Properly sanitize everything in the XML we send to the XMPP server

in this order:
- Make sure it is utf-8 encoded
- Remove all chars that are invalid in XML
- Escape all XML special chars (&'"<>)
This commit is contained in:
Florent Le Coz
2015-02-26 04:58:07 +01:00
parent 53e6b1da69
commit 6a2240f593
2 changed files with 12 additions and 4 deletions
+11 -4
View File
@@ -218,13 +218,12 @@ std::string XmlNode::to_string() const
std::string res("<"); std::string res("<");
res += this->name; res += this->name;
for (const auto& it: this->attributes) for (const auto& it: this->attributes)
res += " " + utils::remove_invalid_xml_chars(it.first) + "='" + res += " " + it.first + "='" + sanitize(it.second) + "'";
utils::remove_invalid_xml_chars(it.second) + "'";
if (this->closed && !this->has_children() && this->inner.empty()) if (this->closed && !this->has_children() && this->inner.empty())
res += "/>"; res += "/>";
else else
{ {
res += ">" + utils::remove_invalid_xml_chars(this->inner); res += ">" + sanitize(this->inner);
for (const auto& child: this->children) for (const auto& child: this->children)
res += child->to_string(); res += child->to_string();
if (this->closed) if (this->closed)
@@ -232,7 +231,7 @@ std::string XmlNode::to_string() const
res += "</" + this->get_name() + ">"; res += "</" + this->get_name() + ">";
} }
} }
res += utils::remove_invalid_xml_chars(this->tail); res += sanitize(this->tail);
return res; return res;
} }
@@ -265,3 +264,11 @@ std::string& XmlNode::operator[](const std::string& name)
{ {
return this->attributes[name]; return this->attributes[name];
} }
std::string sanitize(const std::string& data)
{
if (utils::is_valid_utf8(data.data()))
return xml_escape(utils::remove_invalid_xml_chars(data));
else
return xml_escape(utils::remove_invalid_xml_chars(utils::convert_to_utf8(data, "ISO-8859-1")));
}
+1
View File
@@ -7,6 +7,7 @@
std::string xml_escape(const std::string& data); std::string xml_escape(const std::string& data);
std::string xml_unescape(const std::string& data); std::string xml_unescape(const std::string& data);
std::string sanitize(const std::string& data);
/** /**
* Represent an XML node. It has * Represent an XML node. It has