X-Git-Url: https://git.immae.eu/?a=blobdiff_plain;f=server%2Fhelpers%2Fcustom-validators%2Fplugins.ts;h=f2d4efb32a1c9b82d7677997811c5101b80f0bac;hb=795212f7acc690c88c86d0fab8772f6564d59cb8;hp=ff687dc3fdcc0fb9e12554930b934c8b07ab21cf;hpb=345da516fae80f24c90c2196e96393b489af2243;p=github%2FChocobozzz%2FPeerTube.git diff --git a/server/helpers/custom-validators/plugins.ts b/server/helpers/custom-validators/plugins.ts index ff687dc3f..f2d4efb32 100644 --- a/server/helpers/custom-validators/plugins.ts +++ b/server/helpers/custom-validators/plugins.ts @@ -1,5 +1,5 @@ import { exists, isArray, isSafePath } from './misc' -import * as validator from 'validator' +import validator from 'validator' import { PluginType } from '../../../shared/models/plugins/plugin.type' import { CONSTRAINTS_FIELDS } from '../../initializers/constants' import { PluginPackageJson } from '../../../shared/models/plugins/plugin-package-json.model' @@ -8,13 +8,21 @@ import { isUrlValid } from './activitypub/misc' const PLUGINS_CONSTRAINTS_FIELDS = CONSTRAINTS_FIELDS.PLUGINS function isPluginTypeValid (value: any) { - return exists(value) && validator.isInt('' + value) && PluginType[value] !== undefined + return exists(value) && + (value === PluginType.PLUGIN || value === PluginType.THEME) } function isPluginNameValid (value: string) { return exists(value) && validator.isLength(value, PLUGINS_CONSTRAINTS_FIELDS.NAME) && - validator.matches(value, /^[a-z\-]+$/) + validator.matches(value, /^[a-z-0-9]+$/) +} + +function isNpmPluginNameValid (value: string) { + return exists(value) && + validator.isLength(value, PLUGINS_CONSTRAINTS_FIELDS.NAME) && + validator.matches(value, /^[a-z\-._0-9]+$/) && + (value.startsWith('peertube-plugin-') || value.startsWith('peertube-theme-')) } function isPluginDescriptionValid (value: string) { @@ -33,7 +41,15 @@ function isPluginEngineValid (engine: any) { return exists(engine) && exists(engine.peertube) } -function isStaticDirectoriesValid (staticDirs: any) { +function isPluginHomepage (value: string) { + return exists(value) && (!value || isUrlValid(value)) +} + +function isPluginBugs (value: string) { + return exists(value) && (!value || isUrlValid(value)) +} + +function areStaticDirectoriesValid (staticDirs: any) { if (!exists(staticDirs) || typeof staticDirs !== 'object') return false for (const key of Object.keys(staticDirs)) { @@ -43,40 +59,106 @@ function isStaticDirectoriesValid (staticDirs: any) { return true } -function isClientScriptsValid (clientScripts: any[]) { +function areClientScriptsValid (clientScripts: any[]) { return isArray(clientScripts) && clientScripts.every(c => { return isSafePath(c.script) && isArray(c.scopes) }) } -function isCSSPathsValid (css: any[]) { +function areTranslationPathsValid (translations: any) { + if (!exists(translations) || typeof translations !== 'object') return false + + for (const key of Object.keys(translations)) { + if (!isSafePath(translations[key])) return false + } + + return true +} + +function areCSSPathsValid (css: any[]) { return isArray(css) && css.every(c => isSafePath(c)) } +function isThemeNameValid (name: string) { + return isPluginNameValid(name) +} + function isPackageJSONValid (packageJSON: PluginPackageJson, pluginType: PluginType) { - return isPluginNameValid(packageJSON.name) && - isPluginDescriptionValid(packageJSON.description) && - isPluginEngineValid(packageJSON.engine) && - isUrlValid(packageJSON.homepage) && - exists(packageJSON.author) && - isUrlValid(packageJSON.bugs) && - (pluginType === PluginType.THEME || isSafePath(packageJSON.library)) && - isStaticDirectoriesValid(packageJSON.staticDirs) && - isCSSPathsValid(packageJSON.css) && - isClientScriptsValid(packageJSON.clientScripts) + let result = true + const badFields: string[] = [] + + if (!isNpmPluginNameValid(packageJSON.name)) { + result = false + badFields.push('name') + } + + if (!isPluginDescriptionValid(packageJSON.description)) { + result = false + badFields.push('description') + } + + if (!isPluginEngineValid(packageJSON.engine)) { + result = false + badFields.push('engine') + } + + if (!isPluginHomepage(packageJSON.homepage)) { + result = false + badFields.push('homepage') + } + + if (!exists(packageJSON.author)) { + result = false + badFields.push('author') + } + + if (!isPluginBugs(packageJSON.bugs)) { + result = false + badFields.push('bugs') + } + + if (pluginType === PluginType.PLUGIN && !isSafePath(packageJSON.library)) { + result = false + badFields.push('library') + } + + if (!areStaticDirectoriesValid(packageJSON.staticDirs)) { + result = false + badFields.push('staticDirs') + } + + if (!areCSSPathsValid(packageJSON.css)) { + result = false + badFields.push('css') + } + + if (!areClientScriptsValid(packageJSON.clientScripts)) { + result = false + badFields.push('clientScripts') + } + + if (!areTranslationPathsValid(packageJSON.translations)) { + result = false + badFields.push('translations') + } + + return { result, badFields } } function isLibraryCodeValid (library: any) { - return typeof library.register === 'function' - && typeof library.unregister === 'function' + return typeof library.register === 'function' && + typeof library.unregister === 'function' } export { isPluginTypeValid, isPackageJSONValid, + isThemeNameValid, + isPluginHomepage, isPluginVersionValid, isPluginNameValid, isPluginDescriptionValid, - isLibraryCodeValid + isLibraryCodeValid, + isNpmPluginNameValid }