From 2ede34659b688089ed549ea24416f7610be0a698 Mon Sep 17 00:00:00 2001 From: John Chilton Date: Mon, 28 Aug 2017 16:28:27 -0400 Subject: [PATCH] Fix bad merge of security patch from 17.05 into dev. --- lib/galaxy/datatypes/data.py | 22 +++------------------- 1 file changed, 3 insertions(+), 19 deletions(-) diff --git a/lib/galaxy/datatypes/data.py b/lib/galaxy/datatypes/data.py index 9b20f43a03a..e8aa5c6b13b 100644 --- a/lib/galaxy/datatypes/data.py +++ b/lib/galaxy/datatypes/data.py @@ -372,7 +372,7 @@ class Data(object): tmp_file_name = tmp_fh.name dir_items = sorted(os.listdir(file_path)) base_path, item_name = os.path.split(file_path) - tmp_fh.write('

Directory %s contents: %d items

\n' % (item_name, len(dir_items))) + tmp_fh.write('

Directory %s contents: %d items

\n' % (escape(item_name), len(dir_items))) tmp_fh.write('

\n') for index, fname in enumerate(dir_items): if index % 2 == 0: @@ -386,10 +386,10 @@ class Data(object): # href = url_for(controller='dataset', action='display', # dataset_id=trans.security.encode_id(data.dataset.id), # preview=preview, filename=fname, to_ext=to_ext) - tmp_fh.write('\n' % (bgcolor, fname)) + tmp_fh.write('\n' % (bgcolor, escape(fname))) tmp_fh.write('
%s
%s
\n') tmp_fh.close() - return open(tmp_file_name) + return self._yield_user_file_content(trans, data, file_path) mime = mimetypes.guess_type(file_path)[0] if not mime: try: @@ -443,22 +443,6 @@ class Data(object): return open(filename) - def _yield_user_file_content(self, trans, from_dataset, filename): - """This method is responsible for sanitizing the HTML if needed.""" - if trans.app.config.sanitize_all_html and trans.response.get_content_type() == "text/html": - # Sanitize anytime we respond with plain text/html content. - # Check to see if this dataset's parent job is whitelisted - # We cannot currently trust imported datasets for rendering. - if not from_dataset.creating_job.imported and from_dataset.creating_job.tool_id in trans.app.config.sanitize_whitelist: - return open(filename) - - # This is returning to the browser, it needs to be encoded. - # TODO Ideally this happens a layer higher, but this is a bad - # issue affecting many tools - return sanitize_html(open(filename).read()).encode('utf-8') - - return open(filename) - def _download_filename(self, dataset, to_ext, hdca=None, element_identifier=None): def escape(raw_identifier): return ''.join(c in FILENAME_VALID_CHARS and c or '_' for c in raw_identifier)[0:150]