selenium-webdriver
Version:
The official WebDriver JavaScript bindings from the Selenium project
1 lines • 40.5 kB
HTML
<meta charset="UTF-8"><meta name="viewport" content="width=device-width, initial-scale=1, minimum-scale=1, maximum-scale=1, user-scalable=no"><meta http-equiv="Content-Language" content="en"><meta http-equiv="X-UA-Compatible" content="IE=edge"><title>safestyle.js</title><link href="../../../../dossier.css" rel="stylesheet" type="text/css"><header><div><form><div><input type="search" placeholder="Search" tabindex="1"></div></form></div></header><main><article class="srcfile"><h1>lib/goog/html/safestyle.js</h1><div><table><tr><td><a id="l1"></a><a href="#l1">1</a><td>// Copyright 2014 The Closure Library Authors. All Rights Reserved.<tr><td><a id="l2"></a><a href="#l2">2</a><td>//<tr><td><a id="l3"></a><a href="#l3">3</a><td>// Licensed under the Apache License, Version 2.0 (the "License");<tr><td><a id="l4"></a><a href="#l4">4</a><td>// you may not use this file except in compliance with the License.<tr><td><a id="l5"></a><a href="#l5">5</a><td>// You may obtain a copy of the License at<tr><td><a id="l6"></a><a href="#l6">6</a><td>//<tr><td><a id="l7"></a><a href="#l7">7</a><td>// http://www.apache.org/licenses/LICENSE-2.0<tr><td><a id="l8"></a><a href="#l8">8</a><td>//<tr><td><a id="l9"></a><a href="#l9">9</a><td>// Unless required by applicable law or agreed to in writing, software<tr><td><a id="l10"></a><a href="#l10">10</a><td>// distributed under the License is distributed on an "AS-IS" BASIS,<tr><td><a id="l11"></a><a href="#l11">11</a><td>// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.<tr><td><a id="l12"></a><a href="#l12">12</a><td>// See the License for the specific language governing permissions and<tr><td><a id="l13"></a><a href="#l13">13</a><td>// limitations under the License.<tr><td><a id="l14"></a><a href="#l14">14</a><td><tr><td><a id="l15"></a><a href="#l15">15</a><td>/**<tr><td><a id="l16"></a><a href="#l16">16</a><td> * @fileoverview The SafeStyle type and its builders.<tr><td><a id="l17"></a><a href="#l17">17</a><td> *<tr><td><a id="l18"></a><a href="#l18">18</a><td> * TODO(user): Link to document stating type contract.<tr><td><a id="l19"></a><a href="#l19">19</a><td> */<tr><td><a id="l20"></a><a href="#l20">20</a><td><tr><td><a id="l21"></a><a href="#l21">21</a><td>goog.provide('goog.html.SafeStyle');<tr><td><a id="l22"></a><a href="#l22">22</a><td><tr><td><a id="l23"></a><a href="#l23">23</a><td>goog.require('goog.array');<tr><td><a id="l24"></a><a href="#l24">24</a><td>goog.require('goog.asserts');<tr><td><a id="l25"></a><a href="#l25">25</a><td>goog.require('goog.string');<tr><td><a id="l26"></a><a href="#l26">26</a><td>goog.require('goog.string.Const');<tr><td><a id="l27"></a><a href="#l27">27</a><td>goog.require('goog.string.TypedString');<tr><td><a id="l28"></a><a href="#l28">28</a><td><tr><td><a id="l29"></a><a href="#l29">29</a><td><tr><td><a id="l30"></a><a href="#l30">30</a><td><tr><td><a id="l31"></a><a href="#l31">31</a><td>/**<tr><td><a id="l32"></a><a href="#l32">32</a><td> * A string-like object which represents a sequence of CSS declarations<tr><td><a id="l33"></a><a href="#l33">33</a><td> * ({@code propertyName1: propertyvalue1; propertyName2: propertyValue2; ...})<tr><td><a id="l34"></a><a href="#l34">34</a><td> * and that carries the security type contract that its value, as a string,<tr><td><a id="l35"></a><a href="#l35">35</a><td> * will not cause untrusted script execution (XSS) when evaluated as CSS in a<tr><td><a id="l36"></a><a href="#l36">36</a><td> * browser.<tr><td><a id="l37"></a><a href="#l37">37</a><td> *<tr><td><a id="l38"></a><a href="#l38">38</a><td> * Instances of this type must be created via the factory methods<tr><td><a id="l39"></a><a href="#l39">39</a><td> * ({@code goog.html.SafeStyle.create} or<tr><td><a id="l40"></a><a href="#l40">40</a><td> * {@code goog.html.SafeStyle.fromConstant}) and not by invoking its<tr><td><a id="l41"></a><a href="#l41">41</a><td> * constructor. The constructor intentionally takes no parameters and the type<tr><td><a id="l42"></a><a href="#l42">42</a><td> * is immutable; hence only a default instance corresponding to the empty string<tr><td><a id="l43"></a><a href="#l43">43</a><td> * can be obtained via constructor invocation.<tr><td><a id="l44"></a><a href="#l44">44</a><td> *<tr><td><a id="l45"></a><a href="#l45">45</a><td> * A SafeStyle's string representation ({@link #getSafeStyleString()}) can<tr><td><a id="l46"></a><a href="#l46">46</a><td> * safely:<tr><td><a id="l47"></a><a href="#l47">47</a><td> * <ul><tr><td><a id="l48"></a><a href="#l48">48</a><td> * <li>Be interpolated as the entire content of a *quoted* HTML style<tr><td><a id="l49"></a><a href="#l49">49</a><td> * attribute, or before already existing properties. The SafeStyle string<tr><td><a id="l50"></a><a href="#l50">50</a><td> * *must be HTML-attribute-escaped* (where " and ' are escaped) before<tr><td><a id="l51"></a><a href="#l51">51</a><td> * interpolation.