mirror of
https://github.com/galaxyproject/galaxy.git
synced 2026-09-24 16:30:27 +08:00
Fix bad merge of security patch from 17.05 into dev.
This commit is contained in:
@@ -372,7 +372,7 @@ class Data(object):
|
||||
tmp_file_name = tmp_fh.name
|
||||
dir_items = sorted(os.listdir(file_path))
|
||||
base_path, item_name = os.path.split(file_path)
|
||||
tmp_fh.write('<html><head><h3>Directory %s contents: %d items</h3></head>\n' % (item_name, len(dir_items)))
|
||||
tmp_fh.write('<html><head><h3>Directory %s contents: %d items</h3></head>\n' % (escape(item_name), len(dir_items)))
|
||||
tmp_fh.write('<body><p/><table cellpadding="2">\n')
|
||||
for index, fname in enumerate(dir_items):
|
||||
if index % 2 == 0:
|
||||
@@ -386,10 +386,10 @@ class Data(object):
|
||||
# href = url_for(controller='dataset', action='display',
|
||||
# dataset_id=trans.security.encode_id(data.dataset.id),
|
||||
# preview=preview, filename=fname, to_ext=to_ext)
|
||||
tmp_fh.write('<tr bgcolor="%s"><td>%s</td></tr>\n' % (bgcolor, fname))
|
||||
tmp_fh.write('<tr bgcolor="%s"><td>%s</td></tr>\n' % (bgcolor, escape(fname)))
|
||||
tmp_fh.write('</table></body></html>\n')
|
||||
tmp_fh.close()
|
||||
return open(tmp_file_name)
|
||||
return self._yield_user_file_content(trans, data, file_path)
|
||||
mime = mimetypes.guess_type(file_path)[0]
|
||||
if not mime:
|
||||
try:
|
||||
@@ -443,22 +443,6 @@ class Data(object):
|
||||
|
||||
return open(filename)
|
||||
|
||||
def _yield_user_file_content(self, trans, from_dataset, filename):
|
||||
"""This method is responsible for sanitizing the HTML if needed."""
|
||||
if trans.app.config.sanitize_all_html and trans.response.get_content_type() == "text/html":
|
||||
# Sanitize anytime we respond with plain text/html content.
|
||||
# Check to see if this dataset's parent job is whitelisted
|
||||
# We cannot currently trust imported datasets for rendering.
|
||||
if not from_dataset.creating_job.imported and from_dataset.creating_job.tool_id in trans.app.config.sanitize_whitelist:
|
||||
return open(filename)
|
||||
|
||||
# This is returning to the browser, it needs to be encoded.
|
||||
# TODO Ideally this happens a layer higher, but this is a bad
|
||||
# issue affecting many tools
|
||||
return sanitize_html(open(filename).read()).encode('utf-8')
|
||||
|
||||
return open(filename)
|
||||
|
||||
def _download_filename(self, dataset, to_ext, hdca=None, element_identifier=None):
|
||||
def escape(raw_identifier):
|
||||
return ''.join(c in FILENAME_VALID_CHARS and c or '_' for c in raw_identifier)[0:150]
|
||||
|
||||
Reference in New Issue
Block a user