://...";>` the alt text is 
treated as the source. That alt text is then rewritten or rejected, and the 
real `src` is ignored. Match attributes in sequence instead (`name=value` pairs 
from the tag start), or at least skip matches that fall inside an earlier 
quoted value.



##########
app/src/main/java/org/apache/roller/weblogger/util/InlineImageData.java:
##########
@@ -0,0 +1,156 @@
+/*
+ * Licensed to the Apache Software Foundation (ASF) under one or more
+ * contributor license agreements.  See the NOTICE file distributed with
+ * this work for additional information regarding copyright ownership.
+ * The ASF licenses this file to You under the Apache License, Version 2.0
+ * (the "License"); you may not use this file except in compliance with
+ * the License.  You may obtain a copy of the License at
+ *
+ *     http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.apache.roller.weblogger.util;
+
+import java.util.ArrayList;
+import java.util.Base64;
+import java.util.List;
+import java.util.Locale;
+import java.util.regex.Matcher;
+import java.util.regex.Pattern;
+
+/** Image data URLs accepted in entry content and their locations in HTML. */
+public final class InlineImageData {
+
+    // MySQL's TEXT column holds 65,535 bytes. Leave room for the rest of an 
entry.
+    public static final int MAX_FIELD_BYTES = 60000;
+
+    private static final Pattern IMAGE_TAG = 
Pattern.compile("(?is)<img\\b[^>]*>");

Review Comment:
   🐞Claude Issue: **Blocking:** This is the cause of the failing CodeQL check 
(high: polynomial regex on user data). `[^>]*` also matches `<`, so on text 
with many `<img` and no `>` each `find()` scans to the end of the input, which 
is O(n²). Measured with `"<img ".repeat(n)`: 0.44 s at 50 KB, 1.8 s at 100 KB, 
7.2 s at 200 KB. Any author can make a save take minutes.
   
   Fix: stop at the next tag start. On the same input this ran in 1–3 ms:
   ```java
   private static final Pattern IMAGE_TAG = 
Pattern.compile("(?is)<img\\b[^<>]*>");
   ```
   Add a regression test with a large adversarial input.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to