<tr><td><a id="l52"></a><a href="#l52">52</a><td> * <li>Be interpolated as the entire content of a {}-wrapped block within a<tr><td><a id="l53"></a><a href="#l53">53</a><td> * stylesheet, or before already existing properties. The SafeStyle string<tr><td><a id="l54"></a><a href="#l54">54</a><td> * should not be escaped before interpolation. SafeStyle's contract also<tr><td><a id="l55"></a><a href="#l55">55</a><td> * guarantees that the string will not be able to introduce new properties<tr><td><a id="l56"></a><a href="#l56">56</a><td> * or elide existing ones.<tr><td><a id="l57"></a><a href="#l57">57</a><td> * <li>Be assigned to the style property of a DOM node. The SafeStyle string<tr><td><a id="l58"></a><a href="#l58">58</a><td> * should not be escaped before being assigned to the property.<tr><td><a id="l59"></a><a href="#l59">59</a><td> * </ul><tr><td><a id="l60"></a><a href="#l60">60</a><td> *<tr><td><a id="l61"></a><a href="#l61">61</a><td> * A SafeStyle may never contain literal angle brackets. Otherwise, it could<tr><td><a id="l62"></a><a href="#l62">62</a><td> * be unsafe to place a SafeStyle into a &lt;style&gt; tag (where it can't<tr><td><a id="l63"></a><a href="#l63">63</a><td> * be HTML escaped). For example, if the SafeStyle containing<tr><td><a id="l64"></a><a href="#l64">64</a><td> * "{@code font: 'foo &lt;style/&gt;&lt;script&gt;evil&lt;/script&gt;'}" were<tr><td><a id="l65"></a><a href="#l65">65</a><td> * interpolated within a &lt;style&gt; tag, this would then break out of the<tr><td><a id="l66"></a><a href="#l66">66</a><td> * style context into HTML.<tr><td><a id="l67"></a><a href="#l67">67</a><td> *<tr><td><a id="l68"></a><a href="#l68">68</a><td> * A SafeStyle may contain literal single or double quotes, and as such the<tr><td><a id="l69"></a><a href="#l69">69</a><td> * entire style string must be escaped when used in a style attribute (if<tr><td><a id="l70"></a><a href="#l70">70</a><td> * this were not the case, the string could contain a matching quote that<tr><td><a id="l71"></a><a href="#l71">71</a><td> * would escape from the style attribute).<tr><td><a id="l72"></a><a href="#l72">72</a><td> *<tr><td><a id="l73"></a><a href="#l73">73</a><td> * Values of this type must be composable, i.e. for any two values<tr><td><a id="l74"></a><a href="#l74">74</a><td> * {@code style1} and {@code style2} of this type,<tr><td><a id="l75"></a><a href="#l75">75</a><td> * {@code goog.html.SafeStyle.unwrap(style1) +<tr><td><a id="l76"></a><a href="#l76">76</a><td> * goog.html.SafeStyle.unwrap(style2)} must itself be a value that satisfies<tr><td><a id="l77"></a><a href="#l77">77</a><td> * the SafeStyle type constraint. This requirement implies that for any value<tr><td><a id="l78"></a><a href="#l78">78</a><td> * {@code style} of this type, {@code goog.html.SafeStyle.unwrap(style)} must<tr><td><a id="l79"></a><a href="#l79">79</a><td> * not end in a "property value" or "property name" context. For example,<tr><td><a id="l80"></a><a href="#l80">80</a><td> * a value of {@code background:url("} or {@code font-} would not satisfy the<tr><td><a id="l81"></a><a href="#l81">81</a><td> * SafeStyle contract. This is because concatenating such strings with a<tr><td><a id="l82"></a><a href="#l82">82</a><td> * second value that itself does not contain unsafe CSS can result in an<tr><td><a id="l83"></a><a href="#l83">83</a><td> * overall string that does. For example, if {@code javascript:evil())"} is<tr><td><a id="l84"></a><a href="#l84">84</a><td> * appended to {@code background:url("}, the resulting string may result in<tr><td><a id="l85"></a><a href="#l85">85</a><td> * the execution of a malicious script.<tr><td><a id="l86"></a><a href="#l86">86</a><td> *<tr><td><a id="l87"></a><a href="#l87">87</a><td> * TODO(user): Consider whether we should implement UTF-8 interchange<tr><td><a id="l88"></a><a href="#l88">88</a><td> * validity checks and blacklisting of newlines (including Unicode ones) and<tr><td><a id="l89"></a><a href="#l89">89</a><td> * other whitespace characters (\t, \f). Document here if so and also update<tr><td><a id="l90"></a><a href="#l90">90</a><td> * SafeStyle.fromConstant().<tr><td><a id="l91"></a><a href="#l91">91</a><td> *<tr><td><a id="l92"></a><a href="#l92">92</a><td> * The following example values comply with this type's contract:<tr><td><a id="l93"></a><a href="#l93">93</a><td> * <ul><tr><td><a id="l94"></a><a href="#l94">94</a><td> * <li><pre>width: 1em;</pre><tr><td><a id="l95"></a><a href="#l95">95</a><td> * <li><pre>height:1em;</pre><tr><td><a id="l96"></a><a href="#l96">96</a><td> * <li><pre>width: 1em;height: 1em;</pre><tr><td><a id="l97"></a><a href="#l97">97</a><td> * <li><pre>background:url('http://url');</pre><tr><td><a id="l98"></a><a href="#l98">98</a><td> * </ul><tr><td><a id="l99"></a><a href="#l99">99</a><td> * In addition, the empty string is safe for use in a CSS attribute.