vim syntax html creation is now cached (and should be secure)

master
Stefan Krulj 15 years ago
parent 14f732d8ec
commit 04eae687b0
  1. 34
      pylog_action_impl.py

@ -1,5 +1,5 @@
import os, os.path, sys import os, os.path, stat, sys
import urllib import urllib, hashlib
from datetime import datetime from datetime import datetime
import pylog_config as cfg import pylog_config as cfg
import subprocess,tempfile import subprocess,tempfile
@ -41,8 +41,9 @@ def disp_txt(path):
class BodyParser(HTMLParser): class BodyParser(HTMLParser):
body=False body=False
src='' src=''
blacklist = ['script']
def handle_starttag(self, tag, attrs): def handle_starttag(self, tag, attrs):
if self.body: if self.body and not(tag in self.blacklist):
self.src+='<'+tag self.src+='<'+tag
for attr in attrs: for attr in attrs:
self.src+=' '+attr[0]+'="'+attr[1]+'"' self.src+=' '+attr[0]+'="'+attr[1]+'"'
@ -52,7 +53,7 @@ class BodyParser(HTMLParser):
def handle_endtag(self, tag): def handle_endtag(self, tag):
if tag=='body': if tag=='body':
self.body=False self.body=False
if self.body: if self.body and not(tag in self.blacklist):
self.src+='</'+tag+'>' self.src+='</'+tag+'>'
def handle_data(self, data): def handle_data(self, data):
if self.body: if self.body:
@ -65,7 +66,26 @@ class BodyParser(HTMLParser):
def get_source_html(path): def get_source_html(path):
tmpfile=tempfile.mkstemp(prefix="pylog")[1] tmpdir = os.path.join(tempfile.gettempdir(),"pylog")
cache=False
if not os.path.exists(tmpdir):
os.mkdir(tmpdir,0700)
if os.path.exists(tmpdir):
s=os.stat(tmpdir)
if s.st_mode & stat.S_IRWXU == stat.S_IRWXU and \
s.st_mode & stat.S_IRWXG == 0 and \
s.st_mode & stat.S_IRWXO == 0 and \
os.path.isdir(tmpdir):
f=open(path,'r')
tmpfile=os.path.join(tmpdir,hashlib.sha256(f.read()).hexdigest())
f.close()
cache=True
if not cache:
tmpfile=tempfile.mkstemp(prefix="pylog",dir=tmpdir)[1]
if not cache or (cache and not os.path.exists(tmpfile)):
#we use a fork of vim to generate a nice syntax highlighted html file #we use a fork of vim to generate a nice syntax highlighted html file
#TODO this requires further testing #TODO this requires further testing
p=subprocess.Popen(["/usr/bin/vim",path,\ p=subprocess.Popen(["/usr/bin/vim",path,\
@ -79,6 +99,7 @@ def get_source_html(path):
"+q!",\ "+q!",\
"+q!"],\ "+q!"],\
stdout=subprocess.PIPE,stderr=subprocess.PIPE) stdout=subprocess.PIPE,stderr=subprocess.PIPE)
p.stdout.close() p.stdout.close()
p.stderr.close() p.stderr.close()
p.wait() #wait for child to terminate p.wait() #wait for child to terminate
@ -88,7 +109,8 @@ def get_source_html(path):
bp.feed(f.read()) bp.feed(f.read())
src = bp.src src = bp.src
f.close() f.close()
#delete tmp file #delete tmp file but only if it's not a secure cached file
if not cache:
os.remove(tmpfile) os.remove(tmpfile)
return src return src

Loading…
Cancel
Save