snoopdave commented on code in PR #203: URL: https://github.com/apache/roller/pull/203#discussion_r4174827626
########## app/src/main/java/org/apache/roller/weblogger/util/InlineImageData.java: ########## @@ -0,0 +1,156 @@ +/* + * Licensed to the Apache Software Foundation (ASF) under one or more + * contributor license agreements. See the NOTICE file distributed with + * this work for additional information regarding copyright ownership. + * The ASF licenses this file to You under the Apache License, Version 2.0 + * (the "License"); you may not use this file except in compliance with + * the License. You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ +package org.apache.roller.weblogger.util; + +import java.util.ArrayList; +import java.util.Base64; +import java.util.List; +import java.util.Locale; +import java.util.regex.Matcher; +import java.util.regex.Pattern; + +/** Image data URLs accepted in entry content and their locations in HTML. */ +public final class InlineImageData { + + // MySQL's TEXT column holds 65,535 bytes. Leave room for the rest of an entry. + public static final int MAX_FIELD_BYTES = 60000; + + private static final Pattern IMAGE_TAG = Pattern.compile("(?is)<img\\b[^>]*>"); + private static final Pattern SOURCE_ATTRIBUTE = Pattern.compile( Review Comment: 🐞Claude Issue: **Important:** `SOURCE_ATTRIBUTE` can match `src=` inside another attribute's quoted value. For example, in `<img alt='src="data:image/png;base64,..."' src="https://...">` the alt text is treated as the source. That alt text is then rewritten or rejected, and the real `src` is ignored. Match attributes in sequence instead (`name=value` pairs from the tag start), or at least skip matches that fall inside an earlier quoted value. ########## app/src/main/java/org/apache/roller/weblogger/util/InlineImageData.java: ########## @@ -0,0 +1,156 @@ +/* + * Licensed to the Apache Software Foundation (ASF) under one or more + * contributor license agreements. See the NOTICE file distributed with + * this work for additional information regarding copyright ownership. + * The ASF licenses this file to You under the Apache License, Version 2.0 + * (the "License"); you may not use this file except in compliance with + * the License. You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ +package org.apache.roller.weblogger.util; + +import java.util.ArrayList; +import java.util.Base64; +import java.util.List; +import java.util.Locale; +import java.util.regex.Matcher; +import java.util.regex.Pattern; + +/** Image data URLs accepted in entry content and their locations in HTML. */ +public final class InlineImageData { + + // MySQL's TEXT column holds 65,535 bytes. Leave room for the rest of an entry. + public static final int MAX_FIELD_BYTES = 60000; + + private static final Pattern IMAGE_TAG = Pattern.compile("(?is)<img\\b[^>]*>"); Review Comment: 🐞Claude Issue: **Blocking:** This is the cause of the failing CodeQL check (high: polynomial regex on user data). `[^>]*` also matches `<`, so on text with many `<img` and no `>` each `find()` scans to the end of the input, which is O(n²). Measured with `"<img ".repeat(n)`: 0.44 s at 50 KB, 1.8 s at 100 KB, 7.2 s at 200 KB. Any author can make a save take minutes. Fix: stop at the next tag start. On the same input this ran in 1–3 ms: ```java private static final Pattern IMAGE_TAG = Pattern.compile("(?is)<img\\b[^<>]*>"); ``` Add a regression test with a large adversarial input. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