<tr><td><a id="l100"></a><a href="#l100">100</a><td> *<tr><td><a id="l101"></a><a href="#l101">101</a><td> * The following example values do NOT comply with this type's contract:<tr><td><a id="l102"></a><a href="#l102">102</a><td> * <ul><tr><td><a id="l103"></a><a href="#l103">103</a><td> * <li><pre>background: red</pre> (missing a trailing semi-colon)<tr><td><a id="l104"></a><a href="#l104">104</a><td> * <li><pre>background:</pre> (missing a value and a trailing semi-colon)<tr><td><a id="l105"></a><a href="#l105">105</a><td> * <li><pre>1em</pre> (missing an attribute name, which provides context for<tr><td><a id="l106"></a><a href="#l106">106</a><td> * the value)<tr><td><a id="l107"></a><a href="#l107">107</a><td> * </ul><tr><td><a id="l108"></a><a href="#l108">108</a><td> *<tr><td><a id="l109"></a><a href="#l109">109</a><td> * @see goog.html.SafeStyle#create<tr><td><a id="l110"></a><a href="#l110">110</a><td> * @see goog.html.SafeStyle#fromConstant<tr><td><a id="l111"></a><a href="#l111">111</a><td> * @see http://www.w3.org/TR/css3-syntax/<tr><td><a id="l112"></a><a href="#l112">112</a><td> * @constructor<tr><td><a id="l113"></a><a href="#l113">113</a><td> * @final<tr><td><a id="l114"></a><a href="#l114">114</a><td> * @struct<tr><td><a id="l115"></a><a href="#l115">115</a><td> * @implements {goog.string.TypedString}<tr><td><a id="l116"></a><a href="#l116">116</a><td> */<tr><td><a id="l117"></a><a href="#l117">117</a><td>goog.html.SafeStyle = function() {<tr><td><a id="l118"></a><a href="#l118">118</a><td> /**<tr><td><a id="l119"></a><a href="#l119">119</a><td> * The contained value of this SafeStyle. The field has a purposely<tr><td><a id="l120"></a><a href="#l120">120</a><td> * ugly name to make (non-compiled) code that attempts to directly access this<tr><td><a id="l121"></a><a href="#l121">121</a><td> * field stand out.<tr><td><a id="l122"></a><a href="#l122">122</a><td> * @private {string}<tr><td><a id="l123"></a><a href="#l123">123</a><td> */<tr><td><a id="l124"></a><a href="#l124">124</a><td> this.privateDoNotAccessOrElseSafeStyleWrappedValue_ = '';<tr><td><a id="l125"></a><a href="#l125">125</a><td><tr><td><a id="l126"></a><a href="#l126">126</a><td> /**<tr><td><a id="l127"></a><a href="#l127">127</a><td> * A type marker used to implement additional run-time type checking.<tr><td><a id="l128"></a><a href="#l128">128</a><td> * @see goog.html.SafeStyle#unwrap<tr><td><a id="l129"></a><a href="#l129">129</a><td> * @const<tr><td><a id="l130"></a><a href="#l130">130</a><td> * @private<tr><td><a id="l131"></a><a href="#l131">131</a><td> */<tr><td><a id="l132"></a><a href="#l132">132</a><td> this.SAFE_STYLE_TYPE_MARKER_GOOG_HTML_SECURITY_PRIVATE_ =<tr><td><a id="l133"></a><a href="#l133">133</a><td> goog.html.SafeStyle.TYPE_MARKER_GOOG_HTML_SECURITY_PRIVATE_;<tr><td><a id="l134"></a><a href="#l134">134</a><td>};<tr><td><a id="l135"></a><a href="#l135">135</a><td><tr><td><a id="l136"></a><a href="#l136">136</a><td><tr><td><a id="l137"></a><a href="#l137">137</a><td>/**<tr><td><a id="l138"></a><a href="#l138">138</a><td> * @override<tr><td><a id="l139"></a><a href="#l139">139</a><td> * @const<tr><td><a id="l140"></a><a href="#l140">140</a><td> */<tr><td><a id="l141"></a><a href="#l141">141</a><td>goog.html.SafeStyle.prototype.implementsGoogStringTypedString = true;<tr><td><a id="l142"></a><a href="#l142">142</a><td><tr><td><a id="l143"></a><a href="#l143">143</a><td><tr><td><a id="l144"></a><a href="#l144">144</a><td>/**<tr><td><a id="l145"></a><a href="#l145">145</a><td> * Type marker for the SafeStyle type, used to implement additional<tr><td><a id="l146"></a><a href="#l146">146</a><td> * run-time type checking.<tr><td><a id="l147"></a><a href="#l147">147</a><td> * @const<tr><td><a id="l148"></a><a href="#l148">148</a><td> * @private<tr><td><a id="l149"></a><a href="#l149">149</a><td> */<tr><td><a id="l150"></a><a href="#l150">150</a><td>goog.html.SafeStyle.TYPE_MARKER_GOOG_HTML_SECURITY_PRIVATE_ = {};<tr><td><a id="l151"></a><a href="#l151">151</a><td><tr><td><a id="l152"></a><a href="#l152">152</a><td><tr><td><a id="l153"></a><a href="#l153">153</a><td>/**<tr><td><a id="l154"></a><a href="#l154">154</a><td> * Creates a SafeStyle object from a compile-time constant string.<tr><td><a id="l155"></a><a href="#l155">155</a><td> *<tr><td><a id="l156"></a><a href="#l156">156</a><td> * {@code style} should be in the format<tr><td><a id="l157"></a><a href="#l157">157</a><td> * {@code name: value; [name: value; ...]} and must not have any < or ><tr><td><a id="l158"></a><a href="#l158">158</a><td> * characters in it. This is so that SafeStyle's contract is preserved,<tr><td><a id="l159"></a><a href="#l159">159</a><td> * allowing the SafeStyle to correctly be interpreted as a sequence of CSS<tr><td><a id="l160"></a><a href="#l160">160</a><td> * declarations and without affecting the syntactic structure of any<tr><td><a id="l161"></a><a href="#l161">161</a><td> * surrounding CSS and HTML.