]> git.immae.eu Git - github/Chocobozzz/PeerTube.git/blobdiff - server/helpers/custom-validators/video-captions.ts
Don't inject untrusted input
[github/Chocobozzz/PeerTube.git] / server / helpers / custom-validators / video-captions.ts
index 9abbce04a110b3e7fae1b1fb5429ae6303b808df..59ba005fe3f4b8d8feb152b9e210b559c72feac5 100644 (file)
@@ -1,3 +1,6 @@
+import { UploadFilesForCheck } from 'express'
+import { readFile } from 'fs-extra'
+import { getFileSize } from '@shared/extra-utils'
 import { CONSTRAINTS_FIELDS, MIMETYPES, VIDEO_LANGUAGES } from '../../initializers/constants'
 import { exists, isFileValid } from './misc'
 
@@ -5,17 +8,33 @@ function isVideoCaptionLanguageValid (value: any) {
   return exists(value) && VIDEO_LANGUAGES[value] !== undefined
 }
 
-const videoCaptionTypes = Object.keys(MIMETYPES.VIDEO_CAPTIONS.MIMETYPE_EXT)
-                                .concat([ 'application/octet-stream' ]) // MacOS sends application/octet-stream ><
+const videoCaptionTypesRegex = Object.keys(MIMETYPES.VIDEO_CAPTIONS.MIMETYPE_EXT)
+                                .concat([ 'application/octet-stream' ]) // MacOS sends application/octet-stream
                                 .map(m => `(${m})`)
-const videoCaptionTypesRegex = videoCaptionTypes.join('|')
-function isVideoCaptionFile (files: { [ fieldname: string ]: Express.Multer.File[] } | Express.Multer.File[], field: string) {
-  return isFileValid(files, videoCaptionTypesRegex, field, CONSTRAINTS_FIELDS.VIDEO_CAPTIONS.CAPTION_FILE.FILE_SIZE.max)
+                                .join('|')
+function isVideoCaptionFile (files: UploadFilesForCheck, field: string) {
+  return isFileValid({
+    files,
+    mimeTypeRegex: videoCaptionTypesRegex,
+    field,
+    maxSize: CONSTRAINTS_FIELDS.VIDEO_CAPTIONS.CAPTION_FILE.FILE_SIZE.max
+  })
+}
+
+async function isVTTFileValid (filePath: string) {
+  const size = await getFileSize(filePath)
+
+  if (size > CONSTRAINTS_FIELDS.VIDEO_CAPTIONS.CAPTION_FILE.FILE_SIZE.max) return false
+
+  const content = await readFile(filePath, 'utf8')
+
+  return content?.startsWith('WEBVTT\n')
 }
 
 // ---------------------------------------------------------------------------
 
 export {
   isVideoCaptionFile,
+  isVTTFileValid,
   isVideoCaptionLanguageValid
 }