bhaskargurram-ai opened a new pull request, #707:
URL: https://github.com/apache/shenyu-dashboard/pull/707

   Fixes #613
   
   ## What is the problem
   
   Plugin handle metadata stores an optional validation rule (`extObj.rule`) as 
a regular expression literal, for example `"/^(true|false)$/"` or `"/^[01]$/"` 
in the ShenYu seed data. Seven form call sites passed that admin-editable 
string to `eval()` to build the antd `pattern` rule, so any JavaScript stored 
in a rule ran in the browser of every user who opened one of these forms:
   
   - `src/routes/System/Plugin/AddModal.js`
   - `src/routes/System/NamespacePlugin/AddModal.js`
   - `src/routes/Plugin/Common/Selector.js` (2 sites)
   - `src/routes/Plugin/Common/CommonRuleHandle.js`
   - `src/routes/Plugin/Discovery/ProxySelectorModal.js` (2 sites)
   
   The issue lists the first three files; the last two had the same pattern.
   
   ## What this PR does
   
   - Adds `parseRegExpRule()` in `src/utils/regExpRule.js`. It reads the 
`/source/flags` literal using the same rules as a JavaScript regex literal: an 
escaped `\/` and a `/` inside a character class do not end the source. It 
accepts only the standard RegExp flags (`dgimsuvy`) and builds the pattern with 
`new RegExp(source, flags)`. An empty source, a bad pattern, unknown or 
duplicate flags, or any text after the flags gives `undefined`.
   - All seven call sites now use the helper. A pattern rule is added only when 
the helper returns a `RegExp`. If a stored rule is not a valid regex literal, 
the field gets no pattern rule. Before this change, the same value either threw 
during render or was run as code.
   - Valid rules behave as before. The validation message still shows the 
stored rule text.
   
   ## How I tested it
   
   - Added `src/utils/regExpRule.test.js` (25 cases). It covers the two rule 
formats in ShenYu's `schema.sql`, flags, escaped and character-class slashes, 
invalid flags (`/abc/x`, `/abc/gg`), values that are not regex literals 
(`^\d+$`, `abc`, `//`, `/(/`, non-strings), and payloads such as 
`(()=>{globalThis.pwned=1})()`, `/x/,globalThis.pwned=1` and 
`/x/.constructor.constructor('globalThis.pwned=1')()`. Each payload returns 
`undefined` and leaves `global.pwned` unset.
   - I also ran a throwaway check that I did not commit. For 10 valid literals, 
the parser's `source` and `flags` matched what `eval` returned. The same check 
confirmed that `eval` really does run two of the payloads above.
   - `npx jest --runInBand`: 53 suites, 273 tests passed.
   - `eslint` and `prettier --check` pass on the changed files.
   
   ## Checklist
   
   - [x] Unit tests added for the new helper
   - [x] `npm run test:unit` passes locally
   - [x] ESLint / Prettier clean on changed files
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to