<tr><td><a id="l162"></a><a href="#l162">162</a><td> *<tr><td><a id="l163"></a><a href="#l163">163</a><td> * This method performs basic sanity checks on the format of {@code style}<tr><td><a id="l164"></a><a href="#l164">164</a><td> * but does not constrain the format of {@code name} and {@code value}, except<tr><td><a id="l165"></a><a href="#l165">165</a><td> * for disallowing tag characters.<tr><td><a id="l166"></a><a href="#l166">166</a><td> *<tr><td><a id="l167"></a><a href="#l167">167</a><td> * @param {!goog.string.Const} style A compile-time-constant string from which<tr><td><a id="l168"></a><a href="#l168">168</a><td> * to create a SafeStyle.<tr><td><a id="l169"></a><a href="#l169">169</a><td> * @return {!goog.html.SafeStyle} A SafeStyle object initialized to<tr><td><a id="l170"></a><a href="#l170">170</a><td> * {@code style}.<tr><td><a id="l171"></a><a href="#l171">171</a><td> */<tr><td><a id="l172"></a><a href="#l172">172</a><td>goog.html.SafeStyle.fromConstant = function(style) {<tr><td><a id="l173"></a><a href="#l173">173</a><td> var styleString = goog.string.Const.unwrap(style);<tr><td><a id="l174"></a><a href="#l174">174</a><td> if (styleString.length === 0) {<tr><td><a id="l175"></a><a href="#l175">175</a><td> return goog.html.SafeStyle.EMPTY;<tr><td><a id="l176"></a><a href="#l176">176</a><td> }<tr><td><a id="l177"></a><a href="#l177">177</a><td> goog.html.SafeStyle.checkStyle_(styleString);<tr><td><a id="l178"></a><a href="#l178">178</a><td> goog.asserts.assert(goog.string.endsWith(styleString, ';'),<tr><td><a id="l179"></a><a href="#l179">179</a><td> 'Last character of style string is not \';\': ' + styleString);<tr><td><a id="l180"></a><a href="#l180">180</a><td> goog.asserts.assert(goog.string.contains(styleString, ':'),<tr><td><a id="l181"></a><a href="#l181">181</a><td> 'Style string must contain at least one \':\', to ' +<tr><td><a id="l182"></a><a href="#l182">182</a><td> 'specify a "name: value" pair: ' + styleString);<tr><td><a id="l183"></a><a href="#l183">183</a><td> return goog.html.SafeStyle.createSafeStyleSecurityPrivateDoNotAccessOrElse(<tr><td><a id="l184"></a><a href="#l184">184</a><td> styleString);<tr><td><a id="l185"></a><a href="#l185">185</a><td>};<tr><td><a id="l186"></a><a href="#l186">186</a><td><tr><td><a id="l187"></a><a href="#l187">187</a><td><tr><td><a id="l188"></a><a href="#l188">188</a><td>/**<tr><td><a id="l189"></a><a href="#l189">189</a><td> * Checks if the style definition is valid.<tr><td><a id="l190"></a><a href="#l190">190</a><td> * @param {string} style<tr><td><a id="l191"></a><a href="#l191">191</a><td> * @private<tr><td><a id="l192"></a><a href="#l192">192</a><td> */<tr><td><a id="l193"></a><a href="#l193">193</a><td>goog.html.SafeStyle.checkStyle_ = function(style) {<tr><td><a id="l194"></a><a href="#l194">194</a><td> goog.asserts.assert(!/[<>]/.test(style),<tr><td><a id="l195"></a><a href="#l195">195</a><td> 'Forbidden characters in style string: ' + style);<tr><td><a id="l196"></a><a href="#l196">196</a><td>};<tr><td><a id="l197"></a><a href="#l197">197</a><td><tr><td><a id="l198"></a><a href="#l198">198</a><td><tr><td><a id="l199"></a><a href="#l199">199</a><td>/**<tr><td><a id="l200"></a><a href="#l200">200</a><td> * Returns this SafeStyle's value as a string.<tr><td><a id="l201"></a><a href="#l201">201</a><td> *<tr><td><a id="l202"></a><a href="#l202">202</a><td> * IMPORTANT: In code where it is security relevant that an object's type is<tr><td><a id="l203"></a><a href="#l203">203</a><td> * indeed {@code SafeStyle}, use {@code goog.html.SafeStyle.unwrap} instead of<tr><td><a id="l204"></a><a href="#l204">204</a><td> * this method. If in doubt, assume that it's security relevant. In particular,<tr><td><a id="l205"></a><a href="#l205">205</a><td> * note that goog.html functions which return a goog.html type do not guarantee<tr><td><a id="l206"></a><a href="#l206">206</a><td> * the returned instance is of the right type. For example:<tr><td><a id="l207"></a><a href="#l207">207</a><td> *<tr><td><a id="l208"></a><a href="#l208">208</a><td> * <pre><tr><td><a id="l209"></a><a href="#l209">209</a><td> * var fakeSafeHtml = new String('fake');<tr><td><a id="l210"></a><a href="#l210">210</a><td> * fakeSafeHtml.__proto__ = goog.html.SafeHtml.prototype;<tr><td><a id="l211"></a><a href="#l211">211</a><td> * var newSafeHtml = goog.html.SafeHtml.htmlEscape(fakeSafeHtml);<tr><td><a id="l212"></a><a href="#l212">212</a><td> * // newSafeHtml is just an alias for fakeSafeHtml, it's passed through by<tr><td><a id="l213"></a><a href="#l213">213</a><td> * // goog.html.SafeHtml.htmlEscape() as fakeSafeHtml<tr><td><a id="l214"></a><a href="#l214">214</a><td> * // instanceof goog.html.SafeHtml.