diff options
Diffstat (limited to 'src/sisudoc/ocda/io_in')
| -rw-r--r-- | src/sisudoc/ocda/io_in/carried_names.d | 11 | ||||
| -rw-r--r-- | src/sisudoc/ocda/io_in/read_zip_pod.d | 6 |
2 files changed, 12 insertions, 5 deletions
diff --git a/src/sisudoc/ocda/io_in/carried_names.d b/src/sisudoc/ocda/io_in/carried_names.d index 84a4f3c..eaa233d 100644 --- a/src/sisudoc/ocda/io_in/carried_names.d +++ b/src/sisudoc/ocda/io_in/carried_names.d @@ -128,9 +128,14 @@ template spineCarriedNames() { enum size_t MAX_CARRIED_NAME_LENGTH = 255; /+ one path component +/ enum size_t MAX_CARRIED_PATH_LENGTH = 1024; /+ the whole path +/ enum size_t MAX_CARRIED_PATH_DEPTH = 10; /+ as read_zip_pod.d +/ - /+ ↓ allowed characters: a filename has no separator, a path has "/" +/ - static auto rgx_safe_carried_name = ctRegex!(`^[a-zA-Z0-9._ -]+$`); - static auto rgx_safe_carried_path = ctRegex!(`^[a-zA-Z0-9._/ -]+$`); + /+ ↓ allowed characters: a filename has no separator, a path has "/". + "~" is here because it is spine's own uid separator (InlineMarkup.uid_sep), + which joins a pod name to a document name where the two differ, as in + sisu-manual~sisu_markup.en.ssp. It cannot occur in either half, every + filesystem of interest takes it, and it is unreserved in rfc 3986. + +/ + static auto rgx_safe_carried_name = ctRegex!(`^[a-zA-Z0-9._ ~-]+$`); + static auto rgx_safe_carried_path = ctRegex!(`^[a-zA-Z0-9._/ ~-]+$`); /+ ↓ the checks both rules share, "" when the name is acceptable +/ private string _carriedNameCommon(string _name) { if (_name.length == 0) { diff --git a/src/sisudoc/ocda/io_in/read_zip_pod.d b/src/sisudoc/ocda/io_in/read_zip_pod.d index 18a957c..c96429b 100644 --- a/src/sisudoc/ocda/io_in/read_zip_pod.d +++ b/src/sisudoc/ocda/io_in/read_zip_pod.d @@ -75,8 +75,10 @@ template spineExtractZipPod() { alias MAX_ENTRY_COUNT = MAX_POD_ENTRY_COUNT; enum size_t MAX_PATH_DEPTH = 10; /+ max path components +/ - /+ allowed entry name pattern: alphanumeric, dots, dashes, underscores, forward slashes +/ - static auto rgx_safe_entry_name = ctRegex!(`^[a-zA-Z0-9._/ -]+$`); + /+ allowed entry name pattern: alphanumeric, dots, dashes, underscores, + forward slashes, and "~", spine's own uid separator (as carried_names.d) + +/ + static auto rgx_safe_entry_name = ctRegex!(`^[a-zA-Z0-9._/ ~-]+$`); struct ZipPodResult { string tmp_dir; /+ temp directory containing extracted pod +/ |
