From 04eae687b0c1b1976bbe17ad34e32b44706924b2 Mon Sep 17 00:00:00 2001 From: Stefan Krulj Date: Tue, 13 Mar 2012 14:04:28 +0100 Subject: [PATCH] vim syntax html creation is now cached (and should be secure) --- pylog_action_impl.py | 70 +++++++++++++++++++++++++++++--------------- 1 file changed, 46 insertions(+), 24 deletions(-) diff --git a/pylog_action_impl.py b/pylog_action_impl.py index b0b0c3d..9e03021 100644 --- a/pylog_action_impl.py +++ b/pylog_action_impl.py @@ -1,5 +1,5 @@ -import os, os.path, sys -import urllib +import os, os.path, stat, sys +import urllib, hashlib from datetime import datetime import pylog_config as cfg import subprocess,tempfile @@ -41,18 +41,19 @@ def disp_txt(path): class BodyParser(HTMLParser): body=False src='' + blacklist = ['script'] def handle_starttag(self, tag, attrs): - if self.body: + if self.body and not(tag in self.blacklist): self.src+='<'+tag for attr in attrs: self.src+=' '+attr[0]+'="'+attr[1]+'"' self.src+='>' if tag=='body': self.body=True - def handle_endtag(self, tag): + def handle_endtag(self, tag): if tag=='body': self.body=False - if self.body: + if self.body and not(tag in self.blacklist): self.src+='' def handle_data(self, data): if self.body: @@ -65,31 +66,52 @@ class BodyParser(HTMLParser): def get_source_html(path): - tmpfile=tempfile.mkstemp(prefix="pylog")[1] - #we use a fork of vim to generate a nice syntax highlighted html file - #TODO this requires further testing - p=subprocess.Popen(["/usr/bin/vim",path,\ - "-nEs",\ - "+syn on",\ - "+let html_no_progress=1",\ - "+let html_use_css=1",\ - "+let html_number_lines=1",\ - "+run! syntax/2html.vim",\ - "+w! "+tmpfile,\ - "+q!",\ - "+q!"],\ - stdout=subprocess.PIPE,stderr=subprocess.PIPE) - p.stdout.close() - p.stderr.close() - p.wait() #wait for child to terminate + tmpdir = os.path.join(tempfile.gettempdir(),"pylog") + cache=False + if not os.path.exists(tmpdir): + os.mkdir(tmpdir,0700) + + if os.path.exists(tmpdir): + s=os.stat(tmpdir) + if s.st_mode & stat.S_IRWXU == stat.S_IRWXU and \ + s.st_mode & stat.S_IRWXG == 0 and \ + s.st_mode & stat.S_IRWXO == 0 and \ + os.path.isdir(tmpdir): + f=open(path,'r') + tmpfile=os.path.join(tmpdir,hashlib.sha256(f.read()).hexdigest()) + f.close() + cache=True + + if not cache: + tmpfile=tempfile.mkstemp(prefix="pylog",dir=tmpdir)[1] + if not cache or (cache and not os.path.exists(tmpfile)): + #we use a fork of vim to generate a nice syntax highlighted html file + #TODO this requires further testing + p=subprocess.Popen(["/usr/bin/vim",path,\ + "-nEs",\ + "+syn on",\ + "+let html_no_progress=1",\ + "+let html_use_css=1",\ + "+let html_number_lines=1",\ + "+run! syntax/2html.vim",\ + "+w! "+tmpfile,\ + "+q!",\ + "+q!"],\ + stdout=subprocess.PIPE,stderr=subprocess.PIPE) + + p.stdout.close() + p.stderr.close() + p.wait() #wait for child to terminate + f=open(tmpfile,"r") bp=BodyParser() bp.feed(f.read()) src = bp.src f.close() - #delete tmp file - os.remove(tmpfile) + #delete tmp file but only if it's not a secure cached file + if not cache: + os.remove(tmpfile) return src def disp_source(path):