<tr><td><a id="l215"></a><a href="#l215">215</a><td> * </pre><tr><td><a id="l216"></a><a href="#l216">216</a><td> *<tr><td><a id="l217"></a><a href="#l217">217</a><td> * @see goog.html.SafeStyle#unwrap<tr><td><a id="l218"></a><a href="#l218">218</a><td> * @override<tr><td><a id="l219"></a><a href="#l219">219</a><td> */<tr><td><a id="l220"></a><a href="#l220">220</a><td>goog.html.SafeStyle.prototype.getTypedStringValue = function() {<tr><td><a id="l221"></a><a href="#l221">221</a><td> return this.privateDoNotAccessOrElseSafeStyleWrappedValue_;<tr><td><a id="l222"></a><a href="#l222">222</a><td>};<tr><td><a id="l223"></a><a href="#l223">223</a><td><tr><td><a id="l224"></a><a href="#l224">224</a><td><tr><td><a id="l225"></a><a href="#l225">225</a><td>if (goog.DEBUG) {<tr><td><a id="l226"></a><a href="#l226">226</a><td> /**<tr><td><a id="l227"></a><a href="#l227">227</a><td> * Returns a debug string-representation of this value.<tr><td><a id="l228"></a><a href="#l228">228</a><td> *<tr><td><a id="l229"></a><a href="#l229">229</a><td> * To obtain the actual string value wrapped in a SafeStyle, use<tr><td><a id="l230"></a><a href="#l230">230</a><td> * {@code goog.html.SafeStyle.unwrap}.<tr><td><a id="l231"></a><a href="#l231">231</a><td> *<tr><td><a id="l232"></a><a href="#l232">232</a><td> * @see goog.html.SafeStyle#unwrap<tr><td><a id="l233"></a><a href="#l233">233</a><td> * @override<tr><td><a id="l234"></a><a href="#l234">234</a><td> */<tr><td><a id="l235"></a><a href="#l235">235</a><td> goog.html.SafeStyle.prototype.toString = function() {<tr><td><a id="l236"></a><a href="#l236">236</a><td> return 'SafeStyle{' +<tr><td><a id="l237"></a><a href="#l237">237</a><td> this.privateDoNotAccessOrElseSafeStyleWrappedValue_ + '}';<tr><td><a id="l238"></a><a href="#l238">238</a><td> };<tr><td><a id="l239"></a><a href="#l239">239</a><td>}<tr><td><a id="l240"></a><a href="#l240">240</a><td><tr><td><a id="l241"></a><a href="#l241">241</a><td><tr><td><a id="l242"></a><a href="#l242">242</a><td>/**<tr><td><a id="l243"></a><a href="#l243">243</a><td> * Performs a runtime check that the provided object is indeed a<tr><td><a id="l244"></a><a href="#l244">244</a><td> * SafeStyle object, and returns its value.<tr><td><a id="l245"></a><a href="#l245">245</a><td> *<tr><td><a id="l246"></a><a href="#l246">246</a><td> * @param {!goog.html.SafeStyle} safeStyle The object to extract from.<tr><td><a id="l247"></a><a href="#l247">247</a><td> * @return {string} The safeStyle object's contained string, unless<tr><td><a id="l248"></a><a href="#l248">248</a><td> * the run-time type check fails. In that case, {@code unwrap} returns an<tr><td><a id="l249"></a><a href="#l249">249</a><td> * innocuous string, or, if assertions are enabled, throws<tr><td><a id="l250"></a><a href="#l250">250</a><td> * {@code goog.asserts.AssertionError}.<tr><td><a id="l251"></a><a href="#l251">251</a><td> */<tr><td><a id="l252"></a><a href="#l252">252</a><td>goog.html.SafeStyle.unwrap = function(safeStyle) {<tr><td><a id="l253"></a><a href="#l253">253</a><td> // Perform additional Run-time type-checking to ensure that<tr><td><a id="l254"></a><a href="#l254">254</a><td> // safeStyle is indeed an instance of the expected type. This<tr><td><a id="l255"></a><a href="#l255">255</a><td> // provides some additional protection against security bugs due to<tr><td><a id="l256"></a><a href="#l256">256</a><td> // application code that disables type checks.<tr><td><a id="l257"></a><a href="#l257">257</a><td> // Specifically, the following checks are performed:<tr><td><a id="l258"></a><a href="#l258">258</a><td> // 1. The object is an instance of the expected type.<tr><td><a id="l259"></a><a href="#l259">259</a><td> // 2. The object is not an instance of a subclass.<tr><td><a id="l260"></a><a href="#l260">260</a><td> // 3. The object carries a type marker for the expected type. "Faking" an<tr><td><a id="l261"></a><a href="#l261">261</a><td> // object requires a reference to the type marker, which has names intended<tr><td><a id="l262"></a><a href="#l262">262</a><td> // to stand out in code reviews.<tr><td><a id="l263"></a><a href="#l263">263</a><td> if (safeStyle instanceof goog.html.SafeStyle &&<tr><td><a id="l264"></a><a href="#l264">264</a><td> safeStyle.constructor === goog.html.SafeStyle &&<tr><td><a id="l265"></a><a href="#l265">265</a><td> safeStyle.SAFE_STYLE_TYPE_MARKER_GOOG_HTML_SECURITY_PRIVATE_ ===<tr><td><a id="l266"></a><a href="#l266">266</a><td> goog.html.SafeStyle.TYPE_MARKER_GOOG_HTML_SECURITY_PRIVATE_) {<tr><td><a id="l267"></a><a href="#l267">267</a><td> return safeStyle.privateDoNotAccessOrElseSafeStyleWrappedValue_;<tr><td><a id="l268"></a><a href="#l268">268</a><td> } else {<tr><td><a id="l269"></a><a href="#l269">269</a><td> goog.asserts.fail(<tr><td><a id="l270"></a><a href="#l270">270</a><td> 'expected object of type SafeStyle, got \'' + safeStyle + '\'');<tr><td><a id="l271"></a><a href="#l271">271</a><td> return 'type_error:SafeStyle';<tr><td><a id="l272"></a><a href="#l272">272</a><td> }<tr><td><a id="l273"></a><a href="#l273">273</a><td>};<tr><td><a id="l274"></a><a href="#l274">274</a><td><tr><td><a id="l275"></a><a href="#l275">275</a><td><tr><td><a id="l276"></a><a href="#l276">276</a><td>/**<tr><td><a id="l277"></a><a href="#l277">277</a><td> * Package-internal utility method to create SafeStyle instances.<tr><td><a id="l278"></a><a href="#l278">278</a><td> *<tr><td><a id="l279"></a><a href="#l279">279</a><td> * @param {string} style The string to initialize the SafeStyle object with.<tr><td><a id="l280"></a><a href="#l280">280</a><td> * @return {!goog.html.SafeStyle} The initialized SafeStyle object.<tr><td><a id="l281"></a><a href="#l281">281</a><td> * @package<tr><td><a id="l282"></a><a href="#l282">282</a><td> */<tr><td><a id="l283"></a><a href="#l283">283</a><td>goog.html.SafeStyle.createSafeStyleSecurityPrivateDoNotAccessOrElse =<tr><td><a id="l284"></a><a href="#l284">284</a><td> function(style) {<tr><td><a id="l285"></a><a href="#l285">285</a><td> return new goog.html.SafeStyle().initSecurityPrivateDoNotAccessOrElse_(style);<tr><td><a id="l286"></a><a href="#l286">286</a><td>};<tr><td><a id="l287"></a><a href="#l287">287</a><td><tr><td><a id="l288"></a><a href="#l288">288</a><td><tr><td><a id="l289"></a><a href="#l289">289</a><td>/**<tr><td><a id="l290"></a><a href="#l290">290</a><td> * Called from createSafeStyleSecurityPrivateDoNotAccessOrElse(). This<tr><td><a id="l291"></a><a href="#l291">291</a><td> * method exists only so that the compiler can dead code eliminate static<tr><td><a id="l292"></a><a href="#l292">292</a><td> * fields (like EMPTY) when they're not accessed.<tr><td><a id="l293"></a><a href="#l293">293</a><td> * @param {string} style<tr><td><a id="l294"></a><a href="#l294">294</a><td> * @return {!goog.html.SafeStyle}<tr><td><a id="l295"></a><a href="#l295">295</a><td> * @private<tr><td><a id="l296"></a><a href="#l296">296</a><td> */<tr><td><a id="l297"></a><a href="#l297">297</a><td>goog.html.SafeStyle.prototype.initSecurityPrivateDoNotAccessOrElse_ = function(<tr><td><a id="l298"></a><a href="#l298">298</a><td> style) {<tr><td><a id="l299"></a><a href="#l299">299</a><td> this.privateDoNotAccessOrElseSafeStyleWrappedValue_ = style;<tr><td><a id="l300"></a><a href="#l300">300</a><td> return this;<tr><td><a id="l301"></a><a href="#l301">301</a><td>};<tr><td><a id="l302"></a><a href="#l302">302</a><td><tr><td><a id="l303"></a><a href="#l303">303</a><td><tr><td><a id="l304"></a><a href="#l304">304</a><td>/**<tr><td><a id="l305"></a><a href="#l305">305</a><td> * A SafeStyle instance corresponding to the empty string.<tr><td><a id="l306"></a><a href="#l306">306</a><td> * @const {!goog.html.SafeStyle}<tr><td><a id="l307"></a><a href="#l307">307</a><td> */<tr><td><a id="l308"></a><a href="#l308">308</a><td>goog.html.SafeStyle.EMPTY =<tr><td><a id="l309"></a><a href="#l309">309</a><td> goog.html.SafeStyle.createSafeStyleSecurityPrivateDoNotAccessOrElse('');<tr><td><a id="l310"></a><a href="#l310">310</a><td><tr><td><a id="l311"></a><a href="#l311">311</a><td><tr><td><a id="l312"></a><a href="#l312">312</a><td>/**<tr><td><a id="l313"></a><a href="#l313">313</a><td> * The innocuous string generated by goog.html.SafeUrl.create when passed<tr><td><a id="l314"></a><a href="#l314">314</a><td> * an unsafe value.<tr><td><a id="l315"></a><a href="#l315">315</a><td> * @const {string}<tr><td><a id="l316"></a><a href="#l316">316</a><td> */<tr><td><a id="l317"></a><a href="#l317">317</a><td>goog.html.SafeStyle.INNOCUOUS_STRING = 'zClosurez';<tr><td><a id="l318"></a><a href="#l318">318</a><td><tr><td><a id="l319"></a><a href="#l319">319</a><td><tr><td><a id="l320"></a><a href="#l320">320</a><td>/**<tr><td><a id="l321"></a><a href="#l321">321</a><td> * Mapping of property names to their values.<tr><td><a id="l322"></a><a href="#l322">322</a><td> * @typedef {!Object<string, goog.string.Const|string>}<tr><td><a id="l323"></a><a href="#l323">323</a><td> */<tr><td><a id="l324"></a><a href="#l324">324</a><td>goog.html.SafeStyle.PropertyMap;<tr><td><a id="l325"></a><a href="#l325">325</a><td><tr><td><a id="l326"></a><a href="#l326">326</a><td><tr><td><a id="l327"></a><a href="#l327">327</a><td>/**<tr><td><a id="l328"></a><a href="#l328">328</a><td> * Creates a new SafeStyle object from the properties specified in the map.<tr><td><a id="l329"></a><a href="#l329">329</a><td> * @param {goog.html.SafeStyle.PropertyMap} map Mapping of property names to<tr><td><a id="l330"></a><a href="#l330">330</a><td> * their values, for example {'margin': '1px'}. Names must consist of<tr><td><a id="l331"></a><a href="#l331">331</a><td> * [-_a-zA-Z0-9]. Values might be strings consisting of<tr><td><a id="l332"></a><a href="#l332">332</a><td> * [-,.'"%_!# a-zA-Z0-9], where " and ' must be properly balanced.<tr><td><a id="l333"></a><a href="#l333">333</a><td> * Other values must be wrapped in goog.string.Const. Null value causes<tr><td><a id="l334"></a><a href="#l334">334</a><td> * skipping the property.<tr><td><a id="l335"></a><a href="#l335">335</a><td> * @return {!goog.html.SafeStyle}<tr><td><a id="l336"></a><a href="#l336">336</a><td> * @throws {Error} If invalid name is provided.<tr><td><a id="l337"></a><a href="#l337">337</a><td> * @throws {goog.asserts.AssertionError} If invalid value is provided. With<tr><td><a id="l338"></a><a href="#l338">338</a><td> * disabled assertions, invalid value is replaced by<tr><td><a id="l339"></a><a href="#l339">339</a><td> * goog.html.SafeStyle.INNOCUOUS_STRING.<tr><td><a id="l340"></a><a href="#l340">340</a><td> */<tr><td><a id="l341"></a><a href="#l341">341</a><td>goog.html.SafeStyle.create = function(map) {<tr><td><a id="l342"></a><a href="#l342">342</a><td> var style = '';<tr><td><a id="l343"></a><a href="#l343">343</a><td> for (var name in map) {<tr><td><a id="l344"></a><a href="#l344">344</a><td> if (!/^[-_a-zA-Z0-9]+$/.test(name)) {<tr><td><a id="l345"></a><a href="#l345">345</a><td> throw Error('Name allows only [-_a-zA-Z0-9], got: ' + name);<tr><td><a id="l346"></a><a href="#l346">346</a><td> }<tr><td><a id="l347"></a><a href="#l347">347</a><td> var value = map[name];<tr><td><a id="l348"></a><a href="#l348">348</a><td> if (value == null) {<tr><td><a id="l349"></a><a href="#l349">349</a><td> continue;<tr><td><a id="l350"></a><a href="#l350">350</a><td> }<tr><td><a id="l351"></a><a href="#l351">351</a><td> if (value instanceof goog.string.Const) {<tr><td><a id="l352"></a><a href="#l352">352</a><td> value = goog.string.Const.unwrap(value);<tr><td><a id="l353"></a><a href="#l353">353</a><td> // These characters can be used to change context and we don't want that<tr><td><a id="l354"></a><a href="#l354">354</a><td> // even with const values.<tr><td><a id="l355"></a><a href="#l355">355</a><td> goog.asserts.assert(!/[{;}]/.test(value), 'Value does not allow [{;}].');<tr><td><a id="l356"></a><a href="#l356">356</a><td> } else if (!goog.html.SafeStyle.VALUE_RE_.test(value)) {<tr><td><a id="l357"></a><a href="#l357">357</a><td> goog.asserts.fail(<tr><td><a id="l358"></a><a href="#l358">358</a><td> 'String value allows only [-,."\'%_!# a-zA-Z0-9], got: ' + value);<tr><td><a id="l359"></a><a href="#l359">359</a><td> value = goog.html.SafeStyle.INNOCUOUS_STRING;<tr><td><a id="l360"></a><a href="#l360">360</a><td> } else if (!goog.html.SafeStyle.hasBalancedQuotes_(value)) {<tr><td><a id="l361"></a><a href="#l361">361</a><td> goog.asserts.fail('String value requires balanced quotes, got: ' + value);<tr><td><a id="l362"></a><a href="#l362">362</a><td> value = goog.html.SafeStyle.INNOCUOUS_STRING;<tr><td><a id="l363"></a><a href="#l363">363</a><td> }<tr><td><a id="l364"></a><a href="#l364">364</a><td> style += name + ':' + value + ';';<tr><td><a id="l365"></a><a href="#l365">365</a><td> }<tr><td><a id="l366"></a><a href="#l366">366</a><td> if (!style) {<tr><td><a id="l367"></a><a href="#l367">367</a><td> return goog.html.SafeStyle.EMPTY;<tr><td><a id="l368"></a><a href="#l368">368</a><td> }<tr><td><a id="l369"></a><a href="#l369">369</a><td> goog.html.SafeStyle.checkStyle_(style);<tr><td><a id="l370"></a><a href="#l370">370</a><td> return goog.html.SafeStyle.createSafeStyleSecurityPrivateDoNotAccessOrElse(<tr><td><a id="l371"></a><a href="#l371">371</a><td> style);<tr><td><a id="l372"></a><a href="#l372">372</a><td>};<tr><td><a id="l373"></a><a href="#l373">373</a><td><tr><td><a id="l374"></a><a href="#l374">374</a><td><tr><td><a id="l375"></a><a href="#l375">375</a><td>/**<tr><td><a id="l376"></a><a href="#l376">376</a><td> * Checks that quotes (" and ') are properly balanced inside a string. Assumes<tr><td><a id="l377"></a><a href="#l377">377</a><td> * that neither escape (\) nor any other character that could result in<tr><td><a id="l378"></a><a href="#l378">378</a><td> * breaking out of a string parsing context are allowed;<tr><td><a id="l379"></a><a href="#l379">379</a><td> * see http://www.w3.org/TR/css3-syntax/#string-token-diagram.<tr><td><a id="l380"></a><a href="#l380">380</a><td> * @param {string} value Untrusted CSS property value.<tr><td><a id="l381"></a><a href="#l381">381</a><td> * @return {boolean} True if property value is safe with respect to quote<tr><td><a id="l382"></a><a href="#l382">382</a><td> * balancedness.<tr><td><a id="l383"></a><a href="#l383">383</a><td> * @private<tr><td><a id="l384"></a><a href="#l384">384</a><td> */<tr><td><a id="l385"></a><a href="#l385">385</a><td>goog.html.SafeStyle.hasBalancedQuotes_ = function(value) {<tr><td><a id="l386"></a><a href="#l386">386</a><td> var outsideSingle = true;<tr><td><a id="l387"></a><a href="#l387">387</a><td> var outsideDouble = true;<tr><td><a id="l388"></a><a href="#l388">388</a><td> for (var i = 0; i < value.length; i++) {<tr><td><a id="l389"></a><a href="#l389">389</a><td> var c = value.charAt(i);<tr><td><a id="l390"></a><a href="#l390">390</a><td> if (c == "'" && outsideDouble) {<tr><td><a id="l391"></a><a href="#l391">391</a><td> outsideSingle = !outsideSingle;<tr><td><a id="l392"></a><a href="#l392">392</a><td> } else if (c == '"' && outsideSingle) {<tr><td><a id="l393"></a><a href="#l393">393</a><td> outsideDouble = !outsideDouble;<tr><td><a id="l394"></a><a href="#l394">394</a><td> }<tr><td><a id="l395"></a><a href="#l395">395</a><td> }<tr><td><a id="l396"></a><a href="#l396">396</a><td> return outsideSingle && outsideDouble;<tr><td><a id="l397"></a><a href="#l397">397</a><td>};<tr><td><a id="l398"></a><a href="#l398">398</a><td><tr><td><a id="l399"></a><a href="#l399">399</a><td><tr><td><a id="l400"></a><a href="#l400">400</a><td>// Keep in sync with the error string in create().<tr><td><a id="l401"></a><a href="#l401">401</a><td>/**<tr><td><a id="l402"></a><a href="#l402">402</a><td> * Regular expression for safe values.<tr><td><a id="l403"></a><a href="#l403">403</a><td> *<tr><td><a id="l404"></a><a href="#l404">404</a><td> * Quotes (" and ') are allowed, but a check must be done elsewhere to ensure<tr><td><a id="l405"></a><a href="#l405">405</a><td> * they're balanced.<tr><td><a id="l406"></a><a href="#l406">406</a><td> *<tr><td><a id="l407"></a><a href="#l407">407</a><td> * ',' allows multiple values to be assigned to the same property<tr><td><a id="l408"></a><a href="#l408">408</a><td> * (e.g. background-attachment or font-family) and hence could allow<tr><td><a id="l409"></a><a href="#l409">409</a><td> * multiple values to get injected, but that should pose no risk of XSS.<tr><td><a id="l410"></a><a href="#l410">410</a><td> * @const {!RegExp}<tr><td><a id="l411"></a><a href="#l411">411</a><td> * @private<tr><td><a id="l412"></a><a href="#l412">412</a><td> */<tr><td><a id="l413"></a><a href="#l413">413</a><td>goog.html.SafeStyle.VALUE_RE_ = /^[-,."'%_!# a-zA-Z0-9]+$/;<tr><td><a id="l414"></a><a href="#l414">414</a><td><tr><td><a id="l415"></a><a href="#l415">415</a><td><tr><td><a id="l416"></a><a href="#l416">416</a><td>/**<tr><td><a id="l417"></a><a href="#l417">417</a><td> * Creates a new SafeStyle object by concatenating the values.<tr><td><a id="l418"></a><a href="#l418">418</a><td> * @param {...(!goog.html.SafeStyle|!Array<!goog.html.SafeStyle>)} var_args<tr><td><a id="l419"></a><a href="#l419">419</a><td> * SafeStyles to concatenate.<tr><td><a id="l420"></a><a href="#l420">420</a><td> * @return {!goog.html.SafeStyle}<tr><td><a id="l421"></a><a href="#l421">421</a><td> */<tr><td><a id="l422"></a><a href="#l422">422</a><td>goog.html.SafeStyle.concat = function(var_args) {<tr><td><a id="l423"></a><a href="#l423">423</a><td> var style = '';<tr><td><a id="l424"></a><a href="#l424">424</a><td><tr><td><a id="l425"></a><a href="#l425">425</a><td> /**<tr><td><a id="l426"></a><a href="#l426">426</a><td> * @param {!goog.html.SafeStyle|!Array<!goog.html.SafeStyle>} argument<tr><td><a id="l427"></a><a href="#l427">427</a><td> */<tr><td><a id="l428"></a><a href="#l428">428</a><td> var addArgument = function(argument) {<tr><td><a id="l429"></a><a href="#l429">429</a><td> if (goog.isArray(argument)) {<tr><td><a id="l430"></a><a href="#l430">430</a><td> goog.array.forEach(argument, addArgument);<tr><td><a id="l431"></a><a href="#l431">431</a><td> } else {<tr><td><a id="l432"></a><a href="#l432">432</a><td> style += goog.html.SafeStyle.unwrap(argument);<tr><td><a id="l433"></a><a href="#l433">433</a><td> }<tr><td><a id="l434"></a><a href="#l434">434</a><td> };<tr><td><a id="l435"></a><a href="#l435">435</a><td><tr><td><a id="l436"></a><a href="#l436">436</a><td> goog.array.forEach(arguments, addArgument);<tr><td><a id="l437"></a><a href="#l437">437</a><td> if (!style) {<tr><td><a id="l438"></a><a href="#l438">438</a><td> return goog.html.SafeStyle.EMPTY;<tr><td><a id="l439"></a><a href="#l439">439</a><td> }<tr><td><a id="l440"></a><a href="#l440">440</a><td> return goog.html.SafeStyle.createSafeStyleSecurityPrivateDoNotAccessOrElse(<tr><td><a id="l441"></a><a href="#l441">441</a><td> style);<tr><td><a id="l442"></a><a href="#l442">442</a><td>};</table></div></article><nav><h3><a href="../../../../index.html" tabindex="2">Overview</a></h3><div><input type="checkbox" id="nav-modules" checked/><label for="nav-modules"><h3><span class="selectable" tabindex="2">Modules</span></h3></label><div id="nav-modules-view"></div></div><div><input type="checkbox" id="nav-types" checked/><label for="nav-types"><h3><span class="selectable" tabindex="2">Types</span></h3></label><div id="nav-types-view"></div></div><h3><a href="../../../../Changes.html" tabindex="2">Changes</a></h3></nav></main><footer><div><a href="https://github.com/jleyba/js-dossier">Generated by dossier</a></div></footer><script src="../../../../types.js"></script><script src="../../../../dossier.js"></script>